Skip to content
Data protection & cookies

Your health data requires extra care.

This policy explains which personal data MediBalans processes when you visit the website, book an appointment, purchase a laboratory test or become a patient — and the choices and rights available to you.

Updated 25 August 2026

1. Data controller

MediBalans Christina Biri AB, company registration number 559249-7290, is the controller for the processing described in this policy.

Visiting address: Banérgatan 10, first floor, 115 23 Stockholm, Sweden.
Email: [email protected]
Telephone: +46 76 686 76 67

2. Personal data we process

Website and contact

Technical information such as IP address and server logs, together with the contact details and message that you choose to send us.

Booking

Name, a Swedish personal identity or coordination number when you have one, otherwise date of birth, together with email, telephone number, selected service, practitioner and time. The booking flow must not be used to provide symptoms or other health details.

Laboratory-test purchases

Contact and delivery details, the test ordered, payment status, order details and necessary communication about the sample kit. A test purchase may itself reveal health-related information.

Care, samples and results

Patient records, medical history, prescriptions, laboratory orders, sample identifiers, results and other information required for safe care and follow-up.

Do not send a personal identity/coordination number, date of birth, test results or a detailed medical history through the public chat or ordinary email. The chat is not an emergency service. For urgent symptoms, contact 112 or 1177 as appropriate.

3. Purposes and legal bases

  • To respond to an enquiry and manage a booking, contract, order, delivery and payment.
  • To meet legal obligations, including accounting, patient safety and medical-record requirements.
  • To provide healthcare, medical assessment, laboratory handling and follow-up where the processing is necessary for care.
  • To protect our systems, prevent misuse and document technical errors.

Health data is sensitive personal data. When it is processed in healthcare, the processing is carried out under the rules that apply to healthcare providers, including the Swedish Patient Data Act and the GDPR exception for necessary care under the responsibility of professionals subject to confidentiality. Read more from the Swedish Authority for Privacy Protection (IMY).

4. Who may receive the data?

We restrict access to the people and service providers that need the data for their assignment. Depending on the service you use, recipients may include:

  • booking and patient-record systems, and healthcare professionals involved in your care,
  • Meet Mario for the website's booking and chat functions,
  • Stripe and relevant payment providers to process and document payment,
  • a carrier used to deliver or return a sample kit,
  • Genova Diagnostics or another named laboratory for sample handling and laboratory analysis,
  • IT, hosting, email and security providers, and public authorities where required by law.

Some laboratories or technical providers may be located outside the EU/EEA. Where a service involves such a transfer, it must be limited to what is necessary and covered by an applicable transfer mechanism and safeguards. For a laboratory test, the laboratory and sample destination are stated in the test or order information.

We do not disclose test names, purchase details or customer identifiers to Meta or other advertising platforms for conversion tracking.

5. How long we retain data

We retain data for as long as it is needed for the purpose for which it was collected, and afterwards where required by law, patient safety or legal claims.

  • As a general rule, patient records must be retained for at least ten years after the most recent entry. Read more from 1177.
  • Accounting and transaction records are retained for the period required by accounting legislation.
  • Ordinary contact and booking data is deleted or anonymised when it is no longer needed, unless it has become part of a patient record or other legally required documentation.
  • Technical security logs are retained for a limited period based on security needs.

6. Cookies, local storage and analytics

Optional measurement stays off until you expressly choose it. Before that choice, neither Google Analytics nor Meta Pixel is loaded and no measurement data is sent to those providers. Your choice is stored locally in the browser so the website can remember it. You can open Privacy settings at the bottom of any page at any time to change your choice or withdraw consent.

If you accept website analytics, GA4 (measurement ID G-X8ZN38EGYY) is loaded only after your choice. MediBalans replaces the real page address with a synthetic address that states only a broad page category: clinic, protocols, home tests, IV, Meet Mario, knowledge, booking or other. MediBalans's own integration sends generic events for page view, booking started, booking completed, checkout started, contact and chat started, together with the language group. Enhanced Measurement and automatic event detection must be disabled in the GA4 web stream so that the Google tag does not independently collect form, site-search, scroll or outbound-click events. The exact path, page title, query string, referrer, condition, symptom, test name, booking service, clinician, form values, personal identity number, date of birth, email, phone, price, purchase and customer details are not sent. Only a numeric or specially prefixed opaque campaign ID and a controlled generic source/medium may be carried over; readable campaign names are discarded. Advertising storage, advertising user data, advertising personalisation and Google Signals remain disabled. Google may still process ordinary technical information, its own cookies and a pseudonymous analytics identifier.

If you separately accept limited marketing measurement, Meta Pixel (pixel ID 836514963742786) is loaded in an opaque-origin isolated frame with no referring page address. Meta receives a page view from a neutral measurement page and only the generic event Contact. Booking, completed booking, checkout and purchase events are not sent to Meta because, on a healthcare provider's website, such events could reveal or imply a care relationship. The frame never receives the clinical page address. We do not send a condition, symptom, test or product, booking service, clinician, time, price, purchase, order, form value or customer identifier. No Stripe purchase data is sent to Meta through the Conversions API. When this choice is enabled, Meta may still process ordinary technical information, its own cookies and identifiers if the browser permits them.

When consent is withdrawn, new optional events stop, the Meta frame is removed and known analytics or marketing cookies on the MediBalans domain are deleted. Necessary local or session storage remains in use for security, website functions, remembering the privacy choice and preventing the same generic funnel event from being counted twice during one browser session.

Payment, booking and external services may set their own necessary cookies when you actively open or use their functions. Their own privacy terms then apply alongside this policy.

7. Your rights

Depending on the processing and its legal basis, you may request access, rectification, restriction, erasure or data portability, or object to certain processing. The right to erasure is not absolute; patient records and accounting data may need to be retained by law.

We may need to verify your identity before disclosing or changing data. Read more about your rights from IMY.

8. Contact, questions and complaints

Contact [email protected] if you wish to exercise a right or have questions about how we process your data. Do not include sensitive health information in your first email; we will direct you to an appropriate channel.

If you believe personal data is being processed incorrectly, you may lodge a complaint with the Swedish Authority for Privacy Protection.

We update this policy when our services, providers or legal requirements change. The latest version is always published at this address.