Data Protection Notice for Mira
1. Controller
The online appointment assistant “Mira” is used on the websites of medical practices or healthcare institutions.
The respective practice or organization is responsible for the processing of personal data within the meaning of the applicable data protection laws.
Coorpix AG, Switzerland, provides Mira as a technical platform within the framework of data processing on behalf of the controller.
2. Purpose of Data Processing
Mira is used exclusively for administrative support in structured appointment scheduling and booking.
Mira is not a medical diagnostic system and does not provide medical services.
The information entered during use is used solely for administrative assignment and appointment organization.
3. Processed Data
During use, the following personal data may be processed in particular:
- First and last name
- Date of birth
- Address
- Email address (e.g., for appointment confirmations)
- Voluntarily provided information about the reason for the visit
Information entered in the chat may contain health-related information. This information is processed exclusively for the purpose of administrative appointment allocation.
Mira does not store medical histories, does not provide diagnoses, and does not access existing patient records.
4. Legal Basis
Data processing takes place:
- in the context of initiating or carrying out a treatment relationship
- based on the applicable data protection regulations (in particular revFADP and, where applicable, GDPR)
Particularly sensitive personal data is processed only for the specified purpose and only to the extent necessary.
5. Technical Implementation and Data Processing
The technical provision of Mira is carried out by Coorpix AG as a data processor.
Identification data (e.g., name, date of birth, email address) is processed separately from the content entered.
Identification data is processed on servers located in Switzerland. For certain technical analysis or processing activities, external service providers may be used. In such cases, no directly identifying personal data is transmitted.
If data is transferred abroad, this is done in compliance with the legal requirements for international data transfers (e.g., appropriate safeguards or recognized data protection mechanisms).
Personal data will not be disclosed to unauthorized third parties.
6. Appointment Booking
Once an appointment is successfully selected, the required information is transmitted to the respective practice management system of the practice.
In addition to identification data, a short administrative note regarding the reason for the visit may be recorded where necessary for appointment organization.
Medical documentation is carried out exclusively within the practice management system of the respective institution.
7. Data Retention
Chat and interaction data are processed solely for technical operation, quality assurance, security, and error analysis.
They are deleted or anonymized no later than 90 days after the completion of the respective interaction, unless legal retention obligations or documented security incidents require longer storage.
Long-term storage of medical data takes place exclusively within the system of the respective practice.
8. Rights of Data Subjects
Under applicable data protection laws, data subjects have the right to:
- access
- rectification
- erasure
- restriction of processing
Requests should be directed to the respective practice as the responsible controller. Further information can be found in the privacy policy of the respective institution.
Data subjects also have the right to lodge a complaint with the competent data protection supervisory authority.
.png)