PRIVACY & DATA PROTECTION

Privacy Policy

Read Hospitual’s global privacy notice and the regional privacy addenda that may apply to you

HOSPITUAL PRIVACY NOTICE

Version 3.0 | Effective date: 24 July 2026

1.  About this Notice

HOSPITUAL Limited and its affiliated entities (“Hospitual”, “we”, “our” or “us”) respect the privacy and confidentiality of personal information. We are committed to handling personal information responsibly, transparently and securely, particularly where that information concerns an individual’s health. This Privacy Notice explains how Hospitual collects, uses, stores, shares and protects personal information in connection with its websites, digital healthcare platform, clinical services, communications, governance activities and related operational systems. This Notice should be read together with the country or regional privacy addendum that applies to you. A local addendum may identify the Hospitual entity responsible for your personal information and provide additional information about applicable legal grounds, privacy rights, international transfers, regulators and complaint procedures. If this Notice conflicts with an applicable country or regional addendum, the addendum will take precedence to the extent of that conflict.

2.  Who this Notice Applies To

This Notice applies to:
  • patients and prospective patients;
  • website and platform visitors;
  • individuals who create or manage an account;
  • healthcare professionals who apply to join or provide services through Hospitual;
  • referring clinicians and representatives of healthcare organisations;
  • organisational clients and their authorised users;
  • people who contact us, submit an enquiry, provide feedback or make a complaint; and
  • other individuals whose personal information is provided to us in connection with a Hospitual
Separate notices may apply to employees, workers, job applicants, suppliers, research participants or other specific relationships.

3.  Services Covered

Depending on the country and the availability of locally authorised services, Hospitual may provide:
  • Radiology Second Opinion;
  • Pathology Second Opinion;
  • Online Specialist Consultation; and
  • Medical Record
Hospitual provides remote, non-emergency services. It does not provide emergency care, inpatient care or a physical examination through its platform. The availability and scope of services may differ by country.

4.  The Responsible Hospitual Entity

The Hospitual entity responsible for your personal information depends on your location, the service you use, the website or platform through which you access the service and any relevant contractual arrangement. The responsible entity will normally be identified when you register, purchase a service, enter into a contract or receive service-specific privacy information. For direct-to-patient services, the relevant Hospitual entity will generally determine why and how personal information is processed and will act as a controller or equivalent responsible organisation under applicable law. Where Hospitual provides services to a hospital, clinic, diagnostic centre, insurer or other organisation, Hospitual may process personal information on that organisation’s documented instructions. In that situation, the organisation’s privacy notice may also apply and requests concerning the relevant information may need to be directed to that organisation. Participating healthcare professionals, referring organisations and other healthcare providers may act as separate or joint controllers, custodians or similarly responsible organisations for some processing activities. They may maintain their own clinical records and provide separate privacy information.

5.  Personal Information We Collect

We collect only the personal information reasonably required for the relevant service, relationship or legal purpose. Depending on how you interact with us, this may include the following.

5.1  Identity, eligibility and contact information

  • name, title, date of birth and age;
  • address, country of residence, email address and telephone number;
  • government-issued identification where verification is necessary;
  • account identifiers and verification status;
  • emergency contact or next-of-kin information where relevant; and
  • information needed to confirm that you are eligible to use a service.

5.2  Health and clinical information

  • symptoms, diagnoses, medical history and relevant family history;
  • medicines, allergies, treatments and previous procedures;
  • referral information, clinical questions and supporting correspondence;
  • diagnostic images, DICOM files and associated metadata;
  • pathology slides, digital pathology files, laboratory information and related materials;
  • radiology, pathology and other clinical reports;
  • consultation notes, professional opinions and clinical communications;
  • information about a treating or referring healthcare professional; and
  • safeguarding or patient-safety information where
Health information is sensitive and may be treated as special category data, personal health information or an equivalent protected category under applicable law.

5.3  Account and transaction information

  • username, password hash and authentication information;
  • account settings and communication preferences;
  • services requested, order history, invoices, refunds and transaction records; and
  • limited payment-related information. Payment card details may be collected directly by an authorised payment provider rather than stored by Hospitual.

5.4  Clinician and professional information

  • qualifications, professional history and areas of practice;
  • professional registration and licence details;
  • identity, credentialing and right-to-work records;
  • practising privileges, references and verification outcomes;
  • professional indemnity or insurance information;
  • training, appraisal, audit and performance-related information; and
  • availability, case allocation and service-delivery records.

5.5  Technical, usage and security information

  • IP address and approximate location derived from it;
  • device, operating system and browser information;
  • session, login, authentication and access records;
  • platform activity, timestamps and audit trails;
  • cookie and similar technology information;
  • error, diagnostic and performance data; and
  • records generated for cyber security, fraud prevention and incident

5.6  Communications and governance information

  • emails, telephone and platform communications;
  • support enquiries and service messages;
  • feedback, survey responses and preferences;
  • complaints and privacy requests;
  • clinical governance, quality assurance and peer-review records; and
  • incident, safeguarding, discrepancy, risk, audit and compliance records.
We will tell you if a call or consultation is to be recorded and will provide any additional information or choice required by applicable law.

6.  How We Obtain Personal Information

We may obtain personal information:
  • directly from you when you register, upload records, request a service, attend a consultation, contact us or exercise a privacy right;
  • from a healthcare professional, hospital, clinic, diagnostic provider, laboratory or other referring organisation;
  • from an organisation that has arranged or funded a service for you;
  • from participating healthcare professionals and service providers;
  • from professional registers and other lawful verification sources;
  • automatically when you use our websites, platform or systems; and
  • through governance, safeguarding, security, complaints, audit and regulatory
If you provide information about another person, you must have a lawful basis or appropriate authority to do so and should provide them with relevant privacy information where required. We may take reasonable steps to verify that authority.

7.  How We Use Personal Information

We may use personal information to:
  • assess eligibility and clinical suitability;
  • create and administer accounts;
  • verify identity and prevent impersonation or fraud;
  • receive, organise and review medical records;
  • allocate a case to an appropriately qualified healthcare professional;
  • provide consultations, specialist opinions, reports and related clinical communications;
  • communicate with you and provide service updates;
  • process payments, refunds and financial records;
  • verify, contract with and manage participating clinicians;
  • maintain clinical records and an appropriate audit trail;
  • support continuity of care and communicate with authorised healthcare providers;
  • carry out clinical governance, quality assurance, peer review and discrepancy review;
  • identify and respond to critical, unexpected or safety-related findings;
  • manage complaints, concerns, incidents and safeguarding matters;
  • investigate misuse, security events and suspected fraud;
  • maintain, test, secure and improve our platform and services;
  • meet legal, professional, insurance, contractual and regulatory obligations;
  • establish, exercise or defend legal claims;
  • support business continuity, disaster recovery and organisational administration; and
  • send service communications and, where permitted, optional marketing communications.

    We will not use identifiable clinical information for advertising. We will not sell personal information.

Where information is anonymised so that no individual is reasonably identifiable, we may use it for analytics, service evaluation, capacity planning, quality improvement and statistical purposes, subject to applicable law and appropriate safeguards.

8.  Health Information and Medical Confidentiality

Access to health information is restricted to authorised people who have a legitimate clinical, operational, governance, safeguarding, security or legal need to access it. Clinical information is handled by, or under the responsibility of, appropriately qualified healthcare professionals or other persons subject to professional, contractual or legal duties of confidentiality. Hospitual applies data minimisation and need-to-know principles. A person may have access to only the information necessary for their role. Healthcare professionals remain responsible for complying with applicable professional standards and for maintaining any separate records for which they are responsible.

9.  Age and Eligibility

Hospitual’s clinical services are intended only for individuals aged 18 or over. We do not knowingly accept clinical cases concerning individuals under 18, including cases submitted through an adult’s account. If we have reasonable grounds to believe that a user or the subject of a clinical case is under 18, or that identity or eligibility information is inaccurate, we may pause or decline the service while appropriate checks are completed. We may retain limited information about an attempted or declined submission where necessary for safeguarding, security, fraud prevention, complaints handling or legal compliance. Information about a child may occasionally appear incidentally in an adult patient’s medical record, family history, emergency contact information or safeguarding documentation. We will handle that information only as necessary and in accordance with applicable law.

10.  Identity Verification

We or a participating healthcare professional may request identity documents or other evidence where reasonably necessary for patient safety, clinical governance, fraud prevention, safeguarding or legal and regulatory compliance. If required information is not provided or cannot be verified, we may be unable to provide or continue a service. Copies of identity documents will be retained only for as long as reasonably necessary and access will be restricted.

11.  Clinical Governance, Quality and Patient Safety

Personal information may be reviewed for clinical audit, peer review, quality assurance, discrepancy management, complaints handling, incident investigation, safeguarding, risk management and regulatory reporting. Where reasonably possible, information used for audit or service evaluation will be minimised, pseudonymised or anonymised. Identifiable information will be used where it is necessary to investigate an individual case, protect a person, meet a professional obligation or respond to a legal or regulatory requirement.

12.  Critical and Unexpected Findings

Hospitual services are not emergency services. However, a participating clinician may identify a finding that appears to require urgent attention. In accordance with the relevant service protocol and applicable law, we may use available contact information to alert you, a referring professional, an appropriate healthcare provider or, where necessary, an emergency or safeguarding authority. You should not use Hospitual for an emergency. If you believe you may have a medical emergency, contact the emergency service or urgent healthcare service available in your location.

13.  Sharing Personal Information

We may share personal information, where necessary and proportionate, with:
  • participating healthcare professionals;
  • referring or treating healthcare providers;
  • hospitals, clinics, imaging providers, laboratories and pathology providers;
  • organisations arranging, commissioning or funding a service;
  • secure hosting, storage, communications, identity verification and technology providers;
  • payment processors and financial service providers;
  • professional advisers, auditors, insurers and legal representatives;
  • regulators, professional bodies, courts, law-enforcement bodies and public authorities;
  • safeguarding or emergency services where necessary to protect a person; and
  • a prospective purchaser, investor or successor in connection with a properly managed corporate transaction.
Service providers are required by contract or applicable law to protect personal information and use it only for authorised purposes. Where another healthcare provider determines its own purposes and methods of processing, it will be responsible for its own compliance and may provide a separate privacy notice. We do not disclose health information to an employer, family member, insurer or other third party merely because they request it. Disclosure requires an appropriate legal basis, authority or instruction, subject to limited legal and safety exceptions.

14.  International Processing and Transfers

Hospitual operates across borders and uses technology and service providers that may process personal information outside the country in which it was collected. In particular, authorised processing or storage may take place in the United Kingdom, Canada, the United States or another country in which a Hospitual entity, clinician or contracted provider operates. The privacy and public-authority access laws of another country may differ from those in your location. Where required, we use recognised transfer mechanisms and supplementary contractual, organisational or technical safeguards. These may include adequacy decisions or regulations, approved contractual clauses, transfer agreements, risk assessments, encryption and access controls. The applicable country addendum provides further information about local transfer requirements and how to request information about relevant safeguards.

15.  Data Security

Hospitual uses technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access or misuse. Measures may include:
  • encryption in transit and at rest;
  • role-based and least-privilege access controls;
  • multi-factor authentication;
  • audit logging and access monitoring;
  • secure cloud infrastructure and backups;
  • vulnerability, incident and continuity management;
  • periodic access reviews; and
  • confidentiality, training and contractual
No system can be guaranteed to be completely secure. Users are responsible for protecting their account credentials and should notify us promptly if they suspect unauthorised account access.

16.  Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Notice and to meet applicable clinical, legal, professional, insurance, contractual and regulatory requirements. Retention periods depend on the country, service, record type, relationship and context. Relevant factors include continuity of care, patient safety, limitation periods, professional guidance, complaints or incidents, safeguarding concerns, legal holds and regulatory requirements. When information is no longer required, we will securely delete or anonymise it, or place it beyond routine use until secure deletion is possible. Specific retention information may be set out in the applicable country addendum or Hospitual retention schedule.

17.  Accuracy and Your Responsibilities

We take reasonable steps to keep personal information accurate and up to date. You should provide accurate, complete and current information and tell us if important information changes. A request to correct a clinical record does not necessarily permit the deletion or rewriting of a professional opinion or an accurate historical entry. Where appropriate, a correction, clarification or statement of disagreement may be added while preserving the integrity of the clinical record.

18.  Communications and Marketing

We may send communications necessary to operate an account or provide a requested service, including identity checks, appointment information, report notifications, safety communications, payment messages and changes to important terms. We will send optional electronic marketing only where permitted by applicable law. You can unsubscribe using the link in a marketing message or by contacting us. Opting out of marketing will not stop essential service or patient-safety communications.

19.  Cookies and Similar Technologies

Our websites and platform may use cookies and similar technologies for essential functions, security, user preferences, performance measurement and, where permitted, analytics or marketing. Where consent is required, non-essential technologies will not be used until the appropriate choice has been made. More information is available in the Hospitual Cookie Policy and relevant consent settings.

20.  Automated Decision-Making

Hospitual does not currently use solely automated processing to make clinical decisions about diagnosis or treatment, or other decisions that produce legal or similarly significant effects for patients. We may use automated tools for routine technical or administrative purposes, such as authentication, security alerts, file validation, workflow routing or fraud detection. Where applicable law gives you rights concerning a significant automated decision, we will provide the information and safeguards required by that law.

21.  Your Privacy Rights

Depending on the law that applies to you, you may have rights to:
  • receive information about our processing;
  • access personal information we hold about you;
  • request correction of inaccurate or incomplete information;
  • request deletion, where the information is no longer required and no exception applies;
  • restrict or object to certain processing;
  • receive certain information in a portable format;
  • withdraw consent where processing is based on consent;
  • object to direct marketing;
  • ask for human review of certain automated decisions; and
  • complain to Hospitual or an applicable privacy regulator.
These rights are not absolute. Clinical recordkeeping, patient safety, safeguarding, legal obligations, the rights of others and the establishment or defence of legal claims may limit a request. To protect confidentiality, we may ask for proof of identity and sufficient information to locate the relevant records. The applicable country addendum explains local rights, time limits and complaint routes.

22.  Privacy Requests and Complaints

Privacy requests and complaints may be sent to: Email: [email protected] General enquiries: [email protected] Please describe your request clearly and identify the service and Hospitual entity involved, if known. We will acknowledge and respond in accordance with applicable law. If Hospitual is processing information solely on behalf of an organisational client, we may refer the request to that organisation or assist it in responding.

23.  External Websites and Services

Our services may link to websites, applications or services operated by third parties. Their privacy practices are governed by their own notices. Hospitual is not responsible for an independent third party’s privacy practices merely because a link is provided.

24.  Changes to this Notice

We may update this Notice to reflect changes in our services, technology, legal obligations or governance arrangements. The current version will be published with its effective date. Where a change materially affects how we use personal information, we will provide additional notice where required.

25.  Applicable Addenda

This Privacy Notice should be read together with any country or regional addendum applicable to the relevant service. Published addenda may include:
  • Schedule 1 – United Kingdom Privacy Addendum;
  • Schedule 2 – Canada Privacy Addendum, when issued; and
  • any other country, regional, provincial or state addendum published for a Hospitual

26.  Contact Us

Privacy contact: [email protected] General enquiries: [email protected] The postal address and regulatory contact applicable to you are provided in the relevant country or regional addendum.

UNITED KINGDOM PRIVACY ADDENDUM

Version 1.0 | Effective date: 24 July 2026

This United Kingdom Privacy Addendum (“UK Addendum”) supplements the Hospitual Global Privacy Notice. It applies where HOSPITUAL Limited provides a service to you, where you are located in the United Kingdom and UK data protection law applies, or where the relevant processing is otherwise subject to UK data protection law.

If this UK Addendum conflicts with the Global Privacy Notice, this UK Addendum takes precedence in relation to processing governed by UK law.

1.  UK Responsible Entity

HOSPITUAL Limited, trading as “Hospitual”, is the controller of personal data processed for its direct-to-patient services and for its own platform administration, clinical governance, security, regulatory and business operations.

Registered office:

HOSPITUAL Limited Flat 1 Windsor House Heathfield Gardens London W4 4JT United Kingdom

General enquiries: [email protected]

Data protection contact: [email protected]

Where HOSPITUAL Limited provides contracted services to a hospital, clinic, diagnostic provider or other organisation and acts only on that organisation’s documented instructions, it may act as a processor. The relevant organisation remains responsible for its own privacy notice and for responding to requests as controller, although Hospitual will provide appropriate assistance.

Participating clinicians may be independent controllers for clinical records or professional decisions for which they determine the purposes and means of processing. The applicable contractual and clinical arrangements determine the role of each party for each processing activity.

2.  UK Laws Covered

We process personal data in accordance with applicable UK privacy and data protection law, including:

  • the UK General Data Protection Regulation (“UK GDPR”);
  • the Data Protection Act 2018 (“DPA 2018”);
  • the Data (Use and Access) Act 2025 (“DUAA”), which amends parts of UK data protection law; and
  • the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), where relevant to cookies and electronic marketing.

We also take account of applicable duties of medical confidentiality, professional standards and healthcare regulatory requirements.

3.  Categories of UK Personal Data

The categories described in the Global Privacy Notice apply. Health information, including medical

images, pathology information, reports, symptoms, diagnoses and clinical correspondence, is “special category data” under the UK GDPR and receives additional protection.

Identity documents may include biometric or other sensitive information. We will use such information only where necessary for verification, security, safeguarding or compliance and will apply appropriate access and retention controls.

4.  UK Lawful Bases and Special Category Conditions

We identify an Article 6 lawful basis for each processing purpose. When we process health information or other special category data, we also identify a separate Article 9 condition.

The following table describes the bases most likely to apply. The precise basis depends on the circumstances.

Purpose

UK GDPR Article 6 basis

UK GDPR Article 9 condition, where applicable

Registering an account, receiving a case, providing a consultation, report or second opinion, processing payment and managing the patient relationship

Article 6(1)(b): performance of a contract or steps requested before entering into a contract

Article 9(2)(h): medical diagnosis, provision or management of health care, where processed by or under the responsibility of a professional subject to confidentiality

Maintaining clinical records, clinical governance, quality assurance, peer review, discrepancy review and patient-safety processes

Article 6(1)(c): legal obligation, where a specific obligation applies; and/or Article 6(1)(f): legitimate interests in safe, effective and accountable healthcare

Article 9(2)(h): provision or management of health care; where appropriate, Article 9(2)(g) together with a relevant DPA 2018 Schedule 1 condition

Verifying identity, age, clinician credentials and professional eligibility

Article 6(1)(b), Article 6(1)(c) and/or Article 6(1)(f), depending on context

Article 9(2)(h), or another applicable Article 9 condition where special category data is necessary

Responding to critical or unexpected f indings and protecting lif e

Article 6(1)(d): vital interests, where strictly necessary; Article 6(1)(b), (c) or (f ) may apply in other circumstances

Article 9(2)(c): vital interests only where the individual is physically or legally incapable of consent; and/or Article 9(2)(h) for healthcare

Safeguarding and protecting individuals at risk

Article 6(1)(c): legal obligation, where applicable; and/or Article 6(1)(f): legitimate interests

Article 9(2)(g) together with an applicable substantial-public-interest condition in Schedule 1 DPA 2018; Article 9(2)(h) may also apply

Handling complaints, incidents, regulatory enquiries and

professional obligations

Article 6(1)(c): legal obligation; and/or Article 6(1)(f): legitimate interests in investigating and resolving concerns

Article 9(2)(h); Article 9(2)(f) where necessary for legal claims; or Article 9(2)(g) with an applicable Schedule 1 condition

Preventing f raud, securing systems, authenticating users, maintaining audit logs and investigating misuse

Article 6(1)(c), where a legal duty applies; and/or Article 6(1)(f): legitimate interests in security, confidentiality and f raud prevention

Article 9(2)(f), (g) or (h) only where special category data is necessary and the relevant condition is met

Establishing, exercising or defending legal claims and obtaining legal advice

Article 6(1)(f): legitimate interests; and/or Article 6(1)(c)

Article 9(2)(f): legal claims and judicial acts

Meeting accounting, tax, corporate, insurance and regulatory requirements

Article 6(1)(c): legal obligation; and/or Article 6(1)(f)

Normally not applicable; Article 9(2)(f), (g) or

(h) may apply where relevant health information is necessary

Service analytics, capacity planning and improvement using identifiable or pseudonymised information

Article 6(1)(f): legitimate interests, following a balancing assessment; consent where required

Article 9(2)(h) where genuinely necessary for management of healthcare systems or services; otherwise explicit consent under Article 9(2)(a), or anonymised information

Sending optional electronic marketing

Article 6(1)(a): consent where PECR requires consent; in limited cases Article 6(1)(f) may apply where PECR permits

We do not use health information for marketing

Non-essential cookies or similar technologies

Article 6(1)(a): consent, where required by PECR; another basis may apply to associated processing where a statutory exemption applies

We do not intentionally use health information for advertising cookies

We do not rely on consent as the principal basis for processing necessary to provide healthcare where another lawful basis and Article 9 condition apply. This is because withdrawing consent should not ordinarily prevent us from maintaining information that must be retained for clinical, legal or safety reasons.

Where we rely on legitimate interests, we consider the purpose, necessity and impact on your rights. You may request information about the relevant balancing assessment, subject to the protection of confidential and legally privileged information.

Where Article 9(2)(g) and a DPA 2018 Schedule 1 condition require an Appropriate Policy Document, we will maintain one.

5.  Medical Confidentiality

Health information is processed by, or under the responsibility of, healthcare professionals or other persons who owe an appropriate duty of confidentiality.

We may share relevant information with a treating or referring professional where this is necessary for the requested service, continuity of care or patient safety and is lawful. We will not routinely disclose health information to relatives, employers or insurers without appropriate authority or another lawful basis.

The common-law duty of confidentiality and applicable professional guidance may require consent or another recognised justification in addition to data protection compliance.

6.  Information Obtained from Other Sources

We may receive personal data from referring clinicians, healthcare organisations, diagnostic providers, laboratories, professional registers or an organisation arranging a service.

Where Articles 13 or 14 UK GDPR require us to provide privacy information, we will do so at the relevant time, normally when the data is collected from you or, where it is obtained elsewhere, within the period required by law unless an exemption applies.

7.  Required Information

Some personal data is required to enter into or perform a contract, confirm eligibility, verify identity, maintain clinical safety or comply with legal and professional requirements.

If you do not provide required information, we may be unable to accept a case, provide a service, verify a clinician or respond safely to a request. We will explain the consequence where it is not already clear.

8.  UK Data Sharing

The recipients described in the Global Privacy Notice may receive personal data where necessary and lawful. In the UK this may include:

  • UK-registered healthcare professionals providing or reviewing care;
  • a referring or treating clinician, GP or healthcare organisation;
  • the Care Quality Commission, Information Commissioner’s Office, professional regulators or other competent authorities;
  • NHS bodies or emergency services where lawfully necessary;
  • insurers, auditors and legal advisers;
  • payment, identity, communications and technology providers; and
  • courts, law-enforcement bodies or safeguarding

Where a recipient is a processor, we put in place the contract required by Article 28 UK GDPR. Where parties are independent or joint controllers, we document the arrangement as required and provide appropriate transparency.

9.  International Transfers from the UK

Hospitual uses cloud and technology infrastructure that may involve authorised storage or access in the United States and may use providers or group entities located outside the United Kingdom.

A transfer to a separate organisation outside the UK will be made only where permitted by UK data protection law. Depending on the destination and recipient, we may rely on:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the European Commission Standard Contractual Clauses;
  • another safeguard recognised under Article 46 UK GDPR; or
  • a limited Article 49 derogation where it is lawful and

Where required, we assess the laws and practices of the destination and implement supplementary measures. These may include encryption, strict access controls, data minimisation, contractual limits and transfer risk assessments.

You may contact [email protected] to request further information about the safeguard relevant to a transfer. We may provide a redacted summary or copy where necessary to protect security, confidentiality or commercial information.

10.  UK Retention

We maintain a retention schedule and review retention periods by record type. Clinical records relating to adult services will normally be retained for at least eight years after the end of treatment or the last relevant clinical contact, unless a longer or shorter period is justified by applicable law, professional guidance, limitation periods, an ongoing complaint or incident, safeguarding, a legal hold or another documented requirement.

Indicative periods include:

  • account information: for the life of the account and an appropriate period after closure;
  • core clinical records and reports: normally at least eight years after the end of treatment or last relevant clinical contact;
  • security and access logs: according to risk and operational need, normally not less than six months;
  • complaints, incidents, governance, contracts and legal records: normally six years after closure or expiry, or longer where justified; and
  • identity verification material: only for as long as necessary for the verification and any related legal, fraud or safeguarding purpose.

These periods are subject to the storage-limitation principle. When a record no longer needs to be retained, it will be securely deleted or anonymised.

11.  Your UK Data Protection Rights

Subject to the conditions and exemptions in law, you may have the right to:

  • be informed about the collection and use of your personal data;
  • obtain confirmation that we process your data and receive a copy;
  • have inaccurate personal data corrected and incomplete data completed;
  • request erasure in specified circumstances;
  • request restriction of processing in specified circumstances;
  • object to processing based on legitimate interests or the performance of a public task;
  • object at any time to direct marketing;
  • receive eligible data in a structured, commonly used and machine-readable format and transmit it to another controller;
  • withdraw consent at any time where consent is the basis for processing; and
  • receive safeguards in relation to qualifying solely automated

These rights are not absolute. For example, we may need to retain a clinical record, protect another person’s information, comply with a legal obligation, preserve professional opinions or establish or defend a legal claim.

12.  Exercising Your Rights

Send a request to [email protected] or to the registered office shown in section 1.

Please provide enough information for us to identify you and locate the relevant records. We may request proportionate proof of identity. We will normally respond without undue delay and within one month, subject to any lawful extension or pause while permitted clarification or identification information is obtained.

We do not normally charge a fee. A reasonable fee may be charged, or a request may be refused, where the law permits this because a request is manifestly unfounded or excessive.

Where HOSPITUAL Limited acts only as a processor, we may refer the request to the relevant controller and assist that controller.

13.  Clinical Records and Correction Requests

The right to rectification does not require the deletion of an accurate historical entry or the substitution of one clinician’s professional opinion for another. Where a clinical opinion is disputed, it may be appropriate to preserve the original entry and add a correction, clarification, addendum or statement of disagreement.

Access to health information may also be limited where a statutory exemption applies, including where disclosure would reveal protected information about another person or create a serious risk of harm in circumstances recognised by law.

14.  Automated Decision-Making

HOSPITUAL Limited does not currently make diagnoses, treatment recommendations or other decisions producing legal or similarly significant effects about patients solely by automated means.

If this changes, we will assess the processing, update the relevant privacy information and provide the safeguards required by UK law. These may include meaningful information about the logic involved, the significance and expected consequences, human intervention and the ability to challenge a decision.

15.  Cookies and Electronic Marketing

Our use of cookies, pixels, local storage and similar technologies is governed by PECR and UK GDPR. We use consent where required and provide controls through our cookie interface and Cookie Policy.

Service communications are not marketing. Optional marketing communications will identify Hospitual and provide a straightforward way to opt out. We do not use identifiable health information to target advertising.

16.  Data Protection Complaints

If you are concerned about how we use your personal data, please contact us first: Email: [email protected]

Post: HOSPITUAL Limited, Flat 1 Windsor House, Heathfield Gardens, London W4 4JT, United Kingdom

In accordance with the UK’s data protection complaints requirements, we will facilitate the making of a complaint, acknowledge it within 30 days and investigate and respond without undue delay. We may ask for information needed to understand and investigate the matter and will keep you appropriately informed of progress and outcome.

You also have the right to complain to the Information Commissioner’s Office: Information Commissioner’s Office

Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF United Kingdom

Website: https://ico.org.uk/make-a-complaint/ Telephone: 0303 123 1113

We would appreciate the opportunity to address your concern before you contact the ICO, but you are not required to contact us first.

17.  UK Representative and Data Protection Officer

HOSPITUAL Limited is established in the United Kingdom and does not require a separate UK representative for the processing covered by this Addendum.

The current data protection contact is:

Dr Masoud Moravej

Email: [email protected]

If Hospitual formally appoints a Data Protection Officer under Articles 37 to 39 UK GDPR, the appointment and contact details will be published and communicated as required. Use of a “data protection contact” title in this Addendum should not, by itself, be read as a representation that a statutory DPO appointment is required or has been made.

18.  Updates to this UK Addendum

We may update this UK Addendum to reflect changes in law, regulatory guidance, services, technology or organisational arrangements. The current version will be published with its effective date. Material changes will be notified where required.

CANADA PRIVACY ADDENDUM

Version 1.0 | Effective date: 24 July 2026

1.  Purpose and Application

This Canada Privacy Addendum (“Canada Addendum”) supplements the Hospitual Privacy Notice. It applies where:

  • HOSPITUAL provides the relevant service;
  • an individual uses Hospitual services in Canada;
  • personal information is collected, used or disclosed in connection with a Canadian service; or
  • Canadian federal or provincial privacy law otherwise applies to the

This Canada Addendum should be read together with the Hospitual Privacy Notice. If there is a conflict between this Canada Addendum and the Privacy Notice, this Canada Addendum will take precedence in relation to processing governed by Canadian law.

The privacy rules applicable to health information in Canada may vary by province and by the role of the organisation or healthcare professional involved. This Canada Addendum therefore addresses both federal requirements and the principal provincial requirements that may apply to Hospitual services.

2.  Canadian Responsible Entity

The responsible Canadian entity is:

HOSPITUAL Inc.

Corporation number: 1718977-0

Federally incorporated under the Canada Business Corporations Act on 25 July 2025 Registered office: Unit 1117, 98 Lillian Street, Toronto, Ontario M4S 0A5, Canada General enquiries: [email protected]

Privacy Officer: Dr Masoud Moravej

Privacy enquiries and complaints: [email protected]

HOSPITUAL Inc. is responsible for personal information under its control, including personal information processed for its direct-to-patient services, account and platform administration, privacy and security management, clinical governance, regulatory compliance and Canadian business operations.

Where HOSPITUAL Inc. provides services to a hospital, clinic, diagnostic provider, healthcare professional or other organisation and processes personal information only on that party’s instructions, HOSPITUAL Inc. may act as a service provider, agent, affiliate, information manager or processor, depending on the applicable law and contractual arrangement.

In those circumstances, the relevant organisation or healthcare professional may be the health information custodian or other organisation primarily responsible for the personal health information and may provide a separate privacy notice.

3.  Applicable Canadian Privacy Laws

Depending on the circumstances, HOSPITUAL Inc. may be subject to:

  • the Personal Information Protection and Electronic Documents Act (“PIPEDA”);
  • Canada’s Anti-Spam Legislation (“CASL”);
  • provincial private-sector privacy legislation;
  • provincial health information legislation;
  • professional confidentiality and recordkeeping requirements; and
  • other applicable federal or provincial

PIPEDA generally applies to personal information collected, used or disclosed by private-sector organisations in the course of commercial activities, including personal information transferred across provincial or national borders.

Alberta, British Columbia and Québec have private-sector privacy legislation that has been declared substantially similar to PIPEDA. Provincial health information legislation may also apply to healthcare professionals, healthcare organisations and persons acting on their behalf.

Where more than one law applies, HOSPITUAL Inc. will comply with the requirements applicable to the relevant processing activity.

4.  Responsibility for Personal Health Information

The person or organisation responsible for personal health information depends on the service and the applicable provincial law.

Where a participating healthcare professional or healthcare organisation has custody or control of a clinical record and determines how the information is collected, used and disclosed for healthcare, that professional or organisation may be the health information custodian or equivalent responsible person.

HOSPITUAL Inc. may assist that custodian by:

  • providing the digital platform;
  • securely receiving and transmitting medical records;
  • arranging access to a participating clinician;
  • supporting clinical communications;
  • maintaining technical and security records;
  • providing administrative support; and
  • supporting privacy, quality assurance and clinical governance

When acting on behalf of a custodian, HOSPITUAL Inc. will use personal health information only for authorised purposes and in accordance with the custodian’s instructions, the applicable agreement and the law.

HOSPITUAL Inc. remains independently responsible for personal information it controls for its own purposes, including account administration, security, fraud prevention, legal compliance, complaints handling and corporate records.

5.  Canadian Privacy Principles

HOSPITUAL Inc. applies the following principles when handling personal information:

  • accountability for personal information under its control;
  • identifying the purposes for collection, use and disclosure;
  • obtaining meaningful consent where required;
  • limiting collection to information reasonably necessary for identified purposes;
  • limiting use, disclosure and retention;
  • maintaining reasonable accuracy;
  • protecting information through safeguards appropriate to its sensitivity;
  • providing clear information about privacy practices;
  • providing access and correction rights; and
  • investigating privacy concerns and

Personal health information is considered highly sensitive and is subject to enhanced confidentiality, access and security controls.

6.  Consent and Other Authorised Processing

HOSPITUAL Inc. obtains consent for the collection, use and disclosure of personal information where consent is required by applicable law.

Consent must be meaningful. Individuals should understand:

  • what personal information is being collected;
  • why it is being collected;
  • how it will be used;
  • the types of organisations or persons to whom it may be disclosed;
  • the reasonably foreseeable consequences of the processing; and
  • how consent may be

Because medical and health information is sensitive, express consent may be obtained where required or appropriate.

Consent may be provided electronically or through another legally recognised method. In some circumstances, consent may be implied where the purpose is obvious, the information is voluntarily provided and the law permits implied consent.

Canadian privacy and health information laws also permit or require certain processing without consent. Depending on the circumstances, this may include processing that is necessary:

  • to provide a requested health service;
  • to protect an individual’s health or safety;
  • to investigate fraud, misuse or a breach of an agreement or law;
  • to comply with a court order, subpoena or legal requirement;
  • for an authorised safeguarding or public-health purpose;
  • to collect a debt or process an authorised payment;
  • to establish, exercise or defend a legal claim; or
  • for another purpose permitted or required by applicable

An individual may withdraw consent, subject to reasonable notice and any legal, clinical, contractual or recordkeeping restrictions. Withdrawal will not affect processing already carried out lawfully and may prevent Hospitual or a participating clinician from providing or continuing a service.

7.  Collection, Use and Disclosure

The categories of personal information and the purposes described in the Hospitual Privacy Notice apply to Canadian services.

HOSPITUAL Inc. will collect, use and disclose only the personal information reasonably necessary for purposes that a reasonable person would consider appropriate in the circumstances.

Personal information may be obtained from:

  • the individual;
  • a referring or treating healthcare professional;
  • a hospital, clinic, diagnostic provider, imaging provider, laboratory or pathology provider;
  • a participating clinician;
  • an organisation arranging or funding a service;
  • a professional or regulatory register;
  • an identity verification or payment provider; or
  • another source authorised by the individual or by

HOSPITUAL Inc. does not sell personal information or personal health information. HOSPITUAL Inc. does not use identifiable personal health information for advertising.

8.  Access by Employers, Insurers and Organisational Clients

Where a service is arranged or paid for by an employer, insurer, benefits provider or other organisation, that organisation will not receive an individual’s clinical record merely because it arranged or funded the service.

HOSPITUAL Inc. may provide limited administrative information where necessary to confirm eligibility, use of a benefit, service completion, payment or invoicing.

Personal health information or a clinical report will be disclosed to an employer, insurer or organisational client only where:

  • the individual has provided an appropriate instruction or consent;
  • disclosure is necessary to provide the requested service and is permitted by law;
  • the recipient is legally authorised to receive the information; or
  • disclosure is otherwise required or permitted by applicable

9.  Service Providers and Transfers Outside Canada

HOSPITUAL Inc. may use affiliated entities and service providers located outside Canada. Personal information may therefore be stored in or accessed from countries including the United States and the United Kingdom.

Personal information transferred outside Canada remains subject to HOSPITUAL Inc.’s privacy management arrangements and contractual safeguards, but it may also be subject to the laws of the country in which it is processed. Courts, law-enforcement bodies or public authorities in that country may be able to access information where authorised by local law.

HOSPITUAL Inc. uses contractual, technical and organisational measures appropriate to the sensitivity of the information. These may include:

  • written confidentiality and data protection obligations;
  • restrictions on use and onward disclosure;
  • encryption in transit and at rest;
  • role-based and least-privilege access controls;
  • multi-factor authentication;
  • audit logging and monitoring;
  • security assessment and incident obligations; and
  • requirements concerning return or secure

Where Québec law applies, HOSPITUAL Inc. will conduct the privacy impact assessment required before communicating personal information outside Québec or entrusting it to a person or body outside Québec.

Individuals may contact the Privacy Officer to request further information about the processing of personal information outside Canada.

10.  Safeguards

HOSPITUAL Inc. applies physical, administrative and technical safeguards appropriate to the sensitivity, volume, format and location of personal information.

Safeguards may include:

  • designated privacy and security responsibilities;
  • privacy, confidentiality and security policies;
  • workforce training and confidentiality obligations;
  • role-based access controls;
  • multi-factor authentication;
  • encryption;
  • logging and access review;
  • secure hosting, transmission and backup arrangements;
  • service-provider due diligence and contracts;
  • incident response and business continuity procedures; and
  • secure retention and destruction

Access to personal health information is limited to participating healthcare professionals, authorised Hospitual personnel and authorised service providers who require access for a legitimate clinical, operational, governance, security or legal purpose.

11.  Accuracy, Access and Correction

Individuals may request access to personal information held by HOSPITUAL Inc. and may request correction of information that is inaccurate or incomplete, subject to applicable law.

HOSPITUAL Inc. may require sufficient information to:

  • verify the requester’s identity;
  • locate the relevant records;
  • confirm the requester’s authority; and
  • protect information relating to another

Access may be restricted or refused where permitted by law, including where disclosure would:

  • reveal personal information about another individual;
  • reveal confidential commercial information;
  • breach legal privilege;
  • create a serious risk to health or safety in circumstances recognised by law; or
  • conflict with another applicable legal

A correction request does not necessarily require the deletion or rewriting of an accurate historical entry or a professional opinion or observation made in good faith. Where appropriate, a correction, clarification, addendum or statement of disagreement may be attached to the record.

Where HOSPITUAL Inc. holds information only on behalf of a healthcare professional, hospital or other custodian, the request may be referred to that custodian and HOSPITUAL Inc. will provide reasonable assistance.

Requests will be handled within the period required by applicable law. Under PIPEDA, a response will normally be provided within 30 days, subject to a lawful extension.

12.  Data Portability and Automated Decisions

Where Québec law applies, an individual may be entitled to receive eligible computerised personal information in a structured, commonly used technological format and to request that it be communicated to another authorised person or body, subject to applicable exceptions.

HOSPITUAL Inc. does not currently use processing based exclusively on automated systems to make clinical decisions about an individual’s diagnosis, treatment or care.

If HOSPITUAL Inc. introduces a decision based exclusively on automated processing, it will provide the information and rights required by applicable law, including Québec requirements where relevant.

13.  Retention and Secure Destruction

HOSPITUAL Inc. retains personal information only for as long as reasonably necessary to provide the relevant service and meet applicable clinical, legal, professional, insurance, contractual and regulatory requirements.

The retention period for a clinical record may depend on:

  • the province in which the service is provided;
  • the role of HOSPITUAL and the participating healthcare professional;
  • the requirements of the relevant professional college;
  • the date of the last clinical contact;
  • patient-safety and continuity-of-care needs;
  • applicable limitation periods;
  • an ongoing complaint, incident, audit or investigation;
  • safeguarding concerns; and
  • an actual or anticipated legal

Where a healthcare professional or organisation is the custodian of a clinical record, the retention period applicable to that custodian will govern the record.

Account, payment, security, complaint, governance and corporate records will be retained in accordance with HOSPITUAL Inc.’s retention schedule and applicable law.

When information is no longer required, it will be securely destroyed, deleted or anonymised. If immediate deletion from backup systems is not reasonably practicable, the information will be protected and placed beyond routine use until deletion occurs.

14.  Privacy Incidents and Breach Notification

HOSPITUAL Inc. maintains procedures to identify, contain, investigate, document and respond to suspected privacy or security incidents.

Where PIPEDA applies, HOSPITUAL Inc. will:

  • report a breach of security safeguards to the Office of the Privacy Commissioner of Canada where the breach creates a real risk of significant harm;
  • notify affected individuals where required;
  • notify another organisation or government institution where required to reduce or mitigate the risk of harm; and
  • maintain a record of every breach of security safeguards for at least 24 months after determining that the breach occurred.

Where provincial law applies, HOSPITUAL Inc. will notify the relevant provincial privacy authority, custodian, affected individual or other person where required by that law.

15.  Commercial Electronic Messages

Commercial electronic messages sent by or on behalf of HOSPITUAL Inc. will be managed in accordance with CASL.

Where CASL applies, HOSPITUAL Inc. will:

  • obtain express or implied consent as required;
  • identify the sender and provide required contact information;
  • include a clear and functioning unsubscribe mechanism; and
  • action unsubscribe requests within the period required by

Clinical, account, security, payment and patient-safety communications are not treated as optional marketing merely because they are sent electronically.

HOSPITUAL Inc. does not use personal health information to target marketing communications.

16.  Provincial Requirements

16.1  Ontario

Where Ontario’s Personal Health Information Protection Act, 2004 (“PHIPA”) applies:

  • a healthcare professional or healthcare organisation with custody or control of the clinical record may be the Health Information Custodian;
  • HOSPITUAL may act as an agent or electronic service provider to that custodian;
  • personal health information will be collected, used and disclosed only with consent or as permitted or required by PHIPA;
  • reasonable steps will be taken to protect personal health information against theft, loss and unauthorised use, disclosure, copying, modification or disposal;
  • access and correction requests may be directed to the relevant custodian; and
  • privacy breaches will be reported to the custodian and to the Information and Privacy Commissioner of Ontario or affected individuals where required.

16.2  Québec

Where Québec law applies, including the Act respecting the protection of personal information in the private sector and, where applicable, the Act respecting health and social services information:

  • HOSPITUAL will designate a person responsible for the protection of personal information;
  • the title and contact information of that person will be made available as required;
  • privacy governance policies and practices will be maintained;
  • a privacy impact assessment will be carried out for qualifying information-system or electronic-service projects;
  • a privacy impact assessment will be completed before personal information is communicated or entrusted outside Québec;
  • confidentiality incidents will be documented and reported to the Commission d’accès à l’information and affected individuals where they present a risk of serious injury;
  • eligible access, correction, portability and automated-decision rights will be supported; and
  • French-language privacy information will be made available where

16.3  Alberta

Where Alberta law applies, including the Personal Information Protection Act (“Alberta PIPA”) or the Health Information Act (“HIA”):

  • personal information will be collected, used and disclosed only with consent or as otherwise authorised by law;
  • where a participating healthcare professional is a custodian under HIA, HOSPITUAL may act as an affiliate or information manager;
  • the applicable custodian will remain responsible for health information in its custody or control;
  • access and correction rights will be supported;
  • privacy impact assessments will be completed or submitted where required for systems handling individually identifying health information; and
  • breaches will be reported to the Alberta privacy authority, the Minister, affected individuals or other persons where required.

16.4  British Columbia

Where British Columbia’s Personal Information Protection Act (“BC PIPA”) applies:

  • HOSPITUAL will collect, use and disclose personal information only for purposes that a reasonable person would consider appropriate;
  • consent will be obtained in a form appropriate to the sensitivity of the information;
  • individuals will not be required to consent to unnecessary processing as a condition of receiving a service;
  • collection, use, disclosure and retention will be limited to the identified purposes;
  • reasonable security arrangements will be maintained; and
  • access and correction rights will be

16.5  Other Provinces and Territories

Other provincial or territorial private-sector or health information legislation may apply to a Hospitual service. This may include health information legislation in New Brunswick, Nova Scotia, Newfoundland and Labrador, Manitoba or another jurisdiction.

HOSPITUAL Inc. will assess the requirements applicable to each province or territory before making a regulated clinical service available there. Additional service-specific or provincial privacy information may be provided where necessary.

17.  Privacy Requests and Complaints

Questions, access or correction requests, withdrawals of consent and privacy complaints may be directed to:

Dr Masoud Moravej

Privacy Officer, HOSPITUAL Inc. Email: [email protected]

General enquiries: [email protected]

Postal address: Unit 1117, 98 Lillian Street, Toronto, Ontario M4S 0A5, Canada

HOSPITUAL Inc. will investigate privacy complaints fairly and appropriately. It may request additional information needed to confirm identity, understand the concern or locate the relevant records.

Where another organisation or healthcare professional is the relevant custodian or responsible organisation, HOSPITUAL Inc. may refer the request or complaint to that person and provide reasonable assistance.

18.  Complaints to Canadian Privacy Authorities

An individual may also contact the privacy authority with jurisdiction over the relevant matter, including:

  • the Office of the Privacy Commissioner of Canada;
  • the Information and Privacy Commissioner of Ontario;
  • the Commission d’accès à l’information du Québec;
  • the Office of the Information and Privacy Commissioner of Alberta;
  • the Office of the Information and Privacy Commissioner for British Columbia; or
  • another applicable provincial or territorial privacy

Individuals are not prevented from contacting a privacy authority because they have not first complained to HOSPITUAL Inc., although HOSPITUAL Inc. welcomes the opportunity to address concerns directly.

19.  Changes to this Canada Addendum

HOSPITUAL Inc. may update this Canada Addendum to reflect changes in Canadian privacy law, regulatory guidance, Hospitual services, technology, security arrangements or organisational responsibilities.

The current version will be published with its effective date. Material changes will be communicated where required by applicable law.

Scroll to Top