1. Who We Are
Medicaist Global LLC ("Medicaist", "we", "us") is a health tourism intermediary agency registered in the United States of America. We coordinate medical treatment packages with licensed clinics and hospitals in the Republic of Turkey. Our services primarily target patients in the European Union and United Kingdom.
Data Controller: Medicaist Global LLC
Address: [TODO: Your USA Address]
Privacy Contact: [TODO: [email protected]]
2. Data We Collect
We collect the following categories of personal data:
- Identity Data: Name, date of birth, nationality, passport details.
- Contact Data: Email address, phone number, WhatsApp number, postal address.
- Health Data (Special Category): Medical history, photographs, treatment preferences, BMI, allergies. This data is collected solely to facilitate your medical consultation and treatment planning.
- Financial Data: Payment card details (processed via Stripe; we do not store card numbers).
- Technical Data: IP address, browser type, device information, cookies.
3. Legal Basis for Processing (GDPR Art. 6 & 9)
- Consent (Art. 6(1)(a) & Art. 9(2)(a)): For health data processing and marketing communications.
- Contractual Necessity (Art. 6(1)(b)): To fulfill our service agreement with you.
- Legitimate Interest (Art. 6(1)(f)): For fraud prevention, website analytics, and service improvement.
- Legal Obligation (Art. 6(1)(c)): For tax records and regulatory compliance.
4. International Data Transfers
Your data may be transferred between the following jurisdictions:
- United States (our registered office) — Protected under Standard Contractual Clauses (SCCs).
- Turkey (partner clinics) — Protected under explicit consent and the Turkish Personal Data Protection Law (KVKK).
We ensure all transfers comply with GDPR Chapter V requirements and implement appropriate safeguards.
5. Your Rights (GDPR Articles 15-22)
As a data subject, you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data ("right to be forgotten") (Art. 17)
- Restrict processing (Art. 18)
- Data Portability (Art. 20)
- Object to processing (Art. 21)
- Withdraw Consent at any time (Art. 7(3))
To exercise any right, email: [TODO: [email protected]]. We will respond within 30 days.
6. Data Retention
We retain personal data for 6 years after your last interaction (to comply with medical record and tax obligations). Health data shared with partner clinics is subject to Turkish medical record retention laws.
7. Cookies
We use essential and analytical cookies. For full details, see our Cookie Policy.
8. Complaints
You have the right to lodge a complaint with your local supervisory authority. For UK residents: the Information Commissioner's Office (ICO). For EU residents: your national Data Protection Authority.