Back to home

Legal document

Privacy Policy and Terms of Use

Last updated: 23.09.2026 · translation requires human review

This document governs the use of the website synage.ee, communication related to OÜ MediArte services, and the processing of personal data. Synage.ee is the website of the OÜ MediArte clinic.

1. Service provider and data controller

1.1. OÜ MediArte

OÜ MediArte provides outpatient family medicine services.

  • Registry code: 12709264
  • Address: Lüüsi tn 4-30, 10154 Tallinn, Estonia
  • Service address: Ahtri 4, 2nd floor, 10151 Tallinn, Medemis Clinic
  • License: L07540
  • Email: info@synage.ee · Phone: +372 5565 1677

OÜ MediArte is the data controller for personal data collected on synage.ee and is responsible for healthcare services, doctor's appointments, telehealth appointments, processing of patient health data, documentation, invoicing and patient communication. The healthcare provider is Sergey Saadi.

2. General terms of website use

2.1. Purpose of the website

The website publishes information about OÜ MediArte healthcare services and general topics related to health and lifestyle optimisation. General content on the website is informational and does not automatically mean that a healthcare services contract has been concluded between the user and OÜ MediArte.

In case of an emergency or a rapidly worsening medical condition, call 112or go to an emergency department. The website, email and messaging channels are not intended for emergency care.

2.2. Use of the website

It is prohibited to interfere with the operation of the website, damage its security, violate the rights of third parties, submit false information or share access credentials with unauthorised persons.

2.3. Intellectual property

The website content (texts, videos, materials, designs, photos and logos) belongs to OÜ MediArte or is used lawfully. Copying, distribution, reworking and publishing without permission is prohibited.

2.4. Links to third-party environments

OÜ MediArte is not responsible for the content or security of third-party websites, except to the extent that they are used as authorised processors.

3. Privacy policy – general part

3.1. Definitions

Personal data means any information relating to an identified or identifiable natural person.

Health data is a special category of personal data concerning physical or mental health, health status, diagnoses, examinations, test results, treatment, medical history or other circumstances related to health.

Processing means any operation performed on personal data: collection, recording, organization, storage, use, transmission, deletion and destruction.

3.2. General processing principles

  • data is processed lawfully, fairly and transparently;
  • data is collected for specified and legitimate purposes;
  • only the minimum necessary data is collected;
  • data is kept as accurate and up-to-date as possible;
  • data is stored only as long as necessary or required by law;
  • data is protected with appropriate technical and organizational measures.

3.3. Data subject rights (GDPR)

  • to be informed about the processing of your personal data;
  • to request access, rectification or erasure;
  • to request restriction of processing or to object;
  • to withdraw consent if processing is based on consent;
  • to receive data in a machine-readable format (data portability);
  • to lodge a complaint with the Data Protection Inspectorate: info@aki.ee · aki.ee.

For healthcare services, some rights may be restricted to the extent that data retention arises from the statutory obligations of the healthcare provider.

3.4. Data security

Measures applied: access right restrictions, authentication, confidentiality obligations, secure communication channels, data backup, system and log monitoring, contracts with authorised processors, and additional precautions when handling health data.

4. OÜ MediArte privacy terms for healthcare services

4.1. When this section applies

When a person books a medical appointment, attends an in-person or remote consultation, transmits health data through a clinical channel provided by the physician, uses a health optimisation programme, or communicates with OÜ MediArte as a patient.

4.2. Data processed

General personal data: name, personal identification code, date of birth, contact details, address, language of communication.

Health data: complaints, anamnesis, medical history, diagnoses, test results, medications, allergies, prior treatment, risk factors, treatment plan.

Booking and communication data, payment and accounting data, technical data (IP, browser info, logs, cookies).

4.2.1. Public contact form

The public contact form is for administrative enquiries only. It collects name, email address, optional telephone number, language of communication and preferred contact method. It does not request diagnoses, symptoms, test results or a free-text health description. The enquiry is stored in the web system managed by OÜ MediArte and the notification is sent only to info@synage.ee.

4.3. Purposes and legal bases

  • Provision of healthcare services – contract performance, legal obligation, and GDPR Art. 9(2)(h).
  • Preparation and organization of healthcare services – contract performance and legitimate interest.
  • Documentation and statutory obligations.
  • Continuity of care and cooperation with other healthcare providers.
  • Invoicing and accounting.
  • Defence of legal claims.
  • Marketing – only on the basis of consent; patient health data is never used for marketing.

4.4. Data sources

From the patient themselves, their legal representative, documents submitted by the patient, booking channels, the telehealth platform, and – where permitted by law – from other healthcare providers.

4.5. Data transfers

OÜ MediArte does not sell personal data. Data may be transferred only as necessary to IT and hosting providers, booking and communication channels, the payment-platform provider Montonio Finance OÜ, accounting providers, laboratories and the genetic-test provider, the insurer, public authorities and legal advisors. Montonio processes data obtained on its external payment or instalment platform as an independent controller under its own privacy policy.

International transfers: according to Montonio's published privacy policy, Montonio generally processes personal data within the European Economic Area but may use service providers outside the EEA. In such cases Montonio applies the safeguards required by Chapter V of the GDPR, such as a European Commission adequacy decision or Standard Contractual Clauses. Further details are available in Montonio's privacy policy.

4.6. Telehealth and digital channels

Remote consultations may take place by phone, video link, the eKliinik / Connected platform or another secure channel. Not all health issues can be adequately assessed remotely.

4.7. Messengers and chat channels

Some services provide remote support through a protected channel or via Telegram/WhatsApp. Telegram and WhatsApp are not intended for transmitting health data, test results or sensitive documents. A patient may use these messaging channels only after written acknowledgement and sends information there at their own risk. Messaging channels are not intended for emergency care – in case of an acute condition call 112.

4.8. Retention

  • Healthcare data – in line with regulations governing the documentation of healthcare services.
  • Accounting data – generally 7 years from the end of the financial year.
  • Marketing consent – until consent is withdrawn.
  • Technical logs – 30 days.

4.9. Genetic-test data

The genetic test offered via synage.ee is an informative consumer-genetics test, not a diagnostic clinical genetic test or a national screening programme. Even so, DNA, genetic variants and genetic reports are special-category and highly sensitive personal data under GDPR. They are processed only on the basis of separate consent, the service description and the need to provide healthcare services.

Genetic-test data is used to organise the sample, transmit the data to the genetic-test provider or laboratory, make results available to the patient and provide the doctor's explanation during the consultation. OÜ MediArte does not use genetic data for marketing, profile sale, insurance or employer decisions, or research without a separate clear legal basis. Raw DNA files and full reports are not kept longer than necessary for the service; healthcare documentation created during the consultation is kept under healthcare documentation requirements.

4.10. Payment processing and instalments

We use the payment platform of Montonio Finance OÜ (registry code 14557628) to process service payments. The patient enters their name and email address in the initiation form on Synage.ee; OÜ MediArte uses these to connect the request with the specific service. Montonio receives the order number, amount and generic description “Synage service, order no. [order number]”. The service name, diagnosis, symptoms, test results or other health information are not sent to Montonio.

The patient is then redirected to Montonio. Authentication and processing of personal identification code, income, liabilities, account statements and creditworthiness take place in Montonio's or the creditor's environment. OÜ MediArte does not receive the patient's income, liabilities, account statement or reasons for the credit decision; it receives only the status, reference and payment confirmation needed to administer the order.

OÜ MediArte and Synage are neither a creditor nor a credit intermediary and do not issue or intermediate consumer credit. Any agreement is entered into between the patient and the provider selected on the external platform. The role of Montonio, a creditor or another party is determined by the specific processing operation; they are not automatically treated as processors acting for OÜ MediArte.

Legal basis: performance of a contract (GDPR Art. 6(1)(b)) and compliance with accounting obligations (GDPR Art. 6(1)(c)). Payment-related data is retained for the statutory accounting period of 7 years.

5. Marketing, newsletter and social media

News, offers and notifications are sent only on a valid legal basis. Patient and health data are not used for marketing without separate consent. You can unsubscribe at any time via the unsubscribe link in emails or by writing to info@synage.ee.

Sensitive health data must not be shared in social media comments.

6. Cookies and technical site data

The website uses four categories of cookies:

  • essential – basic site operation, login, session, language selection, CSRF protection and storing your cookie consent. No consent required.
  • analytics – pseudonymous usage statistics.
  • marketing – advertising pixels and campaign performance (e.g. Meta, Google Ads). Marketing cookies are not loaded on this site at present.
  • third-party cookies and embeds – Bunny Stream (video), social media and others. Montonio opens on a separate website and does not load scripts on synage.ee.

Non-essential cookies are used only with your consent. Consent can be changed or withdrawn just as easily as it was given – via the footer link „Cookie settings“ or the button below. Your decision is stored with a timestamp and policy version in our database.

Concrete list

NameProviderThird partyExpiryCategoryPurpose
synage_cookie_consent_v1synage.eeNo1 yearessentialStores your cookie choices
synage_visitor_idsynage.eeNo1 yearessentialPseudonymous identifier for the consent log
sb-*-auth-tokensynage.eeNosessionessentialSigned-in session
_ga, _ga_*Google AnalyticsYes (Google)up to 2 yearsanalyticsUsage statistics (with consent)
__cf_bm, cf_clearanceCloudflareYes (Cloudflare)up to 30 min / 1 yearessentialSecurity and bot protection
Bunny Streambunnycdn.com / b-cdn.netYessessionthird partyVideo player operation
Montonio external-platform cookiesMontonio Finance OÜNo on synage.eeset by Montonioexternal servicePayment or instalments after redirect

7. Minors

The provision of healthcare services to a minor follows applicable law and, where necessary, the involvement of a legal representative.

8. Dispute resolution and applicable law

These terms are governed by Estonian law. Disputes are first resolved by negotiation. Consumers have the right to refer disputes to the Consumer Disputes Committee. Complaints relating to the processing of personal data may be lodged with the Data Protection Inspectorate (info@aki.ee · aki.ee).

9. Changes

OÜ MediArte may amend these terms. The updated version is published on the website and enters into force upon publication, unless a later effective date is indicated in the document.

10. Data retention periods

Data categoryControllerPeriod
Patient healthcare documentationOÜ MediArteUntil the healthcare documentation obligation ends
Genetic test dataOÜ MediArteRaw data/full report until service delivery + 30 days; consultation note under healthcare documentation rules
Accounting and invoice dataOÜ MediArteGenerally 7 years from the end of the financial year
Marketing consentOÜ MediArteUntil withdrawn
Cookie-consent logsOÜ MediArte30 days
Technical logsOÜ MediArte30 days

11. Contact

Email: info@synage.ee

Phone: +372 5565 1677

Enquiries about healthcare services, synage.ee and personal data are handled by OÜ MediArte.

Home