Privacy Notice
HOSPITUAL LIMITED (trading as “Hospitual”)
1. Introduction
HOSPITUAL Limited (“Hospitual”, “we”, “our”, or “us”) respects the privacy and confidentiality of personal information and is committed to protecting personal data in accordance with applicable data protection legislation, healthcare governance obligations, professional confidentiality duties, and information security standards.
This Privacy Notice explains how Hospitual collects, uses, stores, shares, protects, and otherwise processes personal data when individuals use Hospitual digital healthcare services, operational systems, websites, and associated healthcare platforms.
This notice applies to individuals using Hospitual services, including:
- Tele-radiology
- Tele-pathology
- Online and offline medical consultations
- Specialist second opinion services
This notice may also apply to referring healthcare professionals, organisational clients, guardians acting on behalf of patients, and other individuals interacting with Hospitual systems where applicable.
Hospitual processes personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, healthcare confidentiality obligations, and applicable professional and regulatory standards.
This Privacy Notice may be supplemented by additional service-specific privacy information, consent documentation, patient information notices, cookie notices, or contractual terms where relevant.
2. About Us
HOSPITUAL Limited operates a secure digital healthcare platform enabling patients, clinicians, and healthcare organisations to exchange medical information and obtain remote healthcare services and specialist clinical opinions.
Hospitual currently provides remote healthcare services and does not operate emergency services, inpatient facilities, or physical patient-facing clinical premises.
Registered Office:
HOSPITUAL Limited
Flat 1 Windsor House
Heathfield Gardens
London, W4 4JT
United Kingdom
General Enquiries: [email protected]
For direct-to-patient services, Hospitual acts as a Data Controller in relation to personal data processed through its platform, governance activities, operational systems, and associated healthcare services.
In certain organisational or business-to-business service arrangements, Hospitual may act as a Data Processor or independent Data Controller depending on contractual and operational context. Where third-party healthcare providers are involved, they may act as independent Data Controllers.
3. Medical Confidentiality
The confidentiality of medical and health-related information is important to Hospitual.
Access to personal and clinical information is restricted to authorised personnel, participating clinicians, and service providers with a legitimate operational, clinical, governance, safeguarding, security, or legal need to access such information.
Hospitual implements technical and organisational measures designed to reduce the risk of unauthorised access, disclosure, alteration, loss, misuse, or unlawful processing of personal data.
Where Hospitual processes health-related personal data for healthcare purposes, processing is carried out by or under the responsibility of healthcare professionals or persons subject to appropriate confidentiality obligations.
4. Personal Data We Collect
4.1 Identification and Contact Information
- Full name
- Date of birth
- Email address
- Telephone number
- Address information where required
- Emergency or next-of-kin details where provided
4.2 Health and Clinical Information (Special Category Data)
- Medical history and clinical information
- Diagnostic imaging and DICOM files
- Pathology slide scans and related information
- Consultation notes and clinical correspondence
- Radiology, pathology, or surgical reports
- Referral information and supporting clinical documentation
- Safeguarding-related information, where applicable
4.3 Account and Professional Information
- Login and account credentials
- Professional registration information
- Clinician credentialing and verification records
- Professional licence and indemnity information where applicable
4.4 Technical and Security Information
- IP address
- Device and browser information
- Platform activity logs
- Authentication and access records
- Security and audit logs
4.5 Communication and Governance Information
- Emails and correspondence
- Messages submitted through the platform
- Support requests
- Complaints and feedback
- Governance, safeguarding, audit, incident, and compliance-related records
4.6 WhatsApp and Messaging Communications Data
We may also process personal data received via WhatsApp or other messaging services, including contact details, message content, timestamps, and related metadata. This information is handled in line with our confidentiality obligations and is used solely for service delivery, responding to enquiries, complaint handling, safeguarding, and clinical governance purposes where necessary.
5. How We Collect Personal Data
Hospitual may collect personal data:
- Directly from patients, users, clinicians, or healthcare organisations
- Through information uploaded to the Hospitual platform
- Through communications with users, clinicians, or support services
- From referring healthcare professionals or organisations, where applicable
- Through operational, governance, safeguarding, security, or compliance processes
- Through use of Hospitual systems and platform infrastructure
Where users provide personal data relating to another individual, including dependants, children, parents, guardians, emergency contacts, or referring professionals, users should ensure they are authorised or otherwise permitted to provide such information.
6. Identity Verification and Age Controls
Hospitual and/or participating clinicians may request proof of identity, including government-issued photo identification, where reasonably necessary for patient safety, safeguarding, parental responsibility verification, fraud prevention, clinical governance, or legal and regulatory compliance.
Hospitual applies system-based eligibility controls. Users under 18 are not permitted to create accounts.
Where a clinician reasonably considers that identity, age, or parental responsibility cannot be verified, or where a user declines or fails to provide requested identity information, the clinician and/or Hospitual reserves the right to suspend, pause, or decline the provision of services.
In such circumstances, the user will be informed that continuation of services is not possible without appropriate verification, and responsibility for providing accurate identity and eligibility information remains with the user.
Where there is evidence or reasonable concern that a user may be under 18 and not accessing services through a verified parent or legal guardian account, services will be immediately paused or discontinued until appropriate safeguarding verification is completed.
Hospitual retains a safeguarding obligation to ensure that services are not provided to ineligible users, including unverified minors, and clinicians may stop or refuse to proceed with clinical activity where this requirement is not met.
7. How We Use Personal Data
Hospitual may process personal data for purposes including:
- Providing tele-radiology, tele-pathology, offline and online consultation services
- Delivering specialist medical opinions and healthcare communications
- Managing user accounts and platform access
- Verifying clinician credentials and eligibility
- Identity verification and safeguarding
- Clinical governance, quality assurance, peer review, and patient safety
- Incident management, discrepancy review, and complaints handling
- Platform security and fraud prevention
- Regulatory and legal compliance
- Business continuity and operational administration
8. Legal Bases for Processing
8.1 UK GDPR Article 6
- Contract performance
- Legal obligations
- Legitimate interests (including governance, security, safeguarding, fraud prevention, QA, and service improvement)
- Consent where required
Where Legitimate Interests are relied upon, a Legitimate Interests Assessment (LIA) is conducted where appropriate.
8.2 Article 9 – Special Category Data
Health data is processed under:
- Article 9(2)(h) healthcare provision
- Article 9(2)(f) legal claims
- Article 9(2)(c) vital interests
9. Clinical Governance and Patient Safety
Hospitual processes personal data for:
- Clinical audit and quality assurance
- Peer review and discrepancy review
- Incident investigation
- Safeguarding review
- Complaints handling
- Risk management and regulatory reporting
Access is strictly role-based and limited to the minimum necessary information required.
10. Communications
Hospitual may communicate via:
- Platform notifications and feedback forms
- Official company WhatsApp number
11. Sharing Personal Data
Personal data may be shared where necessary with:
- Clinicians and healthcare professionals
- Referring organisations
- Imaging/lab/pathology providers
- Cloud and IT providers
- Regulators and authorities
- Insurers and legal advisers
Access is strictly role-based and limited to the minimum necessary information required.
Hospitual does not sell personal data.
12. International Data Transfers
Transfers outside UK/EEA are protected using:
- IDTA
- UK Addendum to SCCs
- Adequacy regulations
13. Data Retention
- Clinical records: minimum 8 years
- Account data: duration + post-closure retention
- Logs: minimum 6 months
- Other governance/legal records: up to 6 years or longer if required
Retention may be extended under legal hold, safeguarding investigations, regulatory requirements, or legal claims.
14. Data Security
Hospitual implements:
- Encryption at rest and in transit
- Role-based access control (RBAC)
- Multi-factor authentication (MFA)
- Audit logging
- Access controls and reviews
- Secure cloud infrastructure
Security logs and access rights are reviewed regularly by the Security Officer/CTO, with escalation to governance where required.
15. Children and Safeguarding
Hospitual does not permit independent use of its services by individuals under 18.
Safeguarding measures include:
- Age verification
- Consent validation
- Clinical suitability checks
Hospitual may process or disclose data where necessary to protect individuals at risk or comply with safeguarding obligations.
16. Your Rights
Includes:
- Access
- Rectification
- Erasure
- Restriction
- Objection
- Portability
- Withdrawal of consent
Certain rights may be limited for clinical, safeguarding, legal, or regulatory reasons.
17. External Websites
No responsibility for external sites.
18. Data Protection Contact
Email: [email protected]
Postal Address:
HOSPITUAL Limited
Flat 1 Windsor House
Heathfield Gardens
London, W4 4JT
United Kingdom
19. Updates
This notice may be updated periodically.
Last updated: 20 May 2026.
20. Cookies
Further information regarding the use of cookies and similar technologies can be found in the Hospitual Cookie Policy.