Legal Information

Privacy Policy

How we collect, use and protect your personal data.

Last updated: 3 June 2026 · Version 1.0

1. Introduction & Responsibility

1.1 Data controller

  • Legal name: Toronto Group sh.p.k
  • Address: Rruga Pjetër Budi, Tirana
  • Privacy contact email: [email protected]

1.2 DPO (Data Protection Officer)

Berlin Jusufi - Endpoint sh.p.k (external DPO)
Contact: [email protected]

1.3 Applicable law

  • GDPR (General Data Protection Regulation) - for all visitors from the EU/EEA
  • Albanian Law No. 9887/2008 "On the Protection of Personal Data"

2. What We Collect

Type of data Source Purpose
Name, phone, email "Book a Consultation" form Contact for an appointment
Short message Form Consultation preparation
IP, browser, OS Automatic (server logs) Security + statistics
On-site behaviour Analytics cookies (with consent) Content optimisation
Behaviour for ads Meta Pixel + Google Tag (with consent) Retargeting, conversion
Uploaded photo (optional) Pathway 2 form Preliminary assessment

What we do NOT collect: sensitive medical data, scanned identity documents. All medical information is handled only through direct contact / in clinic.

3. Why We Collect It

  • Response to your requests
  • Improvement of the website
  • Advertising of services that may interest you (only with consent)
  • Legal obligations (e.g. keeping invoices)

4. How Long We Keep It

Data Retention period After the period
Lead from the form (not contacted) 6 months Automatic deletion
Lead converted into a patient Transferred to the medical file Per medical law
Server logs 12 months Automatic deletion
Analytics cookies (GA4) 14 months Anonymisation
Marketing cookies (Meta, Google Ads) 180 days Expire automatically
Email to info@, privacy@ 24 months Archiving / deletion

5. Who We Share It With

Within the organisation

  • The reception team
  • The relevant medical department
  • Your coordinator (for international patients)

External processors

  • Google - GA4 (analytics), Google Ads (conversions)
  • Meta - Facebook Pixel (retargeting)
  • Contabo - server hosting
  • medCor - Hospital Management System (our internal hospital management system)

We never sell your data to third parties.

6. Your Rights (GDPR Article 15-22)

  • Right of access - You may request a copy of your data
  • Right to rectification - Inaccurate data
  • Right to erasure - "The right to be forgotten"
  • Right to data portability - Your data in a readable format
  • Right to object - To direct marketing
  • Right to lodge a complaint - With the supervisory authority

How to exercise them

Email: [email protected]
Response time: within 30 days.

7. Advertising Tracking

Meta Pixel

Collects your on-site behaviour to show you relevant adverts on Facebook/Instagram.

Google Tag (GA4 + Ads)

Collects anonymous metrics on site performance and conversion measurement.

How to opt out

  • At the cookie banner: choose "Reject" or "Customise"
  • After accepting: change your consent via the link in the footer

8. Cookies

See our dedicated policy: Cookie Policy

9. Security

  • Data is stored encrypted on our server
  • VPS backups: 30-day rolling
  • Communication with the server: enforced HTTPS
  • Access restricted to authorised staff

10. Changes to This Policy

This policy may be updated when the law changes or our practices change. Major changes will be notified by email (to those who have provided us with an email address).

Current version: 1.0 (3 June 2026)

11. Contact

For privacy questions:

Email: [email protected]

Tel: +355 69 336 0681

Supervisory authority:

Commissioner for the Right to Information and Protection of Personal Data, Tirana
www.idp.al