CALLENDOC PRIVACY POLICY & COOKIE INFORMATION
Last Updated: November 2025
CALLENDOC ("Company," "we," "us," or "our") operates a telemedicine and digital healthcare platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information about you when you visit our website and use our services.
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Services.
1. INFORMATION WE COLLECT
We collect information in the following ways:
1.1 INFORMATION YOU PROVIDE DIRECTLY
- Account Registration: Name, email address, phone number, date of birth, postal address
- Profile Information: Medical history, current health conditions, medications, allergies
- Communication Data: Messages to healthcare professionals, appointment notes, consultation records
- Payment Information: Billing address, payment method details (processed securely by payment processors)
- Health Data: Symptoms, medical test results, health observations you share
1.2 INFORMATION COLLECTED AUTOMATICALLY
- Device Information: IP address, browser type, device type, operating system
- Usage Data: Pages visited, time spent, appointment booking history, features used
- Cookies and Similar Technologies: Session cookies, authentication tokens, preference cookies
- Location Data: General location information (if you permit)
1.3 INFORMATION FROM THIRD PARTIES
- Healthcare Providers: With your consent, health information from medical professionals you consult
- Payment Processors: Transaction data from authorized payment providers
- Analytics Providers: Aggregated usage data from our analytics partners
2. COOKIES & SIMILAR TECHNOLOGIES
2.1 WHAT ARE COOKIES?
Cookies are small files stored on your device that help us recognize you and enhance your experience on our platform.
2.2 COOKIE TYPES
NECESSARY COOKIES (FIRST-PARTY)
These are essential for the platform to function:
- Authentication cookies: Keep you logged into your patient account
- Security cookies: Prevent fraud and unauthorized access to your account
- Session cookies: Enable appointment booking and form submission
- Accessibility cookies: Store your accessibility preferences
PREFERENCE COOKIES (FIRST-PARTY)
Remember your choices:
- Language preferences
- Display settings and theme
- Privacy consent preferences
ANALYTICAL COOKIES (FIRST & THIRD-PARTY)
Help us understand how patients use our service:
- Google Analytics
- Mixpanel
- Usage statistics (completely anonymized)
MARKETING/ADVERTISING COOKIES (THIRD-PARTY)
Enable personalized advertising:
- Ad network cookies
- Retargeting pixels
- Interest-based advertising
2.3 MANAGING YOUR COOKIES
You can control cookies through:
- Our Cookie Consent Banner (displayed on first visit)
- Your Browser Settings (Chrome, Firefox, Safari, Edge)
- Your Patient Account Privacy Settings
Note: Disabling necessary cookies may affect your ability to use the platform and book appointments.
3. LEGAL BASIS FOR PROCESSING (GDPR)
Under the UK GDPR and Data Protection Act 2018, we process your data based on:
- CONTRACT: Processing necessary to provide telemedicine services
- CONSENT: Where you have explicitly agreed (e.g., marketing emails, health data sharing)
- LEGAL OBLIGATION: Compliance with healthcare and tax laws
- LEGITIMATE INTERESTS: Improving services, fraud prevention, security
For health data and sensitive medical information, we only process with your explicit consent.
4. HOW WE USE YOUR INFORMATION
We use your information for:
- Service Delivery: Providing telemedicine consultations and connecting you with healthcare professionals
- Account Management: Managing your patient account and access to services
- Communication: Sending appointment confirmations, reminders, and follow-up information
- Payment Processing: Billing for consultations and refund management
- Service Improvement: Analyzing usage to improve our platform and user experience
- Security: Detecting and preventing fraud, unauthorized access, and misuse
- Compliance: Meeting legal and healthcare regulatory obligations
- Marketing: Sending health tips and service updates (only with your consent)
5. HOW WE SHARE YOUR INFORMATION
5.1 INFORMATION SHARING
We share your information only as necessary:
Healthcare Providers You Consult
- Only with your explicit consent for each consultation
- Healthcare professionals you have selected and booked with
- Information limited to relevant health records and appointment details
Authorized Third Parties
- Payment processors for billing (for confidential payment processing)
- Cloud infrastructure providers for secure data storage
- Email service providers for appointment notifications
- Analytics services (using anonymized data only)
Legal Requirements
- Law enforcement or government agencies (only when legally required)
- Court orders or legal subpoenas
- Healthcare authority requests where required by law
5.2 DATA PROCESSORS
We work with these trusted processors:
- AWS (Cloud Infrastructure) - EU/UK servers only
- Stripe/PayPal (Payment Processing)
- Sendgrid (Email Services)
All processors have Data Processing Agreements and comply with GDPR standards.
5.3 INTERNATIONAL TRANSFERS
Your health data is primarily stored on UK and EU servers. If transferred outside the UK/EEA, we ensure appropriate safeguards (Standard Contractual Clauses).
6. DATA RETENTION
We retain your information for:
- Account Data: For as long as your account exists, plus 6 years (legal requirement)
- Health Records: 10 years minimum (medical and professional standards)
- Transaction Records: 7 years (tax and financial regulations)
- Cookies: Session cookies deleted at end of session; persistent cookies after 1-2 years
- Analytics Data: 26 months (then anonymized)
You may request deletion of your personal data subject to legal retention requirements.
7. YOUR RIGHTS AS A PATIENT
Under UK GDPR and Data Protection Act 2018, you have the right to:
- RIGHT TO ACCESS: Request a copy of your personal and health data
- RIGHT TO RECTIFICATION: Correct inaccurate health information in your records
- RIGHT TO ERASURE: Request deletion of your data (with legal exceptions)
- RIGHT TO RESTRICT PROCESSING: Limit how your data is used
- RIGHT TO DATA PORTABILITY: Receive your data in portable format for another provider
- RIGHT TO OBJECT: Object to marketing communications at any time
- RIGHT TO WITHDRAW CONSENT: Withdraw consent for specific processing immediately
- RIGHTS RELATED TO AUTOMATED DECISIONS: Request human review of automated decisions
To exercise these rights, contact us at [email protected] with your full name, patient account email, and specific request details.
We will respond within 30 days.
8. SECURITY MEASURES
We protect your health data with comprehensive security measures:
- SSL/TLS Encryption: All data transmitted over HTTPS encryption
- End-to-End Encryption: Your health records encrypted both in transit and at rest
- Access Controls: Role-based access - only authorized staff can access patient data
- Multi-Factor Authentication: Available for added account security
- Regular Security Audits: Annual third-party penetration testing and assessments
- Incident Response: Documented procedures for security incidents
- Employee Training: All staff receive data protection compliance training
- Data Minimization: We collect only information necessary for your care
While we maintain robust security standards, no system is 100% secure. We cannot guarantee absolute security.
9. CHILDREN'S PRIVACY
Callendoc is not intended for children under 16. We do not knowingly collect information from children under 16. If we become aware of such collection, we will delete the information immediately and may terminate the account.
Parents or guardians may contact us if concerned about a child's information.
10. THIRD-PARTY SERVICES
Our platform may contain links to third-party services not operated by us. This Privacy Policy does not apply to third-party services, and we are not responsible for their privacy practices.
Third parties may include:
- External healthcare provider profiles
- Payment processors
- Health information resources
- Analytics services
Please review their privacy policies before providing your information.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. Changes will be posted with an updated "Last Updated" date.
Continued use of our Services after changes constitutes your acceptance. For significant changes affecting your rights, we will notify you via email.
12. CONTACT US
For privacy concerns, questions, or to exercise your patient rights:
Email: [email protected]
Data Protection Officer: [email protected]
Mailing Address:
Callendoc
Data Protection Officer
London, United Kingdom
Response Time: Within 30 calendar days
This Privacy Policy is effective as of November 2025 and complies with:
- UK GDPR (UK General Data Protection Regulation)
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations (PECR) 2003
- Healthcare Data Protection Standards
