Privacy Policy
Website: Dr. Veronika Stavrou
Effective Date: 31 July 2026
1. Introduction
Dr. Veronika Stavrou respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how personal information is collected, processed, stored, and protected when you visit this Website, contact the practice, request information, or otherwise communicate with Dr. Veronika Stavrou. This Privacy Policy has been prepared in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Cyprus data protection legislation.
2. Data Controller
The data controller responsible for the processing of your personal data is Dr. Veronika Stavrou, Medical Doctor, with registered address at Andrea Avraamidi 47, Office 111, (Apex Building), Strovolos 2024, Nicosia, Cyprus. For any questions regarding the processing of personal data or the exercise of your data protection rights, you may contact the practice at info@drstavroufmc.com or by telephone at +357 22 282 022.
3. Personal Data We May Collect
When you use this Website or communicate with Dr. Veronika Stavrou, personal information may be collected depending on the nature of your interaction. This may include identification and contact information such as your name, email address, telephone number, and any other information that you voluntarily provide through contact forms, appointment requests, email correspondence, or other communication methods.
Where you voluntarily provide information relating to your health, symptoms, medical history, or treatment needs, such information may constitute special category health data under Article 9 of the GDPR. Any health-related information provided to the practice will be treated confidentially and processed only where permitted by applicable data protection legislation and professional medical confidentiality obligations.
The Website may also automatically collect certain technical information when you visit, including information such as your IP address, browser type, device information, Website usage information, and information collected through cookies or similar technologies.
4. How Personal Data Is Collected
Personal data may be collected directly from you when you complete a contact form, submit an appointment request, contact the practice by email or telephone, or otherwise voluntarily provide information. Certain technical information may also be collected automatically through cookies, website hosting services, analytics services, or other technologies used to maintain and improve the Website.
5. Purpose of Processing Personal Data
Your personal data may be processed for the purposes of responding to enquiries, managing appointment requests, communicating with patients or prospective patients, providing information about medical services, maintaining the security and functionality of the Website, improving Website performance, and fulfilling legal, regulatory, and professional obligations applicable to medical practice.
6. Legal Basis for Processing
Personal data is processed only where there is a lawful basis under applicable data protection legislation. Depending on the circumstances, processing may be based on your consent, where you have provided permission for a specific purpose; on the necessity to respond to your requests or provide requested services; on compliance with legal or professional obligations; or on legitimate interests related to the operation, security, and improvement of the Website and medical practice.
7. Processing of Health Information
Health information is considered special category personal data under the GDPR and receives additional protection. Where health information is processed, Dr. Veronika Stavrou applies appropriate safeguards and ensures that such information is handled confidentially and only accessed by authorized persons where necessary for legitimate healthcare-related purposes or legal obligations.
8. Data Retention
Personal data will only be retained for as long as necessary to fulfil the purposes for which it was collected or for as long as required by applicable legal, regulatory, professional, or medical record-keeping obligations. When personal data is no longer required, it will be securely deleted or anonymised where appropriate.
9. Data Security
Dr. Veronika Stavrou applies appropriate technical and organisational measures designed to protect personal data against unauthorized access, accidental loss, misuse, alteration, disclosure, or destruction. Although reasonable efforts are made to protect information, no method of electronic transmission or storage can be guaranteed to be completely secure.
10. Sharing of Personal Data
Personal data will not be sold, rented, or otherwise disclosed for commercial purposes. Personal information may only be shared where necessary for the operation of the Website, the provision of healthcare services, compliance with legal obligations, or protection of legitimate interests. This may include trusted service providers such as Website hosting providers, technology providers, healthcare professionals involved in care where legally appropriate, or public authorities where disclosure is required by law.
11. International Data Transfers
Some Website service providers or technology providers may process information outside the European Economic Area. Where such transfers occur, appropriate safeguards required under the GDPR will be implemented to ensure that personal data receives an adequate level of protection.
12. Your Data Protection Rights
Under applicable data protection law, you may have the right to request access to your personal data, request correction of inaccurate or incomplete information, request deletion of personal data where legally permitted, request restriction of processing, object to certain types of processing, request data portability where applicable, and withdraw consent where processing is based on consent.
To exercise any of these rights, you may contact Dr. Veronika Stavrou at info@drstavroufmc.com. You also have the right to lodge a complaint with the competent supervisory authority responsible for data protection matters in Cyprus, the Office of the Commissioner for Data Protection.
13. Children’s Privacy
This Website is not intended to knowingly collect personal information from children without appropriate parental or legal guardian consent where such consent is required by law.
14. Updates to This Privacy Policy
This Privacy Policy may be updated periodically to reflect changes in legal requirements, Website functionality, technology, or the way personal data is processed. Any updates will be published on this page together with the revised effective date.
Last updated: 31 July 2026
