Privacy policy

Last updated: August 2026 · Version 2026-08-privacy-v1

1. Our commitment

MedicConsult is a teleconsult and matching platform. The data you entrust to us — especially health information — is handled with the highest level of confidentiality and security.

This policy explains clearly what data we collect, why, who can access it, how it is protected, how long it is kept, and what rights you can exercise.

We do not sell your personal data. We do not use it for targeted advertising. We do not share your consultation file with unauthorised third parties.

2. Ethics, secrecy and sensitive health data

Protection of health data is not only a legal requirement: it is an ethical duty aligned with the Hippocratic tradition of professional secrecy and respect for the person. MedicConsult designs access controls, encryption in transit, and role isolation so that consultation content remains between the patient and the relevant practitioner, plus strictly necessary platform operations.

Informed consent: when you create an account and accept the platform framework, you are informed that sensitive data may be processed to provide teleconsultation, messaging and related documents. You may exercise your rights as described in this policy. Practitioners remain bound by their professional secrecy duties under the law of their practice country.

We take into account, as far as a digital platform reasonably can, respect for privacy and the cultural context of users. We do not use medical content for commercial profiling or third-party advertising.

3. Data controller

The controller of personal data for the MedicConsult platform is the MedicConsult platform operator. Privacy contact details are at the end of this document.

Each doctor who consults with you remains responsible for their own medical practice and for professional and legal duties that apply to them (licence, medical confidentiality under their national framework).

MedicConsult provides the technical tool (account, appointments, payment, messaging, pathway documents). The goal is that confidentiality of exchanges and protection of health data are upheld both by the platform and by practitioners.

4. Data we collect

Depending on how you use the service, we may process in particular: • Identity and account: name, email, phone number, password (stored hashed/encrypted, never in plain text). • Profile data: language preferences, information you provide voluntarily. • Appointment data: chosen doctor, dates and times, duration, status (pending payment, confirmed, completed, cancelled), reason for visit that you enter. • Communication data: messages in the consultation space, attachments (images, documents, voice notes) linked to the appointment. • Health / clinical content: everything you communicate to the doctor (symptoms, history, test results you upload, consultation reports written by the doctor). This data is treated as particularly sensitive.

• Payment data: processed via secure payment providers (e.g. Stripe). MedicConsult does not store your full card number. • Technical data: limited technical logs (security, incident diagnosis), session identifiers, device/browser type as needed for operation and security. • Doctor data (if you are a practitioner): specialty, practice country, ID and diploma documents, verification selfie, Stripe Connect information, languages, bio.

We only collect what is necessary for the service. No health data is requested “for marketing”.

5. Legal bases for processing

Depending on the case, processing is based on: • performance of the contract (providing the platform, booking, payment, consultation messaging); • your consent where the law requires it (certain health-data processing, non-essential cookies if applicable); • our legitimate interests (platform security, fraud prevention, technical improvement), balanced against your rights; • compliance with legal obligations (accounting, responses to competent authorities strictly as required by law).

Health data is processed only in the context of care via teleconsult / the pathway on the platform, and not for other purposes.

6. Purposes of use

Your data is used exclusively to: • create and secure your account; • let you find a doctor, book, pay and consult; • enable confidential exchange between you and the doctor for that appointment; • produce and store the consultation report when the doctor writes it; • handle cancellations, refunds and support; • verify doctors’ identity and documents before approval; • ensure security, detect abuse and protect the integrity of the service; • meet legal and accounting obligations.

We do not use the content of your consultations to commercially profile you, sell patient lists, or train public AI models on your medical conversations without a clear legal basis and notice (this is not how the platform currently operates).

7. Who can access your data?

Access is strictly limited to need-to-know: • You: your account data and your appointment / message history. • The doctor for the appointment: only information needed for that consultation (not your entire life outside that frame). • Platform admin staff: only for operations, support, doctor verification, security or legal compliance — not to “browse files out of curiosity”. • Essential technical providers (hosting, database, authentication, payment, transactional email if used). They act as processors and are not allowed to use your data for their own commercial purposes.

We do not sell, rent or trade your personal or health data to advertisers, data brokers or ad networks.

Disclosure to an authority occurs only if the law requires it (court order, clear legal duty), and limited to what is requested.

8. Security and protection of health data

Protecting patient data is an absolute priority for MedicConsult. The goal is to minimise the risk of leaks, unauthorised access or misuse — and thereby reduce complaints and trust incidents.

Measures implemented (non-exhaustive): • account authentication and role-based isolation (patient, doctor, admin); • database-level access control (security policies: a patient cannot see other patients’ files; a doctor only accesses appointments that concern them); • encrypted communications between your browser and our servers (HTTPS / TLS); • passwords never stored in plain text; • environment separation and limited administrative access; • attachments stored in controlled spaces accessible to appointment participants; • certified payment providers for card data; • reasonable security logging and monitoring; • least-privilege principle for authorised staff.

No system is 100% infallible. If a security incident may affect your data, we commit to handling it diligently, documenting the event, and informing data subjects and/or competent authorities when regulation requires it.

9. Retention periods

We keep your data only as long as needed for the purposes described, then delete or anonymise it, unless a longer legal retention applies (e.g. accounting rules for payments, or data needed for a dispute).

• Inactive accounts: may be closed after a reasonable period of inactivity, with notice where required. • Consultation messages and attachments: kept for the care pathway on the platform and related legal / evidence duties. • Doctor verification documents: for the relationship and control obligations. • Technical security logs: limited to detection and investigation needs.

You may request account deletion; some data may be retained in a restricted form if the law requires it.

10. Your rights

Under the GDPR and applicable laws, you have in particular: • right of access; • right to rectification of inaccurate data; • right to erasure (“right to be forgotten”) where the law allows; • right to restriction of processing; • right to object, where applicable; • right to data portability, where applicable; • right to withdraw consent where processing is based on consent (without affecting prior lawful processing); • right to give instructions about data after death, where applicable.

To exercise these rights: contact us at the address below. We will respond within legal time limits. ID may be requested if there is reasonable doubt about the requester’s identity, to prevent a third party from obtaining your data.

11. Minors

The platform is not intended for children without parental / guardian involvement as required by applicable law. If you believe a minor provided data without authorisation, contact us so we can take appropriate steps.

12. Complaints and authorities

If you believe your data is not adequately protected, contact our privacy team first: we treat such reports as a priority.

You also have the right to lodge a complaint with the competent data protection authority (for example, depending on your situation, the authority of the EU Member State of your habitual residence, place of work, or place of the alleged infringement).

Our goal is to avoid that path: technical security, restricted access and transparency are designed to protect patients and trust in the service.

13. Privacy contact

For questions, rights requests, incident reports or any privacy matter: privacy@medicconsult.com

Please indicate the account email concerned and the nature of your request where possible, without attaching unnecessary health data in the first message if not required.

14. Changes to this policy

We may update this policy to reflect legal, technical or organisational changes. The “last updated” date at the top will be revised. For material changes, we may notify you via the platform or email, and where appropriate ask you to reconfirm under our consent procedures.

Please review this page regularly. The version published on the site is authoritative as of the date shown.

By creating an account, you confirm that you have read this privacy policy.