1. Scope and Controller
This policy explains how personal data are processed through radioterapie.eu, the installable RT Navigator application, the Clinical Navigation Tools, courses, contact forms and related services.
Data Controller: Razvan Alexandru
Address: 140 Rue Claude Monet, Montpellier, France, 34090
Privacy contact: doc.alexandru@outlook.fr
2. Clinical case data remain on the device
| Local-first processing: Patient case information entered into the current Clinical Navigation Tools is processed in the user’s browser or device. It is not transmitted to, stored by or accessible to radioterapie.eu. |
Where a tool provides case saving, the saved information and preferences may be stored in browser storage on that device. The user controls those data. Clearing the site’s browser data, uninstalling the application or using an available delete/reset function may remove them permanently. radioterapie.eu cannot recover locally stored cases.
Users should secure their devices, avoid saving clinical cases on shared devices, use only information necessary for the task and follow their institution’s confidentiality and information-security policies. Identifiable patient information must never be submitted through the contact form, Radar subscription or other networked fields.
If a future feature requires transmission of clinical information, it will not be silently covered by this statement. The feature will require a separate assessment, clear information before use and appropriate technical and legal safeguards.
3. Website access, hosting and security logs
When the website or application shell is requested, the hosting infrastructure may process the IP address, date and time, requested URL, referrer, browser and device information, response status and security-event information. This processing is necessary to deliver and secure the service, diagnose failures and prevent abuse. The legal basis is the Controller’s legitimate interest in operating a secure and reliable service.
Technical logs are available only to authorized personnel and hosting or security providers. They are retained for twelve months and then deleted or irreversibly aggregated, unless a specific security incident or legal obligation requires longer retention.
4. Browser storage and the installable application
The progressive web application uses a service worker and browser cache to make application code and selected resources available reliably. Browser storage may also hold user preferences, local audit queues and saved cases where the user requests those functions. These local records are not an online patient record, are not backed up by radioterapie.eu and should not be treated as the institution’s official medical record.
5. Cookies, consent and audience measurement
radioterapie.eu uses a consent-management platform to record cookie choices and to permit or block non-essential services. Strictly necessary storage may be used without consent where permitted by law. Analytics, measurement, embedded media and similar non-essential technologies are activated only in accordance with the user’s consent and the applicable cookie rules.
The site currently includes a Google tag and may use Google measurement services where consent has been given. Depending on the configured service, data may include an online identifier, IP-derived information, device/browser characteristics, pages visited and interaction events. The exact services, cookies, purposes, providers and durations are listed in the Cookie Policy generated from the current site scan.
Users can withdraw or change consent at any time through the persistent Manage consent control. Refusing non-essential cookies must not prevent access to the core Clinical Navigation Tools.
6. Contact and feedback form
The contact form may collect the sender’s first and last name, email address, optional country or institution, message type, selected Navigator/page, page URL and message. It also records confirmation that the message contains no identifiable patient information.
The purposes are to respond, investigate technical or clinical-scientific reports, improve the tools and assess collaboration proposals. The legal basis is taking steps at the sender’s request and the Controller’s legitimate interest in communication, quality improvement and service safety.
Ordinary contact records are retained for up to 24 months after the last substantive exchange. A report incorporated into the project’s evidence, change-control or safety record may be retained longer in a minimized or de-identified form. Spam and rejected submissions may be deleted sooner.
The form is operated through WordPress and a form-management component and is protected by anti-spam services. Where Google reCAPTCHA or another third-party security service is activated, that provider may process IP, browser/device and interaction signals. Such services are controlled through the consent and security configuration where required.
7. Courses and user accounts
If account registration or course enrolment is enabled, radioterapie.eu may process account identity and contact details, authentication and security records, enrolments, course progress, quiz or assessment results and certificates. Processing is necessary to provide the requested account or educational service and to secure it.
Account and course-progress data are retained while the account is active and for up to two years afterward, unless the user requests earlier deletion or legal, accounting, security or certification requirements justify longer retention.
8. Radar email alerts and subscriptions
Where email alerts are offered, the service may process the email address, selected disease areas/topics, country preferences, subscription status, consent timestamp and delivery events. The legal basis is consent. Subscription data are used only to deliver and administer the selected alerts and are retained until unsubscribe or prolonged inactivity. Limited evidence of consent and suppression information may be retained for up to three years to demonstrate and respect the user’s choice.
Every alert must provide a simple unsubscribe mechanism. Email alerts must never contain identifiable patient information.
9. Country preselection
Where automatic country preselection is available, the service may derive an approximate country from the connection’s IP address so that an appropriate national context can be displayed by default. It does not seek precise location, does not combine the result with clinical case information and allows the user to select another country. The selected preference may be retained locally on the device.
10. Recipients and processors
Personal data are accessible only to the Controller and authorized persons who need them for the stated purposes, together with contracted providers supporting hosting, security, forms, consent management, analytics, email delivery and course delivery. Providers may act as processors or, for some services, as independent controllers under their own notices.
Current categories of providers include the hosting provider, WordPress components, Complianz, Fluent Forms, Tutor LMS, Google services where enabled and the email-delivery provider used for subscriptions. The Cookie Policy provides the current cookie/vendor inventory.
11. International transfers
Some providers may process data outside the European Economic Area. Where applicable, transfers are based on an adequacy decision or appropriate safeguards such as the European Commission’s standard contractual clauses, supplemented where required. Non-essential third-party services remain subject to consent where the law requires it.
12. Rights
Subject to the applicable conditions, individuals may request access, rectification, erasure, restriction, portability or objection and may withdraw consent at any time without affecting earlier lawful processing. Requests should be sent to doc.alexandru@outlook.fr. Identity information will be requested only where reasonably necessary to prevent unauthorized disclosure.
Individuals may also lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL) or another competent supervisory authority.
13. Security and responsibility
The Controller applies proportionate technical and organizational measures, including access control, software updates, encrypted transport, backups, consent controls and minimization. No internet or device-storage system is completely risk-free. Users remain responsible for securing devices and exports under their control.
14. Automated decisions and children
The website does not make decisions producing legal or similarly significant effects about website visitors. The service is intended for adult healthcare professionals and trainees and is not directed to children.
15. Updates
This policy will be updated when data flows, processors or services change. Material changes will be identified by a new revision date and, where appropriate, brought to users’ attention before the new processing begins.
Last updated: 26 August 2026.