Privacy Policy
Read Hospitual’s global privacy notice and the regional privacy addenda that may apply to you
HOSPITUAL PRIVACY NOTICE
Version 3.0 | Effective date: 24 July 2026
1. About this Notice
HOSPITUAL Limited and its affiliated entities (“Hospitual”, “we”, “our” or “us”) respect the privacy and confidentiality of personal information. We are committed to handling personal information responsibly, transparently and securely, particularly where that information concerns an individual’s health. This Privacy Notice explains how Hospitual collects, uses, stores, shares and protects personal information in connection with its websites, digital healthcare platform, clinical services, communications, governance activities and related operational systems. This Notice should be read together with the country or regional privacy addendum that applies to you. A local addendum may identify the Hospitual entity responsible for your personal information and provide additional information about applicable legal grounds, privacy rights, international transfers, regulators and complaint procedures. If this Notice conflicts with an applicable country or regional addendum, the addendum will take precedence to the extent of that conflict.2. Who this Notice Applies To
This Notice applies to:- patients and prospective patients;
- website and platform visitors;
- individuals who create or manage an account;
- healthcare professionals who apply to join or provide services through Hospitual;
- referring clinicians and representatives of healthcare organisations;
- organisational clients and their authorised users;
- people who contact us, submit an enquiry, provide feedback or make a complaint; and
- other individuals whose personal information is provided to us in connection with a Hospitual
3. Services Covered
Depending on the country and the availability of locally authorised services, Hospitual may provide:- Radiology Second Opinion;
- Pathology Second Opinion;
- Online Specialist Consultation; and
- Medical Record
4. The Responsible Hospitual Entity
The Hospitual entity responsible for your personal information depends on your location, the service you use, the website or platform through which you access the service and any relevant contractual arrangement. The responsible entity will normally be identified when you register, purchase a service, enter into a contract or receive service-specific privacy information. For direct-to-patient services, the relevant Hospitual entity will generally determine why and how personal information is processed and will act as a controller or equivalent responsible organisation under applicable law. Where Hospitual provides services to a hospital, clinic, diagnostic centre, insurer or other organisation, Hospitual may process personal information on that organisation’s documented instructions. In that situation, the organisation’s privacy notice may also apply and requests concerning the relevant information may need to be directed to that organisation. Participating healthcare professionals, referring organisations and other healthcare providers may act as separate or joint controllers, custodians or similarly responsible organisations for some processing activities. They may maintain their own clinical records and provide separate privacy information.5. Personal Information We Collect
We collect only the personal information reasonably required for the relevant service, relationship or legal purpose. Depending on how you interact with us, this may include the following.5.1 Identity, eligibility and contact information
- name, title, date of birth and age;
- address, country of residence, email address and telephone number;
- government-issued identification where verification is necessary;
- account identifiers and verification status;
- emergency contact or next-of-kin information where relevant; and
- information needed to confirm that you are eligible to use a service.
5.2 Health and clinical information
- symptoms, diagnoses, medical history and relevant family history;
- medicines, allergies, treatments and previous procedures;
- referral information, clinical questions and supporting correspondence;
- diagnostic images, DICOM files and associated metadata;
- pathology slides, digital pathology files, laboratory information and related materials;
- radiology, pathology and other clinical reports;
- consultation notes, professional opinions and clinical communications;
- information about a treating or referring healthcare professional; and
- safeguarding or patient-safety information where
5.3 Account and transaction information
- username, password hash and authentication information;
- account settings and communication preferences;
- services requested, order history, invoices, refunds and transaction records; and
- limited payment-related information. Payment card details may be collected directly by an authorised payment provider rather than stored by Hospitual.
5.4 Clinician and professional information
- qualifications, professional history and areas of practice;
- professional registration and licence details;
- identity, credentialing and right-to-work records;
- practising privileges, references and verification outcomes;
- professional indemnity or insurance information;
- training, appraisal, audit and performance-related information; and
- availability, case allocation and service-delivery records.
5.5 Technical, usage and security information
- IP address and approximate location derived from it;
- device, operating system and browser information;
- session, login, authentication and access records;
- platform activity, timestamps and audit trails;
- cookie and similar technology information;
- error, diagnostic and performance data; and
- records generated for cyber security, fraud prevention and incident
5.6 Communications and governance information
- emails, telephone and platform communications;
- support enquiries and service messages;
- feedback, survey responses and preferences;
- complaints and privacy requests;
- clinical governance, quality assurance and peer-review records; and
- incident, safeguarding, discrepancy, risk, audit and compliance records.
6. How We Obtain Personal Information
We may obtain personal information:- directly from you when you register, upload records, request a service, attend a consultation, contact us or exercise a privacy right;
- from a healthcare professional, hospital, clinic, diagnostic provider, laboratory or other referring organisation;
- from an organisation that has arranged or funded a service for you;
- from participating healthcare professionals and service providers;
- from professional registers and other lawful verification sources;
- automatically when you use our websites, platform or systems; and
- through governance, safeguarding, security, complaints, audit and regulatory
7. How We Use Personal Information
We may use personal information to:- assess eligibility and clinical suitability;
- create and administer accounts;
- verify identity and prevent impersonation or fraud;
- receive, organise and review medical records;
- allocate a case to an appropriately qualified healthcare professional;
- provide consultations, specialist opinions, reports and related clinical communications;
- communicate with you and provide service updates;
- process payments, refunds and financial records;
- verify, contract with and manage participating clinicians;
- maintain clinical records and an appropriate audit trail;
- support continuity of care and communicate with authorised healthcare providers;
- carry out clinical governance, quality assurance, peer review and discrepancy review;
- identify and respond to critical, unexpected or safety-related findings;
- manage complaints, concerns, incidents and safeguarding matters;
- investigate misuse, security events and suspected fraud;
- maintain, test, secure and improve our platform and services;
- meet legal, professional, insurance, contractual and regulatory obligations;
- establish, exercise or defend legal claims;
- support business continuity, disaster recovery and organisational administration; and
- send service communications and, where permitted, optional marketing communications.
We will not use identifiable clinical information for advertising. We will not sell personal information.
8. Health Information and Medical Confidentiality
Access to health information is restricted to authorised people who have a legitimate clinical, operational, governance, safeguarding, security or legal need to access it. Clinical information is handled by, or under the responsibility of, appropriately qualified healthcare professionals or other persons subject to professional, contractual or legal duties of confidentiality. Hospitual applies data minimisation and need-to-know principles. A person may have access to only the information necessary for their role. Healthcare professionals remain responsible for complying with applicable professional standards and for maintaining any separate records for which they are responsible.9. Age and Eligibility
Hospitual’s clinical services are intended only for individuals aged 18 or over. We do not knowingly accept clinical cases concerning individuals under 18, including cases submitted through an adult’s account. If we have reasonable grounds to believe that a user or the subject of a clinical case is under 18, or that identity or eligibility information is inaccurate, we may pause or decline the service while appropriate checks are completed. We may retain limited information about an attempted or declined submission where necessary for safeguarding, security, fraud prevention, complaints handling or legal compliance. Information about a child may occasionally appear incidentally in an adult patient’s medical record, family history, emergency contact information or safeguarding documentation. We will handle that information only as necessary and in accordance with applicable law.10. Identity Verification
We or a participating healthcare professional may request identity documents or other evidence where reasonably necessary for patient safety, clinical governance, fraud prevention, safeguarding or legal and regulatory compliance. If required information is not provided or cannot be verified, we may be unable to provide or continue a service. Copies of identity documents will be retained only for as long as reasonably necessary and access will be restricted.11. Clinical Governance, Quality and Patient Safety
Personal information may be reviewed for clinical audit, peer review, quality assurance, discrepancy management, complaints handling, incident investigation, safeguarding, risk management and regulatory reporting. Where reasonably possible, information used for audit or service evaluation will be minimised, pseudonymised or anonymised. Identifiable information will be used where it is necessary to investigate an individual case, protect a person, meet a professional obligation or respond to a legal or regulatory requirement.12. Critical and Unexpected Findings
Hospitual services are not emergency services. However, a participating clinician may identify a finding that appears to require urgent attention. In accordance with the relevant service protocol and applicable law, we may use available contact information to alert you, a referring professional, an appropriate healthcare provider or, where necessary, an emergency or safeguarding authority. You should not use Hospitual for an emergency. If you believe you may have a medical emergency, contact the emergency service or urgent healthcare service available in your location.13. Sharing Personal Information
We may share personal information, where necessary and proportionate, with:- participating healthcare professionals;
- referring or treating healthcare providers;
- hospitals, clinics, imaging providers, laboratories and pathology providers;
- organisations arranging, commissioning or funding a service;
- secure hosting, storage, communications, identity verification and technology providers;
- payment processors and financial service providers;
- professional advisers, auditors, insurers and legal representatives;
- regulators, professional bodies, courts, law-enforcement bodies and public authorities;
- safeguarding or emergency services where necessary to protect a person; and
- a prospective purchaser, investor or successor in connection with a properly managed corporate transaction.
14. International Processing and Transfers
Hospitual operates across borders and uses technology and service providers that may process personal information outside the country in which it was collected. In particular, authorised processing or storage may take place in the United Kingdom, Canada, the United States or another country in which a Hospitual entity, clinician or contracted provider operates. The privacy and public-authority access laws of another country may differ from those in your location. Where required, we use recognised transfer mechanisms and supplementary contractual, organisational or technical safeguards. These may include adequacy decisions or regulations, approved contractual clauses, transfer agreements, risk assessments, encryption and access controls. The applicable country addendum provides further information about local transfer requirements and how to request information about relevant safeguards.15. Data Security
Hospitual uses technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access or misuse. Measures may include:- encryption in transit and at rest;
- role-based and least-privilege access controls;
- multi-factor authentication;
- audit logging and access monitoring;
- secure cloud infrastructure and backups;
- vulnerability, incident and continuity management;
- periodic access reviews; and
- confidentiality, training and contractual
16. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Notice and to meet applicable clinical, legal, professional, insurance, contractual and regulatory requirements. Retention periods depend on the country, service, record type, relationship and context. Relevant factors include continuity of care, patient safety, limitation periods, professional guidance, complaints or incidents, safeguarding concerns, legal holds and regulatory requirements. When information is no longer required, we will securely delete or anonymise it, or place it beyond routine use until secure deletion is possible. Specific retention information may be set out in the applicable country addendum or Hospitual retention schedule.17. Accuracy and Your Responsibilities
We take reasonable steps to keep personal information accurate and up to date. You should provide accurate, complete and current information and tell us if important information changes. A request to correct a clinical record does not necessarily permit the deletion or rewriting of a professional opinion or an accurate historical entry. Where appropriate, a correction, clarification or statement of disagreement may be added while preserving the integrity of the clinical record.18. Communications and Marketing
We may send communications necessary to operate an account or provide a requested service, including identity checks, appointment information, report notifications, safety communications, payment messages and changes to important terms. We will send optional electronic marketing only where permitted by applicable law. You can unsubscribe using the link in a marketing message or by contacting us. Opting out of marketing will not stop essential service or patient-safety communications.19. Cookies and Similar Technologies
Our websites and platform may use cookies and similar technologies for essential functions, security, user preferences, performance measurement and, where permitted, analytics or marketing. Where consent is required, non-essential technologies will not be used until the appropriate choice has been made. More information is available in the Hospitual Cookie Policy and relevant consent settings.20. Automated Decision-Making
Hospitual does not currently use solely automated processing to make clinical decisions about diagnosis or treatment, or other decisions that produce legal or similarly significant effects for patients. We may use automated tools for routine technical or administrative purposes, such as authentication, security alerts, file validation, workflow routing or fraud detection. Where applicable law gives you rights concerning a significant automated decision, we will provide the information and safeguards required by that law.21. Your Privacy Rights
Depending on the law that applies to you, you may have rights to:- receive information about our processing;
- access personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request deletion, where the information is no longer required and no exception applies;
- restrict or object to certain processing;
- receive certain information in a portable format;
- withdraw consent where processing is based on consent;
- object to direct marketing;
- ask for human review of certain automated decisions; and
- complain to Hospitual or an applicable privacy regulator.
22. Privacy Requests and Complaints
Privacy requests and complaints may be sent to: Email: [email protected] General enquiries: [email protected] Please describe your request clearly and identify the service and Hospitual entity involved, if known. We will acknowledge and respond in accordance with applicable law. If Hospitual is processing information solely on behalf of an organisational client, we may refer the request to that organisation or assist it in responding.23. External Websites and Services
Our services may link to websites, applications or services operated by third parties. Their privacy practices are governed by their own notices. Hospitual is not responsible for an independent third party’s privacy practices merely because a link is provided.24. Changes to this Notice
We may update this Notice to reflect changes in our services, technology, legal obligations or governance arrangements. The current version will be published with its effective date. Where a change materially affects how we use personal information, we will provide additional notice where required.25. Applicable Addenda
This Privacy Notice should be read together with any country or regional addendum applicable to the relevant service. Published addenda may include:- Schedule 1 – United Kingdom Privacy Addendum;
- Schedule 2 – Canada Privacy Addendum, when issued; and
- any other country, regional, provincial or state addendum published for a Hospitual
26. Contact Us
Privacy contact: [email protected] General enquiries: [email protected] The postal address and regulatory contact applicable to you are provided in the relevant country or regional addendum.UNITED KINGDOM PRIVACY ADDENDUM
Version 1.0 | Effective date: 24 July 2026
This United Kingdom Privacy Addendum (“UK Addendum”) supplements the Hospitual Global Privacy Notice. It applies where HOSPITUAL Limited provides a service to you, where you are located in the United Kingdom and UK data protection law applies, or where the relevant processing is otherwise subject to UK data protection law.
If this UK Addendum conflicts with the Global Privacy Notice, this UK Addendum takes precedence in relation to processing governed by UK law.
1. UK Responsible Entity
HOSPITUAL Limited, trading as “Hospitual”, is the controller of personal data processed for its direct-to-patient services and for its own platform administration, clinical governance, security, regulatory and business operations.
Registered office:
HOSPITUAL Limited Flat 1 Windsor House Heathfield Gardens London W4 4JT United Kingdom
General enquiries: [email protected]
Data protection contact: [email protected]
Where HOSPITUAL Limited provides contracted services to a hospital, clinic, diagnostic provider or other organisation and acts only on that organisation’s documented instructions, it may act as a processor. The relevant organisation remains responsible for its own privacy notice and for responding to requests as controller, although Hospitual will provide appropriate assistance.
Participating clinicians may be independent controllers for clinical records or professional decisions for which they determine the purposes and means of processing. The applicable contractual and clinical arrangements determine the role of each party for each processing activity.
2. UK Laws Covered
We process personal data in accordance with applicable UK privacy and data protection law, including:
- the UK General Data Protection Regulation (“UK GDPR”);
- the Data Protection Act 2018 (“DPA 2018”);
- the Data (Use and Access) Act 2025 (“DUAA”), which amends parts of UK data protection law; and
- the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), where relevant to cookies and electronic marketing.
We also take account of applicable duties of medical confidentiality, professional standards and healthcare regulatory requirements.
3. Categories of UK Personal Data
The categories described in the Global Privacy Notice apply. Health information, including medical
images, pathology information, reports, symptoms, diagnoses and clinical correspondence, is “special category data” under the UK GDPR and receives additional protection.
Identity documents may include biometric or other sensitive information. We will use such information only where necessary for verification, security, safeguarding or compliance and will apply appropriate access and retention controls.
4. UK Lawful Bases and Special Category Conditions
We identify an Article 6 lawful basis for each processing purpose. When we process health information or other special category data, we also identify a separate Article 9 condition.
The following table describes the bases most likely to apply. The precise basis depends on the circumstances.
Purpose | UK GDPR Article 6 basis | UK GDPR Article 9 condition, where applicable |
Registering an account, receiving a case, providing a consultation, report or second opinion, processing payment and managing the patient relationship | Article 6(1)(b): performance of a contract or steps requested before entering into a contract | Article 9(2)(h): medical diagnosis, provision or management of health care, where processed by or under the responsibility of a professional subject to confidentiality |
Maintaining clinical records, clinical governance, quality assurance, peer review, discrepancy review and patient-safety processes | Article 6(1)(c): legal obligation, where a specific obligation applies; and/or Article 6(1)(f): legitimate interests in safe, effective and accountable healthcare | Article 9(2)(h): provision or management of health care; where appropriate, Article 9(2)(g) together with a relevant DPA 2018 Schedule 1 condition |
Verifying identity, age, clinician credentials and professional eligibility | Article 6(1)(b), Article 6(1)(c) and/or Article 6(1)(f), depending on context | Article 9(2)(h), or another applicable Article 9 condition where special category data is necessary |
Responding to critical or unexpected f indings and protecting lif e | Article 6(1)(d): vital interests, where strictly necessary; Article 6(1)(b), (c) or (f ) may apply in other circumstances | Article 9(2)(c): vital interests only where the individual is physically or legally incapable of consent; and/or Article 9(2)(h) for healthcare |
Safeguarding and protecting individuals at risk | Article 6(1)(c): legal obligation, where applicable; and/or Article 6(1)(f): legitimate interests | Article 9(2)(g) together with an applicable substantial-public-interest condition in Schedule 1 DPA 2018; Article 9(2)(h) may also apply |
Handling complaints, incidents, regulatory enquiries and professional obligations | Article 6(1)(c): legal obligation; and/or Article 6(1)(f): legitimate interests in investigating and resolving concerns | Article 9(2)(h); Article 9(2)(f) where necessary for legal claims; or Article 9(2)(g) with an applicable Schedule 1 condition |
Preventing f raud, securing systems, authenticating users, maintaining audit logs and investigating misuse | Article 6(1)(c), where a legal duty applies; and/or Article 6(1)(f): legitimate interests in security, confidentiality and f raud prevention | Article 9(2)(f), (g) or (h) only where special category data is necessary and the relevant condition is met |
Establishing, exercising or defending legal claims and obtaining legal advice | Article 6(1)(f): legitimate interests; and/or Article 6(1)(c) | Article 9(2)(f): legal claims and judicial acts |
Meeting accounting, tax, corporate, insurance and regulatory requirements | Article 6(1)(c): legal obligation; and/or Article 6(1)(f) | Normally not applicable; Article 9(2)(f), (g) or (h) may apply where relevant health information is necessary |
Service analytics, capacity planning and improvement using identifiable or pseudonymised information | Article 6(1)(f): legitimate interests, following a balancing assessment; consent where required | Article 9(2)(h) where genuinely necessary for management of healthcare systems or services; otherwise explicit consent under Article 9(2)(a), or anonymised information |
Sending optional electronic marketing | Article 6(1)(a): consent where PECR requires consent; in limited cases Article 6(1)(f) may apply where PECR permits | We do not use health information for marketing |
Non-essential cookies or similar technologies | Article 6(1)(a): consent, where required by PECR; another basis may apply to associated processing where a statutory exemption applies | We do not intentionally use health information for advertising cookies |
We do not rely on consent as the principal basis for processing necessary to provide healthcare where another lawful basis and Article 9 condition apply. This is because withdrawing consent should not ordinarily prevent us from maintaining information that must be retained for clinical, legal or safety reasons.
Where we rely on legitimate interests, we consider the purpose, necessity and impact on your rights. You may request information about the relevant balancing assessment, subject to the protection of confidential and legally privileged information.
Where Article 9(2)(g) and a DPA 2018 Schedule 1 condition require an Appropriate Policy Document, we will maintain one.
5. Medical Confidentiality
Health information is processed by, or under the responsibility of, healthcare professionals or other persons who owe an appropriate duty of confidentiality.
We may share relevant information with a treating or referring professional where this is necessary for the requested service, continuity of care or patient safety and is lawful. We will not routinely disclose health information to relatives, employers or insurers without appropriate authority or another lawful basis.
The common-law duty of confidentiality and applicable professional guidance may require consent or another recognised justification in addition to data protection compliance.
6. Information Obtained from Other Sources
We may receive personal data from referring clinicians, healthcare organisations, diagnostic providers, laboratories, professional registers or an organisation arranging a service.
Where Articles 13 or 14 UK GDPR require us to provide privacy information, we will do so at the relevant time, normally when the data is collected from you or, where it is obtained elsewhere, within the period required by law unless an exemption applies.
7. Required Information
Some personal data is required to enter into or perform a contract, confirm eligibility, verify identity, maintain clinical safety or comply with legal and professional requirements.
If you do not provide required information, we may be unable to accept a case, provide a service, verify a clinician or respond safely to a request. We will explain the consequence where it is not already clear.
8. UK Data Sharing
The recipients described in the Global Privacy Notice may receive personal data where necessary and lawful. In the UK this may include:
- UK-registered healthcare professionals providing or reviewing care;
- a referring or treating clinician, GP or healthcare organisation;
- the Care Quality Commission, Information Commissioner’s Office, professional regulators or other competent authorities;
- NHS bodies or emergency services where lawfully necessary;
- insurers, auditors and legal advisers;
- payment, identity, communications and technology providers; and
- courts, law-enforcement bodies or safeguarding
Where a recipient is a processor, we put in place the contract required by Article 28 UK GDPR. Where parties are independent or joint controllers, we document the arrangement as required and provide appropriate transparency.
9. International Transfers from the UK
Hospitual uses cloud and technology infrastructure that may involve authorised storage or access in the United States and may use providers or group entities located outside the United Kingdom.
A transfer to a separate organisation outside the UK will be made only where permitted by UK data protection law. Depending on the destination and recipient, we may rely on:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission Standard Contractual Clauses;
- another safeguard recognised under Article 46 UK GDPR; or
- a limited Article 49 derogation where it is lawful and
Where required, we assess the laws and practices of the destination and implement supplementary measures. These may include encryption, strict access controls, data minimisation, contractual limits and transfer risk assessments.
You may contact [email protected] to request further information about the safeguard relevant to a transfer. We may provide a redacted summary or copy where necessary to protect security, confidentiality or commercial information.
10. UK Retention
We maintain a retention schedule and review retention periods by record type. Clinical records relating to adult services will normally be retained for at least eight years after the end of treatment or the last relevant clinical contact, unless a longer or shorter period is justified by applicable law, professional guidance, limitation periods, an ongoing complaint or incident, safeguarding, a legal hold or another documented requirement.
Indicative periods include:
- account information: for the life of the account and an appropriate period after closure;
- core clinical records and reports: normally at least eight years after the end of treatment or last relevant clinical contact;
- security and access logs: according to risk and operational need, normally not less than six months;
- complaints, incidents, governance, contracts and legal records: normally six years after closure or expiry, or longer where justified; and
- identity verification material: only for as long as necessary for the verification and any related legal, fraud or safeguarding purpose.
These periods are subject to the storage-limitation principle. When a record no longer needs to be retained, it will be securely deleted or anonymised.
11. Your UK Data Protection Rights
Subject to the conditions and exemptions in law, you may have the right to:
- be informed about the collection and use of your personal data;
- obtain confirmation that we process your data and receive a copy;
- have inaccurate personal data corrected and incomplete data completed;
- request erasure in specified circumstances;
- request restriction of processing in specified circumstances;
- object to processing based on legitimate interests or the performance of a public task;
- object at any time to direct marketing;
- receive eligible data in a structured, commonly used and machine-readable format and transmit it to another controller;
- withdraw consent at any time where consent is the basis for processing; and
- receive safeguards in relation to qualifying solely automated
These rights are not absolute. For example, we may need to retain a clinical record, protect another person’s information, comply with a legal obligation, preserve professional opinions or establish or defend a legal claim.
12. Exercising Your Rights
Send a request to [email protected] or to the registered office shown in section 1.
Please provide enough information for us to identify you and locate the relevant records. We may request proportionate proof of identity. We will normally respond without undue delay and within one month, subject to any lawful extension or pause while permitted clarification or identification information is obtained.
We do not normally charge a fee. A reasonable fee may be charged, or a request may be refused, where the law permits this because a request is manifestly unfounded or excessive.
Where HOSPITUAL Limited acts only as a processor, we may refer the request to the relevant controller and assist that controller.
13. Clinical Records and Correction Requests
The right to rectification does not require the deletion of an accurate historical entry or the substitution of one clinician’s professional opinion for another. Where a clinical opinion is disputed, it may be appropriate to preserve the original entry and add a correction, clarification, addendum or statement of disagreement.
Access to health information may also be limited where a statutory exemption applies, including where disclosure would reveal protected information about another person or create a serious risk of harm in circumstances recognised by law.
14. Automated Decision-Making
HOSPITUAL Limited does not currently make diagnoses, treatment recommendations or other decisions producing legal or similarly significant effects about patients solely by automated means.
If this changes, we will assess the processing, update the relevant privacy information and provide the safeguards required by UK law. These may include meaningful information about the logic involved, the significance and expected consequences, human intervention and the ability to challenge a decision.
15. Cookies and Electronic Marketing
Our use of cookies, pixels, local storage and similar technologies is governed by PECR and UK GDPR. We use consent where required and provide controls through our cookie interface and Cookie Policy.
Service communications are not marketing. Optional marketing communications will identify Hospitual and provide a straightforward way to opt out. We do not use identifiable health information to target advertising.
16. Data Protection Complaints
If you are concerned about how we use your personal data, please contact us first: Email: [email protected]
Post: HOSPITUAL Limited, Flat 1 Windsor House, Heathfield Gardens, London W4 4JT, United Kingdom
In accordance with the UK’s data protection complaints requirements, we will facilitate the making of a complaint, acknowledge it within 30 days and investigate and respond without undue delay. We may ask for information needed to understand and investigate the matter and will keep you appropriately informed of progress and outcome.
You also have the right to complain to the Information Commissioner’s Office: Information Commissioner’s Office
Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF United Kingdom
Website: https://ico.org.uk/make-a-complaint/ Telephone: 0303 123 1113
We would appreciate the opportunity to address your concern before you contact the ICO, but you are not required to contact us first.
17. UK Representative and Data Protection Officer
HOSPITUAL Limited is established in the United Kingdom and does not require a separate UK representative for the processing covered by this Addendum.
The current data protection contact is:
Dr Masoud Moravej
Email: [email protected]
If Hospitual formally appoints a Data Protection Officer under Articles 37 to 39 UK GDPR, the appointment and contact details will be published and communicated as required. Use of a “data protection contact” title in this Addendum should not, by itself, be read as a representation that a statutory DPO appointment is required or has been made.
18. Updates to this UK Addendum
We may update this UK Addendum to reflect changes in law, regulatory guidance, services, technology or organisational arrangements. The current version will be published with its effective date. Material changes will be notified where required.
CANADA PRIVACY ADDENDUM
Version 1.0 | Effective date: 24 July 2026
1. Purpose and Application
This Canada Privacy Addendum (“Canada Addendum”) supplements the Hospitual Privacy Notice. It applies where:
- HOSPITUAL provides the relevant service;
- an individual uses Hospitual services in Canada;
- personal information is collected, used or disclosed in connection with a Canadian service; or
- Canadian federal or provincial privacy law otherwise applies to the
This Canada Addendum should be read together with the Hospitual Privacy Notice. If there is a conflict between this Canada Addendum and the Privacy Notice, this Canada Addendum will take precedence in relation to processing governed by Canadian law.
The privacy rules applicable to health information in Canada may vary by province and by the role of the organisation or healthcare professional involved. This Canada Addendum therefore addresses both federal requirements and the principal provincial requirements that may apply to Hospitual services.
2. Canadian Responsible Entity
The responsible Canadian entity is:
HOSPITUAL Inc.
Corporation number: 1718977-0
Federally incorporated under the Canada Business Corporations Act on 25 July 2025 Registered office: Unit 1117, 98 Lillian Street, Toronto, Ontario M4S 0A5, Canada General enquiries: [email protected]
Privacy Officer: Dr Masoud Moravej
Privacy enquiries and complaints: [email protected]
HOSPITUAL Inc. is responsible for personal information under its control, including personal information processed for its direct-to-patient services, account and platform administration, privacy and security management, clinical governance, regulatory compliance and Canadian business operations.
Where HOSPITUAL Inc. provides services to a hospital, clinic, diagnostic provider, healthcare professional or other organisation and processes personal information only on that party’s instructions, HOSPITUAL Inc. may act as a service provider, agent, affiliate, information manager or processor, depending on the applicable law and contractual arrangement.
In those circumstances, the relevant organisation or healthcare professional may be the health information custodian or other organisation primarily responsible for the personal health information and may provide a separate privacy notice.
3. Applicable Canadian Privacy Laws
Depending on the circumstances, HOSPITUAL Inc. may be subject to:
- the Personal Information Protection and Electronic Documents Act (“PIPEDA”);
- Canada’s Anti-Spam Legislation (“CASL”);
- provincial private-sector privacy legislation;
- provincial health information legislation;
- professional confidentiality and recordkeeping requirements; and
- other applicable federal or provincial
PIPEDA generally applies to personal information collected, used or disclosed by private-sector organisations in the course of commercial activities, including personal information transferred across provincial or national borders.
Alberta, British Columbia and Québec have private-sector privacy legislation that has been declared substantially similar to PIPEDA. Provincial health information legislation may also apply to healthcare professionals, healthcare organisations and persons acting on their behalf.
Where more than one law applies, HOSPITUAL Inc. will comply with the requirements applicable to the relevant processing activity.
4. Responsibility for Personal Health Information
The person or organisation responsible for personal health information depends on the service and the applicable provincial law.
Where a participating healthcare professional or healthcare organisation has custody or control of a clinical record and determines how the information is collected, used and disclosed for healthcare, that professional or organisation may be the health information custodian or equivalent responsible person.
HOSPITUAL Inc. may assist that custodian by:
- providing the digital platform;
- securely receiving and transmitting medical records;
- arranging access to a participating clinician;
- supporting clinical communications;
- maintaining technical and security records;
- providing administrative support; and
- supporting privacy, quality assurance and clinical governance
When acting on behalf of a custodian, HOSPITUAL Inc. will use personal health information only for authorised purposes and in accordance with the custodian’s instructions, the applicable agreement and the law.
HOSPITUAL Inc. remains independently responsible for personal information it controls for its own purposes, including account administration, security, fraud prevention, legal compliance, complaints handling and corporate records.
5. Canadian Privacy Principles
HOSPITUAL Inc. applies the following principles when handling personal information:
- accountability for personal information under its control;
- identifying the purposes for collection, use and disclosure;
- obtaining meaningful consent where required;
- limiting collection to information reasonably necessary for identified purposes;
- limiting use, disclosure and retention;
- maintaining reasonable accuracy;
- protecting information through safeguards appropriate to its sensitivity;
- providing clear information about privacy practices;
- providing access and correction rights; and
- investigating privacy concerns and
Personal health information is considered highly sensitive and is subject to enhanced confidentiality, access and security controls.
6. Consent and Other Authorised Processing
HOSPITUAL Inc. obtains consent for the collection, use and disclosure of personal information where consent is required by applicable law.
Consent must be meaningful. Individuals should understand:
- what personal information is being collected;
- why it is being collected;
- how it will be used;
- the types of organisations or persons to whom it may be disclosed;
- the reasonably foreseeable consequences of the processing; and
- how consent may be
Because medical and health information is sensitive, express consent may be obtained where required or appropriate.
Consent may be provided electronically or through another legally recognised method. In some circumstances, consent may be implied where the purpose is obvious, the information is voluntarily provided and the law permits implied consent.
Canadian privacy and health information laws also permit or require certain processing without consent. Depending on the circumstances, this may include processing that is necessary:
- to provide a requested health service;
- to protect an individual’s health or safety;
- to investigate fraud, misuse or a breach of an agreement or law;
- to comply with a court order, subpoena or legal requirement;
- for an authorised safeguarding or public-health purpose;
- to collect a debt or process an authorised payment;
- to establish, exercise or defend a legal claim; or
- for another purpose permitted or required by applicable
An individual may withdraw consent, subject to reasonable notice and any legal, clinical, contractual or recordkeeping restrictions. Withdrawal will not affect processing already carried out lawfully and may prevent Hospitual or a participating clinician from providing or continuing a service.
7. Collection, Use and Disclosure
The categories of personal information and the purposes described in the Hospitual Privacy Notice apply to Canadian services.
HOSPITUAL Inc. will collect, use and disclose only the personal information reasonably necessary for purposes that a reasonable person would consider appropriate in the circumstances.
Personal information may be obtained from:
- the individual;
- a referring or treating healthcare professional;
- a hospital, clinic, diagnostic provider, imaging provider, laboratory or pathology provider;
- a participating clinician;
- an organisation arranging or funding a service;
- a professional or regulatory register;
- an identity verification or payment provider; or
- another source authorised by the individual or by
HOSPITUAL Inc. does not sell personal information or personal health information. HOSPITUAL Inc. does not use identifiable personal health information for advertising.
8. Access by Employers, Insurers and Organisational Clients
Where a service is arranged or paid for by an employer, insurer, benefits provider or other organisation, that organisation will not receive an individual’s clinical record merely because it arranged or funded the service.
HOSPITUAL Inc. may provide limited administrative information where necessary to confirm eligibility, use of a benefit, service completion, payment or invoicing.
Personal health information or a clinical report will be disclosed to an employer, insurer or organisational client only where:
- the individual has provided an appropriate instruction or consent;
- disclosure is necessary to provide the requested service and is permitted by law;
- the recipient is legally authorised to receive the information; or
- disclosure is otherwise required or permitted by applicable
9. Service Providers and Transfers Outside Canada
HOSPITUAL Inc. may use affiliated entities and service providers located outside Canada. Personal information may therefore be stored in or accessed from countries including the United States and the United Kingdom.
Personal information transferred outside Canada remains subject to HOSPITUAL Inc.’s privacy management arrangements and contractual safeguards, but it may also be subject to the laws of the country in which it is processed. Courts, law-enforcement bodies or public authorities in that country may be able to access information where authorised by local law.
HOSPITUAL Inc. uses contractual, technical and organisational measures appropriate to the sensitivity of the information. These may include:
- written confidentiality and data protection obligations;
- restrictions on use and onward disclosure;
- encryption in transit and at rest;
- role-based and least-privilege access controls;
- multi-factor authentication;
- audit logging and monitoring;
- security assessment and incident obligations; and
- requirements concerning return or secure
Where Québec law applies, HOSPITUAL Inc. will conduct the privacy impact assessment required before communicating personal information outside Québec or entrusting it to a person or body outside Québec.
Individuals may contact the Privacy Officer to request further information about the processing of personal information outside Canada.
10. Safeguards
HOSPITUAL Inc. applies physical, administrative and technical safeguards appropriate to the sensitivity, volume, format and location of personal information.
Safeguards may include:
- designated privacy and security responsibilities;
- privacy, confidentiality and security policies;
- workforce training and confidentiality obligations;
- role-based access controls;
- multi-factor authentication;
- encryption;
- logging and access review;
- secure hosting, transmission and backup arrangements;
- service-provider due diligence and contracts;
- incident response and business continuity procedures; and
- secure retention and destruction
Access to personal health information is limited to participating healthcare professionals, authorised Hospitual personnel and authorised service providers who require access for a legitimate clinical, operational, governance, security or legal purpose.
11. Accuracy, Access and Correction
Individuals may request access to personal information held by HOSPITUAL Inc. and may request correction of information that is inaccurate or incomplete, subject to applicable law.
HOSPITUAL Inc. may require sufficient information to:
- verify the requester’s identity;
- locate the relevant records;
- confirm the requester’s authority; and
- protect information relating to another
Access may be restricted or refused where permitted by law, including where disclosure would:
- reveal personal information about another individual;
- reveal confidential commercial information;
- breach legal privilege;
- create a serious risk to health or safety in circumstances recognised by law; or
- conflict with another applicable legal
A correction request does not necessarily require the deletion or rewriting of an accurate historical entry or a professional opinion or observation made in good faith. Where appropriate, a correction, clarification, addendum or statement of disagreement may be attached to the record.
Where HOSPITUAL Inc. holds information only on behalf of a healthcare professional, hospital or other custodian, the request may be referred to that custodian and HOSPITUAL Inc. will provide reasonable assistance.
Requests will be handled within the period required by applicable law. Under PIPEDA, a response will normally be provided within 30 days, subject to a lawful extension.
12. Data Portability and Automated Decisions
Where Québec law applies, an individual may be entitled to receive eligible computerised personal information in a structured, commonly used technological format and to request that it be communicated to another authorised person or body, subject to applicable exceptions.
HOSPITUAL Inc. does not currently use processing based exclusively on automated systems to make clinical decisions about an individual’s diagnosis, treatment or care.
If HOSPITUAL Inc. introduces a decision based exclusively on automated processing, it will provide the information and rights required by applicable law, including Québec requirements where relevant.
13. Retention and Secure Destruction
HOSPITUAL Inc. retains personal information only for as long as reasonably necessary to provide the relevant service and meet applicable clinical, legal, professional, insurance, contractual and regulatory requirements.
The retention period for a clinical record may depend on:
- the province in which the service is provided;
- the role of HOSPITUAL and the participating healthcare professional;
- the requirements of the relevant professional college;
- the date of the last clinical contact;
- patient-safety and continuity-of-care needs;
- applicable limitation periods;
- an ongoing complaint, incident, audit or investigation;
- safeguarding concerns; and
- an actual or anticipated legal
Where a healthcare professional or organisation is the custodian of a clinical record, the retention period applicable to that custodian will govern the record.
Account, payment, security, complaint, governance and corporate records will be retained in accordance with HOSPITUAL Inc.’s retention schedule and applicable law.
When information is no longer required, it will be securely destroyed, deleted or anonymised. If immediate deletion from backup systems is not reasonably practicable, the information will be protected and placed beyond routine use until deletion occurs.
14. Privacy Incidents and Breach Notification
HOSPITUAL Inc. maintains procedures to identify, contain, investigate, document and respond to suspected privacy or security incidents.
Where PIPEDA applies, HOSPITUAL Inc. will:
- report a breach of security safeguards to the Office of the Privacy Commissioner of Canada where the breach creates a real risk of significant harm;
- notify affected individuals where required;
- notify another organisation or government institution where required to reduce or mitigate the risk of harm; and
- maintain a record of every breach of security safeguards for at least 24 months after determining that the breach occurred.
Where provincial law applies, HOSPITUAL Inc. will notify the relevant provincial privacy authority, custodian, affected individual or other person where required by that law.
15. Commercial Electronic Messages
Commercial electronic messages sent by or on behalf of HOSPITUAL Inc. will be managed in accordance with CASL.
Where CASL applies, HOSPITUAL Inc. will:
- obtain express or implied consent as required;
- identify the sender and provide required contact information;
- include a clear and functioning unsubscribe mechanism; and
- action unsubscribe requests within the period required by
Clinical, account, security, payment and patient-safety communications are not treated as optional marketing merely because they are sent electronically.
HOSPITUAL Inc. does not use personal health information to target marketing communications.
16. Provincial Requirements
16.1 Ontario
Where Ontario’s Personal Health Information Protection Act, 2004 (“PHIPA”) applies:
- a healthcare professional or healthcare organisation with custody or control of the clinical record may be the Health Information Custodian;
- HOSPITUAL may act as an agent or electronic service provider to that custodian;
- personal health information will be collected, used and disclosed only with consent or as permitted or required by PHIPA;
- reasonable steps will be taken to protect personal health information against theft, loss and unauthorised use, disclosure, copying, modification or disposal;
- access and correction requests may be directed to the relevant custodian; and
- privacy breaches will be reported to the custodian and to the Information and Privacy Commissioner of Ontario or affected individuals where required.
16.2 Québec
Where Québec law applies, including the Act respecting the protection of personal information in the private sector and, where applicable, the Act respecting health and social services information:
- HOSPITUAL will designate a person responsible for the protection of personal information;
- the title and contact information of that person will be made available as required;
- privacy governance policies and practices will be maintained;
- a privacy impact assessment will be carried out for qualifying information-system or electronic-service projects;
- a privacy impact assessment will be completed before personal information is communicated or entrusted outside Québec;
- confidentiality incidents will be documented and reported to the Commission d’accès à l’information and affected individuals where they present a risk of serious injury;
- eligible access, correction, portability and automated-decision rights will be supported; and
- French-language privacy information will be made available where
16.3 Alberta
Where Alberta law applies, including the Personal Information Protection Act (“Alberta PIPA”) or the Health Information Act (“HIA”):
- personal information will be collected, used and disclosed only with consent or as otherwise authorised by law;
- where a participating healthcare professional is a custodian under HIA, HOSPITUAL may act as an affiliate or information manager;
- the applicable custodian will remain responsible for health information in its custody or control;
- access and correction rights will be supported;
- privacy impact assessments will be completed or submitted where required for systems handling individually identifying health information; and
- breaches will be reported to the Alberta privacy authority, the Minister, affected individuals or other persons where required.
16.4 British Columbia
Where British Columbia’s Personal Information Protection Act (“BC PIPA”) applies:
- HOSPITUAL will collect, use and disclose personal information only for purposes that a reasonable person would consider appropriate;
- consent will be obtained in a form appropriate to the sensitivity of the information;
- individuals will not be required to consent to unnecessary processing as a condition of receiving a service;
- collection, use, disclosure and retention will be limited to the identified purposes;
- reasonable security arrangements will be maintained; and
- access and correction rights will be
16.5 Other Provinces and Territories
Other provincial or territorial private-sector or health information legislation may apply to a Hospitual service. This may include health information legislation in New Brunswick, Nova Scotia, Newfoundland and Labrador, Manitoba or another jurisdiction.
HOSPITUAL Inc. will assess the requirements applicable to each province or territory before making a regulated clinical service available there. Additional service-specific or provincial privacy information may be provided where necessary.
17. Privacy Requests and Complaints
Questions, access or correction requests, withdrawals of consent and privacy complaints may be directed to:
Dr Masoud Moravej
Privacy Officer, HOSPITUAL Inc. Email: [email protected]
General enquiries: [email protected]
Postal address: Unit 1117, 98 Lillian Street, Toronto, Ontario M4S 0A5, Canada
HOSPITUAL Inc. will investigate privacy complaints fairly and appropriately. It may request additional information needed to confirm identity, understand the concern or locate the relevant records.
Where another organisation or healthcare professional is the relevant custodian or responsible organisation, HOSPITUAL Inc. may refer the request or complaint to that person and provide reasonable assistance.
18. Complaints to Canadian Privacy Authorities
An individual may also contact the privacy authority with jurisdiction over the relevant matter, including:
- the Office of the Privacy Commissioner of Canada;
- the Information and Privacy Commissioner of Ontario;
- the Commission d’accès à l’information du Québec;
- the Office of the Information and Privacy Commissioner of Alberta;
- the Office of the Information and Privacy Commissioner for British Columbia; or
- another applicable provincial or territorial privacy
Individuals are not prevented from contacting a privacy authority because they have not first complained to HOSPITUAL Inc., although HOSPITUAL Inc. welcomes the opportunity to address concerns directly.
19. Changes to this Canada Addendum
HOSPITUAL Inc. may update this Canada Addendum to reflect changes in Canadian privacy law, regulatory guidance, Hospitual services, technology, security arrangements or organisational responsibilities.
The current version will be published with its effective date. Material changes will be communicated where required by applicable law.