top of page

PRIVACY & HEALTH DATA NOTICE

Operational Draft v1.0
Last updated: 27 August 2026

1. Who controls your data

Krinex is a product of Flytohealth Kft. ("Krinex", "we", "us").

 

Controller:
Flytohealth Kft.
Registered office: 1037 Budapest, Táborhegyi út 16. G. ép. Fsz. 3. ajtó, Hungary
Company registration number: 01-09-436151
Tax number: 32663596-2-41

Privacy contact:
contact@krinex.ai

2. What this Notice covers

This Notice applies when you use Krinex Clinical public medical intake, secure document upload, patient portal and related clinical-review workflows.

​

Krinex Clinical is an AI-assisted clinical intelligence and information-preparation platform. It supports clinical review workflows. It does not replace emergency medical care or the professional judgment of an authorized clinician.

3. Information We May Process

Depending on the service you use, we may process:

​

- identity and contact information, such as name, email address, telephone/WhatsApp number, country and account identifiers;
- demographic and clinical-context information you provide through the intake form;
- information concerning health, including symptoms, diagnoses, medical history, medications, allergies, previous procedures and treatment goals;
- medical documents and images that you choose to upload;
- case, referral and partner-link information needed to route and administer your case;
- communications and workflow records;
- technical, security and audit information required to operate and protect the service.

​

Health information is a special category of personal data under the GDPR.

4. Why We Use Information

We may process your information to:

​

- receive and administer your clinical intake;
- organize and analyse the information and documents you submit;
- reconstruct relevant clinical context and identify missing or conflicting information;
- prepare information for authorized clinician review;
- support care coordination and case workflow management;
- allow clinicians to request additional information where needed;
- prepare, review and deliver clinician-approved outputs;
- maintain security, audit trails, service integrity and operational records;
- comply with applicable legal and regulatory obligations.

5. Legal basis and explicit consent for health data

For the public Krinex Clinical intake workflow, we rely on your consent under Article 6(1)(a) GDPR where consent is the applicable legal basis.

​

Because the intake may include data concerning health, we ask for your explicit consent for the processing of that health data under Article 9(2)(a) GDPR.

​

Certain limited processing may also be necessary to comply with legal obligations, protect the security and integrity of the service, establish or defend legal claims, or meet other lawful requirements where applicable.

​

You may withdraw consent for future processing by contacting contact@krinex.ai.
Withdrawal does not affect processing that was lawful before withdrawal. Some information may still need to be retained where another legal obligation or lawful basis requires it.

6. AI-assisted processing and human oversight

Krinex Clinical may use AI-assisted tools to extract, structure, organize and analyse information contained in your intake and submitted medical documents.

​

AI-assisted output may help identify relevant information, chronology, relationships, uncertainty, missing information and safety signals for review.

​

AI-assisted output does not by itself constitute a final medical decision. Clinical interpretation, editing, approval and professional responsibility remain with the authorized clinician or other responsible human reviewer for the relevant workflow.

​

For more information, see the Krinex Clinical AI-Assisted Processing Notice.

7. Who may receive or process your information

Access is limited according to role and workflow need. Depending on your case, information may be accessible to:

​

- authorized Krinex personnel involved in operating or supporting the service;
- the authorized clinician or clinical reviewer assigned to your case;
- a referring healthcare or partner organization where your case was submitted through   that organization's secure referral link and disclosure is necessary for the agreed   workflow;
- contracted technology and service providers supporting hosting, secure storage, communications, document processing, AI-assisted processing, security and platform operations.

​

Service providers act under contractual and data-protection obligations appropriate to their role.

8. International Data Transfers

Some contracted technology providers may process data outside Hungary or the European Economic Area. Where GDPR transfer restrictions apply, Krinex will use an applicable lawful transfer mechanism and appropriate safeguards, such as an adequacy decision or
Standard Contractual Clauses, as required.

​

Before publication, verify this section against the actual processor/subprocessor list and current transfer agreements.

9. How long we keep information

We keep personal and clinical information only for as long as necessary for the purposes described in this Notice, including the clinical-review workflow, continuity, security, audit, dispute handling and applicable legal obligations.

​

A specific retention schedule should be approved and inserted here before this Notice is treated as final legal policy. Do not publish an invented retention period.

10. Security

Krinex uses technical and organizational safeguards intended to protect personal and health information, including controlled access, secure links, role-based authorization, auditability and appropriate security controls within the platform and its contracted
services.

​

No internet-based service can guarantee absolute security.

11. Automated Decision-Making

Krinex Clinical is designed as a human-reviewed workflow. AI-assisted processing may support information preparation and clinical review, but the platform is not intended to make solely automated final medical decisions about you without meaningful human
review.

12. Your rights

Subject to the GDPR and applicable law, you may have rights to:

​

- access your personal data;
- correct inaccurate or incomplete data;
- request erasure;
- request restriction of processing;
- object to certain processing;
- receive data in a portable format where applicable;
- withdraw consent where processing is based on consent;
- lodge a complaint with a competent data-protection supervisory authority.

​

To exercise a privacy right, contact:
contact@krinex.ai

​

You may also contact the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) or another competent supervisory authority where applicable.

13. Partner-referred cases

If you enter Krinex Clinical through a secure Partner assessment link, the referral token may associate your submitted case with the referring Partner organization for workflow and care-coordination purposes.

​

The relevant Partner may act as a separate controller, joint controller or recipient depending on the specific relationship and service arrangement. This role allocation should be documented contractually for each Partner model.

14. Changes to this Notice

We may update this Notice as the service, processing activities or legal requirements change. The current version and effective date will be published on the Krinex website.

​

Contact
contact@krinex.ai

bottom of page