1. Overview
At Sarita, we respect your right to control your personal data. This page explains how you can request the deletion of your data in accordance with GDPR (General Data Protection Regulation) and Meta's data policies.
Sarita is operated by JBA WEB AGENCY SRL (CUI: 45013493, Nr. Reg. Com.: J2021003372228), with registered office at Șos. Păcurari 54, Bl. 554, Sc. A, Et. 5, Ap. 13, Cod Poștal 700547, Iași, Romania.
2. For Patients — How to Request Data Deletion
To request deletion of your personal data, follow these steps:
- Send an email to salut@sarita.ro with the subject line "Data Deletion Request"
- Include your name, phone number, and email address used for booking
- We will verify your identity and process your request within 30 days
- You will receive a confirmation email once your data has been deleted
3. What Data Gets Deleted
- Your personal information (name, phone number, email) is anonymized — replaced with non-identifiable placeholders
- Appointment records are anonymized (dates and times retained for clinic statistics, but all personal identifiers removed)
- OTP codes are automatically deleted after 5 minutes (no action needed)
- Notification logs containing your contact information are purged
- Your data is removed from all active systems and backups within 30 days
4. For Clinics — Deleting Patient Data
Clinic administrators can delete patient data directly from the dashboard:
- Navigate to: Patients → Select Patient → GDPR Delete
- This action anonymizes all patient data and is irreversible
- An audit log entry is created for compliance purposes
5. For Clinic Administrators — Deleting Your Account
To delete your clinic account and all associated data:
- Contact us at salut@sarita.ro
- Include your clinic name and registered email address
- Account deletion includes: clinic profile, all patient data (anonymized), appointment history, schedule settings, notification logs
- Processing time: within 30 days of verified request
6. Automatic Data Retention
- Patient data is automatically anonymized after 24 months of inactivity
- OTP codes expire and are deleted automatically every 5 minutes
- Expired authentication tokens are cleaned up daily
- This automatic process requires no action from you
7. Data We Cannot Delete
- Anonymized statistical data (appointment counts, no-show rates) — cannot be linked back to individuals
- Audit logs required by law (retained for 24 months, contain action records but no personal data after anonymization)
- Data required for ongoing legal proceedings
8. Facebook / Meta Data
If you connected to Sarita through Meta/Facebook services (WhatsApp), you can also manage your data through Meta's settings. Sarita processes WhatsApp data solely for appointment notifications. Deleting your data from Sarita will stop all WhatsApp notifications from our platform.
9. Contact
For all data deletion requests:
Email: salut@sarita.ro
Data Protection Officer: Alexandru Baltag (alexandru.baltag@gmail.com)
Response time: within 30 days
Supervisory authority: ANSPDCP Romania (anspdcp.ro)