Privacy Policy

Last updated: May 31, 2026

This Privacy Policy describes how Remote Health OÜ (hereinafter "we", "Randevunu AI", or the "Company"), which operates the Randevunu AI service, collects, uses, and protects your personal data. By using our service, you agree to this policy.

1. Data Controller

Your data is controlled by Remote Health OÜ, established under Estonian law.

  • Legal name: Remote Health OÜ
  • Registration number: 16140230 (Eesti äriregister)
  • Address: Viru väljak 2, 10111 Tallinn, Estonia
  • Privacy contact: hello@remotehealth.eu

Turkish users can also exercise their rights under KVKK through this same contact.

2. Data We Collect

2.1. Information You Provide Directly

  • Account information: Full name, email address, profile URL (slug). If you sign in with Google, we receive your name and email from Google.
  • Profile information (for professionals): Professional title, bio, timezone, services offered, price, duration, working hours.
  • Booking information: Full name, email, optional phone, optional notes, booking date/time.
  • Chat content: Messages you write while booking through the AI assistant.

2.2. Information Collected Automatically

  • Technical data: IP address, browser type, device info, visit time. We use these for security, rate limiting, and basic analytics.
  • Cookies: Authentication cookies needed to keep your session alive. We do not use marketing or advertising cookies.

2.3. Google Calendar Integration (optional)

If professionals choose to connect Google Calendar:

  • To prevent double bookings, we read your busy time slots from Google Calendar. We do not store event titles or attendee lists.
  • We automatically add confirmed bookings as events to your calendar.
  • You can disconnect this integration any time from the Profile page. When disconnected, tokens stored at Google are deleted.

3. How We Use Data

  • To operate the service and manage bookings
  • To send booking confirmations, reminders, and cancellation emails (transactional emails — no consent required)
  • For the AI assistant to suggest the correct service and availability
  • Security (attack detection, rate limiting, abuse prevention)
  • To meet legal obligations
  • To improve the service (aggregate, anonymous metrics)

Marketing: We do not currently send marketing emails. If we want to in the future, we will ask for your explicit consent.

4. Legal Bases (GDPR)

For users in the EU, our legal bases for processing personal data are:

  • Contract: Providing the account, booking, and service (GDPR Art. 6(1)(b))
  • Legitimate interest: Security, fraud prevention, service improvement (GDPR Art. 6(1)(f))
  • Legal obligation: Tax, accounting, authority requests (GDPR Art. 6(1)(c))
  • Explicit consent: Google Calendar integration and optional marketing (GDPR Art. 6(1)(a))

5. Data Retention Period

  • Active account: Stored as long as your account remains active.
  • After account deletion: Minimum required period under legal obligations (tax records, etc.) — under Estonian law, financial records 7 years.
  • Chat messages: AI chat is not currently stored permanently; deleted when the session ends.
  • Rate limit logs: Automatically deleted after 24 hours.

6. Data Sharing (Sub-Processors)

To run the service, we use the following third-party service providers (sub-processors). All are contractually bound to comply with GDPR and equivalent standards:

  • Supabase (US): Database and authentication. Privacy policy
  • Vercel (US): Website hosting and CDN. Privacy policy
  • Anthropic (US): AI chat assistant (Claude). Chat content is processed in real time; Anthropic does not use user content for training. Privacy policy
  • Google (US): Sign in with Google and optional Google Calendar integration. Privacy policy
  • Resend (US): Transactional email delivery (booking confirmation, reminders). Privacy policy

Apart from these, we do not sell, rent, or share your data with third parties for marketing purposes.

7. International Data Transfers

All of the sub-processors above process data in the United States. For the EU, these transfers are safeguarded by Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework.

Turkish users must consent to international transfer of their data; by using the service, you give explicit consent for this transfer (KVKK Art. 9). You can withdraw this consent any time via email; however, we will not be able to provide the service in that case.

8. Data Security

  • All connections are encrypted with TLS (HTTPS).
  • Passwords are stored hashed (never in plain text).
  • Database access is restricted with Row Level Security (RLS).
  • OAuth tokens are stored encrypted.

Still, no transmission over the internet is 100% secure; we do not provide an absolute security guarantee.

9. Your GDPR Rights (EU Users)

  • Access: Find out what data we hold about you.
  • Rectification: Request correction of incorrect data.
  • Erasure ("right to be forgotten"): Request deletion of your account and data.
  • Restrict processing: Request to stop specific processing activities.
  • Data portability: Receive your data in machine-readable format.
  • Object: Object to processing based on legitimate interest.
  • Complaint: File a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

10. Your KVKK Rights (Turkish Users)

Under KVKK Art. 11 (Law No. 6698):

  • Learn whether your personal data is being processed
  • If processed, request information about it
  • Learn the purpose of processing and whether used appropriately
  • Know the third parties to whom data is transferred (in/out of country)
  • Request correction if processed incompletely or incorrectly
  • Request deletion or destruction
  • Request that corrections/deletions be reported to third parties
  • Object to results against you from automated systems
  • Demand compensation if you suffer damages due to unlawful processing

To exercise these rights, write to hello@remotehealth.eu. We respond within 30 days.

11. Cookies

We only use essential cookies: session and security. If you disable these, the service will not work. We do not use advertising or analytics cookies.

12. Children

Our service is not intended for children under 16, and we do not knowingly collect their personal data. If you have submitted a child under 16's data to us, contact us to have it deleted immediately.

13. Changes to This Policy

We may update this policy from time to time. We notify you of material changes by email or in the service. The "Last updated" date is always at the top of the page.

14. Contact

For any questions about this policy or your personal data: