This Privacy Policy explains how personal data may be collected, used, stored, and protected when you visit satamgati.com, use the contact form, or communicate through the website.
The website is an informational website presenting the work, background, and areas of practice of Dr. Nikolai Romasco (Satamgati Das). It does not offer online payment, online checkout, or direct online purchase of services.
What personal data may be collected
Depending on how you use the website, the following categories of personal data may be collected:
- name
- email address
- phone number
- message content submitted through the contact form or by email
- technical data such as IP address, browser type, device type, operating system, referring page, and website usage data
- cookie and analytics data, where applicable
Please do not send unnecessary sensitive personal data through the initial contact form.
If you voluntarily include information relating to your health, symptoms, or other sensitive matters in your message, such information may be processed only to the extent necessary to review and respond to your enquiry and to determine whether further direct communication is appropriate.
How personal data is collected
Personal data may be collected in the following ways:
- when you submit a message through the contact form
- when you contact the website owner by email or phone
- automatically through cookies, server logs, analytics tools, or similar technologies when you browse the website
- through technical systems needed to keep the website secure and functioning properly
Why personal data is processed
Personal data may be processed for the following purposes:
- to respond to enquiries and communication requests
- to provide information requested through the website
- to assess whether direct communication or a potential appointment discussion is appropriate
- to maintain website functionality, performance, and security
- to prevent misuse, spam, fraud, or malicious activity
- to comply with legal obligations where applicable
- to establish, exercise, or defend legal claims where necessary
Legal bases for processing
Depending on the context, personal data may be processed on one or more of the following legal bases:
- your consent, where consent is required
- taking steps at your request before entering into a possible professional relationship, where you contact the website owner and ask to be contacted back
- legitimate interests, such as operating the website, responding to general enquiries, maintaining security, and protecting the website from abuse
- compliance with legal obligations, where processing is required by law
If you voluntarily send health-related or other sensitive personal data through the website, such data will only be processed where there is an appropriate legal basis under applicable data protection law, including, where relevant, your explicit consent or another lawful exception permitted by law.
Sensitive personal data
The website is not designed to encourage the submission of medical records or large amounts of sensitive health information through the initial contact form.
Users are asked to share only the minimum information necessary for an initial enquiry.
If health-related data is voluntarily submitted, it will be handled with additional care appropriate to its sensitive nature and only for a limited and relevant purpose.
Cookies and similar technologies
The website may use cookies or similar technologies that are necessary for the functioning, security, and performance of the website.
Where optional cookies are used, including analytics, preferences, or embedded third-party services, they should be managed through the website’s cookie notice, consent banner, or related settings.
More detailed information may be provided in a separate Cookie Policy if one is published on the website.
Analytics and website statistics
The website may use analytics tools to understand general website traffic and improve content, performance, and usability.
Where analytics are not strictly necessary, they should be used only in accordance with applicable consent requirements.
Analytics data is used in aggregated form whenever possible and is not intended to identify you personally unless technically required for security or fraud prevention.
Who may receive personal data
Personal data may be shared only where reasonably necessary and appropriate, including with:
- website hosting providers
- email service providers
- website maintenance or technical support providers
- analytics or security providers, where used
- legal, regulatory, or public authorities where disclosure is required by law
Such recipients should only receive data to the extent necessary for their role.
Personal data is not sold to third parties.
International data transfers
Some website tools or technical service providers may process data outside your country or outside the European Economic Area.
If personal data is transferred outside the EEA, such transfer should take place only where appropriate safeguards required by applicable data protection law are in place.
How long personal data is kept
Personal data is kept only for as long as reasonably necessary for the purpose for which it was collected, including:
- the time needed to respond to your enquiry
- any follow-up period reasonably connected to that enquiry
- the period necessary to meet legal, regulatory, tax, accounting, or record-keeping obligations, where applicable
- the period necessary to protect legal rights or resolve disputes
Technical and analytics data may be retained for shorter or system-defined periods, depending on the tool used and the purpose involved.
Data security
Reasonable technical and organisational measures are taken to protect personal data against unauthorised access, misuse, disclosure, alteration, or destruction.
However, no internet-based system or transmission method can be guaranteed to be completely secure. For that reason, while reasonable efforts are made to protect data, absolute security cannot be guaranteed.
Your rights
Under applicable data protection law, you may have the right to:
- request access to your personal data
- request correction of inaccurate or incomplete data
- request deletion of your personal data
- request restriction of processing
- object to certain processing based on legitimate interests
- withdraw consent at any time where processing is based on consent
- request data portability, where applicable
- lodge a complaint with a competent data protection authority
These rights are not absolute and may depend on the legal basis and circumstances of the processing.
How to exercise your rights
If you wish to exercise any of your rights, you may contact the controller using the contact details stated in this Privacy Policy.
To protect privacy and security, you may be asked to provide enough information to verify your identity before a request is fulfilled.
Supervisory authority
If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with the competent supervisory authority.
Children’s privacy
This website is not intended for unsupervised use by children for the submission of personal data.
If personal data relating to a child is submitted, this should be done only by or with the knowledge and authority of a parent or legal guardian, where required by applicable law.
Third-party websites
This website may contain links to third-party websites or services. This Privacy Policy does not apply to those external websites.
You should review the privacy policies of any third-party website you visit.
Changes to this Privacy Policy
This Privacy Policy may be updated from time to time to reflect legal, technical, or operational changes.
The latest version will always be published on this page with the updated date shown at the top.
Contact
If you have questions about this Privacy Policy or about the processing of your personal data, please contact us through the contact page.