Privacy Policy
Data processing and privacy policy in accordance with GDPR Regulation (EU) 2016/679
Effective: January 1, 2025
1 Data Controller
MedSoft s.r.o., Company ID: 46163581, registered at Fraňa Kráľa 2204/1, 915 01 Nové Mesto nad Váhom, Slovak Republic, operating the online service InfoSMS.online — a bulk SMS messaging gateway — acts as the data controller within the meaning of Article 4(7) of the GDPR.
In this policy the terms "we", "us" or "our company" refer to MedSoft s.r.o. The term "you" or "user" refers to a visitor of our website or a client using our services.
2 What Personal Data We Process
In connection with providing the SMS gateway service, we process the following categories of personal data:
- Registration data — the email address used when creating an account
- Operational data — records of sent and received SMS messages, including recipient and sender phone numbers, message content, timestamps and delivery status
- Technical data — IP address upon access to the portal and API, device type and web browser
- Payment and credit records — credit top-up and consumption history; payment card details are never stored on our servers
- Support correspondence — content of messages sent to our customer support
Recipient phone numbers are entered into the system by you as the customer and operator of your campaigns. In this relationship we act as a data processor — we process the numbers solely for the purpose of technically delivering the message.
3 Purpose and Legal Basis of Processing
- Service provision — account registration and management, SMS sending. Legal basis: performance of a contract (Art. 6(1)(b) GDPR)
- Billing and credit — recording payments and consumption. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR)
- Security and system protection — abuse detection, API protection. Legal basis: legitimate interest (Art. 6(1)(f) GDPR)
- Compliance with legal obligations — retention of operational records for law enforcement purposes. Legal basis: legal obligation (Art. 6(1)(c) GDPR)
- Customer support — communication when resolving technical issues. Legal basis: legitimate interest (Art. 6(1)(f) GDPR)
4 Data Retention
We retain personal data only for as long as necessary to fulfil the purpose of processing.
- Client account data — for the duration of the contractual relationship and 3 years after its termination
- SMS operational records — at least 12 months from the date of sending due to the statutory obligation to retain operational data
- Billing records — 10 years in accordance with accounting legislation
- Technical logs (IP addresses, access logs) — 90 days
After the applicable retention period, personal data are promptly anonymised or physically deleted.
5 Sharing Personal Data with Third Parties
We do not sell or provide your personal data to third parties for marketing purposes. We may share data exclusively in the following cases:
- SMS aggregators — technical intermediaries for SMS delivery (e.g. EuroSMS). These partners process recipient phone numbers solely for the purpose of message delivery and are contractually bound by confidentiality obligations.
- Public authorities — where required by law or on the basis of a lawful request from law enforcement authorities.
- Hosting and infrastructure services — the servers on which InfoSMS.online runs are located within the European Union.
6 Data Transfers Outside the EU
We process and store personal data exclusively on servers within the European Union. We do not transfer your data to third countries or international organisations unless we notify you in advance and ensure an adequate level of protection.
7 Your Rights
Under the GDPR you have the following rights in relation to us:
- Right of access — you may request confirmation of whether we process your personal data and a copy of that data
- Right to rectification — you may request correction of inaccurate or incomplete data
- Right to erasure — you may request deletion of data where the purpose of processing has ceased; this right does not apply to data we are legally required to retain
- Right to restriction of processing — you may request a temporary suspension of the processing of your data
- Right to data portability — you may request your data in a machine-readable format
- Right to object — you may object to processing based on legitimate interest
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time
- Right to lodge a complaint — you may contact the Office for Personal Data Protection of the Slovak Republic (dataprotection.gov.sk)
Please send requests to exercise your rights to info@medsoft.sk. We will respond to your request within 30 days.
8 Cookies
InfoSMS.online uses only strictly necessary (functional) cookies — cookies without which the portal would not function properly. These cookies are used solely for:
- Maintaining login during an active session (session cookie)
- Remembering your language preference
We do not use analytical cookies (Google Analytics), advertising cookies or any third-party tracking cookies.
9 Security of Personal Data
We have implemented appropriate technical and organisational measures to protect your personal data:
- Email addresses and phone numbers are stored in the database in encrypted form
- Portal access is password-protected; API access is secured with unique keys
- Communication with the server takes place over an encrypted connection (HTTPS)
- Database access is restricted to authorised personnel only
10 Changes to the Privacy Policy
We may update this policy from time to time in connection with changes in legislation or our services. We will notify you of material changes by email or by a notice in the client portal. The date of the last update is shown at the top of this document.