Doktor Plus

Privacy Policy

Last updated: August 17, 2026

Introduction

Through these Privacy Rules, BBlab Duško Bajić S.P. (hereinafter: BBlab Duško Bajić S.P.) provides information on the collection, processing and protection of personal data in accordance with the Personal Data Protection Act of BiH, with the aim of giving users clear information about which personal data it processes, why it processes them, how it protects them and which rights users have in relation to that processing.

BBlab Duško Bajić S.P. acts as the controller of personal data, which means that it determines the purposes and means of processing users' personal data, in accordance with the Personal Data Protection Act of Bosnia and Herzegovina.

This notice applies to users whose personal data are collected through the website named DoktorPlus, located at https://www.doktor-plus.com/, and the mobile application named „DoktorPlus“.

By using the Website/Application, as well as by registering an account, the user confirms that they are familiar with this Policy.

Definitions of Terms

For the purposes of this Policy, the following terms have the meanings set out below:

Show all definitions
Controller
a natural or legal person, public authority or other competent body which, alone or jointly with others, determines the purposes and means of the processing of personal data. For the purposes of this Privacy Policy, the controllers of personal data are BBlab Duško Bajić S.P., as well as the healthcare institutions/clinics that provide consultation services through the Website and Application, whereby each of the listed entities acts in the capacity of controller, independently and/or as joint controllers, depending on the specific processing, in accordance with applicable personal data protection regulations.
Processor
a natural or legal person, public authority that processes personal data on behalf of the data controller.
Personal data
any data relating to a natural person whose identity has been established or can be established.
Processing
any operation or set of operations performed on personal data or on sets of personal data, by automated or non-automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Data subject
a natural person whose identity has been established or can be established, directly or indirectly, in particular by reference to identifiers such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
Recipient
a natural or legal person, public authority to which personal data are disclosed, whether or not a third party. Public authorities which may receive personal data in the course of a particular inquiry in accordance with the law shall not be regarded as recipients, but the processing of those data must comply with the applicable data protection rules according to the purposes of the processing.
Third party
a natural or legal person, public authority, Agency or other body which is not the data subject, the data controller, the processor, or persons authorised to process personal data under the direct authority of the data controller or processor.
Consent
of the data subject — any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
Personal data breach
a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Health-related data
personal data related to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information about their health status.
Processing of special categories of personal data
the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation, is prohibited.
Service
the provision of a digital platform through which users are enabled to access information about healthcare institutions and healthcare professionals, to schedule and carry out healthcare consultation services, to communicate between users (patients) and healthcare providers, as well as to use other functionalities and benefits that the Controller makes available through the Website and/or Application.
Account registration
the process by which a natural person, when visiting the Website or using the Application, creates a user account by entering basic identification data (first and last name, e-mail address and password), thereby gaining the ability to use the services provided by the Controller.
Website/Application visitor
a natural person who accesses the content of the Doktor Plus Website and/or Application without registering a user account and without using healthcare services.
Notification recipient
a natural person who is a Visitor or registered User of the Website/Application and who has given explicit consent to receive notifications, newsletters, informational or promotional messages by e-mail, telephone or other means of communication.
Person who submitted an inquiry
a natural person who is a Visitor or User of the Website/Application and who contacts Doktor Plus through the contact form, e-mail or telephone, in order to obtain information, answers to specific questions or to exercise their rights in connection with the processing of personal data or use of services.
Patient
a natural person who is a registered User and who, through the Website and/or Application, schedules, uses or has used the healthcare consultation services provided by healthcare institutions or healthcare professionals through the Doktor Plus platform.
User
a collective term for the Visitor, registered account user, Notification recipient, Person who submitted an inquiry and Patient, depending on the specific activity and purpose of processing personal data.
User's friend
a natural person whose e-mail address the User enters within the "Send invitations" functionality, for the purpose of sending an invitation to download the Application and create an Account with the Controller, with the option of adding an accompanying message.
Healthcare professional
a person with acquired secondary education in the field of healthcare, an integrated academic study of the first and second cycle of medicine, dentistry, pharmacy, or the first cycle of academic or vocational study or equivalent in the field of health education and healthcare, who directly provides healthcare services.
Private healthcare institution / Clinic
in accordance with the Healthcare Act of the Republic of Srpska and the Healthcare Act of the Federation of BiH, registered to perform healthcare activities and which, through the Website and/or Application, provides healthcare consultation services to users (patients).
Doktor Plus Website / Website
the website https://www.doktor-plus.com/, which is used for the Bosnia and Herzegovina market and managed by the Controller, through which users are enabled to access information about services, healthcare institutions and healthcare professionals, schedule medical consultations, communicate with service providers, as well as use other functionalities related to the provision of services through the platform.
Doktor Plus Application / Application
a mobile application available for download through the Google Play and App Store platforms, which is used for the Bosnia and Herzegovina market and managed by the Controller, through which users are enabled to use services available on the Website or functionally related to it, including scheduling and carrying out medical consultations, communication and management of the user account.
General Terms
the document governing the contractual relationship between the Controller and the User, which prescribes the conditions and rules for using the Website and/or Application, as well as the rights and obligations of the User in connection with the use of services provided through the Website and/or Application.
Account
a user profile of a natural person created by registration on the Website and/or Application, by entering basic identification data (first and last name, e-mail address), as well as by creating a password, with mandatory verification of the account via a verification code that the Website and/or Application delivers to the e-mail address entered by the user, all in accordance with the technical and security instructions determined by the Controller.
ZZLP
Personal Data Protection Act of BiH ("Official Gazette of BiH", no. 12/2025).
GDPR
General Data Protection Regulation of the European Union (2016/679).
Agency
the Personal Data Protection Agency in Bosnia and Herzegovina, an independent supervisory authority for monitoring the application of the ZZLP, with the aim of protecting the fundamental rights and freedoms of natural persons in connection with the processing of personal data in Bosnia and Herzegovina.

Data Controller Information

Business name: BBlab Duško Bajić S.P. Banja Luka

Registered office: Nikole Pašića 40, 78000 Banja Luka, Bosnia and Herzegovina

Tax ID (JIB): 4511441040007

Tel: +387 66 245 183

Website: https://www.doktor-plus.com/

E-mail: dusko@doktor-plus.com

Depending on the purpose of the processing of personal data, BBlab Duško Bajić s.p. Banja Luka and the healthcare institutions that provide healthcare consultation services through the Website and/or the Application act either as independent controllers or in a controller – processor relationship, in accordance with the ZZLP.

BBlab Duško Bajić s.p. Banja Luka acts as an independent controller in respect of the processing of personal data that it carries out for the purposes of registering and managing user accounts, authenticating users, managing and administering the Platform, ensuring the security of the information system, keeping records of the Platform's operation, providing technical support, fulfilling legal obligations, as well as other purposes for which it independently determines the purposes and means of processing.

Every healthcare institution using the Platform acts as an independent controller in respect of the processing of personal data carried out for the purposes of providing healthcare, scheduling and conducting healthcare consultations, keeping medical records, processing data on patients' health status and fulfilling legal obligations in the field of healthcare.

Where BBlab processes personal data on behalf of a healthcare institution in order to enable use of the Platform — including hosting, data storage, technical maintenance, backups, management of user permissions, technical support and other processing operations necessary for the functioning of the Platform — BBlab acts as a processor, while the healthcare institution acts as the controller, in accordance with Article 57 of the Personal Data Protection Act of Bosnia and Herzegovina and the concluded Data Processing Agreement.

To exercise rights relating to the processing of personal data connected with the provision of healthcare services, data subjects may contact the healthcare institution directly as the controller, or BBlab, which will, if the request does not fall within its competence, forward it without undue delay to the competent healthcare institution so that it may act in accordance with the Act.

Categories of Data Subjects

For the purposes of this Policy, personal data may relate to the following categories of persons:

  • Website/Application visitor a natural person who accesses the content of the Doktor Plus Website and/or Application without registering a user account and without using healthcare services.
  • Notification recipient a natural person who is a Visitor or registered User of the Website/Application and who has given explicit consent to receive notifications, newsletters, informational or promotional messages by e-mail, telephone or other means of communication.
  • Person who submitted an inquiry a natural person who is a Visitor or User of the Website/Application and who contacts Doktor Plus through the contact form, e-mail or telephone, in order to obtain information, answers to specific questions or to exercise their rights in connection with the processing of personal data or use of services.
  • Patient a natural person who is a registered User and who, through the Website and/or Application, schedules, uses or has used the healthcare consultation services provided by healthcare institutions or healthcare professionals through the Doktor Plus platform.
  • User a collective term for the Visitor, registered account user, Notification recipient, Person who submitted an inquiry and Patient, depending on the specific activity and purpose of processing personal data.
  • User's friend a natural person whose e-mail address the User enters within the "Send invitations" functionality, for the purpose of sending an invitation to download the Application and create an Account with the Controller, with the option of adding an accompanying message.
  • Healthcare professional a natural person, employed by a private healthcare institution/clinic, who directly provides healthcare consultation services through the Website/Application.

Categories, Types and Purposes of Processing

Depending on the category of data subject and the purpose of processing, the Controller, independently or as a joint controller with healthcare institutions/clinics, collects and processes the following personal data:

a) From Website/Application visitors

  • IP address;
  • device identifiers and platform information;
  • internet browser data;
  • basic data on the use of the Website/Application.

Purpose of processing: ensuring the technical functioning of the Website/Application, information security, statistical analysis of traffic and improvement of functionality.

b) From Notification recipients

  • e-mail address;
  • telephone number.

Purpose of processing: sending informational and promotional notifications, newsletters and other communications.

c) From Persons who submitted an inquiry

  • first and last name;
  • e-mail address;
  • telephone number;
  • data from the content of inquiries and communications that the person submits on their own initiative when contacting the Controller.

Purpose of processing: providing the requested information, exercising the rights of data subjects and keeping records of communications.

d) From Patients

User account data

  • first and last name;
  • e-mail address;
  • telephone number (including use for OTP verification purposes);
  • date of birth;
  • gender (optional);
  • profile photo (optional).

Purpose of processing: registration and management of the user account, user identification, enabling the use of services and communication regarding the services.

Data on healthcare consultations (special category of personal data)

  • data on scheduled and completed consultations;
  • text messages exchanged with healthcare professionals;
  • images and other content shared during consultations (e.g. photographs of symptoms, test results or medical documentation);
  • consultation history and duration.

Purpose of processing: providing healthcare and consultation services through the platform, maintaining medical records in accordance with the law and ensuring continuity of healthcare.

Payment data

  • tokenized payment card data;
  • data on executed transactions and charging of services.

Purpose of processing: processing payments, charging for services, and financial and accounting recordkeeping.

The Controller does not collect or store the full payment card number, the CVV number or the PIN. Payment data are processed through an external, PCI DSS-compliant payment service provider, whereby the Controller has access solely to the data necessary to confirm and record a successfully executed transaction.

e) From User's friends

  • e-mail address;
  • any data from the content of the message that the User enters on their own initiative when sending the invitation.

Purpose of processing: sending an invitation to use the Application, at the initiative of the User.

When using the "Send invitation" functionality, the User is obliged to act conscientiously and responsibly, and to enter only the contact details of persons whom they reasonably assume would be interested in using the Application. The Controller does not use this data for other purposes, does not store it permanently, and enables the Recipient of the invitation to request the deletion of their data at any time.

f) From Healthcare professionals

  • first and last name;
  • professional data (title, specialisation, healthcare institution/clinic);
  • contact details for official purposes;
  • data on consultations to the extent necessary for the provision of healthcare services through the platform.

Purpose of processing: enabling the provision of healthcare services through the platform, organisation of work and communication with Patients.

g) Technical data (for all categories of data subjects, depending on use)

  • device identifiers and platform information;
  • push notification tokens (Firebase Cloud Messaging);
  • technical and security logs;
  • application usage analytics, if enabled by the user.

Purpose of processing: maintaining system security, technical support, and improving the functionality and stability of the platform.

The Controller processes only those personal data that are necessary to achieve the specific purpose of processing, in accordance with the principles of lawfulness, data minimisation and proportionality, prescribed by applicable legislation.

Use of artificial intelligence (AI) technologies

In order to improve the quality and efficiency of the services provided through the Platform, DoktorPlus may use technologies based on artificial intelligence for the automatic transcription of audio/video consultations and the generation of consultation summaries. These functionalities serve solely as administrative support for healthcare professionals and do not constitute a basis for automated medical decision-making, nor do they replace the professional judgement of a physician.

To provide these functionalities, DoktorPlus may engage sub-processors, including but not limited to LiveKit for audio/video communication and transcription, and Mistral AI for generating consultation summaries. These sub-processors process personal data solely on the instructions of DoktorPlus, applying appropriate technical and organisational protection measures.

As the use of AI functionalities is not necessary for the provision of the healthcare service, they will be used solely with the prior explicit consent of the user. If the user does not give consent, the healthcare consultation may also be conducted without the use of AI functionalities, where this is organisationally possible.

DoktorPlus will endeavour to use AI services which, under the agreed terms of use, do not use user data to train or improve their artificial intelligence models.

Existence of Automated Decision-Making

The Controller does not make decisions that produce legal effects or similarly significantly affect users, and which are based solely on the automated processing of personal data.

Data Retention Period

Users' personal data is kept for as long as is necessary to achieve the purposes of processing set out in this Privacy Policy, unless applicable regulations require a longer retention period.

Where the processing of personal data is based on the User's consent, such data is kept until the moment the consent is withdrawn, in accordance with the provisions of this Policy, unless there is another valid legal basis for its further processing.

Exceptions to data deletion

By way of exception to the above, the Controller will not proceed with the deletion of personal data in the following cases:

  • if the User has not fulfilled their contractual obligations in connection with the use of services through the Doktor Plus Website and/or Application;
  • if the Controller is, in accordance with the applicable regulations of Bosnia and Herzegovina, obliged or authorised to retain certain personal data;
  • if there is another lawful and justified legitimate interest of the Controller, including the establishment, protection or defence of legal claims.

In the cases listed above, personal data is kept for the duration of the legal obligation or legitimate interest, but no longer than the periods prescribed by law, and at most three (3) years in cases where the processing is based on the Controller's legitimate interest.

Special categories of data – health data

Data on health status and other medical documentation is processed and kept by healthcare institutions/clinics as independent controllers, in accordance with the special regulations in the field of healthcare, in particular the Act on Healthcare Documentation and Records in the Field of Healthcare and the Act on Records in the Field of Healthcare, within the time periods prescribed by those laws.

BBlab Duško Bajić S.P. retains health data only to the extent and for the period necessary for the technical enabling of the healthcare consultation service through the platform, after which such data is deleted or anonymised, unless its further retention is necessary under applicable regulations or for the establishment or defence of legal claims.

Data of Notification recipients

Personal data of Notification recipients who have given consent to the processing and storage of their data for the purpose of being informed about news, promotional offers and other notifications, including the sending of newsletters and being contacted by e-mail or telephone, is kept until the consent is withdrawn.

Data collected through inquiries and communications

Personal data collected through inquiries, questions or other communications carried out through the Website and/or Application, e-mail or telephone, is deleted or anonymised no later than one (1) year from the date on which a final response is provided to the User or Visitor, unless its further retention is necessary to comply with legal obligations or to protect legal claims.

Record of retention periods

Detailed retention periods for individual categories of personal data are set out in the Record of Personal Data Processing Activities maintained by the Controller, in accordance with the Personal Data Protection Act of Bosnia and Herzegovina (ZZLP) and the guidelines of the competent Agency.

Technical and Organizational Security Measures

The Controller applies modern measures for the protection of personal data, such as:

  • Implementation of database pseudonymisation whenever possible;
  • Application of modern methods of protection and access control to data sources containing personal data;
  • restricting access to personal data to authorised persons only (the "need to know" principle);
  • All employees and persons engaged by the Controller are bound to maintain the confidentiality of the personal data they process in the course of performing their duties, and are regularly familiarised with the rules and obligations in the field of personal data protection;
  • When transferring personal data to third parties, processors, the Controller ensures that the data is transferred via secure communication channels and that appropriate security standards for data protection are applied at the processor's premises;
  • antivirus and firewall protection;
  • User data is kept on secure servers, with the application of appropriate technical protective measures. All transactions relating to payment for services through the Website/Application are protected by the use of SSL technology;
  • Personal data is processed in accordance with the principles of proportionality and minimisation, and is kept in a form that allows for the identification of persons only for as long as is necessary to achieve the purpose of processing;
  • As part of the organisational protective measures, the Controller has concluded joint controllership agreements with joint controllers, as well as appropriate personal data processing agreements with processors, in order to ensure the lawful and secure processing of personal data;
  • periodic reviews and testing of security measures.

Payment card data is neither processed nor accessible to the Controller at any time. Card payment processing is performed by an authorised card payment provider that applies the highest international standards of security and data protection, with confidential data being transmitted in encrypted form.

Recipients of Personal Data

Users' personal data may be disclosed to third parties which, on behalf of and at the direction of DoktorPlus, provide certain services necessary for the functioning of the Platform, including maintenance of the information system, hosting, sending electronic notifications, processing electronic payments (Monri Payments), as well as providing audio/video communication, transcription and consultation-summary generation functionalities using artificial intelligence technologies (LiveKit and Mistral AI).

Appropriate data processing agreements have been concluded with all processors and sub-processors, defining their obligations regarding the protection of the confidentiality, integrity and availability of personal data, in accordance with the applicable personal data protection regulations.

Personal data may also be disclosed to competent authorities and courts where this is prescribed by law or necessary for the exercise or protection of rights and the fulfilment of legal obligations.

Specific processors and recipients

Healthcare professionals and healthcare institutions/clinics

receive profile data, messages from consultations and shared images in order to provide medical advice.

Railway.com

hosting service provider; its servers are located within European Union member states.

Firebase (Google)

for the delivery of push notifications; receives only the device token, not personal health data.

Monri Payments

PCI-compliant payment processor; receives only the data necessary to process transactions.

LiveKit

audio/video communication and transcription of consultations; used solely with the user's prior explicit consent.

Mistral AI

generation of consultation summaries; used solely with the user's prior explicit consent.

Analytics services (Mixpanel)

anonymised application usage data, not including health information.

We do not sell personal data to third parties. We share data solely as described above or when required by law.

International Data Transfers

Users' personal data may be processed and stored outside the territory of Bosnia and Herzegovina, solely in accordance with the ZZLP.

Data are stored and processed on the server infrastructure of the hosting service provider Railway.com, whose servers are located within European Union member states. European Union member states ensure an adequate level of personal data protection in accordance with the General Data Protection Regulation (GDPR).

Railway processes personal data in accordance with the concluded data processing agreement and applies appropriate technical and organisational protection measures.

In addition to the server infrastructure, the LiveKit and Mistral AI services may also be used in the provision of certain Platform functionalities, whereby any transfer of personal data is carried out with the application of appropriate safeguards in accordance with the ZZLP.

The Controller takes all reasonable measures to ensure that personal data are processed securely and in accordance with this Privacy Policy, regardless of the location at which they are hosted.

Personal Data Breach Notification

The data controller is required to notify the Agency of a personal data breach without undue delay and, where feasible, not later than 72 hours after having become aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the Agency is not made within 72 hours, the data controller is required to provide the Agency with reasons for the delay.

Notifying the data subject of a personal data breach

The data controller is required to notify the data subject in writing without delay of a personal data breach, where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons.

Your Rights

Users have the following rights in the processing of personal data:

  • Right to information about the processing, and to access and a copy of the data

  • Right to rectification of inaccurate data and/or completion of incomplete data

  • Right to erasure of data

    where there is no longer a legal basis for further processing or retention

  • Right to restriction of processing

  • Right to data portability

    This right does not apply to medical findings, assessments, opinions and other health data generated in the course of the provision of healthcare services by healthcare professionals.

  • Right to object to processing based on legitimate interest

  • Right to withdraw previously given consent to the processing of data

The data subject (User) may exercise their rights in accordance with the ZZLP and these Rules by contacting the Controller at the e-mail address: dpo@doktor-plus.com.

Each request will be responded to as soon as possible, and at the latest within 30 days of receipt of the request. That period may, where necessary, be extended by 60 days, taking into account the complexity and number of requests received.

If a user considers that the processing of their personal data has been carried out contrary to applicable regulations, they have the right to lodge a complaint with the competent supervisory authority – the Personal Data Protection Agency of Bosnia and Herzegovina, Dubrovačka 6, 71000 Sarajevo, Bosnia and Herzegovina, email: azlpinfo@azlp.ba, or to bring an action before the competent court.

Data Deletion

You have the right to request the deletion of your personal data at any time.

How to request deletion

To request the deletion of your account and personal data, please send an email to our support team. Include your registered email address in the request.

Request Data Deletion

What will be deleted

  • Your profile information (name, email, phone, photo)
  • Your consultation history and messages
  • Your stored payment methods

Note: Some data may be retained for legal compliance purposes (e.g. financial records for tax purposes, medical records as required by healthcare regulations). Such data is securely stored and used only for legal compliance.

Children's Privacy

Doktor Plus is intended for users aged 18 and over. We do not knowingly collect personal data from children under 18. If you believe we have inadvertently collected data from a minor, please contact us immediately at dpo@doktor-plus.com and we will take steps to delete such information.

Cookies

The Controller uses cookies and similar technologies to ensure the proper functioning of the website, improve user experience, analyse traffic and, with user consent, display relevant advertising.

We currently use two categories of cookies:

  • Necessary cookies required for the basic functioning of the website (e.g. maintaining the session after login). These cookies cannot be disabled.
  • Analytical cookies help us understand how visitors use the site (e.g. number of visits, most viewed pages). These are set only with your consent.

Detailed information about the types of cookies, their purpose, duration and how to manage the settings is available in the Cookie Policy, which forms an integral part of this document and is published on the website https://doktor-plus.com/cookies.

Version and Updates

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on the Website and/or in the Application and updating the "Last updated" date. We encourage you to review this policy periodically. Continued use of the application after changes constitutes acceptance of the updated policy.

Date of last version: August 17, 2026

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Privacy inquiries: dpo@doktor-plus.com

General support and data deletion: support@doktor-plus.com

Postal address: BBlab Duško Bajić S.P., Nikole Pašića 40, 78000 Banja Luka, Bosnia and Herzegovina

Supervisory authority: Personal Data Protection Agency of BiH, Dubrovačka 6, 71000 Sarajevo, azlpinfo@azlp.ba