Privacy Notice

Last updated: 22 April 2026

1. Who we are

This Privacy Notice describes how Staykeasy S.r.l ("Staykeasy", "we", "us"), trading as HealthConcierge24, collects and processes personal data when you use our website and services (the "Service"). Staykeasy S.r.l acts as data controller for the personal data described below.

For privacy questions: privacy@healthconcierge24.com.

2. Personal data we collect

  • Account data: name, email, password (hashed), professional details (specialty, structure type, address, phone).
  • Patient request data entered by patients into the concierge: name, email, phone, message content, scheduling preferences.
  • Configuration data: assistant settings, services, schedule, FAQs you create.
  • Usage and telemetry: pages viewed, actions taken, device/browser info, IP address, timestamps.
  • Support communications: messages you send to our support team.

3. Purposes and legal bases

  • Provide the Service (account, concierge, dashboard) โ€” performance of contract.
  • Process patient requests on behalf of professionals โ€” performance of contract / legitimate interest of the professional.
  • Security, fraud prevention, abuse detection โ€” legitimate interest.
  • Service improvement and analytics โ€” legitimate interest.
  • Customer support โ€” performance of contract.
  • Legal and tax obligations โ€” legal obligation.
  • Marketing communications (where applicable) โ€” consent, withdrawable at any time.

4. How we share data

We share personal data only with categories of recipients necessary to operate the Service:

  • Hosting and infrastructure providers (cloud hosting, database, edge functions).
  • AI processing providers used to generate concierge replies, under data processing agreements.
  • Email and communication providers for transactional notifications.
  • Professional advisers (legal, accounting) where strictly necessary.
  • Public authorities where required by law.

We do not sell personal data.

5. International transfers

Some of our subprocessors may process personal data outside the European Economic Area. Where this happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions.

6. Retention

We keep personal data only for as long as needed for the purposes above: account data for the duration of the account plus a limited period after closure for legal/accounting purposes; patient request data according to the professional's configuration and applicable medical record obligations; logs for a limited period for security and debugging. After these periods, data is deleted or anonymised.

7. Your rights

Under the GDPR you have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • request erasure;
  • restrict or object to processing;
  • data portability;
  • withdraw consent at any time, where processing is based on consent;
  • lodge a complaint with your supervisory authority (in Italy, the Garante per la protezione dei dati personali).

To exercise your rights, email privacy@healthconcierge24.com. We respond within one month.

8. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, authentication, audit logging and regular reviews.

9. Cookies

We use strictly necessary cookies to operate the Service (authentication, session, security). We may use limited analytics cookies to understand aggregate usage. You can manage cookies through your browser settings.

10. Changes

We may update this Privacy Notice. Material changes will be notified through the Service or by email. The "Last updated" date above reflects the latest version.