Privacy policy

Privacy policy (GDPR)

How Lumora processes your personal data, including sensitive health data, under the General Data Protection Regulation (GDPR).

Data controller

Lumora – The Surgery Clinic is the data controller for the data you provide to us. Contact: info@lumora.clinic.

Data we process

  • Name, email, phone number and country.
  • Information about the desired treatment, budget and preferred timing.
  • Health data you choose to provide in forms or chat (special category data under Article 9 GDPR).
  • Conversation history from chat and email.

Purposes and legal basis

  • Answering and forwarding your request — your consent and pre-contractual steps.
  • Processing of health data — your explicit consent under Article 9(2)(a) GDPR.
  • Follow-up and administration — our legitimate interest in managing the client relationship.
  • Accounting and legal obligations — legal obligation.

Recipients and third-country transfers

After your explicit consent, relevant data is shared with the clinic you have chosen, which involves a transfer to Turkey (a third country). We also use IT providers for hosting, email, CRM and AI chat that process data on our behalf as processors.

We never sell your data.

Retention

Requests that do not proceed are normally deleted within 12 months. Data linked to a completed booking is kept for as long as needed for follow-up and legal requirements, after which it is deleted.

Your rights

Contact info@lumora.clinic to exercise any of these rights.

  • Access to your data.
  • Rectification of incorrect data.
  • Erasure and restriction of processing.
  • Data portability and objection to processing.
  • Withdraw your consent at any time, without affecting processing already carried out.
  • Lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

Cookies

We only use necessary cookies and local storage for language selection and to keep your chat session working.

Call usContact us