Privacy Policy

Introduction

This text, called the Privacy Policy, explains in simple terms how we process the personal data we collect from you or which you voluntarily provide to us in the context of providing our medical services, transactions, or your communication with our practice.

Data Controller

The data controller for personal data is the company under the name “Blionas A. Neurosurgery E.E.”, based in Paiania, Attica, 7 Serron Street, P.C. 190 02, with VAT number 802218582 (Tax Office of Koropi) and GEMI number 172356103000, legally represented by its manager, Alexandros Blionas, Neurosurgeon.

Contact details: tel. +30 697 004 0595, email: info@blionas-neurosurgery.com

Our priority is the lawful processing of this data and your complete and transparent information regarding it. For any questions, do not hesitate to contact us.

Privacy Policy Contents

First Section: General Information

What is personal data
What is personal data processing
Is the processing of personal data concerning you mandatory?
When and how we collect your data
Which principles we follow when processing data

Second Section: Analysis of Processing A. Categories of data we process B. Purposes of processing – Legal bases of processing C. Recipients of data D. Time and place of retention E. Your rights

Third Section: Additional Information

FIRST SECTION: General Information

1. What is personal data?

The term “personal data” (hereinafter “PD” or “data”) refers to any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one whose identity can be verified, directly or indirectly, in particular by reference to an identifier such as name, identity number, address, telephone number, but also by reference to one or more factors specific to the physical, physiological, genetic, psychological, economic, cultural or social identity of that person. In brief, PD is any information relating to a natural person that either directly reveals their identity or may reveal it.

A special category of PD consists of health data (medical history, diagnoses, imaging examinations, treatments, etc.), which, due to the nature of our services, constitute the primary subject of the processing we conduct and enjoy enhanced protection.

2. What is personal data processing?

Any operation or set of operations performed with or without the use of automated means on personal data or sets of personal data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

In other words, almost any action, from the moment a PD is created until the moment it is destroyed (or fully anonymized), constitutes a processing operation.

The processing of PD is lawful provided it is carried out within the framework defined by the relevant legislation, namely the General Data Protection Regulation (EU) 2016/679 (GDPR) and national law 4624/2019.

3. Is the processing of personal data concerning you mandatory?

The provision of certain data is necessary for the provision of our medical services, appointment scheduling, invoicing, and communication with you.

Through this policy we inform you of the processing rules we follow. If you do not provide us with the data referred to below, we may not be able to provide you with our services or respond to your request.

4. When and how we collect your data

We collect your data:

A. When we provide you with our medical services (in person or remotely — online assessment/second opinion)
B. When you communicate with us (by telephone, email, or through the website forms)
C. When you visit our website

5. Which principles we follow when processing data

When processing your data we apply the principles of Article 5 GDPR, meaning your data:

a) are processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”),

b) are collected for specified, explicit and legitimate purposes and are not further processed in a manner incompatible with those purposes (“purpose limitation”),

c) are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”),

d) are accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (“accuracy”),

e) are kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (“storage limitation”),

f) are processed in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (“integrity and confidentiality”).

SECOND SECTION: Analysis of Processing

A. Categories of PD we process

Our practice collects and subsequently processes (stores, etc.) primarily the following categories of PD:

Full name, father’s name, date of birth, VAT number, national ID or passport number, home address/area, telephone number (landline/mobile), email address

Invoicing details (services, value), payment details (bank account/IBAN — full card details are not stored by us, see Section D)

Health data: medical history, symptoms, clinical findings, imaging and laboratory examinations (e.g. MRI scans), diagnoses, treatment plans, surgical records, as well as documents you send us in the context of a remote assessment or second opinion

Browsing data and the internet protocol (IP) address of your terminal device when browsing our website

B. Purposes of processing – Legal bases of processing

We collect and process the above categories of PD for the following purposes:

Provision of healthcare services: diagnosis, treatment, surgical and conservative management, monitoring, remote medical assessment and second opinion
Appointment management and patient service (maintenance of patient records, communication)
Invoicing, payments and credits
Establishment, exercise or support of legal claims
Compliance with legislation (medical, tax, etc.)

Legal bases of processing:

Article 6(1)(b) GDPR: processing is necessary for the performance of a contract to which the data subject is party (provision of services, invoicing)

Article 6(1)(c) GDPR: processing is necessary for compliance with a legal obligation to which the controller is subject (e.g. maintenance of medical records, tax legislation)

Article 9(2)(h) GDPR (specifically for health data): processing is necessary for the purposes of medical diagnosis and the provision of healthcare, and is carried out by a healthcare professional subject to the obligation of medical confidentiality

Article 9(2)(f) GDPR: for the establishment, exercise or defence of legal claims

C. Recipients of data

Access to your data is restricted to only those persons who are strictly necessary and bound by confidentiality. Where applicable, your data may be transferred to:

Affiliated private clinics and diagnostic centers, in the context of your care

Affiliated healthcare professionals (e.g. anesthesiologist) participating in your care

Insurance companies, if you request this for the coverage of your expenses

Certified payment service providers, when you pay by card (card data processing is carried out by them — we do not store full card details)

Providers of technical services acting as processors on our behalf: our website hosting and technical support company (iServices) and Google cloud storage services (Google Drive), where digital records are maintained. Google may process data outside the European Economic Area; in such cases, the transfer is covered by approved GDPR mechanisms (EU-US adequacy decision / standard contractual clauses)

Public authorities, where required by law

D. Time – Place of retention of PD

The processing of PD is limited in time to what is strictly necessary for the purposes of processing.

The medical record in particular is kept for the period specified by the legislation on medical records (Article 14 of Law 3418/2005 — Code of Medical Ethics), i.e. at minimum ten (10) years from the patient’s last visit.

Tax and transactional data are retained for as long as required by tax legislation, as well as for the safeguarding of our legal claims.

In the event of credit/debit card use, we do not store card details (card number, CVV), and in the case of telephone transactions we delete them immediately upon completion.

Your remaining data are retained at our practice premises in physical form or, where applicable, in digital form in the infrastructures referred to in Section C, with appropriate security measures.

E. Your rights

We process the above data in accordance with this policy and ensure the exercise of your rights through a corresponding procedure.

Our response to your requests (whether concerning the exercise of rights or the submission of complaints) is provided free of charge, without delay and in any event within one (1) month of receipt of the request and verification of your identity. If your request is complex or a large number of requests have been submitted simultaneously, we will inform you within that month of any extension of up to two (2) additional months, as provided by the GDPR.

If your requests are manifestly unfounded or excessive, in particular due to their repetitive nature, we are entitled to charge a reasonable fee based on administrative costs or to refuse to act on the request.

Specifically, you have the following rights:

Right to information on all the above matters and any other matters relating to the processing of your data
Right of access, i.e. the right to receive a copy of the data we hold about you, including your medical record
Right to rectification/updating, in the event that certain data is or becomes inaccurate. Rectification is made within seven (7) working days of submission of a written request and verification of your identity
Right to erasure. This right is subject to limitations, particularly due to the statutory obligation to retain medical records
Right to restriction of processing, when: a) you contest the accuracy of the data and for the period required for its verification, b) the processing is unlawful and you request, instead of erasure, restriction of its use, c) we no longer need the data for the purposes of processing, but they are required by you for the establishment, exercise or defence of legal claims, and in related cases
Right to object to processing, on grounds relating to your particular situation, when processing is not based on a legal obligation or the performance of a contract
Right to data portability, i.e. the right to receive the data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller
Right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr), if you consider that we are violating data protection legislation

THIRD SECTION: Additional Information

A. Our practice uses modern and updated organisational and technical measures to prevent unlawful intrusion, access or dissemination of your personal data. Your health data are additionally covered by medical confidentiality.

B. We do not carry out automated individual decision-making or profiling within the meaning of Article 22 GDPR.

C. Our website uses cookies to facilitate your browsing and to collect traffic statistics through the Google Analytics service. For more information, please visit the Cookie Policy.

D. Contact forms and submission of medical information

Through the website forms you can send us a contact message or, in the context of the remote assessment service, medical information (history, examinations, imaging files). The medical information you send us is covered by medical confidentiality and is processed exclusively for the purpose of your medical assessment, in accordance with the above (Article 9(2)(h) GDPR).

Please do not send sensitive information concerning third parties, unless you are acting lawfully on their behalf (e.g. as a parent/guardian or legal representative).

E. Revisions to the Privacy Policy

We reserve the right to periodically modify or revise this Privacy Policy. In the event of changes, the date of modification or revision will be indicated in the new Policy, which will take effect from that date. We encourage you to periodically review this Policy in order to stay informed about any changes in the way we manage your personal data.

F. Contact – Requests – Complaints

If you have questions, comments or complaints regarding the management or protection of your personal data, or if you wish to exercise any of your rights, please contact us at info@blionas-neurosurgery.com or at the contact details above.

To submit a complaint or report a personal data breach, you may contact the Hellenic Data Protection Authority (1-3 Kifissias Avenue, P.C. 115 23, Athens, tel. 210 6475600, fax 210 6475628, email for breach notification: databreach@dpa.gr, general email: contact@dpa.gr).

Last updated: 23 July 2026

 

Google User Data

Our application requests access to Google Calendar using the calendar.events scope, granted by the practice administrator (Dr. Alexandros Blionas), solely to synchronize appointment bookings between the Easy Appointments plugin and the connected Google Calendar.

Data accessed: Calendar event data (title, start/end time, event ID) for the single Google Calendar account connected by the administrator.

Data use: This data is used exclusively to create, update, and delete calendar events corresponding to patient appointments, and to check calendar availability. It is never used for advertising, profiling, or any purpose unrelated to appointment scheduling.

Data sharing: We do not sell, share, transfer, or disclose Google user data to any third party or external service.

Data protection: OAuth tokens are stored in the WordPress database with restricted access, transmitted only over HTTPS/TLS, and are never exposed to website visitors or patients.

Data retention/deletion: Calendar event data is retained only while the corresponding appointment exists. OAuth tokens are deleted immediately if the administrator disconnects the Google Calendar integration or revokes access via their Google Account.”

Μπλιώνας Αλέξανδρος
Μπλιώνας Αλέξανδρος
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.