What data we store and where
Who controls your data, where it physically sits, how long it is kept, and how to ask for a copy. Without the legal jargon, with pointers to the source documents.
Heltio stores medical records, so the question "what do you know about me and where does it sit" is a fair one — and both the patient and the clinic entrusting us with their data ask it. This page answers it briefly and points at the documents that carry the full, binding version.
What we store
- Patient identifying data — first name, surname, PESEL, date of birth, contact and address details.
- Medical records — appointments, clinical notes, treatment plans, assessments and measurements, exercise programmes, visit summaries, attachments uploaded by the clinic, ICD-10, ICD-9 and ICF codes.
- Billing data — invoices, receipts, passes, payment history.
- Account data — the e-mail address and the sign-in identity. We do not store passwords; the authentication provider handles them.
- Consents and requests — a record of what the patient consented to and when, and the requests filed under the GDPR.
- The audit trail — who touched what, and when.
Where it sits
The whole data infrastructure sits inside the European Union. The database and the files are with a hosting provider in Frankfurt, the encryption keys in a key-management service in the same region, transactional e-mail and SMS with EU providers, payments with a Polish operator.
The most sensitive fields — the PESEL number, the bank account number and the body of the clinical note among them — are additionally encrypted at column level, with a separate key for each clinic. A leak of the database copy alone would not reveal their content.
The full, current list of the parties we entrust processing to, with their location and data category, is in the processing agreement. Changing that list requires notice to the clinic in advance and gives it a right to object.
For how long
The retention periods come from legislation, not from a Heltio decision:
- Medical records — 20 years from the last entry, with the exceptions provided for in the Patients' Rights Act (longer for children's records, shorter for some results and images).
- Invoices and billing data — 5 years from the end of the tax year.
- The audit trail — 5 years.
The clinic sets its own retention period in Settings → GDPR & Privacy, within a range of 6 to 99 years; the default is 20. Once the period has run, the data is deleted automatically unless a legal hold applies to it. Details and the legal basis: data retention.
How to ask for your data
A patient with portal access does it themselves: the menu under the avatar, Privacy & Consent, the Download My Data button. Heltio prepares a copy, and the download link is valid for a few minutes — you can come back for a fresh one at any time.
Without the portal, the request is filed directly with the clinic. The clinic gives its GDPR contact address in its own privacy policy; it sets it in Settings → GDPR & Privacy in the GDPR contact email field.
The clinic sees every request in one place, each with its statutory deadline. All the rights under Articles 15 to 22 GDPR are handled — access, rectification, erasure, restriction, portability and objection. The full description: data subject rights.
Related
- Processing agreement and sub-processors — the binding provider list.
- Encryption and data residency — exactly how we protect the data.
- Data subject rights — how to file a request and what to expect.
- How to report a breach — when something has gone wrong.