Data Deletion Instructions
Last updated: May 8, 2026
DEEPPLANE™ (operated by Gamevato OÜ, Estonia) gives every user — surgeon and patient — a clear path to delete the personal data we hold. This page explains the two routes, what is deleted, and how long it takes.
1. What data we store about you
Depending on how you used DEEPPLANE™, we may have stored:
- Account information — email, hashed password, display name, role (patient / surgeon / admin)
- Surgeon profile data (claimed surgeons only) — credentials, hospital affiliation, biography, languages, consultation availability, contact methods
- Meta (Facebook / Instagram / Threads) data — when you connected your Meta accounts via our Postiz integration to publish editorial content, we received: a long-lived OAuth access token, your Meta user/page ID, page name, profile picture URL. We did not collect your password or your private message history.
- Public-record biographical data (unclaimed surgeons) — sourced from publicly available board-certification registries, hospital directories, peer-reviewed publications, and conference programs. Each source is cited on the surgeon's profile under Editorial provenance.
- Inquiry submissions — patient inquiries forwarded to surgeons (name, country, message, contact preference)
- Web traffic events — anonymous Google Analytics 4 events; no cross-site tracking, no fingerprinting
2. Self-service deletion
a. Revoke Meta (Facebook / Instagram / Threads) access
You can disconnect DEEPPLANE™ Postiz from your Meta accounts at any time and Meta will instruct us to invalidate the token automatically:
- Open Facebook → Settings & privacy → Settings → Apps and Websites
- Find DEEPPLANE™ Postiz in the list of active apps
- Click Remove
- Optional: tick Delete posts, photos, and videos — this signals us to also delete the access-token row in our database
On Instagram and Threads (which share the Meta Login layer) follow the same steps inside the respective app's privacy settings. Our system honors Meta's deauthorization webhook automatically — your token, page-id and profile-picture URL are removed from our database within 24 hours of the webhook arriving.
b. Delete your DEEPPLANE™ account
Surgeons and patients with accounts can self-delete from the surgeon panel or the user dashboard:
- Sign in at /surgeon-panel/dashboard
- Open Settings → Account
- Click Delete my account permanently
- Confirm by typing
DELETEin the dialog
3. Email-based deletion request
If self-service is not available to you (for example: you are a surgeon whose public-directory profile was sourced from public records and you do not have a DEEPPLANE™ account), send a request from your verifiable professional email to:
Subject line: Delete my data. Include the URL of the page you want removed and any contact you would like us to use to confirm identity. We acknowledge within 24 hours and complete deletion within 30 days, in line with GDPR Article 17 right to erasure.
Surgeons who arrive on their own profile page can also click Request removal in the editorial banner at the top of the profile — it routes to the same review queue.
4. What we delete vs. what we keep
On a verified deletion request we permanently remove:
- Your profile page and its server cache
- Your Meta OAuth token and any cached profile metadata
- Inquiry submissions you sent or received
- Wallet balance + Stripe customer record (refund first)
- Audit log entries identifying you (replaced with anonymized placeholder)
We retain, in pseudonymized form, only what is required by law or essential safety:
- Tax and accounting records (Estonian commercial code: 7 years)
- Aggregate, irreversibly anonymized statistics (e.g., "total inquiries from country X in 2026")
- System backups for up to 30 days, after which the data is fully purged on the next rolling backup cycle
5. Public-record provenance
Where a surgeon's profile is sourced from public records (board certification, peer-reviewed publications, conference proceedings) under our editorial-purpose use, we still honor deletion requests from the surgeon as a courtesy and within the 24-hour SLA, even though the underlying source remains public. Once removed, the URL returns a 410 Gone response and is unindexed from search engines.
6. Contact
Questions about how we handle deletion?
- Email: [email protected]
- Postal: Gamevato OÜ, Tartu mnt 67/1-13b, Tallinn 10115, Estonia
- See also: Privacy Policy · Terms of Service