Legal

Privacy Policy

Effective date: 15 June 2026  ·  Last updated: 15 June 2026

1. Who We Are

Mercano Global SRL ("we", "us", "our") is a company incorporated in Romania under ID RO43621443. We operate the Stasio practice management platform (the "Service").

We act in two distinct roles depending on the category of personal data involved:

  • Data Controller — for data we collect directly about our customers (practitioners, managers and their staff) during account registration, billing and platform administration.
  • Data Processor — for personal data about patients, clients or third parties that our customers upload and manage through the platform. In this role we act strictly on the instructions of the customer (the Data Controller).

2. Data We Collect as Controller

When you register and use the Service, we collect the following categories of personal data about you as our customer:

  • Account data: name, email address and password (stored as a one-way hash; we cannot recover it).
  • Business data: practice or company name, business address, VAT/CUI number and contact details.
  • Billing data: subscription plan and payment status. Card details are processed and stored exclusively by Paddle Payments Ltd. / Stripe Payments Europe Ltd.; we retain only a tokenised reference.
  • Usage data: login times, features accessed, support communications and in-app activity logs used for security monitoring and service improvement.
  • Technical data: IP addresses, browser type and device identifiers collected for security, fraud prevention and audit purposes.

3. Data We Process on Your Behalf (Processor Role)

When you use the Service to manage your practice, you upload and process personal data about your patients and clients. We process this data solely on your instructions as Data Processor. We have no independent right to use this data and do not sell, share or otherwise exploit it for any purpose beyond providing the Service. The contractual terms governing this processing are set out in Section 6 of our Terms of Service (the Data Processing Agreement).

Categories of data processed on your behalf may include:

  • Patient and client names, contact information and demographic data
  • Appointment records and session history
  • Clinical notes, assessments and session documentation
  • Files, certificates and uploaded documents
  • Therapy goals and progress records
  • Payment records linked to sessions

4. Legal Bases for Processing (Controller Role)

  • Contract performance (Art. 6(1)(b) GDPR): processing account and billing data to provide and administer the Service.
  • Legitimate interests (Art. 6(1)(f) GDPR): processing usage and technical data for security monitoring, fraud prevention and service improvement, where those interests are not overridden by your rights and freedoms.
  • Legal obligation (Art. 6(1)(c) GDPR): processing data required by Romanian and EU law, including fiscal, accounting and anti-money-laundering obligations (Law 82/1991, Romanian Fiscal Code).

5. Sub-processors and Third-Party Services

We use the following sub-processors to deliver the Service. Each is bound by data protection obligations at least equivalent to those imposed on us under GDPR and Romanian Law 190/2018:

Sub-processor Purpose Location Transfer basis
Hostinger International Ltd Server infrastructure Germany (EU/EEA) Within EU — no transfer
Cloudflare Ireland Limited Storage & Security EU / USA EU–US Data Privacy Framework; Standard Contractual Clauses (fallback, Commission Decision 2021/914)
OneSignal, Inc. Emails and push notifications USA EU–US Data Privacy Framework; Standard Contractual Clauses (fallback, Commission Decision 2021/914)
Twilio Inc. SMS and WhatsApp notifications USA / Ireland EU–US Data Privacy Framework; Standard Contractual Clauses (Commission Decision 2021/914)
Paddle Payments Ltd. / Stripe Payments Europe Ltd. Payment processing and subscription billing Ireland (EU/EEA) Within EU — no transfer
jsDelivr (Prospect One)
cdn.jsdelivr.net
Delivery of static front-end assets European Union (Poland) Within EU — no transfer
Cloudflare, Inc.
cdnjs.cloudflare.com
Delivery of static front-end assets USA / Global CDN Standard Contractual Clauses (Commission Decision 2021/914)

This list may be updated from time to time. We will notify you at least fourteen (14) days in advance via email or through the platform interface of any intended additions or replacements to our sub-processor list, giving you the opportunity to object to such changes.

6. International Data Transfers

Where personal data is transferred to sub-processors outside the EU/EEA, we ensure appropriate safeguards in accordance with GDPR Chapter V. Specifically, we rely on:

  • The European Commission's EU–US Data Privacy Framework adequacy decision (July 2023), where the sub-processor is certified thereunder; and
  • Standard Contractual Clauses (SCCs) approved by the European Commission under Decision 2021/914 as a supplementary or alternative safeguard.

7. Data Retention

Customer account data

Account and billing data is retained for the duration of your active subscription and for a minimum of 6 years after account closure, as required by Romanian fiscal and accounting law (Law 82/1991 and the Fiscal Code).

Practice data (processor role)

Data you upload to the platform is retained for the duration of your active subscription.

Backups

Deleted data is purged from all backup cycles within 30 days of the primary deletion event.

8. Security Measures

We implement appropriate technical and organisational measures in accordance with Art. 32 GDPR, including:

  • Column-level encryption at rest for sensitive clinical data
  • TLS encryption for all data in transit
  • Secure passkey authentication for user accounts
  • Role-based access controls with the principle of least privilege
  • Append-only audit logs for all security-relevant events
  • Files stored securely in the cloud
  • Signed and verified webhook payloads
  • Regular security reviews

In the event of a personal data breach likely to result in risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority within 72 hours and inform affected controllers without undue delay, in accordance with Arts. 33–34 GDPR.

9. Patients and End-Users

If you are a patient or client whose personal data has been entered by a practitioner using our platform, the practitioner is the Data Controller for your data. Mercano Global SRL processes your data only on the practitioner's instructions and does not independently control its use.

To exercise your data rights — including access, rectification, erasure or portability — please contact your practitioner directly. If you are unable to reach the practitioner, you may contact us and we will make reasonable efforts to assist within the limits of our processor role.

We do not carry out automated decision-making or profiling within the meaning of Art. 22 GDPR that would produce legal or similarly significant effects for patients or clients.

10. Your Rights (Customers)

As a customer, you have the following rights under GDPR and Romanian Law 190/2018:

  • Right of access (Art. 15 GDPR) — request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16 GDPR) — request correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR) — request deletion of your data, subject to mandatory legal retention obligations.
  • Right to restriction (Art. 18 GDPR) — request that we limit how we use your data in certain circumstances.
  • Right to portability (Art. 20 GDPR) — receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21 GDPR) — object to processing carried out on the basis of legitimate interests.

To exercise any of these rights, contact us at the details in Section 12. We will respond within one month as required by Art. 12(3) GDPR.

11. Cookies

The platform uses only strictly necessary session cookies to maintain your authenticated session and to remember your user interface preferences. These are essential for the operation of the Service and do not require your consent under Art. 5(3) of the ePrivacy Directive (Recital 25). We do not use tracking, advertising or analytics cookies.

Do Not Track. We do not monitor your activity across third-party websites or services, and we do not permit third parties to do so through the platform. Because no such tracking takes place, we do not alter our behaviour in response to browser "Do Not Track" (DNT) signals or similar mechanisms — there is nothing for them to switch off.

12. Supervisory Authority

You have the right to lodge a complaint with the Romanian supervisory authority:

ANSPDCP
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
www.dataprotection.ro

You also have the right to lodge a complaint with the supervisory authority of your EU member state of habitual residence or place of work.

· For privacy-related enquiries, data subject requests or to report a concern, don't hesitate to contact us.

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice at least 30 days before taking effect. The current version is always available at this URL.