Privacy
Privacy and data protection policy.
Central de Saúde processes your data to provide healthcare. This page explains what data we collect — at the clinic and through the digital channels we make available — what it is used for, how long we keep it and what you can request at any time.
Last updated: 18 August 2026
English translation provided for convenience. If there is any discrepancy, the Portuguese version prevails.
1. Controller
The controller of your personal data is Central de Saúde, a medical clinic based in Lourinhã. This policy covers every clinic channel: in-person care, this website, online appointment requests, the patient portal, consent tablets and video consultations.
For any privacy question, write to [email protected] or call 261 416 600.
As a small clinic, operating from a single location without large-scale processing or systematic monitoring, the appointment of a Data Protection Officer is not legally required. We have not appointed one: privacy requests are handled directly by the clinic through the contacts above.
- FERREIRA SIMÕES E PEREIRA - CUIDADOS DE SAÚDE, LDA., NIF 503663425.
- Rua Engenheiro Adelino Amaro da Costa, 6 RC, 2530-109 Lourinhã.
- Telephone: 261 416 600.
- Email: [email protected].
- Website: https://www.centraldesaude.com.
2. Where we collect your data
Most of your data is collected in person, at reception and in the consultation room. Some digital channels also collect data, and each collects different information — which is why they are listed separately here.
- At the clinic: creating a patient record, booking appointments, and carrying out consultations, tests and sample collections.
- On this website: nothing that identifies you. The site has no forms or private area, and visit statistics are aggregated and cookie-free (section 10).
- Online appointment requests: when you request an appointment through the public page without creating an account.
- Patient portal: when you enter your personal area to view documents or contact us. Sign-in uses a code sent to your email address.
- Consent tablets: when you sign informed consent on a clinic tablet.
- Video consultation: when the consultation takes place by video on the clinic’s own server.
3. Personal data we collect
We collect only the data needed for each purpose. Health data is special-category data and receives enhanced protection.
- Identification: name, date of birth, gender, civil identification number, SNS user number, beneficiary number, address, email and telephone number.
- Health data: medical history, diagnoses, allergies, medication, test and examination results, reports, and records of consultations and treatments.
- Administrative and billing data: appointments, amounts, payment methods, tax documents, agreements and insurance, and correspondence with the clinic.
- Informed consent: name, image of the signature and its cryptographic fingerprint (SHA-256), date and signed document — so that we can prove who consented to what.
- Online appointment request: name, email, telephone number and the reason you provide.
- Patient portal: sign-in email, one-time access code (stored encrypted, never in clear text), active sessions, messages and documents shared with you.
- Video consultation: the video session and the network metadata needed to establish it. The clinic does not record sessions — the video server does not even have a recording component installed.
- Access log: we keep who within the clinic accessed your record, when and for what purpose. This is a security obligation and also allows us to show you the list if you ask for it.
- Website visits: the page visited, visit source, device type and country, in aggregated form. Your IP address is processed to deliver the site to you, but is not used to identify you or combined with your patient-record data.
4. Purposes and legal basis for processing
Each processing activity has a purpose and a legal basis. Where the basis is consent, you may withdraw it at any time without affecting what was lawfully done before.
- Providing healthcare, including by video consultation. Basis: art. 9.º, n.º 2, al. h) do RGPD — preventive medicine, diagnosis and care under a professional duty of confidentiality.
- Informed consent for clinical procedures. Basis: art. 9.º, n.º 2, al. h) do RGPD — the signed document proves that the procedure was explained to you.
- Administrative management, billing and relationships with agreements and insurers. Basis: art. 6.º, n.º 1, al. b) e c).
- Processing your online appointment request. Basis: art. 6.º, n.º 1, al. b) — steps taken at your request before the consultation.
- Giving you access to your data through the portal and communicating with you through that channel. Basis: art. 6.º, n.º 1, al. b) e art. 9.º, n.º 2, al. h).
- Appointment reminders and non-essential communications. Basis: art. 6.º, n.º 1, al. a) — consent, which may be withdrawn.
- Aggregated website-use statistics. Basis: art. 6.º, n.º 1, al. f) — a legitimate interest in understanding which pages are useful, using data that does not identify you and without cookies.
- System security and access logs for the clinical record. Basis: art. 6.º, n.º 1, al. c) e f), and art. 5.º, n.º 2 — accountability.
- Compliance with legal obligations: communications to ACSS, ERS and other public entities, tax obligations, and responses to judicial or police authorities. Basis: art. 6.º, n.º 1, al. c).
5. Retention periods
We keep data for as long as necessary for each purpose. Once the period ends, it is deleted or irreversibly anonymised, and the deletion is recorded.
The periods below are those applied by our systems, rather than a separate written summary.
- Clinical record, including tests, imaging and associated consents: 20 years from the last clinical act. This is a conservative internal policy, above the legal minimum of 10 years, because an incomplete clinical record primarily harms the patient.
- Access logs for health data: 20 years after the access, so that we can show you the history if you request it.
- Accounting and tax documents: 10 years, under tax legislation.
- Appointment requests that do not lead to a patient record: 2 years after the last contact.
- Patient-portal sessions and access codes: expire within minutes or hours, and sessions end after inactivity.
- Website statistics: aggregated from the outset, with no individual retention period because there is no individual record.
- Communication consents: until you withdraw them.
6. Who can access your data
Central de Saúde does not sell or provide personal data for commercial purposes, and does not use it for advertising.
Within the clinic, access to the clinical record is limited to professionals involved in your care, all bound by confidentiality, and is logged.
Outside the clinic, data is shared only with those needed to provide the service to you, or where required by law. The technical providers below process data on our behalf under a processing agreement and may not use it for their own purposes.
- Laboratory (Germano de Sousa) and other healthcare providers, where needed for continuity of your treatment.
- Health subsystems, agreements and insurers, for billing and reimbursement within their responsibility.
- Hetzner — the server where the application and database run, and where documents are stored.
- The clinic’s dedicated video server — signalling and transmission of the video consultation, separate from the main server.
- Cloudflare — delivery of this website and aggregated visit statistics, as well as storage of backups, which leave the server already encrypted.
- Resend — sending transactional emails, including the portal sign-in code.
- Sentry — detecting technical application errors.
- Public authorities, including ACSS, ERS and judicial or police authorities, where the law requires it. These requests are logged and, where the law allows, can be communicated to you.
7. Transfers outside the European Union
The main infrastructure — server, database and documents — is hosted in the European Union.
Some supporting services are provided by companies based outside the European Union. In those cases, a transfer may take place only under the safeguards in Chapter V of the RGPD, in particular standard contractual clauses approved by the European Commission.
We are reconciling the contracted region and applicable mechanism with each provider, and this section will be updated with the result. If you want to know where your data is held at a particular time, ask us through the contacts in section 12 and we will respond.
8. Your rights
Under the RGPD, you have the rights below. You may exercise them free of charge and without having to explain why.
Where processing is based on your consent, you may withdraw it at any time, without affecting what was lawfully done before.
You may also complain to the supervisory authority, Comissão Nacional de Proteção de Dados (CNPD).
- Access: find out what data we process and receive a copy — including the list of people who accessed your record.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask for deletion where there is no legal obligation to retain the data. That obligation almost always exists for clinical records, and we will explain why.
- Restriction: ask for processing to be blocked without deleting the data.
- Data portability: receive the data you provided in a structured, machine-readable format.
- Objection: object to processing based on legitimate interest, including website statistics.
- Not to be subject to automated decisions: we do not make decisions about you solely by automated means.
9. Security of your data
We adopt technical and organisational measures to protect your data against unauthorised access, alteration, disclosure or destruction.
If there is a data breach likely to create a risk to your rights, we notify CNPD within the legal 72-hour period and inform you when the risk is high.
- Access to the clinical record restricted to professionals involved in your care, bound by confidentiality, with individual authentication and a second factor.
- A record of every access to health data, including who accessed it, when and for what purpose.
- Communications always encrypted in transit (HTTPS), and backups encrypted before leaving the server.
- Portal access codes stored irreversibly, never in plain text, with lockout after failed attempts.
- Staff training on confidentiality and data protection.
11. Children’s data
When care involves patients under 16, data is processed with the express written consent of their legal representatives, under the RGPD and Lei n.º 58/2019.
The form identifies the legal representative, the clinic and the purposes in clear language. The clinic’s digital channels are intended for adults: the patient portal is not aimed at children, and a child’s data is accessed by the legal representative.
12. How to exercise your rights
To exercise any of these rights, or to ask a question about how your data is processed, contact us through one of the methods below.
We respond within 30 days, under art. 12.º do RGPD. If the request is complex, we may extend this by a further two months; in that case, we will tell you why within the first month. We may need to verify your identity before responding — this is how we make sure we do not give your data to someone else.
This policy is updated whenever processing activities or the law changes. The current version is always on this page, with the last-update date at the top.
- Email: [email protected].
- Telephone: 261 416 600.
- In person, at the clinic reception during opening hours.
- Livro de Reclamações Eletrónico and the ERS channel, through the useful links on this page.