1. Who We Are
Sarita is a service operated by JBA WEB AGENCY SRL (hereinafter "the Controller"), an online appointment booking platform for medical clinics and other service providers.
Legal name: JBA WEB AGENCY SRL
CUI: 45013493
Nr. Reg. Com.: J2021003372228
Registered office: Șos. Păcurari 54, Bl. 554, Sc. A, Et. 5, Ap. 13, Cod Poștal 700547, Iași, Romania
Website: https://sarita.ro
Contact email: salut@sarita.ro
2. What Data We Collect
From patients (via the booking widget):
- Full name — to identify the appointment
- Phone number — for WhatsApp notifications and confirmation
- Email address — for OTP verification and email notifications
- Visit reason (optional) — to help prepare the consultation
From clinics (via the dashboard):
- Clinic name, address, phone number, reception email
- Work schedule and appointment settings
- Account data: name, email, authentication method
Automatically collected:
- IP address — for rate limiting and abuse prevention
- Browser type — for technical logs and diagnostics
3. How We Use Your Data
- Processing and confirming appointment bookings
- Sending confirmations and notifications (email, WhatsApp)
- Sending 24-hour appointment reminders
- Displaying appointment history in the clinic dashboard
- Generating anonymized statistics for clinics
- Fraud prevention through rate limiting and OTP verification
We do not sell and do not share personal data with third parties for marketing purposes.
4. Legal Basis for Processing
- Consent — the patient explicitly checks the GDPR consent checkbox before completing a booking
- Contract performance — processing the appointment requested by the data subject
- Legitimate interest — abuse prevention (rate limiting, OTP verification)
5. Data Retention
- Patient appointment data: 24 months from the appointment date, then automatically anonymized
- Clinic account data: duration of the subscription + 30 days after termination
- OTP codes: automatically deleted after 5 minutes
- Notification logs: 12 months
- Audit logs: 24 months (legal requirement)
6. Data Security
- AES-256-GCM encryption at rest for all personal data (name, phone, email)
- HTTPS/TLS encryption for all communications
- Complete multi-tenant isolation — clinic data is strictly separated by clinic identifier
- Bcrypt password hashing
- OTP verification required for every booking
- Rate limiting on all endpoints
- Regular security audits
7. Your Rights Under GDPR
You have the right to:
- Access — find out what data we hold about you
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Data portability — receive your data in a structured, machine-readable format
- Object to processing — oppose the processing of your data
- Restrict processing — limit how we use your data
- Withdraw consent — at any time, without affecting the lawfulness of prior processing
To exercise any of these rights, contact us at salut@sarita.ro. We will respond within 30 days.
8. Third-Party Data Processors
- Meta Platforms (WhatsApp Business API) — appointment notifications via WhatsApp
- Resend — email delivery (confirmations, reminders, OTP)
- Google — OAuth authentication (optional, for dashboard login)
- Railway — backend hosting and database (EU servers)
- Vercel — frontend hosting (dashboard and widget)
9. International Data Transfers
Some of our processors (including Meta Platforms and Vercel) may transfer data outside the European Economic Area (EEA). Where such transfers occur, we ensure adequate protection through Standard Contractual Clauses (SCCs) as approved by the European Commission, in accordance with Article 46 of the GDPR.
10. Children's Privacy
Our service is not directed at individuals under the age of 16. We do not knowingly collect personal data from minors. If you believe a minor has submitted data through our platform, please contact us at salut@sarita.ro and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. We encourage you to review this page periodically. Continued use of Sarita after changes are posted constitutes acceptance of the revised policy.
12. Contact & Supervisory Authority
For questions or requests regarding data protection:
Email: salut@sarita.ro
Data Protection Officer: Alexandru Baltag —
alexandru.baltag@gmail.com
You also have the right to lodge a complaint with the Romanian supervisory authority:
ANSPDCP (Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania
www.anspdcp.ro