Skip to content Skip to footer

Data Protection & GDPR Compliance Statement

Get Doctor Second Opinion (GDSO)
Operated by NEXTPEAK SRLS

Last updated: August 2026
Effective date: August 2026

  1. Introduction and Scope

Get Doctor Second Opinion (“GDSO”, “we”, “us” or “our”) is a digital platform operated by NEXTPEAK SRLS, an Italian company, that facilitates access to medical second-opinion services.

This Data Protection Statement outlines our overarching technical, organizational, and legal compliance frameworks under the Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR). It supplements our main Privacy Policy & Data Protection Notice and Cookie Policy, providing detailed insight into how NEXTPEAK SRLS guarantees data protection, security, and integrity across all digital operations.

  1. Who We Are

The entity responsible as Data Controller under Article 4(7) GDPR for all data processing activities conducted through GDSO is:

NEXTPEAK SRLS

Trading as Get Doctor Second Opinion (GDSO)

Via Celso 35

73048 Nardò (LE)

Italy

VAT / Tax ID: IT 05477050750

Email: [email protected]

Website: www.getdoctorsecondopinion.com

For dedicated GDPR, Privacy, or Data Protection inquiries, please contact:

[email protected]

  1. Core Principles of Processing

NEXTPEAK SRLS strictly adheres to the core data protection principles set out in Article 5 GDPR:

● Lawfulness, Fairness, and Transparency: Data is processed lawfully, fairly, and in a transparent manner in relation to the data subject.

● Purpose Limitation: Collected exclusively for specified, explicit, and legitimate medical coordination purposes and not further processed in a manner incompatible with those purposes.

● Data Minimization: Restricted strictly to what is adequate, relevant, and necessary in relation to the medical second-opinion requested.

● Accuracy: Maintained accurately and, where necessary, kept up to date.

● Storage Limitation: Kept in a form permitting identification of data subjects for no longer than is necessary for the purposes for which personal data is processed.

● Integrity and Confidentiality: Processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

  1. Enhanced Safeguards for Health Data (Special Category Data)

Medical and clinical information processed by GDSO constitutes “Special Category Data” under Article 9 GDPR.

To process sensitive medical records, laboratory findings, diagnostic images, and specialist consultation reports, GDSO enforces enhanced security controls:

● Legal Mechanism: Processing relies on explicit, unambiguous consent obtained under Article 9(2)(a) GDPR alongside Article 6(1)(b) GDPR (Performance of Contract).

● Isolation of Clinical Data: Case documentation and patient records are transmitted and stored within dedicated, encrypted healthcare storage environments completely segregated from public web analytical systems.

● Strict Need-to-Know Access: Access to health documentation is locked down solely to authorized platform administrators and the specific qualified medical specialist or participating healthcare institution assigned to the review.

  1. Technical and Organizational Security Measures (TOMs)

Pursuant to Article 32 GDPR, NEXTPEAK SRLS implements state-of-the-art technical and organizational measures designed to ensure a level of security appropriate to the high-risk nature of medical data:

5.1 Technical Measures

● End-to-End Encryption: Data in transit is protected using modern TLS encryption standards. Data at rest is secured via robust cryptographic standards (AES-256).

● Access Control & Authentication: Multi-factor authentication (MFA), role-based access controls (RBAC), and strict session time-outs prevent unauthorized internal or external access.

● Secure File Infrastructure: Dedicated, secure file transfer portals built to safely receive, display, and transfer heavy medical DICOM images and clinical files.

● System Resilience: Daily automated backups, load balancing, and anti-DDoS protections enforced at the web application firewall (WAF) level.

5.2 Organizational Measures

● Confidentiality Obligations: All personnel, contractors, and network specialists operate under strict contractual confidentiality obligations and statutory professional secrecy rules.

● Incident Management Protocol: Documented procedures to detect, evaluate, log, and report potential security breaches within statutory GDPR deadlines.

● Periodic Compliance Reviews: Regular audits of technical vendor agreements, access logs, and data lifecycle management routines.

  1. Data Processor Management (Article 28 GDPR)

Where third-party service providers process data on our behalf (e.g., cloud hosting, email delivery, infrastructure security, payment processing via Stripe), NEXTPEAK SRLS ensures:

● Mandatory Data Processing Agreements (DPAs) incorporating Article 28 GDPR requirements are established prior to service integration.

● Providers are selected exclusively based on their ability to offer sufficient guarantees of technical security and compliance with European data protection standards.

● Processors operate strictly on documented instructions from NEXTPEAK SRLS.

  1. International Data Transfers (Chapter V GDPR)

When a medical second opinion requires consultation with international medical specialists or institutions outside the European Economic Area (EEA), NEXTPEAK SRLS guarantees that cross-border transfers strictly comply with Chapter V GDPR through:

● European Commission Adequacy Decisions under Article 45 GDPR;

● Standard Contractual Clauses (SCCs) adopted by the European Commission under Article 46 GDPR; or

● Explicit Patient Consent under Article 49(1)(a) GDPR, obtained after informing the individual of the specific context and necessity of the transfer for their medical evaluation.

  1. Individual Data Subject Rights

Under Chapter III of the GDPR, you possess the following actionable rights regarding your personal and health data:

● Right of Access (Art. 15 GDPR): Obtain confirmation as to whether your data is being processed and receive a copy of your personal data.

● Right to Rectification (Art. 16 GDPR): Request immediate correction of inaccurate or incomplete medical or contact information.

● Right to Erasure / “To Be Forgotten” (Art. 17 GDPR): Request deletion of personal data where processing is no longer required, subject to mandatory legal, statutory, or medical record retention requirements.

● Right to Restriction of Processing (Art. 18 GDPR): Limit the processing of data under specific contested scenarios.

● Right to Data Portability (Art. 20 GDPR): Receive personal data provided to GDSO in a structured, commonly used, machine-readable format.

● Right to Object (Art. 21 GDPR): Object at any time to processing based on legitimate interests.

● Right to Withdraw Consent (Art. 7(3) GDPR): Revoke consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

To exercise any of these rights, please submit your written request to:

[email protected].

For security, identity verification may be required before fulfilling the request.

  1. Data Breach Notification (Articles 33 & 34 GDPR)

NEXTPEAK SRLS maintains an active Data Breach Response Plan. In the event of a physical or technical security incident affecting personal data:

● The competent supervisory authority (Garante per la Protezione dei Dati Personali) will be notified without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to rights and freedoms.

● Affected data subjects will be communicated with directly without undue delay if the personal data breach is likely to result in a high risk to their rights and freedoms.

  1. Supervisory Authority and Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data infringes the GDPR.

For NEXTPEAK SRLS, the primary Lead Supervisory Authority is:

Garante per la Protezione dei Dati Personali

Piazza Venezia n. 11

00187 Roma,

Italy

Website: www.garanteprivacy.it

You also retain the right to lodge a complaint with the local data protection authority in the EU/EEA member state of your habitual residence or place of work.

  1. Contact

For questions or operational matters relating to GDPR compliance, data security, or medical data handling, please contact:

NEXTPEAK SRLS

Trading as Get Doctor Second Opinion (GDSO)

Via Celso 35

73048 Nardò (LE)

Italy

Email: [email protected]

Website: www.getdoctorsecondopinion.com

Telephone: +39 334 890 6466

Last updated: August 2026

Receive News

Subscribe for the Updates!