Privacy Policy

Last updated June 22, 2026

1. Introduction

Healthcare Abroad is committed to protecting your personal data and ensuring transparency regarding how we collect, use, and safeguard your information.

This Privacy Policy explains how we process your personal information when you visit our websites, contact us, or use our services.


This Policy is designed to comply with:

  1. EU GDPR
  2. UK GDPR

depending on your location.


By using our website or our services, you acknowledge the processing described in this Policy.


2. Data Controller Information

Healthcare Abroad operates through multiple legal entities within the European Union and the United Kingdom. Depending on your location and the stage of your treatment journey, your personal data may be processed by one or more of the following entities:


European Union (EU) - Ireland

Your Healthcare Abroad Limited

Registered office: 7 Upper Ballymount Road, Ballymount, Dublin 24, D24 DVW2, Ireland


Spain (EU - Treatment Delivery)

Healthcare Abroad, S.L.

NIF: B72891344

Registered office: Avda. de Gandia, 45, Denia, 03700, Alicante, Spain


Healthcare Abroad entities may act as independent data controllers or joint controllers, depending on the nature of the processing. In particular, Healthcare Abroad, S.L. processes personal and medical data where necessary for the coordination and delivery of treatment in Spain.


Each entity is responsible for complying with applicable data protection law in relation to the processing it undertakes, including the EU General Data Protection Regulation (GDPR) and, where relevant, the UK GDPR as it applies to the processing of personal data of individuals located in the United Kingdom.


For questions or to exercise your data protection rights, please contact: compliance@healthcareabroad.com. Requests will be routed to the appropriate entity.


3. Key Definitions

Personal Data: Any information relating to an identified or identifiable natural person.

Special Category Data: Sensitive information such as health or medical data.

Processing: Any operation performed on personal data, such as collection, storage, sharing, or deletion.

Data Subject: The individual to whom the personal data relates.

We/Us: Healthcare Abroad.


4. Data Protection Principles

We follow the core principles of GDPR / UK GDPR:

  1. Processing is lawful, fair, and transparent
  2. Data is collected for specific purposes
  3. Data collected is limited to what is necessary
  4. Data is kept only for as long as needed
  5. We take steps to maintain accuracy
  6. We implement security measures to protect your information
  7. You retain rights over your personal data


5. Personal Data We Collect

We collect the following categories of data:


5.1 Information you provide directly

This may include:

  1. Name, address, contact details
  2. Date of birth
  3. Treatment information and medical history (where relevant)
  4. Details submitted through our consent form
  5. Communications with our team


5.2 Special Category (Medical) Information

Where relevant to your treatment journey, we may process:

  1. Referral details
  2. Clinical notes
  3. Scans or imaging
  4. Diagnosis and treatment history
  5. Information from your GP or healthcare provider


This information is processed where necessary for the provision of healthcare under Article 9(2)(h) GDPR, and with explicit consent only where legally required for optional processing.


5.3 Information collected automatically

When using our website, we may collect:

  1. IP address
  2. Device and browser information
  3. Usage data (pages viewed, interactions)
  4. Cookies and analytics information (see Section 10)


5.4 Information from authorised partners

We may receive information from:

  1. Healthcare providers
  2. Medical specialists
  3. Referring clinicians
  4. Service providers supporting treatment coordination

Only information relevant to facilitating your care or communication is shared with us.


5.5 Publicly available information

In limited circumstances, we may use publicly available information to assist with identity verification or administrative processes.


6. How We Use Your Information

We use personal data to:

  1. Provide and manage our services
  2. Assess your suitability for treatment
  3. Coordinate consultations and hospital appointments
  4. Communicate with you regarding your care
  5. Arrange administrative and travel-related steps (where applicable)
  6. Manage billing, documentation, and legal requirements
  7. Improve website functionality and service quality
  8. Respond to queries and support requests

We do not use your medical information for marketing.


7. Legal Bases for Processing

We process your personal data under the following legal bases:


7.1 Contractual necessity (Article 6(1)(b))

To provide services you request, including arranging treatment.


7.2 Legal obligations (Article 6(1)(c))

Where required by law or regulatory authorities.


7.3 Legitimate interests (Article 6(1)(f))

For administrative purposes, service improvement, and ensuring efficient operations.

We ensure these interests do not override your rights.


7.4 Explicit consent (Article 9(2)(a))

For optional processing activities, such as contacting your GP, providing reimbursement support, or communication preferences, where consent is required.


7.5 Provision of healthcare (Article 9(2)(h))

Where processing is necessary for arranging medical care or treatment.

You may withdraw consent for optional processing at any time.


8. Sharing Your Information

We share information only where necessary and with appropriate safeguards.


8.1 Healthcare providers

Relevant information may be shared with authorised hospitals and medical specialists in:

  1. Ireland
  2. The UK
  3. The EU/EEA

This includes Healthcare Abroad, S.L. in Spain, where processing is necessary to assess, coordinate, and deliver medical treatment.


This is strictly on a need-to-know basis for assessing and delivering treatment.


Where information is shared with providers in the United Kingdom, appropriate safeguards and UK GDPR requirements are applied.


8.2 Authorised service providers

We may use carefully selected providers to support:

  1. Communication
  2. Case management
  3. Secure transmission of documentation
  4. Administrative functions

We do not name specific systems or vendors for security reasons.

All providers operate under contract and with appropriate data protection safeguards.


8.3 GP, Credit Union, or others

Only where you provide explicit consent.


8.4 Legal obligations

We may disclose information where required by law, regulators, or court order.


9. International Transfers

Information may be transferred between:

  1. Ireland
  2. The UK
  3. EU/EEA partner hospitals

Transfers between the UK and the EU/EEA are supported by adequacy regulations and, where required, appropriate contractual safeguards.


10. How We Protect Your Information

We implement appropriate technical and organisational measures, including:

  1. Secure communication protocols
  2. Controlled access to medical information
  3. Measures to prevent unauthorised disclosure
  4. Monitoring for security vulnerabilities
  5. Staff training in data protection

No consumer messaging apps are used for sharing medical information.


11. Cookies and Analytics

We use cookies and similar technologies to:

  1. Understand website usage
  2. Improve user experience
  3. Maintain core website functionality

You can adjust cookie settings in your browser.

Analytics services may process data in accordance with their own privacy policies.


12. Data Retention

We retain personal data only for as long as necessary for:

  1. Providing services
  2. Fulfilling legal obligations
  3. Managing treatment records
  4. Accounting and audit requirements

Retention periods vary depending on the type of information.


Typical retention periods include:

  1. Medical records and imaging: up to 7 years
  2. Administrative communications: up to 3 years
  3. Reimbursement documentation: up to 7 years


13. Your Rights

You have rights under GDPR / UK GDPR, including:

  1. Access to your data
  2. Correction
  3. Deletion
  4. Restriction
  5. Objection
  6. Data portability
  7. Withdrawal of consent
  8. The right to complain to a supervisory authority

To exercise your rights, email: dpo@healthcareabroad.com


14. Children

We do not knowingly collect information from children under 16 unless required to provide healthcare services with appropriate authorisation.


15. Contact Details

For questions or rights requests: dpo@healthcareabroad.com


Supervisory authority (Ireland):

Data Protection Commission

Canal House, Station Road

Portarlington, Co. Laois, R32 AP23

Email: info@dataprotection.ie


United Kingdom Supervisory Authority:

Information Commissioner’s Office (ICO)

Website: https://www.ico.org.uk


16. Changes to This Policy

This Policy may be updated as our services and systems evolve.

Significant changes will be communicated via our website.