Privacy policy
How we collect, use, and protect your personal and medical information. Plain-language version below.
- We never sell your data.
- TLS 1.3 in transit, AES-256 at rest.
- Delete on request, 5-day SLA.
What we collect
When you request a quote, second opinion, or speak with a case manager, we collect:
- Identity: name, country of residence, date of birth when relevant to clinical matching.
- Contact: email, phone, WhatsApp, preferred language.
- Clinical: medical reports, imaging, diagnoses, current medications — only what you explicitly share with us.
- Usage: pages viewed, approximate location from IP, device type. Never tied to named individuals unless you log in.
What we do with it
- Route your case to 1–3 matching hospitals and coordinate itemized quotes.
- Facilitate communication between you, the hospital's international desk, and your case manager.
- Send transactional updates about your case (quote, visa, travel).
- Improve the service: anonymized usage patterns, never individual browsing histories.
What we never do
- Sell your data. Not to insurers, pharma, or marketers.
- Share your clinical records outside hospitals you've explicitly authorised.
- Run targeted advertising based on medical history.
- Store financial data — all payments go through regulated processors (Stripe, PayTabs, bank wires) with no card details stored on our servers.
Who sees your data
- You and your case manager — always.
- Hospital international desks you've been matched to — only the specific hospitals, only the records you've authorised.
- Medical panel for second opinions — your case, de-identified where possible, shared with the specific panel member reviewing it.
- Service providers: our hosting (Supabase, Cloudflare), email (Resend), upload (Cloudflare R2), SMS/WhatsApp gateway. Each is bound by data-processing agreements.
We publish a list of sub-processors on request. Email medcastsdigital@gmail.com.
Your rights (GDPR, UK GDPR, and beyond)
- Access: ask for a copy of everything we hold about you.
- Correct: fix inaccuracies.
- Delete: we delete all identifiable records within 30 days of request, except where legal retention applies (billing records, minimum 7 years in most jurisdictions).
- Portability: export your clinical uploads in original format at any time.
- Withdraw consent: at any time, for any purpose. Stops active processing; past actions (already-sent quotes) stand.
To exercise any of these: email medcastsdigital@gmail.com from the email address on file. We respond within 5 working days.
Retention
- Active case data: retained while your case is open and 12 months after last contact.
- Medical records you uploaded: deleted from our systems within 90 days of case closure unless you request extended retention.
- Transactional records (quotes, invoices): 7 years, required by most tax authorities.
- Anonymized analytics: indefinite, but never re-identifiable.
International transfers
Your clinical data may transit to hospitals outside your home country — that's the nature of medical travel. Standard Contractual Clauses (SCCs) apply to EU and UK data subjects; adequacy frameworks apply where available. You always see and approve which hospitals receive your records before we send anything.
Security
Encryption in transit (TLS 1.3) and at rest (AES-256 at the storage layer). Upload vault is on Cloudflare R2 with pre-signed URLs expiring in 7 days. Case managers access via SSO with 2FA. We run quarterly penetration tests and disclose breaches to affected users within 72 hours, per GDPR Article 33.
Children
Where you're arranging medical travel for a minor, we require explicit documentation of parental responsibility. We don't hold direct accounts for under-18s.
Contact
- Data Protection Officer: medcastsdigital@gmail.com
- EU/UK representative: via the same address; response in-language for 8 locales.
- Regulatory contact: if we don't resolve your concern, you can file with your national data-protection authority.
Changes to this policy
We'll update this page when material changes happen and notify active case clients by email. The date at the top of this page reflects the current version.
Other things to know about how we operate
Privacy is one slice of the trust layer. The pages below cover the rest — terms, editorial process, security, and how we accept reports.
- Legal Terms of service Coordinator scope, payment, refunds, dispute resolution.
- Process Editorial + corrections policy Sourcing, AI use, corrections SLA.
- Trust Security disclosure How we accept reports from researchers.
- Action Report a safety incident Anonymous channel for clinical concerns.
- Reviewers Medical board Clinicians behind specialty + condition pages.
- Quality Accreditation registry JCI, NABH, ISO and 10 others.
- About Who we are Coordinator-not-clinician scope.
- Contact Contact us Data subject access requests + corrections.