Privacy Policy
Last updated June 22, 2026
1. Introduction
Healthcare Abroad is committed to protecting your personal data and ensuring transparency regarding how we collect, use, and safeguard your information.
This Privacy Policy explains how we process your personal information when you visit our websites, contact us, or use our services.
This Policy is designed to comply with:
- EU GDPR
- UK GDPR
depending on your location.
By using our website or our services, you acknowledge the processing described in this Policy.
2. Data Controller Information
Healthcare Abroad operates through multiple legal entities within the European Union and the United Kingdom. Depending on your location and the stage of your treatment journey, your personal data may be processed by one or more of the following entities:
European Union (EU) - Ireland
Your Healthcare Abroad Limited
Registered office: 7 Upper Ballymount Road, Ballymount, Dublin 24, D24 DVW2, Ireland
Spain (EU - Treatment Delivery)
Healthcare Abroad, S.L.
NIF: B72891344
Registered office: Avda. de Gandia, 45, Denia, 03700, Alicante, Spain
Healthcare Abroad entities may act as independent data controllers or joint controllers, depending on the nature of the processing. In particular, Healthcare Abroad, S.L. processes personal and medical data where necessary for the coordination and delivery of treatment in Spain.
Each entity is responsible for complying with applicable data protection law in relation to the processing it undertakes, including the EU General Data Protection Regulation (GDPR) and, where relevant, the UK GDPR as it applies to the processing of personal data of individuals located in the United Kingdom.
For questions or to exercise your data protection rights, please contact: compliance@healthcareabroad.com. Requests will be routed to the appropriate entity.
3. Key Definitions
Personal Data: Any information relating to an identified or identifiable natural person.
Special Category Data: Sensitive information such as health or medical data.
Processing: Any operation performed on personal data, such as collection, storage, sharing, or deletion.
Data Subject: The individual to whom the personal data relates.
We/Us: Healthcare Abroad.
4. Data Protection Principles
We follow the core principles of GDPR / UK GDPR:
- Processing is lawful, fair, and transparent
- Data is collected for specific purposes
- Data collected is limited to what is necessary
- Data is kept only for as long as needed
- We take steps to maintain accuracy
- We implement security measures to protect your information
- You retain rights over your personal data
5. Personal Data We Collect
We collect the following categories of data:
5.1 Information you provide directly
This may include:
- Name, address, contact details
- Date of birth
- Treatment information and medical history (where relevant)
- Details submitted through our consent form
- Communications with our team
5.2 Special Category (Medical) Information
Where relevant to your treatment journey, we may process:
- Referral details
- Clinical notes
- Scans or imaging
- Diagnosis and treatment history
- Information from your GP or healthcare provider
This information is processed where necessary for the provision of healthcare under Article 9(2)(h) GDPR, and with explicit consent only where legally required for optional processing.
5.3 Information collected automatically
When using our website, we may collect:
- IP address
- Device and browser information
- Usage data (pages viewed, interactions)
- Cookies and analytics information (see Section 10)
5.4 Information from authorised partners
We may receive information from:
- Healthcare providers
- Medical specialists
- Referring clinicians
- Service providers supporting treatment coordination
Only information relevant to facilitating your care or communication is shared with us.
5.5 Publicly available information
In limited circumstances, we may use publicly available information to assist with identity verification or administrative processes.
6. How We Use Your Information
We use personal data to:
- Provide and manage our services
- Assess your suitability for treatment
- Coordinate consultations and hospital appointments
- Communicate with you regarding your care
- Arrange administrative and travel-related steps (where applicable)
- Manage billing, documentation, and legal requirements
- Improve website functionality and service quality
- Respond to queries and support requests
We do not use your medical information for marketing.
7. Legal Bases for Processing
We process your personal data under the following legal bases:
7.1 Contractual necessity (Article 6(1)(b))
To provide services you request, including arranging treatment.
7.2 Legal obligations (Article 6(1)(c))
Where required by law or regulatory authorities.
7.3 Legitimate interests (Article 6(1)(f))
For administrative purposes, service improvement, and ensuring efficient operations.
We ensure these interests do not override your rights.
7.4 Explicit consent (Article 9(2)(a))
For optional processing activities, such as contacting your GP, providing reimbursement support, or communication preferences, where consent is required.
7.5 Provision of healthcare (Article 9(2)(h))
Where processing is necessary for arranging medical care or treatment.
You may withdraw consent for optional processing at any time.
8. Sharing Your Information
We share information only where necessary and with appropriate safeguards.
8.1 Healthcare providers
Relevant information may be shared with authorised hospitals and medical specialists in:
- Ireland
- The UK
- The EU/EEA
This includes Healthcare Abroad, S.L. in Spain, where processing is necessary to assess, coordinate, and deliver medical treatment.
This is strictly on a need-to-know basis for assessing and delivering treatment.
Where information is shared with providers in the United Kingdom, appropriate safeguards and UK GDPR requirements are applied.
8.2 Authorised service providers
We may use carefully selected providers to support:
- Communication
- Case management
- Secure transmission of documentation
- Administrative functions
We do not name specific systems or vendors for security reasons.
All providers operate under contract and with appropriate data protection safeguards.
8.3 GP, Credit Union, or others
Only where you provide explicit consent.
8.4 Legal obligations
We may disclose information where required by law, regulators, or court order.
9. International Transfers
Information may be transferred between:
- Ireland
- The UK
- EU/EEA partner hospitals
Transfers between the UK and the EU/EEA are supported by adequacy regulations and, where required, appropriate contractual safeguards.
10. How We Protect Your Information
We implement appropriate technical and organisational measures, including:
- Secure communication protocols
- Controlled access to medical information
- Measures to prevent unauthorised disclosure
- Monitoring for security vulnerabilities
- Staff training in data protection
No consumer messaging apps are used for sharing medical information.
11. Cookies and Analytics
We use cookies and similar technologies to:
- Understand website usage
- Improve user experience
- Maintain core website functionality
You can adjust cookie settings in your browser.
Analytics services may process data in accordance with their own privacy policies.
12. Data Retention
We retain personal data only for as long as necessary for:
- Providing services
- Fulfilling legal obligations
- Managing treatment records
- Accounting and audit requirements
Retention periods vary depending on the type of information.
Typical retention periods include:
- Medical records and imaging: up to 7 years
- Administrative communications: up to 3 years
- Reimbursement documentation: up to 7 years
13. Your Rights
You have rights under GDPR / UK GDPR, including:
- Access to your data
- Correction
- Deletion
- Restriction
- Objection
- Data portability
- Withdrawal of consent
- The right to complain to a supervisory authority
To exercise your rights, email: dpo@healthcareabroad.com
14. Children
We do not knowingly collect information from children under 16 unless required to provide healthcare services with appropriate authorisation.
15. Contact Details
For questions or rights requests: dpo@healthcareabroad.com
Supervisory authority (Ireland):
Data Protection Commission
Canal House, Station Road
Portarlington, Co. Laois, R32 AP23
Email: info@dataprotection.ie
United Kingdom Supervisory Authority:
Information Commissioner’s Office (ICO)
Website: https://www.ico.org.uk
16. Changes to This Policy
This Policy may be updated as our services and systems evolve.
Significant changes will be communicated via our website.
