1. Introduction & Responsibility
1.1 Data controller
- Legal name: Toronto Group sh.p.k
- Address: Rruga Pjetër Budi, Tirana
- Privacy contact email: [email protected]
1.2 DPO (Data Protection Officer)
Berlin Jusufi - Endpoint sh.p.k (external DPO)
Contact: [email protected]
1.3 Applicable law
- GDPR (General Data Protection Regulation) - for all visitors from the EU/EEA
- Albanian Law No. 9887/2008 "On the Protection of Personal Data"
2. What We Collect
| Type of data | Source | Purpose |
|---|---|---|
| Name, phone, email | "Book a Consultation" form | Contact for an appointment |
| Short message | Form | Consultation preparation |
| IP, browser, OS | Automatic (server logs) | Security + statistics |
| On-site behaviour | Analytics cookies (with consent) | Content optimisation |
| Behaviour for ads | Meta Pixel + Google Tag (with consent) | Retargeting, conversion |
| Uploaded photo (optional) | Pathway 2 form | Preliminary assessment |
What we do NOT collect: sensitive medical data, scanned identity documents. All medical information is handled only through direct contact / in clinic.
3. Why We Collect It
- Response to your requests
- Improvement of the website
- Advertising of services that may interest you (only with consent)
- Legal obligations (e.g. keeping invoices)
4. How Long We Keep It
| Data | Retention period | After the period |
|---|---|---|
| Lead from the form (not contacted) | 6 months | Automatic deletion |
| Lead converted into a patient | Transferred to the medical file | Per medical law |
| Server logs | 12 months | Automatic deletion |
| Analytics cookies (GA4) | 14 months | Anonymisation |
| Marketing cookies (Meta, Google Ads) | 180 days | Expire automatically |
| Email to info@, privacy@ | 24 months | Archiving / deletion |
5. Who We Share It With
Within the organisation
- The reception team
- The relevant medical department
- Your coordinator (for international patients)
External processors
- Google - GA4 (analytics), Google Ads (conversions)
- Meta - Facebook Pixel (retargeting)
- Contabo - server hosting
- medCor - Hospital Management System (our internal hospital management system)
We never sell your data to third parties.
6. Your Rights (GDPR Article 15-22)
- Right of access - You may request a copy of your data
- Right to rectification - Inaccurate data
- Right to erasure - "The right to be forgotten"
- Right to data portability - Your data in a readable format
- Right to object - To direct marketing
- Right to lodge a complaint - With the supervisory authority
How to exercise them
Email: [email protected]
Response time: within 30 days.
7. Advertising Tracking
Meta Pixel
Collects your on-site behaviour to show you relevant adverts on Facebook/Instagram.
Google Tag (GA4 + Ads)
Collects anonymous metrics on site performance and conversion measurement.
How to opt out
- At the cookie banner: choose "Reject" or "Customise"
- After accepting: change your consent via the link in the footer
8. Cookies
See our dedicated policy: Cookie Policy
9. Security
- Data is stored encrypted on our server
- VPS backups: 30-day rolling
- Communication with the server: enforced HTTPS
- Access restricted to authorised staff
10. Changes to This Policy
This policy may be updated when the law changes or our practices change. Major changes will be notified by email (to those who have provided us with an email address).
Current version: 1.0 (3 June 2026)
11. Contact
For privacy questions:
Email: [email protected]
Tel: +355 69 336 0681
Supervisory authority:
Commissioner for the Right to Information and Protection of Personal Data, Tirana
www.idp.al