Skip to content
medifisys

Legal

Privacy and data

The short version: we hold your account, your bookings and your journey messages. We deliberately do not hold your medical records — those go from you to the hospital directly.

Last updated 2 September 2026

1. What we collect

We collect the minimum needed to make a booking work and to let partners identify you on arrival.

  • Account details: name, email, phone, country of residence.
  • Booking data: what you requested, from whom, for when, and the price the hospital quoted. We do not process your payment and never hold your card details.
  • Journey messages: updates written by your hospital, accommodation and transfer partner.
  • Technical data: IP address and basic request logs, retained for 30 days for security purposes.

2. What we deliberately do not collect

We do not store, transmit or process your medical records, imaging, pathology or diagnoses. You send those to the treating hospital directly, and they hold them under the medical records law of their own jurisdiction.

This is a design decision, not an oversight. A marketplace has no business holding clinical data, and keeping that surface at zero is what makes the rest of this document short.

We do not store card numbers. Payment details are handled by the payment provider on their own infrastructure.

3. GDPR and HIPAA

For users in the EU and UK, our lawful basis is contract performance for booking data, and legitimate interest for security logging. You have the right to access, correct, port and erase your data, and to object to processing.

HIPAA applies to covered entities and their business associates in the United States. Because Medifisys does not create, receive, maintain or transmit protected health information on behalf of a covered entity, we do not act as a business associate. Where a US-based partner requires a business associate agreement for a specific integration, we execute one for that integration.

Data processing agreements are in place with each sub-processor: our hosting provider, our payment processors, and our email and messaging providers.

4. Who we share with

Only the partners on your own booking, and only what they need to deliver their part of it.

  • The hospital receives your name, contact details, arrival date and any notes you wrote for them.
  • Accommodation and transfer partners receive your name, contact number and dates.
  • Product vendors receive a delivery address and the items ordered — not your procedure.
  • We do not sell data, and we do not share it with advertisers. Advertising on this platform is placement-based, not audience-based.

5. Retention and deletion

Account data is retained while your account is open. Request deletion at privacy@medifisys.com and we action it within 30 days.

Bookings with a completed payment are retained in anonymised form for the period our payment processors and tax obligations require, then destroyed. Anonymised means the financial record survives and the person does not.

6. Cookies

We set one cookie: an httpOnly, SameSite session cookie that keeps you signed in. It carries no tracking identifier and is not readable by scripts.

There are no third-party advertising or analytics cookies on this site. If that ever changes, it will be behind a consent prompt and this section will say so.

7. Security

Passwords are hashed with bcrypt. Sessions are signed tokens with a seven-day expiry, stored in an httpOnly cookie. All traffic is served over TLS.

If we become aware of a breach affecting your data, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of it.

This document is written to be read, not to be survived. If any part of it is unclear, ask us at our contact page and we will explain it and, if it is genuinely unclear, rewrite it.