Privacy policy
This page sets out, point by point, what data the Medaro portal collects, why, and how long it is kept. It describes how the portal actually works rather than offering general legal wording: every point can be checked against our data schema and server settings. The document is marked version v3 — that is the version recorded in the consent log when you tick the box during registration. What changed since version v2 is listed in the last section.
Who processes your data
Medaro is a medical directory for Armenia: a catalogue of doctors, clinics, pharmacies and laboratories, patient reviews, and a guide to compulsory health insurance. The portal does not provide medical care, does not book appointments and does not keep medical records.
The personal data controller is QWERTY LLC (Republic of Armenia), registration number 282.110.1073657, TIN 00922045. Postal address for legally significant correspondence: 44 Paronyan Street, Yerevan, Republic of Armenia. We accept personal data requests by e-mail at info@medaro.am — the same address is shown in the site footer.
The basis for processing
For registered users the basis is consent. During registration you tick two boxes: consent to the processing of personal data (this document, version v3) and consent to publishing your review under the portal rules. A doctor applying for verification ticks a third one — consent to the processing of diploma and licence documents.
Every consent is written to the log as a separate row: who agreed, to which document, in which version and at what minute. We do not write the IP address to that log, even though the database has a column for it.
A visitor without an account ticks nothing: the server request log, the anonymous site-search statistics, the Google Analytics counter and the maps work for everyone. What each of them collects, why and for how long is set out in the sections below.
When this document changes in substance, we raise the version number, publish the new text on this same page and list what changed. Registered users who are signed in see a notice on the site that the policy has been updated, with a link to the new text. We do not collect consent again: the log keeps the record of the version you agreed to. If you do not agree with the new version, write to info@medaro.am and we will delete the account; what happens to your reviews is explained under “Your rights”.
What we store
The list is closed: the portal keeps nothing about you beyond what is named here.
- Account: email address, display name, interface language and role (patient, doctor, administrator). The password is stored only as an irreversible hash in the authentication service — we never see it. There is a phone field in the database, but we neither ask for it at registration nor fill it in.
- Sign-in sessions: the time of sign-in, the IP address and the browser string of every active session. The sign-in service keeps them to protect the account; the record is deleted when you log out. The sign-in service also keeps an event log (sign-in, sign-out, password change): the time and the account, without the IP address.
- Reviews: the text, the overall score and three facet scores, the language, the visit date, the doctor or organisation the review is about, the signature (“Name S.” or a pen name you choose), and the creation and publication dates. Your real name is never shown next to a review, and the internal link between a review and an account is closed at database level to everyone except you and a moderator.
- Visit confirmation: the date of the visit, the confirmation method and — if you confirm with a receipt — the receipt file itself in private storage. The file is needed only for the check and is deleted afterwards under our procedure.
- Doctor cards. Most cards were compiled by us from open sources — the websites of the clinics where the doctor works: name, specialty, position, place of practice, gender, photo. Under each photo we state the clinic, a link to the page it was taken from, and the date. A doctor can ask at any time to correct the information or remove the photo: with the “Spotted an error?” button on their page (request type “Remove or replace the photo”) or by email to info@medaro.am. A request to remove a photo is carried out without discussion: we take it off the page and out of storage at once, and out of the Cloudflare cache and the site’s backup copy the same day. A doctor who has verified the profile then fills it in themselves: education, years of experience, languages, description, consultation price.
- Doctor verification documents (diploma, certificate, licence): held in private storage and available only to that doctor and to a portal administrator. They are never shown to patients.
- Doctors’ replies to reviews and reports about reviews, together with the reason given and the status of the case.
- “Spotted an error?” messages: the text, the page it refers to, the request type and — only if you left one yourself — a contact for the reply. We need them to correct data or remove a photo.
- Service logs: the consent log and the log of moderator and administrator actions (who changed what). It exists so that decisions on reviews and verification can be audited.
- Server request log: the time, IP address and country, browser and device type, the full address of the page opened, the response code; for file uploads, also the account and the file. Why we keep it and who sees it is described under “Server request log”.
- Site-search statistics — anonymously: the query text, the section, the language, the day, how many times it was searched for and how much was found; the table itself holds nothing that links a query to you. See the statistics section for details.
- Letters to clinics: the address we wrote to, the organisation, the date of sending, and the marks that the letter was opened and which links in it were clicked. This is data from business correspondence with an organisation, not with a patient.
- Letters you send to info@medaro.am — in our mailbox (see “Who we share data with” about email).
- Backups. So as not to lose data in a failure, every night we copy the database and the file storage; the copies contain everything listed above. They are kept on our server, on the portal administrator’s work computer and, encrypted, in Google Drive — only we hold the encryption key, so Google cannot see the contents. Daily copies are kept for 30 days, and copies taken on the first day of the month for up to 3 months. No backup is kept longer than 3 months, so deleted data disappears from the backups for good within 3 months at most.
- The camera and your location are switched on only with your permission: the camera for the visit QR-code scanner in the review form, the location for the “Near me” button on the map. The camera image and your coordinates are not sent to our server; only the visit code that was read is sent.
Our own statistics: doctor pages, site search and letters to clinics
The portal counts how many times during a day the page of a doctor who has verified their profile was opened and how many times the “Call” button on it was pressed. The doctor sees these two numbers in their dashboard and uses them to judge how the profile performs.
Only the daily total is stored: the doctor, the date, the kind of event and the number. No IP address, no user agent, no page URL and no exact event time are kept, so an individual person cannot be reconstructed from this table.
The identifier from the medaro_vid cookie never reaches the database: before writing it is turned into an irreversible hash together with a server-side secret. The table that tells us this visitor has already been counted today is cleared automatically after two days.
The statistics are tied neither to your account nor to your profile: the daily total contains no user identifier and no visitor identifier.
One honest caveat: at the moment of a request our server sees both the technical cookie and — if you are signed in — your session, because they arrive together in the same request. They are not linked in storage, but it would be untrue to claim that such a link is technically impossible.
Since version v3 the portal also counts what people search for on the site — to see which doctors, clinics, tests and services the catalogue is missing. This covers the search for doctors, clinics, laboratories and conditions, the search on the map and, on organisation pages, the search in the price list and in services under state health insurance. Until now, the text you typed into the search for clinics, tests, conditions, the map or a price list never left your browser; now, when you stop typing or leave the page, the result of the search goes to our server: the query itself, the site section, the page language and the number of results found. Intermediate variants while you type are not sent. The query text does not go to Google: it is cut out of the page addresses the Google Analytics counter sees, and the counter’s “Site search” feature is switched off.
Only the daily total is stored: the query, the section, the language, the date, how many times it was searched for, how many times the search found nothing and how many results the latest search found. The query is reduced to a plain form (lower case, no extra spaces or punctuation) and cut to 64 characters. Queries that look like an email address, a website address, a phone number or a document number (five or more digits in a row, or six or more digits in total) are dropped entirely — already in the browser and again on the server. With the “Do Not Track” or Global Privacy Control signal on, the query is not counted. The IP address is not written to the statistics table: the server keeps it only in memory — so that one person is not counted many times a day and to guard against inflated counts; a repeat of the same query from the same IP address within a day is counted once. There is no cookie, device, account or exact time in this table either, so this table alone cannot tell who searched for what. But the very fact that a search result was sent, like any request to the site, enters the server request log — with the IP address and the time, without the query text. And the doctor search changes the page address, and the log records such an address in full, together with the search text (see “Server request log”). Only portal administrators see the totals.
An honest caveat here too: if someone types a person’s name into the search, it is stored as query text — with no link to whoever searched, but it is stored. If such a query needs to be removed, write to info@medaro.am — we will delete it from the statistics, and it will leave the backups within 3 months at most. So that it is not counted again, the query text itself stays only in a closed exclusion list — with no counts and no search dates; only administrators see that list.
Letters to clinics are a separate story. We write to the management of clinics, pharmacies and laboratories at the addresses they have published on their own websites: we tell them about the portal and link to their page in the catalogue. This is business correspondence with an organisation; we never use patients’ addresses for such letters.
In such a letter we see two things: that it was opened — through a transparent one-pixel image that the mail program loads from our server — and which links in it were clicked: “Open the clinic page”, the video about the portal, or simply the site address. The links run through our own domain, and where each of them leads is fixed on our server behind a short keyword: an outside site cannot be slipped into such a link. We count this for one purpose only — to understand whether the mailing is of any use and whether it is worth writing again.
What is stored: the address the letter went to, the organisation, the date it was sent, the marks that it was opened and which links were clicked, and the line by which the mail program or browser introduces itself. The last one is needed to tell a live opening from a preload by a mail service. We do not store the IP address in the mailing tables: what matters to us is the response, not where you connected from. Loading the images of a letter and following its links are ordinary requests to our server: they enter the request log with the full IP address and the full address of the link, including the letter’s code, so the log shows which organisation the letter was sent to. Marks about openings and clicks are kept for 6 months, the record of the letter itself for 12 months from the day it was sent.
Opting out is simple: reply with a single word — “no”, “stop”, “unsubscribe”, any of them will do — and we strike the address off the list; there will be no second letter. No explanation is needed. The same reply can be sent to info@medaro.am. A request not to write again we remember even after the remaining records about the letter are deleted — otherwise we would forget it and write again.
One honest caveat here too: “the letter was opened” is an estimate, not a fact. Apple and Google mail apps often load the images in a letter by themselves, before the person has even seen it — the opening is counted although nobody started reading. So we treat only a click on a link as a fact, and the number of openings as an approximate estimate.
Server request log
Since version v3 our server keeps a log of requests to the site. Its purpose is security, failure analysis and the investigation of abuse: to see attacks, break-ins, password guessing and abuse, and to know who uploaded what to the site. Pages that Cloudflare serves from its own cache never reach our server and do not enter the log.
For each request the log records: the date and time; the IP address in full (Cloudflare passes it to our server) and the country derived from it; the line by which the browser introduces itself (user agent) and the device type derived from it — phone, tablet or computer; the request method; the full page address, including the parameters after “?”; the response code, its size and how long it took to prepare; and the site you came from — its domain only.
The page address is recorded in full. It shows which page you opened — for example, the page of a particular doctor, clinic, laboratory or condition — which filters you chose and what you searched for, if the search text was in the address. The IP address is recorded in full for every address, including the service addresses of our statistics and the images and links in letters to clinics. There is one exception: the values of sign-in parameters — one-time codes and keys from email-confirmation and password-recovery letters and the like — are replaced with the mark “[скрыто]” (Russian for “hidden”), so that the log cannot give access to other people’s accounts. The part of the address after “#” is never sent to the server by the browser at all.
What the log does not contain: what you send in the body of a request — form contents (except what the browser itself puts into the page address, such as the doctor search text) — passwords, cookies, the text of reviews and messages, or the account you are signed in with. The exception is uploading files to the site (currently, documents for doctor verification): uploads go to a separate upload log — the time, IP address, country, browser, the account that uploaded the file, the file name and type, size and result. It also records when and from which IP address these documents were opened.
The technical logs of the server’s services — file storage, gateway, sign-in service, tunnel — may also contain IP addresses: for example, the storage records one for every request for a doctor’s photo. These logs are limited in size and are overwritten as they fill up — at today’s traffic, after roughly 1–5 weeks.
The logs are kept only on our own server in Armenia and are not included in backups. Only server administrators have access to them. We pass them to no one and combine them with nothing — neither with Google Analytics nor with accounts; we may disclose records only on a lawful request from an authorised state body. The request log and the upload log are kept for 12 months, after which records are deleted automatically.
The log covers all requests, including those with the “Do Not Track” signal on: it is not traffic statistics but protection of the site. Records are tied to an IP address, not to a name. To find out what the log holds about your IP address, write to info@medaro.am stating the address and the approximate time.
How long we keep data
The retention periods in force today.
- Account, reviews and doctor profile — for as long as you use the portal.
- Sign-in sessions on the server — until you log out; the sign-in service event log — 12 months.
- Rejected verification documents — 90 days, after which the file is deleted from storage.
- Daily statistics for a doctor — 400 days.
- The table that records “this visitor has already been counted today” — 2 days.
- Site-search statistics (anonymous daily totals) — 24 months; queries that have only ever been searched for once — 90 days.
- The server request log and the file upload log — 12 months.
- Technical logs of the server’s services — roughly 1–5 weeks at today’s traffic: they are limited in size and overwrite themselves.
- Visit data in Google Analytics — 14 months.
- DMARC reports at PowerDMARC — under that service’s terms: as long as they are needed for it to work and as required by law.
- Cookies: sb-medaro-auth until you log out, but no longer than 400 days; sb-medaro-auth-code-verifier until sign-in is complete; NEXT_LOCALE until you close the browser; medaro_vid for 48 hours; _ga and _ga_JQZD411NCY for up to two years (the period is set by Google Analytics, and the browser may shorten it). Any of them can be deleted in your browser settings at any moment.
- The consent log and the moderator action log are kept for as long as we need them to demonstrate that processing was lawful and that decisions on reviews were justified.
- “Spotted an error?” messages — until the message has been dealt with and for 12 months after that.
- Letters to clinics: marks about openings and clicks — 6 months; the record of the letter itself — 12 months.
- Letters in the info@medaro.am mailbox — with no time limit: this is our correspondence with you and with organisations, including your requests about your data.
- Backups of the database and files: daily ones for 30 days, those taken on the first day of the month for up to 3 months; no backup is kept longer than 3 months. The copy of the public pages at Cloudflare is replaced with a new one every night.
Your rights
You have the right to obtain a copy of your data, to correct it, to delete your account and to withdraw consent.
Some of this is not yet available as a button: the “My account” section shows your reviews and their status, but there is no self-service account deletion on the site yet. Write to info@medaro.am from the address the account is registered to and we will carry out the request and reply by email.
About reviews specifically: when an account is deleted the reviews do not disappear from doctors’ pages — they lose the link to you and stay anonymous. Otherwise ratings would lose scores retroactively and the picture other patients see would be distorted. If you want the text of your own review taken down, say so in the message.
Medical confidentiality
A doctor’s reply to a review is public text: every visitor to the page can read it.
For that reason a doctor’s reply must not disclose information about the patient: the diagnosis, treatment and test results, the date and circumstances of the visit, or the name. A reply containing such details is not published.
Every doctor’s reply is moderated before publication — a doctor cannot publish text directly. A doctor also does not moderate reviews about themselves and cannot delete them: the only tools available are a public reply and a report to a moderator.
What changed in version v3
Compared with version v2 of 11 September 2026.
- A server request log has been introduced — the full IP address and the full address of the page opened, for security and the investigation of abuse; it is kept for 12 months, only on our own server, and only administrators have access to it.
- The portal counts what people search for on the site: anonymous daily totals, with no IP addresses or cookies in the statistics table.
- Google Analytics sees clicks on phone numbers and “Call” buttons (except short and emergency numbers) and clicks through to maps. The policy now spells out what else it sees and how long it keeps data (14 months).
- All services through which data passes are named: Cloudflare and the site’s backup copy there, OpenStreetMap mini-maps on organisation pages, Zoho email, encrypted backups in Google Drive, the PowerDMARC service for DMARC reports.
- We now say plainly that most doctor cards were compiled from clinics’ websites, and how to ask for a photo to be removed.
- Sign-in sessions, “Spotted an error?” messages, backups, the camera and location are described; cookie names and lifetimes and retention periods are made precise; the medaro_vid cookie is now set only on the pages of doctors who have verified their profile.
- The promise to collect consent again when the version changes has been removed: when the policy changes in substance, the site now shows registered users a notice with a link to the new text and does not ask for consent again.
Version v3 of 4 October 2026; the previous one is v2 of 11 September 2026. The document describes how the portal actually works. A new version is published on this same page with a new number and date and a list of what changed.