Privacy Policy

ODEON Health A.M.K.E. ("ODEON Health", "we", "us") is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, how we use it, and what rights you have under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Greek data protection law.

01

Who We Are

ODEON Health A.M.K.E. is a Greek non-profit association (Αστική Μη Κερδοσκοπική Εταιρεία) registered in ODEON Health A.M.K.E., 84400 Paros, Cyclades | Greece.

DetailInformation
Full legal nameODEON Health A.M.K.E.
RegistrationG.E.MI. 194135838000 · AFM 803301500
Registered addressODEON Health A.M.K.E., 84400 Paros, Cyclades | Greece
Data ControllerODEON A.M.K.E.
GDPR contactMehdi Khaled · privacy@odeonhealth.org
Websiteodeonhealth.org
02

What Data We Collect and Why

We collect personal data in the following contexts. We only collect what is necessary for the stated purpose.

ContextData collectedPurposeLegal basis
Website contact form Name, email address, role/title, institution name, message content Responding to institutional enquiries and partnership requests Legitimate interests (Art. 6(1)(f) GDPR)
DHSAT / AI-SAT assessment (L1–L3, institutional deployment) Assessment responses; competency scores by domain; assigned level; professional role; department (as provided by deploying institution) Generating individual and institutional capability reports; tracking competency development Legitimate interests (Art. 6(1)(f) GDPR) — processing is covered by the institutional contract between ODEON Health and the deploying institution
DHSAT / AI-SAT assessment (L4–L5, direct individual enrolment) As above, plus identity verification data for credentialling Issuing verifiable digital credentials; tracking specialist pathway progress Explicit consent (Art. 6(1)(a) GDPR) — provided at point of individual registration
ODEON Health Academy — course participation Course completion records; module scores; learning activity logs Issuing credentials; generating progress reports; CME record-keeping Contract performance (Art. 6(1)(b)) and/or legitimate interests (Art. 6(1)(f))
Digital credentials (badges) Name; credential type and level; date of issue; issuing institution Issuing and verifying Open Badges / IMS Global credentials Contract performance (Art. 6(1)(b))
Website session Session cookies (strictly necessary); browser type; approximate location (country level) Maintaining session state; ensuring site security Legitimate interests (Art. 6(1)(f)) — strictly necessary cookies do not require consent

Note on institutional deployments (L1–L3): Where ODEON Health deploys the assessment on behalf of an institutional partner, the institution is responsible for informing their clinical workforce of the assessment and its purpose. ODEON Health acts as data controller and the institution acts as deploying partner under a Data Processing Agreement.

03

How We Use Your Data

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

04

Who We Share Your Data With

We do not sell personal data. We share personal data only with the following categories of recipients, all of whom are contractually bound to process data in accordance with GDPR.

RecipientRoleLocationData shared
OVM FranceDatabase hosting sub-processorFrance (EU)Assessment and user data
EurekosLearning Management System (LMS)Denmark (EU)Course completion, learning logs
CertifierDigital credential issuanceAWS Dublin (EU)Name, credential type, issue date
Institutional partnersDeploying organisations (L1–L3)EU / EEAAggregated institutional reports only — no individual identifiable data shared without explicit consent
Regulatory bodiesWhere legally requiredEU / EEAMinimum necessary to comply with legal obligation

All sub-processors are located within the EU or EEA, or operate under Standard Contractual Clauses (SCCs) where applicable.

05

How Long We Keep Your Data

Data categoryRetention periodRationale
Contact form submissions2 years from last contactStandard correspondence retention
Assessment responses and scores5 years from date of assessmentStandard professional records retention; supports longitudinal competency tracking
Digital credentialsDuration of credential validity + 5 yearsCredential verification and audit purposes
Course completion records5 years from course completionCME accreditation records; professional development evidence
Session cookiesSession duration onlyStrictly necessary; no persistent tracking

After the applicable retention period, data is securely deleted or anonymised. Anonymised, aggregated data (from which no individual can be identified) may be retained indefinitely for research and curriculum development purposes.

06

Cookies

ODEON Health uses session cookies only. These are strictly necessary for the operation of our website and assessment platform. They expire at the end of your browser session and do not track you across other websites.

We do not use analytics cookies, advertising cookies, or any third-party tracking technologies. No cookie consent banner is required.

07

Your Rights Under GDPR

As a data subject, you have the following rights. To exercise any of them, contact us at privacy@odeonhealth.org. We will respond within 30 days.

RightWhat it means
Access (Art. 15)Request a copy of the personal data we hold about you.
Rectification (Art. 16)Request correction of inaccurate or incomplete data.
Erasure (Art. 17)Request deletion of your personal data where there is no overriding legitimate reason to retain it.
Portability (Art. 20)Request your data in a structured, machine-readable format.
Restriction (Art. 18)Request that we limit processing of your data in certain circumstances.
Objection (Art. 21)Object to processing based on legitimate interests.
Withdraw consentWhere processing is based on consent (L4–L5), withdraw it at any time without affecting prior processing.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA)www.dpa.gr — or the supervisory authority in your country of residence.

08

Data Security

ODEON Health implements appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include:

09

International Transfers

All primary data processing takes place within the EU or EEA. Where any sub-processor operates infrastructure outside the EEA (for example, Certifier via AWS Dublin), ODEON Health ensures adequate safeguards are in place through Standard Contractual Clauses (SCCs) as approved by the European Commission.

ODEON Health's services are currently available to institutions within the EU and EEA. Worldwide availability is anticipated in a future phase; this policy will be updated accordingly.

10

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the version number and date at the top of the document and, where changes are material, notify institutional partners directly. Continued use of ODEON Health services after any update constitutes acceptance of the revised policy.

This policy was last updated in September 2026.

11

Contact

For any questions about this Privacy Policy or to exercise your data subject rights: