Skip to content
Audience: DPO / Compliance

GDPR at Heltio — who is responsible for what

The division of roles between the practice and Heltio, where the GDPR settings sit in the app, and what really leaves our infrastructure.

Last reviewed:

The practice is the controller of patient data: it decides the purposes and means of the processing and answers to the patient and to the supervisory authority. Heltio is the processor — it acts on the practice's documented instructions and answers for the technical and organisational measures.

Heltio is a controller only in respect of its own data: visitors to heltio.pl, sales contacts, subscription accounts and internal security records.

How to do it

The practice's GDPR settings live at /settings/gdpr, in the navigation as GDPR & Privacy. Only the practice owner or administrator can get in — the other roles see "You need owner or admin permissions to access GDPR settings. Contact your clinic administrator."

The page has six sections:

  • Compliance Overview — the number of pending and overdue requests, and the retention period that is set.
  • Data subject requests — all six rights from Articles 15–22 with the statutory deadline. The Register a request button also lets you enter a request that arrived by e-mail, post, telephone or in person; the deadline runs from the date it arrived, not from the day it was entered.
  • Deletion Requests — the older route from the patient portal, kept separately.
  • Audit-log retention — the Audit-log retention (years) field, accepting values from 6 to 99.
  • Data Controller Contact — the address patients are given in the information notice.
  • Records of Processing Activities — the Download RoPA (JSON) button generates the Article 30 document.

When data leaves Heltio

Patient data leaves Heltio's infrastructure in three situations: to P1 (the Polish e-Health Centre — a separate public controller, a statutory obligation), to the communication-channel providers (e-mail, SMS), and to the AI providers.

That last route opens only after four independent conditions have been met:

  1. Heltio has the master switch on, on the server side.
  2. The practice has the AI features enabled.
  3. Someone with administrator permissions has accepted the document AI Sub-processors — Data Processing Agreement (the button unlocks only after the whole text has been scrolled through).
  4. The specific AI feature is enabled by its own switch.

Before the content reaches a provider, Heltio replaces names, PESEL numbers, addresses, phone numbers and the practice name with placeholders; the response is translated back only on our side. Two exceptions are stated outright in the disclosure document itself: images of handwritten notes go without redaction (text recognition needs the raw pixels), and a visit recording reaches the transcription provider unchanged — and only that one requires separate, documented patient consent.

The disclosure document lists every provider individually together with its region and retention period. You open it under Settings → AI Features → View disclosure.

What is missing

It is more honest to list this than to let you read between the lines:

  • Automatic deletion of medical records after the retention period. The job that computes it runs in report-only mode and by default does not run at all. Details: Retention policy.
  • An "access history" page for the patient. The column pointing at whose data was viewed is populated, but no patient-facing screen reads it yet.
  • Final versions of the legal documents. The pages /polityka-prywatnosci, /dpa, /regulamin and /podprocesorzy carry a Draft banner stating that the document is awaiting counsel's review.

Contact

The address of Heltio's data protection officer — iod@heltio.pl — is given in the privacy policy and in the site footer. The practice gives patients its own GDPR contact address, set in the Data Controller Contact section.

Was this article helpful?