The practice is the controller of patient data: it decides the purposes and means of the processing and answers to the patient and to the supervisory authority. Heltio is the processor — it acts on the practice's documented instructions and answers for the technical and organisational measures.
Heltio is a controller only in respect of its own data: visitors to heltio.pl, sales contacts, subscription accounts and internal security records.
How to do it
The practice's GDPR settings live at /settings/gdpr, in the navigation as GDPR & Privacy. Only the practice owner or administrator can get in — the other roles see "You need owner or admin permissions to access GDPR settings. Contact your clinic administrator."
The page has six sections:
- Compliance Overview — the number of pending and overdue requests, and the retention period that is set.
- Data subject requests — all six rights from Articles 15–22 with the statutory deadline. The Register a request button also lets you enter a request that arrived by e-mail, post, telephone or in person; the deadline runs from the date it arrived, not from the day it was entered.
- Deletion Requests — the older route from the patient portal, kept separately.
- Audit-log retention — the Audit-log retention (years) field, accepting values from 6 to 99.
- Data Controller Contact — the address patients are given in the information notice.
- Records of Processing Activities — the Download RoPA (JSON) button generates the Article 30 document.
When data leaves Heltio
Patient data leaves Heltio's infrastructure in three situations: to P1 (the Polish e-Health Centre — a separate public controller, a statutory obligation), to the communication-channel providers (e-mail, SMS), and to the AI providers.
That last route opens only after four independent conditions have been met:
- Heltio has the master switch on, on the server side.
- The practice has the AI features enabled.
- Someone with administrator permissions has accepted the document AI Sub-processors — Data Processing Agreement (the button unlocks only after the whole text has been scrolled through).
- The specific AI feature is enabled by its own switch.
Before the content reaches a provider, Heltio replaces names, PESEL numbers, addresses, phone numbers and the practice name with placeholders; the response is translated back only on our side. Two exceptions are stated outright in the disclosure document itself: images of handwritten notes go without redaction (text recognition needs the raw pixels), and a visit recording reaches the transcription provider unchanged — and only that one requires separate, documented patient consent.
The disclosure document lists every provider individually together with its region and retention period. You open it under Settings → AI Features → View disclosure.
What is missing
It is more honest to list this than to let you read between the lines:
- Automatic deletion of medical records after the retention period. The job that computes it runs in report-only mode and by default does not run at all. Details: Retention policy.
- An "access history" page for the patient. The column pointing at whose data was viewed is populated, but no patient-facing screen reads it yet.
- Final versions of the legal documents. The pages
/polityka-prywatnosci,/dpa,/regulaminand/podprocesorzycarry a Draft banner stating that the document is awaiting counsel's review.
Contact
The address of Heltio's data protection officer — iod@heltio.pl — is given in the privacy policy and in the site footer. The practice gives patients its own GDPR contact address, set in the Data Controller Contact section.
Related
- Processors and data processing agreements — the full provider list and the discrepancy concerning AI.
- Data subject rights — how a patient request travels through the app.
- Encryption and data residency — exactly what is encrypted.
- Roles and permissions — the access boundary inside the practice.