Our four principles
Privacy at GetClinic isn't a 30-page policy nobody reads. It's a short set of commitments we hold ourselves to, and a set of practical controls you can act on at any time.
What we collect
Five categories of information. Each has a single purpose, a defined retention period, and is independently auditable. Nothing here is shared with marketers or insurers without your explicit, separate consent.
How we use it
Each piece of data has a defined “lawful basis” under GDPR — contract, consent, legal obligation, or legitimate interest. We log every access internally and audit it. No one at GetClinic can browse medical records out of curiosity; access is role-restricted and timestamped.
Two things we explicitly do not do: we don't sell your data, and we don't use your medical record to train AI models without your specific, separate opt-in (and even then, only on de-identified data).
How it's secured
Your rights
Six specific rights under GDPR. We honour them globally — regardless of where you live.
Data retention
Different data categories carry different legal minimum retention periods. Where the law lets us, we delete on request immediately; where it doesn't (medical records, financial records), we anonymise rather than retain identifiable data.
International transfers
Our HQ is in Istanbul. Our partner clinics span 11 countries. When your data crosses borders, we use the EU Standard Contractual Clauses (SCCs) where applicable, and equivalent safeguards everywhere else.
Specifically: for UK and EU patients, your data is processed under UK GDPR / EU GDPR with full SCCs. For US patients, we maintain HIPAA business-associate agreements with every clinic that treats US-resident patients. For Saudi patients, we comply with the PDPL and the Saudi Data & AI Authority's cross-border framework.
Contact our Data Protection Officer
For any privacy question, complaint, or formal data-subject request, write to our DPO. We respond within 7 working days (sooner for urgent matters).
Esra Demirci
CIPP/E, CIPM · 8 years in healthtech privacyIf you're not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority — for UK residents, the ICO; for EU residents, your national data protection authority.