Privacy Policy

Last updated:

This Privacy Policy explains how Netforza ("we", "us") collects, uses and protects your personal data when you use REDHO (the "Application"), an AI-powered health information service.

REDHO provides health information only. It is not a medical service and does not replace a consultation with a qualified healthcare professional.

1. Who is responsible for your data

The data controller is Netforza. For any question or request about your personal data, contact us at netforza.com@gmail.com.

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Law of the Republic of Moldova No. 133/2011 on personal data protection.

2. Data we collect

  • Account data: email address, name (optional), password (stored only as a secure hash), language preference and account creation date.
  • Social sign-in data: if you sign in with Google, we receive your Google account identifier, email address, whether the email is verified, and your name. We do not receive your Google password or access to other Google data.
  • Health profile: information you provide in the health questionnaire, such as date of birth, biological sex, gender identity, height, weight, body build, ethnicity, chronic conditions, medications, supplements, allergies, pregnancy or breastfeeding status, smoking and alcohol use, surgeries, family history, mental health conditions, healthcare providers, physical activity, diet and blood type.
  • Medical records: diseases, test results, medications, surgeries, allergies and other entries you add, with their dates and descriptions.
  • Consultations: the symptoms you describe, your answers to clarifying questions, follow-up messages, the AI-generated questions, analyses and summaries, any diagnosis from your doctor that you choose to add, and the prompts sent to the AI models.
  • Technical data: cookies needed to keep you signed in and remember your language (see section 8), and server logs such as request errors.

Health data is a special category of personal data. Providing it is voluntary, but the Application cannot give personalised analyses without it.

3. How we use your data and legal bases

  • To create and manage your account and let you sign in, including with Google (performance of a contract, GDPR Art. 6(1)(b)).
  • To generate AI health analyses, clarifying questions and answers based on your symptoms, health profile and medical history (your explicit consent, GDPR Art. 9(2)(a), and performance of a contract).
  • To check that submitted content is health-related, prevent abuse and keep the service secure (legitimate interests, GDPR Art. 6(1)(f)).
  • To apply usage limits, provide premium features and handle support requests (performance of a contract).
  • To comply with legal obligations (GDPR Art. 6(1)(c)).

We do not sell your personal data, do not use it for advertising, and do not make decisions with legal or similarly significant effects about you based solely on automated processing. AI outputs are informational only.

You can withdraw your consent at any time by deleting the relevant information or asking us to delete your account. Withdrawal does not affect processing carried out before it.

4. AI providers and other recipients

To produce an analysis, the text of your consultation, together with relevant parts of your health profile and medical history, is sent to one or more of the following AI model providers, which process it on our behalf through their business APIs:

  • OpenAI (GPT models)
  • Anthropic (Claude models)
  • Google (Gemini models)

Google also acts as a sign-in provider if you choose to sign in with Google; its handling of your Google account is governed by Google's own privacy policy.

Authorised administrators of the Application can access account and consultation data where needed to operate, support and secure the service. We may also disclose data where required by law or to protect our rights.

5. International transfers

The AI providers listed above may process data outside the European Economic Area and the Republic of Moldova, including in the United States. Where this happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions.

6. How long we keep your data

  • Account, health profile, medical records and consultations are kept for as long as your account exists.
  • When you ask us to delete your account, we permanently delete it together with your health profile, medical records, consultations and linked sign-in accounts within 30 days.
  • Accounts that were registered but never completed the health questionnaire may be deactivated and removed.
  • We may keep limited data longer where required by law.

7. Your rights

Subject to applicable law, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate data (you can edit most of it directly in the Application);
  • request erasure of your data and account;
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw your consent at any time;
  • lodge a complaint with a supervisory authority, such as the National Center for Personal Data Protection of the Republic of Moldova (datepersonale.md), the Romanian National Supervisory Authority for Personal Data Processing (dataprotection.ro), or the authority in your EU country of residence.

To exercise your rights, including deleting your account, email us at netforza.com@gmail.com from the email address linked to your account. We will respond within 30 days.

8. Cookies

We use only cookies that are strictly necessary for the Application to work:

  • auth-token: keeps you signed in (7 days);
  • NEXT_LOCALE: remembers your language (1 year);
  • oauth_google_state and oauth_google_verifier: protect the Google sign-in flow (10 minutes).

We do not use analytics, advertising or tracking cookies.

9. Security

We protect your data with measures such as encrypted connections (HTTPS), hashed passwords, HTTP-only session cookies and access restricted to authorised administrators. No method of transmission or storage is completely secure, but we work to protect your information and will notify you and the authorities of a personal data breach where required by law.

10. Children

The Application is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. The date at the top shows when it was last changed. If the changes are significant, we will notify you in the Application or by email.

12. Contact