GetClinic
Sign in
Privacy & data security

Your medical record is yours — and ours to protect.

The honest, plain-English version of what we collect, who sees it, how it's secured, and what you can ask us to do about any of it.

Quick actions

Our four principles

Privacy at GetClinic isn't a 30-page policy nobody reads. It's a short set of commitments we hold ourselves to, and a set of practical controls you can act on at any time.

What we collect

Five categories of information. Each has a single purpose, a defined retention period, and is independently auditable. Nothing here is shared with marketers or insurers without your explicit, separate consent.

How we use it

Each piece of data has a defined “lawful basis” under GDPR — contract, consent, legal obligation, or legitimate interest. We log every access internally and audit it. No one at GetClinic can browse medical records out of curiosity; access is role-restricted and timestamped.

Two things we explicitly do not do: we don't sell your data, and we don't use your medical record to train AI models without your specific, separate opt-in (and even then, only on de-identified data).

Who sees what

We share data on the principle of minimum necessary: each party gets the smallest slice they need to do their job. Here's the complete list.

WhoWhatWhenLawful basis

How it's secured

Independent audit reportKPMG, March 2026 · 28 pages · available on request to verified patients.

Your rights

Six specific rights under GDPR. We honour them globally — regardless of where you live.

Data retention

Different data categories carry different legal minimum retention periods. Where the law lets us, we delete on request immediately; where it doesn't (medical records, financial records), we anonymise rather than retain identifiable data.

See the retention schedule per category in the “What we collect” table above.

International transfers

Our HQ is in Istanbul. Our partner clinics span 11 countries. When your data crosses borders, we use the EU Standard Contractual Clauses (SCCs) where applicable, and equivalent safeguards everywhere else.

Specifically: for UK and EU patients, your data is processed under UK GDPR / EU GDPR with full SCCs. For US patients, we maintain HIPAA business-associate agreements with every clinic that treats US-resident patients. For Saudi patients, we comply with the PDPL and the Saudi Data & AI Authority's cross-border framework.

Contact our Data Protection Officer

For any privacy question, complaint, or formal data-subject request, write to our DPO. We respond within 7 working days (sooner for urgent matters).

Data Protection Officer

Esra Demirci

CIPP/E, CIPM · 8 years in healthtech privacy
Email: [email protected]Post: GetClinic Ltd, DPO Office, Maslak Mahallesi, 34485 Istanbul, TurkeyEU representative: GDPR.eu Compliance Services, Dublin

If you're not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority — for UK residents, the ICO; for EU residents, your national data protection authority.

Trust without theatre

Have a privacy concern? We respond in 7 working days.

We treat every request seriously, including from people who haven't booked with us. Your privacy is non-negotiable.

Email our DPO Download the full PDF policy