WhatsApp contactViber contact
Instagram profileTikTok profileYouTube channel
Weekdays 09–20h · Sat 09–17h · Sun 10–17h Contact us
Medical Time LogoMedical Time Logo
HomeAbout usServicesPackagesPrice listBlogContact
Data protection

Privacy policy

How Medical Time collects, uses and protects your data — on the website, in the shop and in the mobile app.

Last updated: 29 August 2026

Contents

  1. 1. Who processes your data
  2. 2. What data we collect
  3. 3. Why we process it, and on what legal basis
  4. 4. Health data is held to a stricter standard
  5. 5. Cookies and traffic measurement
  6. 6. The mobile app
  7. 7. Who your data may be shared with
  8. 8. How long we keep data
  9. 9. How we protect it
  10. 10. Your rights
  11. 11. Deleting your account and data
  12. 12. Minors
  13. 13. Transfers outside Serbia
  14. 14. Changes to this policy
  15. 15. How to contact us

Medical Time is a private hospital. People entrust us not only with a name and a phone number, but with diagnoses, test results and information about their health — data the law classes as especially sensitive and protects more strictly than any other.

This policy is written to be read, not skipped. It sets out exactly what we collect, why, who it may be shared with, how long it stays with us, and what you can ask of us at any time.

It applies to the medicaltime.rs website, to the online shop and to the MedicalTime mobile app for Android and iPhone.

1. Who processes your data

The data controller is Medical Time, Krunska 9, Vračar, 11000 Belgrade, Serbia. This means we decide why and how your data is processed, and we are accountable for it.

For any question about data processing, and to exercise the rights described in this policy, you can reach us by phone on +381 62 399 888, by post at the address above, or through the form on the Contact page.

We deliberately do not publish an email address on the site — bots harvest it and turn it into spam. A message sent through the form reaches the same people just as quickly.

2. What data we collect

We do not collect everything from everyone. What we hold about you depends entirely on what you have done with us.

  • If you only read the site: technical data your browser sends to every website — IP address, device and browser type, language and the pages you opened. With your consent, also visit data through measurement tools.
  • If you write to us through the form: your name, the way you would like us to reply (a phone number or email address you enter yourself) and the content of your message.
  • If you subscribe to our news: your email address and the language you want to receive messages in.
  • If you open an account: first and last name, email address, phone number, password (never in readable form, only as an irreversible cryptographic hash) and account settings — language, theme and cookie choices.
  • If you are a patient: date of birth, gender, address, and a national ID number or passport number for foreign nationals — without these, medical records cannot be kept as the law requires.
  • A patient's health data: the reason for the visit, diagnoses, prescribed therapies and medicines, examinations and operations performed, results and documents you gave us or that we produced, and signed consent forms.
  • If you buy something: what was bought, the amount, the time and status of payment, and the details needed for the invoice.
  • If you use the mobile app: a device identifier used to deliver notifications, and the app version.

We never see or store your payment card details. You enter the card number on the bank's page, inside its own system; all we receive back is whether the payment succeeded.

3. Why we process it, and on what legal basis

Every processing operation must have a purpose and a legal basis. Ours has four:

  • Providing healthcare and keeping medical records — the basis is the law: a healthcare institution is required to keep records on every patient and to retain them for a prescribed period.
  • Doing what you asked for — booking an appointment, a purchase in the shop, issuing an invoice, answering your message.
  • Your consent — for non-essential cookies, for news by email and for notifications on your device. Consent is as easy to withdraw as it is to give.
  • Our legitimate interest — keeping the system secure, preventing account abuse and automated form spam, and being able to show who changed a record and when.

4. Health data is held to a stricter standard

Under the Personal Data Protection Act, health data is especially sensitive and subject to special rules. In practice, this is what that means here.

A patient record is not visible to everyone who works at the hospital. Access is tied to a role and to specific permissions, and every change leaves a trace of who made it and when.

  • We do not use health data for advertising, ours or anyone else's.
  • We do not sell it and do not pass it to third parties for their own benefit.
  • We do not use it for automated decision-making about you, or for profiling.
  • We forward it to another healthcare institution or doctor only when you ask us to, or when the law requires it.

5. Cookies and traffic measurement

A cookie is a small record a website leaves in your browser. Some are essential for the site to work at all — they remember that you are signed in, which language you chose and how you answered the cookie question. We cannot switch these off, because without them the site stops working.

Everything else is your choice. You are asked on your first visit, and you can change your answer whenever you like — through “Cookie settings” on the site or in your account settings.

Until you answer, measurement tools run in consentless mode: they write no cookies and do not link the visit to you.

  • Essential — sign-in, language, theme, cookie choices. Always on.
  • Traffic measurement — Google Analytics via Google Tag Manager. It shows how many people arrive and which pages they read, so we know what to improve.
  • Marketing and location services — enabled only if you explicitly allow them.
  • Convenience — animations, sliders, automatic saving of what you type. Turning them off disables those features, but the site remains usable.

6. The mobile app

The MedicalTime app shows the same thing as your account on the website, from the same server. It collects nothing in the background and does not track you while you are not using it.

The permissions it requests exist for a specific feature, and are requested at the moment that feature is needed:

  • Camera and microphone — only during a video consultation. The call runs directly between the two devices and is not recorded.
  • Notifications — so you receive a message about an appointment, a result or a new message. If you decline, the app works normally, just silently.
  • Bluetooth — so a call can be routed through wireless headphones.
  • Internet access — without it the app has nowhere to fetch data from.

The app does not request access to your location, contacts, calendar or messages. Screenshots are deliberately disabled inside it and backups are switched off — a patient record must not end up in the phone's gallery or in the cloud.

7. Who your data may be shared with

We do not sell data. Not to anyone, not ever, under any conditions. It is available only to those without whom the service cannot be delivered, and only to the extent required.

  • Hospital staff — and only those whose role and permissions cover that particular record.
  • The bank that processes card payments — you enter card details with them, not with us.
  • A laboratory, when an analysis is performed outside the hospital — only the data needed for that result.
  • The company that maintains our servers and network — as a processor, under contract and bound to confidentiality.
  • Google — for traffic measurement (with your consent), protecting forms against bots, delivering notifications to your device, showing the map on the Contact page, and Google sign-in if you choose it yourself.
  • Competent state authorities — where the law obliges us, to the extent the law requires.

8. How long we keep data

Data that no longer serves a purpose has no reason to exist. Retention periods, however, are not always ours to decide — for much of the documentation they are set by law.

  • Medical records — for as long as the Act on Medical Documentation and Records in Healthcare requires. We cannot delete this data on request before that period expires.
  • Invoices and accounting records — ten years, as required by the Accounting Act.
  • Account data — for as long as the account exists, and after deletion only what we are legally required to retain.
  • Messages from the contact form — for the duration of the exchange and a short period after it.
  • News subscription — until you unsubscribe; the link is in every message.
  • Cookies — until each one expires, or until you withdraw consent.

9. How we protect it

Security is not one measure but several, layered so that the failure of one does not open the door.

  • All traffic between you and us is encrypted.
  • Passwords are stored as an irreversible hash — not even we can read them.
  • Access is tied to a role and to individual permissions, not to “all or nothing”.
  • Patient results and attachments are held in private storage that cannot be reached by guessing an address.
  • Changes to a record leave a trace: who, what and when.
  • In the mobile app, screenshots and data backups are disabled.

No system is absolutely secure, and anyone who claims otherwise is not telling the truth. Should a data breach nevertheless occur, we will act as the law requires and notify both the supervisory authority and you, where that is prescribed.

10. Your rights

The Personal Data Protection Act gives you rights you may exercise at any time, free of charge:

  • To learn what data we hold about you and to receive a copy of it.
  • To correct data that is inaccurate or out of date.
  • To request erasure — to the extent the law does not require us to retain the data.
  • To request restriction of processing, or to object to it.
  • To receive your data in a form you can transfer to someone else.
  • To withdraw consent you have given — without affecting processing that was lawful up to that point.
  • To lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection if you believe we have done something wrong.

We respond to requests within 30 days at the latest. Before we send or delete anything, we must be satisfied that the request really comes from you — otherwise anyone could ask for someone else's medical record.

11. Deleting your account and data

You can delete your account yourself, from the app or from the website, and you need neither our permission nor an explanation.

Because part of the data is medical documentation the law requires us to keep, we have written out on a separate page exactly what is deleted immediately, what remains, and for how long.

How to delete your account

12. Minors

Accounts on the website and in the app are intended for adults. A minor may be a patient, but the account is opened and consent is given by a parent or guardian, who also communicates with us on their behalf.

If we establish that an account was opened by a child without a parent's knowledge, we will close it and delete the data we are not required to keep.

13. Transfers outside Serbia

Our servers and medical records are in Serbia.

The services we use for traffic measurement, form protection, maps and notifications are provided by Google, so that data — and only that data — may also be processed outside the country, under the safeguards such transfers require. Health data is not transferred this way.

14. Changes to this policy

We change this policy when what we do changes — a new service, a new tool, a new legal requirement. The date of the last change is always shown at the top of this page.

When a change is significant we will not pass over it in silence: we will tell you on the site, in the app or by message, depending on who it concerns.

15. How to contact us

For any question about your data, to exercise a right under this policy, or to object to the way we process data:

  • Phone: +381 62 399 888
  • Post: Medical Time, Krunska 9, Vračar, 11000 Belgrade, Serbia
  • The form on the Contact page — the fastest route; the message goes straight to the right person
Open the Contact page
Medical Time

A modern private hospital in Belgrade: examinations, diagnostics, surgery, aesthetic medicine, therapies and care — with an expert team of doctors and modern equipment.

Facebook Instagram YouTube TikTok
Secure payment via:
Raiffeisen Bank
Navigation
HomeAbout usServicesPackagesPrice listBlogPartnersContact
Services
All servicesPlastic SurgerySurgeryAesthetic MedicineInfusionsOrthopedicsDiagnosticsDoctor ExaminationsHospital AccommodationTherapiesTESLA TreatmentHome VisitsHome Doctor VisitsInfusion TherapyInternational Medical TransportHome Care Nursing
Contact
+381 62 399 888
Krunska 9, Vračar, 11000 Belgrade, Serbia
Weekdays 09–20h · Sat 09–17h · Sun 10–17h
Write to us
© 2026 Medical Time. All rights reserved.Privacy policyDelete accountMedical Time — private hospital in Belgrade