Privacy Policy

Check if You Qualify

EU Healthcare Cross-Border Treatment Limited

Version 2.0, effective 1 August 2026

How we collect, use, share and protect personal and medical information when you use our services.

1. Who We Are and How to Contact Us

Data controller: EU Healthcare Cross-Border Treatment Limited

Address: 5 Fitzwilliam Square, Dublin, D02 R744, Ireland
General enquiries:
info@euhealthcare.ie
Privacy enquiries and rights requests:
compliance@euhealthcare.ie

EU Healthcare is the data controller for the personal information it decides to collect and use for its own coordination, administrative, legal and business purposes. In some circumstances, another organisation, such as a hospital group, may be a separate data controller for the information it receives and creates.

2. Who This Policy Applies To

This policy applies to personal information relating to:

  • people who make an enquiry or request an eligibility review;
  • current and former patients using our coordination service;
  • parents, guardians and authorised representatives;
  • emergency contacts and next of kin;
  • GPs, consultants and other healthcare professionals whose details appear in patient documentation;
  • people who use our website, online forms or communication channels; and
  • any other person whose information is provided to us in connection with a patient enquiry or treatment journey.

3. Our Role

EU Healthcare provides coordination and administrative support for patients seeking treatment abroad, including patients who may apply for reimbursement under the EU Cross-Border Healthcare Directive Scheme. Depending on the circumstances, we may:

  • respond to an enquiry and explain the coordination process;
  • carry out an initial administrative review of referral or reimbursement documentation;
  • facilitate an introduction to a partner hospital group;
  • coordinate medical documents and communications;
  • support the arrangement of an initial consultation, assessment or treatment;
  • provide practical information and coordination support in relation to travel and accommodation; and
  • assist with relevant administrative and reimbursement documentation.

EU Healthcare is not a medical provider and does not provide medical advice, diagnosis, clinical care or treatment. Clinical decisions are made by the treating hospital and its medical team. Eligibility and reimbursement decisions are made by the Health Service Executive (HSE), not EU Healthcare.

4. Information We Collect

The information we collect depends on your enquiry and the services requested. It may include:

  • identity and contact details, including your name, address, date of birth, email address and telephone number;
  • PPS number or other identifiers where needed for HSE forms or lawful administrative requirements;
  • medical history, symptoms, diagnoses, medications, allergies and previous treatments;
  • GP or consultant referrals, waiting-list letters and other eligibility documentation;
  • scans, X-rays, medical images, test results and clinical reports;
  • details of consultations, proposed treatment plans, quotations and hospital correspondence;
  • payment, invoice and reimbursement documentation;
  • travel and accommodation information where practical support is requested;
  • details of a parent, guardian, representative, next of kin or emergency contact;
  • records of consent, signatures and DocuSign or electronic-signature audit information;
  • emails, telephone notes and other communications; and
  • technical and website information, including IP address, device information, cookies and interaction data.

We aim to collect and use only the information reasonably necessary for the purposes described in this policy.

5. How We Obtain Information

We may obtain personal information:

  • directly from you through our website, questionnaire, email, telephone, DocuSign or other communication channels;
  • from a parent, guardian or authorised representative;
  • from your GP, consultant, hospital or other healthcare professional where you have authorised the disclosure or another lawful basis applies;
  • from partner hospitals or hospital groups in connection with your consultation, treatment or follow-up;
  • from the HSE or another public body where relevant and lawful; and
  • automatically through our website, cookies, analytics and security logs.

6. Why We Use Information and Our Legal Bases

Data-protection law requires us to identify a lawful basis for using ordinary personal data and, where health information is involved, an additional condition for processing special-category data. The table below summarises the bases we may rely on. The precise basis depends on the activity and circumstances.

Where we rely on legitimate interests, we consider the impact on your rights and interests before proceeding. Where we rely on consent, you may withdraw that consent as explained below. This policy should be read together with any specific consent form or privacy information provided for a particular service.

8. Who We Share Information With

We may share personal information, where necessary and lawful, with:

  • Quirónsalud, including IDCQ Hospitales y Sanidad, S.L.U. and relevant affiliated hospitals, clinics and companies;
  • HLA Hospital Group, including HLA Servicios Asistencia Integral de Salud, S.L. and relevant affiliated hospitals, clinics and companies;
  • the relevant hospitals, consultants, clinics and medical teams involved in reviewing or treating your case;
  • your GP, consultant, Irish hospital or other healthcare professional where authorised or otherwise lawful;
  • the HSE or another public body where you ask us to assist with documentation or where disclosure is legally required;
  • electronic-signature, email, cloud-storage, hosting, form, CRM, IT-support and cybersecurity providers acting under appropriate contractual obligations;
  • accountants, auditors, solicitors, insurers and other professional advisers;
  • travel or accommodation providers where you specifically ask us to assist and only to the extent necessary;
  • courts, regulators, law-enforcement bodies and public authorities where required by law; and
  • a purchaser, investor or successor organisation in connection with a genuine business transaction, subject to appropriate confidentiality and legal safeguards.

We do not sell personal data. We require service providers acting on our behalf to use information only for agreed purposes and to apply appropriate confidentiality and security measures.

*Disclaimer - This service provides coordination and administrative support for patients seeking treatment abroad under the EU Cross Border Healthcare Directive. We do not provide medical advice or clinical care. All treatment decisions are made between the patient and the healthcare provider.

Copyright notice © 2026 EU Cross Border Healthcare Directive. All rights reserved.

EU Healthcare Cross-Border Treatment Limited

5 Fitzwilliam Square, Dublin, D02 R744.

info@euhealthcare.ie

Contact UsFAQsTreatments CoveredTreatments CoveredFAQsContact Us

EU Healthcare Cross-Border Treatment Limited (“EU Healthcare”, “we”, “us” or “our”) understands that medical information is highly personal. We are committed to handling personal data lawfully, fairly, transparently and securely while helping patients access treatment abroad and coordinate the related administrative process.

This Privacy Policy explains what information we collect, where it comes from, why we use it, the legal bases we rely on, who it may be shared with, how long we keep it and the rights available to you.

Plain-English summary

We use personal and medical information to respond to enquiries, facilitate introductions to partner hospital groups, coordinate consultations and treatment, provide practical support and assist with relevant reimbursement documentation. We do not sell personal information.

7. Special-Category Health Information

Information about your physical or mental health, medical history, diagnosis, treatment and related care is special-category personal data and receives additional protection under data-protection law.

We will generally ask for your explicit consent before processing or sharing health information for a referral or coordination purpose. In limited circumstances, another lawful condition may apply, such as where processing is necessary for the establishment, exercise or defence of legal claims or where another healthcare-related condition is available and appropriate.

We do not use medical information for unrelated advertising or sell it to third parties.

9. Partner Hospitals and Independent Controllers

Partner hospital groups, individual hospitals, consultants and medical teams will generally use patient information for their own clinical, legal, regulatory and administrative purposes. They may therefore act as separate data controllers for the information they receive and create.

Once introduced, the hospital group may contact you directly, arrange an initial consultation and advise on the most appropriate hospital, specialist or treatment pathway. The provider may ask you to complete its own registration, privacy and clinical-consent documentation. You should review the provider’s privacy notice when it is supplied.

10. International Transfers

Our partner hospital groups are based within the European Economic Area (EEA). Some technology or service providers may, however, store or access information outside the EEA.

Where a transfer outside the EEA requires additional safeguards, we will use an approved transfer mechanism, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate. Further information about relevant safeguards may be requested using the privacy contact details above.

11. How We Protect Information

We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include:

  • encrypted transmission and secure document storage where appropriate;
  • role-based access controls and account authentication;
  • limiting access to authorised personnel and providers who require the information;
  • confidentiality obligations and data-processing agreements;
  • secure disposal and deletion procedures;
  • staff guidance and awareness measures; and
  • incident-response and breach-management procedures.

No method of transmission or storage is completely secure. We review our measures periodically and update them where reasonably necessary.

12. How Long We Keep Information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, and to meet legal, accounting, insurance, regulatory and claims-related requirements.

Indicative retention periods may include:

  • unsuccessful or abandoned enquiries: generally 12 to 24 months after the enquiry closes, unless a longer period is reasonably required;
  • patient coordination, consent and treatment-administration records: generally up to seven years after completion or closure of the case, subject to legal review;
  • financial and tax records: for the period required by applicable accounting and tax law;
  • complaints, incidents and legal claims: for the duration of the matter and any relevant limitation period;
  • website logs and analytics information: for shorter periods set according to the relevant system or cookie; and
  • marketing records: until consent is withdrawn, an objection is made or the information is no longer needed.

These periods are guidelines and may be shortened or extended where justified. When information is no longer required, it will be securely deleted or anonymised.

13. Your Data-Protection Rights

Subject to the conditions and exemptions in data-protection law, you may have the right to:

  • request access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • request deletion of information in certain circumstances;
  • request restriction of processing;
  • object to processing based on legitimate interests or to direct marketing;
  • receive certain information in a portable format and ask for it to be transferred where applicable;
  • withdraw consent at any time, without affecting processing already carried out lawfully; and
  • exercise rights relating to solely automated decisions that produce legal or similarly significant effects.

These rights are not absolute. For example, we may need to retain information to comply with law, manage a legal claim or maintain a minimal suppression record after a marketing objection.

To exercise a right, contact compliance@euhealthcare.ie. We may ask for information reasonably necessary to verify your identity and locate the relevant records. We normally respond within one month, subject to any lawful extension for complex or multiple requests.

14. Withdrawing Consent

Where we rely on your consent, you may withdraw it at any time by contacting compliance@euhealthcare.ie 
or info@euhealthcare.ie.

Withdrawal will not affect the lawfulness of processing carried out before the withdrawal. It may mean that we or the treatment provider can no longer review your case, continue a referral, arrange a consultation or provide further coordination support. Where information has already been shared with a separate hospital controller, you may also need to contact that provider directly.

15. Information You Must Provide

You are not generally under a legal obligation to provide medical information to EU Healthcare. However, without the information reasonably required for your enquiry, referral, consent or documentation, we may be unable to review your case, introduce you to a partner hospital group, coordinate an initial consultation or provide administrative support.

Where information is required by law, by the HSE or by a treatment provider, we will explain this where reasonably possible.

16. Automated Decision-Making

EU Healthcare does not currently make treatment, clinical or reimbursement decisions solely through automated processing. Any initial eligibility review or administrative assessment is subject to human involvement. Treatment decisions are made by the relevant medical team, and reimbursement decisions are made by the HSE.

17. Website, Cookies and Marketing

When you use our website, we may collect technical information through essential cookies, server logs and security tools. With your consent, we may also use analytics, advertising or conversion-measurement technologies to understand website performance and improve our communications.

Our cookie banner and Cookie Policy should explain the cookies in use, their purposes, providers, duration and how you can change your choices. Non-essential cookies should not be placed before the required consent has been obtained.

We may send service communications that are necessary to respond to your enquiry or coordinate your case. Promotional email or text messages will only be sent where a lawful basis applies, and each message will provide a way to opt out. We do not use health information to target unrelated marketing.

18. Children and Authorised Representatives

Where a patient is under 18 or is represented by another person, we may collect information about the parent, guardian or authorised representative and ask for evidence of their authority. We will take reasonable steps to ensure that consent and privacy information are provided to the appropriate person and, where suitable, explained to the patient in an age-appropriate manner.

19. Questions and Complaints

Please contact us first if you have a question or concern about how your information has been handled. We will review the matter and aim to respond promptly.

Privacy contact

compliance@euhealthcare.ie

You also have the right to lodge a complaint with the Irish Data Protection Commission. You are not required to contact us before making a complaint, although we would appreciate the opportunity to address your concern.

Visit the Data Protection Commission website

20. Changes to This Policy

We may update this Privacy Policy to reflect changes to our services, legal requirements, partner arrangements or technology. The latest version will be published on our website with an updated effective date. Where a change is significant, we may provide an additional notice where appropriate.