Privacy and health-data processing notice
Last updated: 22 July 2026
Controller
The personal-data controller is SIA “LUC MEDICAL”, registration No. 41503049560, Rīgas iela 54A, Daugavpils, LV-5401, Latvia. Privacy questions and data-subject requests: info@klinikaluc.lv, +371 65444200.
Data we process
Contact and identity details, appointment and payment information, information supplied by the patient for the clinician, uploaded medical documents, consultation outcomes, and technical security data such as access time, action and IP address. Health information is special-category personal data.
Purposes and legal bases
Data is processed to identify the patient, administer appointments and payments, provide healthcare, prepare and deliver medical records, meet accounting duties, protect the system and establish or defend legal claims. Depending on the operation, the legal basis is performance of a contract, compliance with a legal obligation, provision of healthcare under the responsibility of a health professional, the controller’s legitimate interest in protecting the service and, where required, the patient’s explicit consent.
Recipients and service providers
Access is limited to the clinician assigned to the patient and authorised LUC MEDICAL staff within their duties. Technical operation may involve hosting, managed database, email, file-storage, identity and payment providers, including UpCloud, Google Workspace/Drive and Paysera. They receive only the data necessary for their service and under applicable data-processing terms. Where processing occurs outside the EEA, a GDPR transfer mechanism and supplementary safeguards must apply.
Retention
Medical records and accounting data are retained for the periods required by law. Appointment, payment and audit records are kept as long as necessary to evidence the service, protect security and establish or defend legal claims. Unused one-time access codes expire quickly. Data must not be retained longer than required for its purpose unless the law requires otherwise.
Security
The portal uses encrypted HTTPS connections, role-based access, Google Workspace authentication for clinicians and administrators, one-time codes for patients, CSRF protection, restricted document access and access-event logging. No information system can guarantee absolute security; LUC MEDICAL must regularly assess risk and maintain appropriate technical and organisational safeguards.
Your rights
You may request access to and a copy of your data, correction of inaccurate data and, where applicable, erasure, restriction, objection and data portability. Consent may be withdrawn for future processing, but withdrawal does not affect prior lawful processing or records that must be retained by law. We may securely verify your identity before releasing data. We will respond without undue delay, normally within one month.
Complaints
We encourage you to contact LUC MEDICAL first so the matter can be checked and resolved promptly. You also have the right to complain to the Latvian Data State Inspectorate — Datu valsts inspekcija (Elijas iela 17, Riga, LV-1050; pasts@dvi.gov.lv; dvi.gov.lv) and to use other legal remedies. Filing a complaint does not itself establish that a breach occurred.
Contact and emergencies
For privacy matters contact info@klinikaluc.lv. The portal is not an emergency service; call 112 in an emergency.