Who we are
Obeocure Ltd (UK) and Obeocure Healthcare Private Limited (India) are joint controllers for patient enquiries. Contact: privacy@obeocure.com. A Data Protection Officer will be named before personal data is processed in production.
What we collect
Identity and contact data; health data you send (letters, imaging reports, histories); travel preferences; payment references. Health data is special category data. We process it with explicit consent, and where needed to protect vital interests in an emergency already under our coordination.
Why
To assess whether we can help, to obtain opinions from partner hospitals you have agreed we may contact, to arrange travel and stay, and to keep records of the coordination. We do not sell data. We do not use medical documents for advertising or model training.
Sharing
With hospitals and consultants on our panel, only after you agree. With visa authorities, only the invitation file. With processors under written contracts (encrypted storage, email, telephony). Transfers from the UK to India are done with appropriate safeguards (standard contractual clauses or successor tools) and a transfer assessment.
Retention
Enquiry files that do not proceed: 12 months, then deletion unless you ask us to keep them. Coordinated treatment files: 8 years, aligned to clinical record practice, then review. You may withdraw consent; we will explain if we must keep a subset for legal claims.
Your rights
Access, correction, erasure, restriction, portability, objection, and the right to complain to the ICO (UK) or the Data Protection Board of India. We will answer within one month.
Security
TLS in transit. Encrypted object storage at rest in the UK/EU for incoming reports. Role-based access. Coordinators see the file they are assigned. No shared “info@” mailbox as the only copy of a scan.
Cookies
Essential cookies run the site. Analytics, if you accept, are privacy-preserving and do not track medical form contents.