Quekly — Privacy Policy

Effective date: 29 August 2026

This Privacy Policy explains how NUN Analytics and Research, Unipessoal LDA ("we", "us", the operator) processes personal data through the Quekly mobile application and its backend when you book and manage medical appointments. We are the data controller. For any privacy request, contact us at info@nun-ar.org.

NUN ANALYTICS AND RESEARCH, UNIPESSOAL LDA
Sociedade por Quotas · NIPC/NIF 517775816
Rua José Correia Pires, número 4-B, 2800-694 Almada, Setúbal, Portugal
Data protection contact: info@nun-ar.org
Supervisory authority: Comissão Nacional de Proteção de Dados (CNPD), cnpd.pt

1. Who this applies to

Quekly is used by three types of people: patients (who book appointments), and clinic staff — doctors and administrators (who manage appointments). The app is intended for users in the European Union, Central Asia, and other regions. Because our company is established in the European Union, we apply the EU General Data Protection Regulation (GDPR) to all users, regardless of where they are located.

2. What data we collect

Patients

  • Profile you provide: full name, date of birth, phone number, and preferred app language (Uzbek, Russian or English).
  • Device identifier: a random, server-generated account ID (user_id) created for your device so your bookings stay linked to you. It is not your name and is not an advertising identifier. The app holds a sign-in token for this ID which is valid for 365 days and is renewed every time you use the app. If you reinstall the app or clear its data, that token is gone: the app registers a new identity, and the bookings and conversations of the old one can no longer be reached from the app. They remain in the database until they are deleted — section 11 explains how.
  • Female or male: asked once, when the app first starts. The account works without an answer. It is stored on your account and used for one thing: routing you to the right specialty — for example, not offering a gynaecologist to a man. It is not a gender profile and nothing else reads it.
  • Appointment records: the doctor you booked, the appointment date, time and duration, a booking reference/QR code, the appointment status (booked, confirmed, served, cancelled, no-show), and related timestamps.
  • Attendance history & risk indicator: from your booking records the clinic can see your history of completed, cancelled and missed appointments, and a simple derived "risk" level (low / medium / high) based on missed appointments. This is calculated on the fly and is visible only to clinic staff.
  • Messages to the automatic assistant and prescriptions written for you by a doctor, including the times you mark a dose as taken. See sections 3–5.
  • Reviews you leave about a doctor: a rating from 1 to 5 and, if you write one, a free-text comment. A review is linked to your account and to the appointment it is about. It is shown publicly in the app under an abbreviated name (for example "Islam K."); your full name is never published. Because a review names the doctor, it also reveals the specialty you attended — treat it as information about your health.
Health-related information. Quekly does not store medical records, diagnoses or test results. It does hold data that concerns your health: the doctor and medical specialty you book (for example a cardiologist or gynecologist), the content of your conversations with the automatic assistant, and prescriptions entered by your doctor. Section 3 explains how that data is handled.

Clinic staff (doctors, administrators)

  • Login name and a securely hashed password (bcrypt — we never store passwords in plain text), role (doctor / admin), and, for doctors, a professional profile (name, specialty, years of experience, short bio, working hours).

Technical data

  • IP address: used by our server to secure the service and limit abuse (rate-limiting). It is never written to our database and is not used to build a profile of you. It is written to the web server's access log, which is kept for 14 days and then deleted.
  • Security logs: records of key actions (e.g. an appointment marked as served) with timestamps, used for auditing. They hold account identifiers, never names or phone numbers, and are kept for 12 months. Error logs are scrubbed of personal data automatically, as far as that can be done reliably: quoted values and digit sequences that look like a phone number are removed, but automatic scrubbing cannot guarantee that every stray fragment is caught.

What we do NOT collect

  • No advertising identifiers, no cross-app or cross-site tracking.
  • No third-party analytics, advertising or marketing SDKs.
  • No contacts and no access to your photo library. The camera is used only, on your explicit permission, to scan an appointment QR code; scans are processed on the device. The microphone is used only while you dictate a message — see section 6.
  • Location: only if you allow it. The coordinates are used at that moment to show facilities near you and, while you are using the automatic assistant, to suggest a nearby facility to book at. They are not stored in our database and are kept out of our server access logs.
  • We never sell your personal data.

3. Health data

Some of the data processed in Quekly belongs to the special category of Art. 9 GDPR — data concerning health. This is:

  • the content of your conversations with the automatic assistant;
  • those messages when you agree to show them to a doctor;
  • prescriptions entered by a doctor, and your marks that a dose was taken;
  • appointment information, including the doctor's specialty.

Legal basis. This processing is carried out on the basis of your explicit consent (Art. 9(2)(a) GDPR), given separately from consent to the processing of other data. Consent may be withdrawn at any time; withdrawal does not affect the lawfulness of processing carried out before it.

Where it is processed. All data is stored and processed on servers rented by the operator inside the European Union. It is not transferred to third parties.

4. The automatic assistant

What it is. The automatic assistant is a software service that, based on the text you enter, suggests which specialist to turn to, shows the doctors of the selected facility and helps you book an appointment. The assistant is not a doctor and does not provide medical care.

What it does not do. The assistant does not establish a diagnosis, does not name probable illnesses, does not prescribe or recommend medicines, does not judge how urgent a condition is, and does not replace an in-person consultation. Decisions about treatment are made solely by a doctor.

How a request is processed. The language model runs locally on the operator's servers. The text of your messages is not passed to external artificial-intelligence providers, is not used to train models, and does not leave the operator's infrastructure.

Automated processing. Automatic rules are applied while a message is processed: detection of signs of conditions that require emergency help, and selection of a medical specialty. These rules do not take decisions producing legal effects for the user and do not restrict access to medical care. You can contact a facility directly at any time, bypassing the assistant.

Retention. Conversations with the assistant and the stored notes about past requests are kept for 30 days, after which they are deleted automatically. You can delete them at any moment in the profile section of the app.

One anonymous counter stays behind. When the automatic rules spot a phrase suggesting a condition that needs emergency help, a single row is written down: the category (for example "chest pain"), the language, the time, and a salted cryptographic hash of the phrase — never the phrase itself, and never a message. Nothing on that row points at you: no account identifier is stored on it. It is what lets us show that the detector still works, so it survives when you delete your conversation and when you delete your account. These rows are deleted after 180 days.

Backups. Deleted data may remain in daily backups for up to 14 days after deletion, after which the backups are overwritten.

Showing the conversation to your doctor

With a separate agreement, the doctor you have booked can read the messages you wrote to the assistant. Only your own messages travel, word for word, unedited and not summarised; the assistant's replies are not shown to the doctor.

The basis is your explicit consent (Art. 9(2)(a) GDPR), given separately for each appointment and switched off by default. Declining changes nothing: the appointment stands and the doctor is not told. You can withdraw at any moment, and access ends immediately.

Who sees it. Only the doctor of the appointment the consent was given for. The facility's administrator and the operator's staff do not. Every time a doctor opens the conversation it is written to an access log.

For how long. Access is open until a day after the appointment closes, and never longer than the 30 days the conversation itself is kept — nor after you delete your history.

If your messages name other people — a child, a partner, a relative — those words are shown too. Nothing is cut out, because editing them would stop them being your words.

The doctor may record what they consider medically relevant in your medical file at the facility. That record belongs to the facility and is kept under its rules, not ours.

5. Prescriptions and reminders

What is processed. A doctor of the facility can enter a prescription into the app: the name of the medicine, the dosage, the times and duration of the course, and notes. This information is visible to the patient it is addressed to, to the doctor who wrote it, and to the administrator of the corresponding facility.

Reminders. The app builds reminders on your device from the schedule entered by the doctor. Reminders are sent on behalf of the app, not on behalf of the doctor. The doctor does not track whether a reminder was delivered or whether a dose was taken on time.

Limitations. Delivery of a reminder depends on the state of the device, the notification settings and network availability. The operator does not guarantee delivery. A reminder does not replace the doctor's prescription; responsibility for following the course lies with the patient.

Retention. Prescriptions are medical records and are not deleted together with the assistant conversation: clearing a chat must not destroy the reason you are taking something. They are kept while your account exists and are erased with it — see section 11. Anything the doctor wrote into the facility's own medical file belongs to the facility and is kept under its rules, not ours.

6. Voice input

Speech recognition is performed on your device, by the operating system's own on-device recogniser, which the app requests explicitly. The audio is not saved to a file, is not transmitted to the operator's servers, and is not transmitted to the platform vendor or to any other speech-recognition service. Only the recognised text is sent to the server, where it is processed like any other message to the assistant.

Where the app cannot obtain that guarantee — a device, an operating system version or a language for which no on-device recogniser is available — the dictation button is not shown at all, rather than quietly falling back to a recogniser that would send your speech elsewhere. You can always type instead.

7. Why we process your data and our legal bases (GDPR)

  • To provide the appointment service (create, view, reschedule, cancel bookings) — performance of a contract with you (Art. 6(1)(b)).
  • To provide healthcare / manage medical appointments, including appointment data that may reveal health information — provision of health care and management of health-care systems (Art. 9(2)(h)) and/or your explicit consent (Art. 9(2)(a)).
  • To run the automatic assistant and to keep prescriptions and their reminders — your explicit consent (Art. 9(2)(a)), as described in section 3.
  • To remind you of appointments — reminders are shown as local notifications on your own device; the server does not send push messages to you.
  • To keep the service secure and reliable (authentication, rate-limiting, auditing) — our legitimate interests (Art. 6(1)(f)).

8. Where your data is stored and how we protect it

  • Hosting: our backend and database run on servers operated by Netcup GmbH in a data center in Germany (European Union).
  • The assistant's language model runs on that same server. No external AI service receives your messages.
  • Encryption in transit: all traffic between the app and the server uses HTTPS/TLS.
  • Passwords: staff passwords are stored only as bcrypt hashes.
  • Access control: access is authenticated with signed tokens (JWT) and restricted by role — patients can only access their own data; doctors see only their own patients; administrators are limited to clinic-management functions.
  • Backups: the database is backed up daily so your appointments are not lost; backups are kept for 14 days. As a safeguard against a backup job that stops running, the seven most recent copies are always kept, even once they are older than that.

9. Sharing and third parties

We share personal data only with the following, and only as needed to run the service:

  • Netcup GmbH (Germany, EU) — hosting provider acting as our data processor.
  • The facility you booked — only when you agree to show your assistant conversation to its doctor. The facility acts as a separate data controller: its doctor uses that data to provide care on their own legal basis.
  • Apple and Google — distribute the app (App Store / TestFlight, and Google Play). Their processing is governed by their own privacy policies. We do not send them your appointment or health data.
  • Brevo (Sendinblue, France, EU) and our SMTP provider — deliver the e-mail the service sends: account letters to clinic staff and correspondence with clinics applying to join. No patient data passes through them. Patients have no e-mail address in Quekly, so no e-mail about a patient is ever generated.
  • Telegramonly if your clinic uses the optional data-export feature. In that case an administrator can export appointment data as a file and send it to a clinic Telegram chat; that file is transmitted to Telegram. This feature is off unless the clinic enables it.

We do not share your data with advertisers or data brokers, and no provider of artificial intelligence services receives your data.

10. How long we keep your data

Your profile and your appointment records are kept for as long as your account exists. They are the clinic's appointment records, and nothing removes them on a timer — what ends them is you deleting the account, which you can do at any moment (section 11). Everything that does have a fixed end is listed here.

  • Assistant conversations and the notes about past requests: 30 days, or until you delete them yourself.
  • A doctor's access to a conversation: until a day after the appointment closes, and never beyond the 30 days above.
  • Prescriptions and dose marks: while your account exists; erased together with the account.
  • Security (audit) log: 12 months. When an account is deleted these entries stay, but they stop pointing at anyone — see section 11.
  • The anonymous emergency-phrase counter described in section 4: 180 days.
  • Technical idempotency keys (which stop a double tap from booking twice): 24 hours. A scheduled job removes them.
  • Backups: deleted data may survive in daily backups for up to 14 days.

11. Deleting your account

You can delete your Quekly account at any time, from your profile in the app. Deletion is immediate and permanent: there is no undo, no grace period, and no way for us or for the clinic to restore the account afterwards.

It erases everything held under your account: the account itself and the answer to the female/male question; your profile (name, date of birth, phone number); every appointment, past and future, together with the name it was booked under; your whole conversation with the assistant and the summary made from it; your consents to show that conversation to a doctor; prescriptions written for you inside Quekly and their intake schedule; your reviews; and your language preference. A future appointment is released, so that time returns to the doctor's calendar for other patients.

Two things stay, with no link to you. The clinic's security (audit) log keeps its entries — that an appointment was created at a certain time for a certain doctor, that it was cancelled — because the clinic has to be able to show what happened in its own booking system. Your identifier is removed from those entries, including from the details recorded alongside; what is left describes an event, not a person. The other is the anonymous emergency-phrase counter from section 4, which never held an identifier in the first place. Backups made before the deletion roll off within 14 days. Records the clinic keeps outside Quekly — on paper or in its own systems — are not ours to delete; ask the clinic directly.

If you have already uninstalled the app, you can still request deletion. The page /delete-account explains what we need in order to find the right account without deleting somebody else's, and requests can be sent to info@nun-ar.org. We act as soon as the account can be identified, and in any case within one month.

12. Your rights

In respect of your data you have the right of: access, rectification, erasure, restriction of processing, portability, objection to processing, and withdrawal of consent. Requests are sent to info@nun-ar.org and are handled within one month.

Erasure does not need a letter. The app deletes your account and everything under it immediately, and a public request page exists for the case where the app is already gone — see section 11.

You may include your Quekly patient code (shown in the app as QUEKLY • XXXX) to help us locate your records.

Consent to show a conversation to a doctor is withdrawn separately, in the app, for each appointment. Withdrawal ends access immediately; it cannot undo what the doctor has already read or already written into the facility's own records.

You also have the right to lodge a complaint with the supervisory authority — CNPD (cnpd.pt) — or with the supervisory authority of your country of residence.

13. Children

Quekly is not directed to children and is not intended for anyone under 16. Where a patient is a minor, the app should be used on their behalf by a parent or legal guardian, in line with local law. Because the health data in Quekly is processed on the basis of explicit consent, Art. 8 GDPR also applies: several member states have set the digital age of consent lower than 16 (as low as 13). In those countries the local age governs, and below it a parent or guardian must give or authorise the consent.

14. Changes to this policy

We may update this policy. Material changes will be reflected here with a new effective date.

15. Contact

NUN ANALYTICS AND RESEARCH, UNIPESSOAL LDA
Sociedade por Quotas · NIPC/NIF 517775816
Rua José Correia Pires, número 4-B, 2800-694 Almada, Setúbal, Portugal
Email: info@nun-ar.org
Supervisory authority: CNPD, cnpd.pt