Legal
Privacy and data
The short version: we hold your account, your bookings and your journey messages. We deliberately do not hold your medical records — those go from you to the hospital directly.
Last updated 2 September 2026
1. What we collect
We collect the minimum needed to make a booking work and to let partners identify you on arrival.
- Account details: name, email, phone, country of residence.
- Booking data: what you requested, from whom, for when, and the price the hospital quoted. We do not process your payment and never hold your card details.
- Journey messages: updates written by your hospital, accommodation and transfer partner.
- Technical data: IP address and basic request logs, retained for 30 days for security purposes.
2. What we deliberately do not collect
We do not store, transmit or process your medical records, imaging, pathology or diagnoses. You send those to the treating hospital directly, and they hold them under the medical records law of their own jurisdiction.
This is a design decision, not an oversight. A marketplace has no business holding clinical data, and keeping that surface at zero is what makes the rest of this document short.
We do not store card numbers. Payment details are handled by the payment provider on their own infrastructure.
3. GDPR and HIPAA
For users in the EU and UK, our lawful basis is contract performance for booking data, and legitimate interest for security logging. You have the right to access, correct, port and erase your data, and to object to processing.
HIPAA applies to covered entities and their business associates in the United States. Because Medifisys does not create, receive, maintain or transmit protected health information on behalf of a covered entity, we do not act as a business associate. Where a US-based partner requires a business associate agreement for a specific integration, we execute one for that integration.
Data processing agreements are in place with each sub-processor: our hosting provider, our payment processors, and our email and messaging providers.
5. Retention and deletion
Account data is retained while your account is open. Request deletion at privacy@medifisys.com and we action it within 30 days.
Bookings with a completed payment are retained in anonymised form for the period our payment processors and tax obligations require, then destroyed. Anonymised means the financial record survives and the person does not.
7. Security
Passwords are hashed with bcrypt. Sessions are signed tokens with a seven-day expiry, stored in an httpOnly cookie. All traffic is served over TLS.
If we become aware of a breach affecting your data, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of it.
This document is written to be read, not to be survived. If any part of it is unclear, ask us at our contact page and we will explain it and, if it is genuinely unclear, rewrite it.