Home/Personal data protection policy
Legal information

Personal data protection policy

Doxamed Personal Data Protection Policy

Established on September 1, 2026.

Doxamed, a simplified joint-stock company with a single shareholder (SASU), registered in the Commercial and Companies Register of Nanterre under number 887 672 137, located at 351 Bureaux de la Colline, 92213 Saint-Cloud Cedex (France) (hereinafter "Doxamed"), processes personal data as part of its business activities. Terms beginning with a capital letter in this policy are defined at the end of this page, in the "Definitions" section.

  • This privacy policy (the "Policy") describes how Doxamed collects, uses and processes your personal data as a data controller, in compliance with applicable regulations. The Policy applies in France.
  • It applies to personal data that we collect from our clients, suppliers, service providers and subcontractors in the course of performing all types of contracts. It also applies to personal data of users of our website www.doxamed.com, individuals who wish to apply for our job offers, our employees and more broadly all other individuals we may legitimately need to contact in the course of our activities.
  • Doxamed may update this Policy as our business evolves and in response to changes in applicable law. We encourage you to read it carefully and review it regularly to stay informed of any updates we may make.
  • Doxamed respects your privacy and is committed to protecting and upholding your rights regarding the confidentiality of your personal data. If you disagree with any aspects of this Policy, you have legal rights set out in the sections "Your rights regarding your personal data", "Dispute resolution" and "Contact" below.

1.Sources of personal data collected

We collect personal data about you from the following sources:

  • the personal data you provide to us directly as part of our relationship, whether current or prospective in nature (for example when you contact us by email, phone or any other means, or when you give us your business card, or when you visit our premises);
  • personal data collected from our website when you navigate it or when you use the functions and resources available or accessible through it;
  • personal data relating to appointment bookings in connection with our services ;
  • personal data provided by third parties (such as a credit rating agency or a business information website like Infogreffe).

Notice for visitors and users of our website: use of our website and personal data communicated by its users are subject to the provisions of our Privacy Policy and terms of use.

2.Purposes of processing and legal bases

Purposes of processing your personal data

We process your personal data for the following purposes:

  • enable our stakeholders to request information about Doxamed and its services* ;
  • prepare and submit commercial proposals, participate in calls for tenders or calls for proposals* ;
  • enable tracking of commercial and contractual relationships with our clients (quotation delivery, invoice delivery, order fulfilment, technical support and monitoring, dispute management where applicable, etc.);
  • offer our contacts and prospects the opportunity to participate in events organized by Doxamed as part of trade shows, seminars and professional conferences* ;
  • conduct calls for proposals or calls for tender and enable the management of commercial and contractual relationships with our suppliers, service providers and subcontractors* ;
  • to fulfil our contractual obligations;
  • conduct client satisfaction surveys* ;
  • conduct promotional activities for our services with clients and prospects* ;
  • carry out quality audits* ;
  • managing unsolicited applications and applications received in response to job postings*, and ensuring the management of human resources for our employees, interns, apprentices and social representatives;
  • ensure the physical security of our premises (including the visitor log and CCTV recordings) and the electronic security of our systems* ;
  • improve our products and services (identify issues, plan improvements, create new ones)* ;
  • ensure financial, legal and accounting management, and audit* ;
  • in the context of legal proceedings (establishment, exercise or defence of rights in court)* ;
  • organise teleconsultation and other appointment schedules across Doxamed-equipped sites;
  • comply with our legal obligations.

Legal foundations

In order to process your personal data in accordance with the purposes set out above, we rely on one or more legal bases:

  • the processing may be necessary to perform the contract you have concluded with us, or to take the necessary steps to conclude it;
  • treatment may be necessary to comply with a legal obligation;
  • the processing may be based on your prior consent (this legal basis is used only for optional processing, not for necessary or mandatory processing);
  • We have a legitimate interest in processing personal data for the purposes listed above and marked with an asterisk (*).

3.Personal data involved

The personal data we may collect varies depending on the purpose of processing. It is primarily intended to enable the identification of individuals in the context of their dealings with Doxamed. In any case, the personal data collected will be limited to data necessary for the purposes set out in section 2 above.

Notice for visitors and users of our website: certain features of our site can only be used if certain personal data is provided. You are free to provide, or not to provide, all or part of the personal data requested; however, if you decide not to provide it in full, certain services and/or features of the site may not work or may only work partially.

Personal data relating to clients and prospects

  • personal information (surname, given name(s)) and contact details (postal address, delivery address, secretary contact details where applicable, telephone number, email address) of contacts within the client or prospective company;
  • information relating to quotes and orders (statements and amounts);
  • information on payment methods and procedures (payment date, payment statements, amount paid);
  • information on client needs or constraints collected through satisfaction surveys, which may be used to ensure our marketing communications are relevant and timely;
  • additional personal data that our clients have chosen to share with us, insofar as they are necessary to achieve the purposes set out in section 2 above.

Personal data relating to suppliers, service providers and subcontractors

  • personal information (name, first name(s)) and contact details (postal address, secretary contact details where applicable, telephone number, email address) of our contacts at the supplier, service provider or subcontracting company;
  • additional personal data that our contacts have chosen to share with us, to the extent that they are necessary to fulfil the purposes set out in section 2 above.

Personal data relating to candidates applying for our job offers

  • personal information (name, surname(s), photo) ;
  • demographic information (gender, date of birth/age, place of birth, nationality);
  • professional information (occupation, employment status, professional address);
  • contact details (postal address, phone number, email address) ;
  • professional background, qualifications and motivation.

Personal data relating to our employees, trainees, apprentices and corporate officers

We collect all information necessary for the effective management of our workforce, including identity details, marital status, personal contact information, professional background, qualifications, banking details, social security information and administrative records, all in accordance with applicable legal and regulatory requirements.

Personal data relating to individuals booking an appointment through our services

Personal data you provide on the dedicated website (in practice on our service providers' or subcontractors' systems, such as Doctolib or Anamnèse)—namely your first name, surname, phone number and email address—are collected and processed solely to book your appointment slot (date and time). This programme is specifically designed to help schedule appointments, reduce waiting times, and optimise and simplify the work of healthcare professionals.

According to the website in question, online appointment booking may not be available and may be arranged through other methods, or even on a walk-in basis — this programme depends on the services offered by Doxamed, which evolve over time.

4.Recipients of personal data collected

The recipients of personal data are: (i) authorized internal Doxamed departments, (ii) authorized Doxamed suppliers, service providers and subcontractors, and (iii) healthcare professionals involved, for the purposes of file management and service delivery.

5.Protection of children's personal data

Doxamed does not knowingly collect or retain personal data of minors, except within the scope of its appointment booking service as described in section 3 above.

6.Sensitive personal data

Health data: your health data is neither processed nor retained by Doxamed, but solely by the healthcare professionals involved, working with Doxamed, within the framework of their applicable regulations.

Doxamed does not seek to collect or process sensitive personal data as part of its normal operations. However, this may occur only in the following exceptional circumstances:

  • compliance with a legal obligation, when processing is required or permitted by applicable law (for example, to meet our various reporting obligations);
  • the detection and prevention of criminal offences (including fraud prevention);
  • consent, where we have obtained, in accordance with applicable law, your prior and explicit consent (this legal basis is used only for optional processing).

If you provide us with sensitive personal data belonging to third parties, you must inform us of this explicitly.

7.Sharing personal data with third parties

We may share your personal data with the third parties listed below, each within their respective scope and only regarding the personal data relevant to them:

  • the legally authorised authorities, whether judicial or administrative, at their request, or for the purpose of reporting actual or suspected security breaches, in accordance with applicable law;
  • external accountants, statutory auditors, lawyers and other professional advisors to Doxamed, bound by confidentiality obligations;
  • our service providers, suppliers or subcontractors (suppliers of modules and equipment, payment services, freight and transport companies, IT service providers, etc.) ;
  • any prospective buyer, in the event that we were to sell or transfer all or part of our assets or activities (including in the event of a reorganisation, dissolution or liquidation).

When one of our service providers or subcontractors participates in processing your personal data (for example Doctolib or Anamnèse, which provide booking systems, or any other supplier), they are subject to contractual obligations requiring them to (i) process your personal data only in accordance with our prior written instructions, (ii) implement appropriate confidentiality and data security protection measures, and (iii) comply with any other obligation imposed by applicable regulations.

Regarding data specifically related to individuals booking an appointment, your personal data is shared only with the staff and healthcare professionals involved in ensuring the proper coordination of your appointment sequence.

8.Limitation and retention period of personal data

We take all appropriate measures to ensure that the volume of personal data we process is limited to what is reasonably necessary for the purposes set out in this Policy, and that such data is retained only for as long as necessary in relation to those same purposes.

The criteria used to determine retention periods are as follows:

  • We retain your personal data in a form that allows us to identify you for as long as necessary to fulfil the legitimate purposes described in section 2 of this Policy;
  • We keep them for the applicable limitation period (the period during which a person may lodge a complaint with us or take legal action against us in relation to them);
  • In any case, no later than five (5) years after the personal data concerned is communicated, it will be permanently destroyed or anonymized.

Regarding personal data specifically related to your appointment bookings (teleconsultations or otherwise), Doxamed deletes this data within one month of the end of the contract concerning the relevant Doxamed site (that is, the contract concluded between Doxamed and its client who ordered the deployment of the relevant module or health space). This date can be provided to you on simple request by email to the address contact@doxamed.com / pdebondy@lawval.com.

9.Transfer of personal data outside the European Union

We do not transfer personal data outside the European Union.

Regarding Doctolib, its personal data management policy is available at the following address: media.doctolib.com/.../B2C-PrivacyPolicy-Apr-23-FR.pdf.

Regarding Anamnèse, its personal data management policy is available at www.anamnese.care.

10.Your rights regarding your personal data

Depending on the type of processing, within the framework set by the GDPR, you have a number of rights concerning the processing of your personal data:

Right not to share your personal data with us

In such a situation, we may be unable to provide you with the full range of our products and services — for example, to process your orders or appointment bookings without the necessary information and contact details.

Right to object (processing based on legitimate interest or public interest)

You can object at any time to us processing your personal data. Your request will be handled promptly and we will cease the processing in question, unless we can demonstrate legitimate and compelling reasons that override your personal interests, or if the processing is necessary for the establishment, exercise or defence of a legal claim.

Right to withdraw consent

Where a processing activity is based on your consent, you may withdraw it at any time — we will then stop that particular processing, unless there is another legal basis for continuing it, which we would inform you of. Withdrawal of consent does not affect the lawfulness of processing carried out before we received notification of your withdrawal.

Right of access

You can request access to or a copy of your personal data, along with information on the nature of processing and the persons who may access it. This access is free, unless the request is manifestly unfounded or abusive, or a request for additional copies (reasonable administrative costs may then apply where permitted by law).

Right to erasure

You may request deletion of your personal data in certain circumstances — particularly when it is no longer necessary for the purposes for which it was collected, when you withdraw your consent, or when it has, in exceptional cases, been processed unlawfully. We may refuse such a request on legal grounds (freedom of expression, legal obligations, public health, archival or research purposes, exercise of a legal right).

Right to restrict processing

You may request the restriction of processing of your personal data in certain circumstances (where you contest the accuracy of the data, object to the processing, consider the processing unlawful, or where data is retained solely for the establishment, exercise or defence of legal claims).

Right to rectify

You can request correction of inaccurate or incomplete personal data concerning you.

Right to data portability

For data we process based on your consent or in the course of performing a contract, you may request to obtain and transfer them to another data controller in a structured, commonly used and machine-readable format.

Right to lodge a complaint with a data protection authority

To exercise any of these rights, or for any questions relating to this Policy, please use the contact details provided in the "Contact" section below. We may ask you to provide proof of your identity before processing your request.

If you believe, after contacting us, that your data protection rights are not being respected, you can lodge a complaint with the CNIL (French Data Protection Authority):

Commission Nationale de l’Informatique et des Libertés
3, place de Fontenoy — TSA 80715
75334 Paris Cedex 07 — France

11.Data security and privacy

We are committed to implementing all necessary measures to protect your personal data against misuse, loss, damage, disclosure, destruction, unauthorised access, and any other form of unlawful or unauthorised processing, in compliance with applicable law, through appropriate technical and organisational safeguards.

Because the Internet is an open system, data transmission over this network is not entirely secure: although we implement all reasonable measures to protect your personal data, we cannot guarantee the security of information transmitted to us via the Internet, such transmission occurring at your own risk.

Access to personal data is limited to Doxamed employees, interns, apprentices, corporate officers, suppliers, service providers and subcontractors who need to access it in the course of their work. All persons with access to your personal data are bound by a confidentiality obligation and may face disciplinary measures and/or other sanctions if they fail to comply.

12.Conflict resolution

Although Doxamed has taken all appropriate measures to protect your personal data, no transmission or storage technology is completely failsafe.

If you have reason to believe your personal data security has been compromised or that your data has been used unlawfully or abusively, please contact Doxamed:

  • by mail, to the address: Doxamed, Head Office — 351 Bureaux de la Colline, 92213 Saint-Cloud Cedex (France);
  • by email at contact@doxamed.com ;
  • with a copy to Maître Philippe de Bondy — 51 avenue Raymond Poincaré, 75116 Paris, pdebondy@lawval.com, in their capacity as external Data Protection Officer (DPO) for Doxamed.

Doxamed will handle complaints concerning the use and disclosure of your personal data and will attempt to resolve them in accordance with the principles set out in the Policy. Unauthorised access to personal data or misuse of such data may constitute an offence under applicable legislation.

13.Contact

For any question relating to this Policy, to unsubscribe from Doxamed's commercial information, or to exercise your rights regarding your personal data, you can write to contact@doxamed.com or pdebondy@lawval.com.

14.Cookie Policy

When you visit our website, we may store cookies on your device, or read cookies already present on your device, provided we have always obtained your prior explicit consent.

This cookie policy applies to the website operated and controlled by Doxamed at the address www.doxamed.com.

What is a cookie?

A "cookie" is a small file of information stored on your computer's hard drive that records your browsing activity on a website, so that on your next visit we can present you with personalised options based on information from your previous visit. Cookies can also be used to analyse traffic and for advertising and marketing purposes. Almost all websites use them and they do not damage your system.

There are different types of cookies, distinguished by their origin, function and lifespan:

  • Session cookiesstored on your computer only during your web session and automatically deleted when you close your browser — they typically store a session identifier that allows you to visit our sites without having to log in again on every page.
  • Persistent cookiesstored as a file on your computer and retained after you close your browser, readable by the website that created them on your next visit. We use persistent cookies for Google Analytics and for personalization.
  • Strictly necessary cookiesessential for using our site effectively, they cannot be disabled. Without them, certain services cannot be provided. They do not collect information that can be used for commercial purposes or to remember pages you have visited.
  • Performance cookiesthey allow us to monitor and improve our website performance (count visits, identify traffic sources, see which pages are most visited).
  • Functionality cookiesThey allow our website to remember your choices (username, language, country…) and to provide enhanced features, such as viewing a video or posting a comment.
  • Personalisation cookiesthey allow us to share information about solutions that may be of interest to you.

Why do we use cookies?

We use cookies to track your use of our website. This helps us understand how you use it and monitor trends among individuals and larger groups, so we can develop and improve our website and services in response to our visitors' wishes and needs.

What is the duration of the cookies we use?

The duration of cookies we use on our website does not exceed twelve (12) months.

Some cookies are placed by third parties, who are responsible for them.

How can you manage cookies?

Most Internet browsers are programmed to accept cookies automatically. Depending on the browser you use, you can configure it to receive a warning before cookies are installed — allowing you to accept or refuse them — or to always refuse them. Consult the "help" button (or equivalent) in your browser to find out how to do this. Disabling cookies may affect your browsing experience on our website.

If you access our website from different devices, please ensure that each browser on each device is configured according to your preferences.

You can find out more about allaboutcookies.orgDoxamed is neither affiliated with nor responsible for third-party websites.

You can also unsubscribe from cookies from certain companies by visiting aboutads.info/choices and youronlinechoices.comDoxamed is neither affiliated with nor responsible for these third-party websites.

15.Definitions

  • Data protection authorityindependent public authority legally responsible for supervising compliance with applicable data protection laws.
  • Personal dataany information relating to an identified or identifiable person, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific elements.
  • Sensitive personal datadata revealing racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, as well as genetic data, health data, data relating to sexual life, criminal convictions or offences, or related security measures.
  • Data controllerentity that determines the purposes and means of processing personal data.
  • GDPRRegulation (EU) 2016/679 on general data protection.
  • Subcontractornatural or legal entity that processes personal data on behalf of the data controller, other than its employees.
  • Treatment / Treatany operation performed on personal data, whether or not using automated processes, such as collection, recording, organisation, structuring, storage, adaptation or alteration, extraction, consultation, use, communication by transmission, dissemination or any other form of making available, linking or interconnection, restriction, erasure or destruction.