Privacy Policy
Last updated: 25 August 2026
This Privacy Policy explains how “PRIVATE DIAGNOSTIC LABORATORY BIOXOROS MEDICAL SINGLE-MEMBER P.C.” (“BIOXOROS”) processes and protects personal data in connection with this website and the provision of diagnostic services.
1. Data controller
The data controller is BIOXOROS MEDICAL SINGLE-MEMBER P.C. For privacy matters, you may contact us using the details shown on the website’s Contact page.
2. Data we may process
Depending on the service, we may process identification and contact details, information required to provide and bill services, insurance information, and health data relating to referrals, samples, laboratory tests and results. Health data are a special category of personal data and receive enhanced protection.
3. Purposes and legal bases
We process data only where necessary, including to provide laboratory/diagnostic services, identify the person tested, issue and securely deliver results, meet obligations towards insurers and public authorities, comply with accounting and tax requirements, assure quality and security, and establish or exercise legal claims. The applicable legal bases arise, as appropriate, under Articles 6 and 9 GDPR, including the necessity of health care/medical diagnosis, compliance with legal obligations and, where genuinely required, consent.
4. Recipients
Access is limited to authorised persons and service providers on a need-to-know basis. Where lawful and necessary, data may be disclosed to treating healthcare professionals, insurers/public bodies, IT and technical-support providers, accounting or other professional advisers, and competent authorities, subject to appropriate confidentiality and security safeguards.
5. Retention
Personal data are retained no longer than necessary for the relevant purposes and for periods required by applicable healthcare, tax, insurance or other legislation. Where no specific period applies, retention is determined by necessity, legal obligations and limitation periods for legal claims.
6. Security and test results
Appropriate technical and organisational measures are used to protect data against unauthorised access, loss, alteration or disclosure. Online test results are accessed through the dedicated results service and/or the sLIS Mobile application and are subject to the relevant authentication and security mechanisms.
7. Your rights
Subject to the GDPR, you may exercise rights of access, rectification, erasure, restriction, objection and, where applicable, data portability. Where processing relies on consent, consent may be withdrawn without affecting the lawfulness of prior processing. Some rights may be limited where processing or retention is required by law, necessary for healthcare, or required for legal claims.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority.
8. Cookies and technical data
The website may use strictly necessary cookies for secure and proper operation. Non-essential cookies or similar technologies may only be enabled in accordance with applicable law and, where required, after prior user consent. Technical logs may be retained for security, troubleshooting and service protection.
9. External links
The website contains links to third-party services such as maps, app stores and other external services. Processing by those third parties is governed by their own privacy policies.
10. Legal framework and updates
This policy is applied in accordance with Regulation (EU) 2016/679 (GDPR), Greek Law 4624/2019 and, for electronic communications/cookies, Greek Law 3471/2006, as amended. We may update it when our services, technology or the legal framework change. The current version and update date are published on this page.
