Last updated: 12 September 2026
This Privacy Policy explains how INOQARE collects, uses, shares, stores and protects personal data when individuals use the INOQARE website, Platform and related healthcare access services.
These services may include video consultations, medical second opinions, international healthcare navigation, access to healthcare professionals and institutions, medical document management and other digital healthcare services.
Because INOQARE services may involve health data, additional safeguards may apply.
For processing activities where INOQARE determines the purposes and essential means of processing, the data controller is:
INOQARE
Simplified Joint-Stock Company with a Sole Shareholder
Share capital: EUR 500
Registered office: 45 Place Nicole Neuburger, 93140 Bondy, France
Registration: 980 324 511 R.C.S. Bobigny
Depending on the service concerned, a healthcare professional, clinic or hospital may act as an independent data controller in relation to personal data processed for the provision of medical care.
The respective legal role of INOQARE and each healthcare provider depends on the actual purpose and means of each processing activity.
INOQARE's data protection contact is:
Data Protection Officer – INOQARE
Email: dpo@inoqare.com
You may contact the DPO regarding:
This Privacy Policy may apply to:
The exact categories of personal data processed depend on the service being used.
INOQARE may process:
When necessary for healthcare-related services, INOQARE may process health-related personal data including:
Health data receives enhanced protection under applicable data protection law.
INOQARE may process information relating to healthcare professionals including:
The information required may vary by jurisdiction.
For clinics, hospitals and medical partners, INOQARE may process:
When a user purchases a service, information may include:
Full payment card information may be processed directly by the relevant payment provider rather than being stored by INOQARE.
INOQARE may collect technical information such as:
Such information may be necessary for cybersecurity, authentication, fraud prevention and system integrity.
Depending on the relevant service, INOQARE may process personal data to:
The legal basis depends on the relevant processing activity.
INOQARE may rely on:
Where processing is necessary to provide a service requested by the user.
For example:
Where processing is necessary to comply with legal, tax, accounting, regulatory or judicial obligations.
Where appropriate, INOQARE may process data for legitimate interests including:
Such processing is subject to an assessment of the rights and freedoms of the individuals concerned.
Where applicable law requires consent.
Where processing relies on consent, the user may withdraw that consent subject to applicable legal conditions.
Health data constitutes a special category of personal data.
Where the GDPR applies, processing of health data requires both:
Depending on the processing activity, this may include explicit consent or another legally permitted condition relating to healthcare services.
INOQARE does not assume that every health-data processing activity is automatically based on consent.
The appropriate legal basis is assessed according to the specific processing activity.
For video consultations, relevant information may be made available to the healthcare professional providing the service.
This may include:
The healthcare professional remains responsible for clinical decisions and may have independent legal obligations relating to maintenance of medical records.
Where a patient requests a second medical opinion, INOQARE may process information including:
INOQARE may organise these records to facilitate review by the appropriate healthcare professional.
INOQARE does not itself issue the medical second opinion.
INOQARE may use artificial intelligence or automated technologies to support certain features.
Such systems may assist with:
For example, technology may help structure documents submitted as part of a second medical opinion request.
Such tools are not intended to independently make a medical diagnosis or replace a healthcare professional's clinical judgment.
Where a legally significant decision is made solely through automated processing, INOQARE will apply the protections required by applicable law.
Depending on the service and only where necessary, personal data may be shared with:
Access should be limited to the data reasonably necessary for the relevant purpose.
INOQARE uses services provided by Amazon Web Services (AWS) as part of its technical infrastructure.
The relevant EMEA entity may include:
Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy
L-1855 Luxembourg
Luxembourg
INOQARE provides international healthcare access services.
Personal data may therefore in certain circumstances need to be accessed or transferred internationally.
This may occur, for example, where a patient asks to consult a healthcare professional or healthcare institution located in another country.
Where the GDPR applies and personal data is transferred outside the European Economic Area, INOQARE uses an appropriate legal transfer mechanism where required.
Depending on the destination, this may include:
Additional security measures may be used where appropriate.
Questions regarding international transfers may be sent to: dpo@inoqare.com
The laws applicable to a healthcare interaction may differ depending on:
INOQARE may therefore apply different privacy or compliance requirements depending on the relevant jurisdiction.
INOQARE applies technical and organisational measures intended to protect personal information according to its sensitivity and associated risks.
Measures may include, where applicable:
For security reasons, INOQARE does not publicly disclose technical details that could weaken the security of its systems.
INOQARE retains personal data only for as long as reasonably necessary for the purposes for which it was collected and as required or permitted by law.
Retention periods may depend on:
Different categories of personal data may therefore have different retention periods.
INOQARE maintains internal retention rules which may be updated to reflect applicable legal requirements.
Users may request deletion of their account by contacting: dpo@inoqare.com
Deletion of a user account does not necessarily result in immediate deletion of every associated record.
Certain information may need to be retained where required or permitted for:
Where retention is no longer necessary, information will be deleted or anonymised in accordance with applicable law.
Where the GDPR applies and subject to legal conditions, users may have rights including:
You may request confirmation as to whether your data is processed and obtain access to relevant personal data.
You may request correction of inaccurate or incomplete personal information.
You may request deletion of certain personal data where the applicable legal requirements are met.
You may request restriction of processing in certain circumstances.
You may object to certain processing based on legitimate interests.
Where applicable, you may request certain personal data in a structured, commonly used and machine-readable format.
Where processing relies on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Where applicable, you may have rights relating to decisions based solely on automated processing.
Requests should be sent to:
Data Protection Officer – INOQARE
dpo@inoqare.com
INOQARE may request additional information where reasonably necessary to verify the identity of the requester and protect personal data against unauthorised disclosure.
If you believe that your personal data is being processed unlawfully, you may contact INOQARE's DPO: dpo@inoqare.com
Where the GDPR applies, you also have the right to lodge a complaint with the competent supervisory authority.
Certain INOQARE services may be used in connection with a minor's healthcare.
Where applicable, INOQARE may process information concerning:
INOQARE may request information necessary to verify whether an adult is legally entitled to act for the minor.
Healthcare professionals remain subject to the medical, ethical and legal requirements governing treatment of minors in their jurisdiction.
INOQARE may use cookies and similar technologies for purposes including:
Where legally required, non-essential cookies are activated only after consent.
Users can manage cookie preferences through INOQARE's consent management interface.
Further details are available in the Cookie Policy.
INOQARE may send service-related communications concerning:
These communications may be necessary for providing the requested service and are not necessarily marketing communications.
Marketing communications are sent only where permitted under applicable law.
Users may unsubscribe from marketing messages through the mechanism provided in those communications.
INOQARE may provide documents intended to help users submit claims to insurers.
Such documents may include:
INOQARE does not guarantee reimbursement.
Whether reimbursement is provided depends on the relevant insurer, insurance contract, policy conditions and eligibility rules.
INOQARE may receive personal data from:
Where applicable data protection law requires it, individuals will be provided with the appropriate information regarding indirect collection.
Users should use the secure features provided by INOQARE for medical information whenever available.
Users are encouraged not to send unnecessary sensitive health information through unsecured communication channels.
Access to medical information is limited according to user permissions, professional roles and legitimate service requirements.
Where INOQARE becomes aware of a personal data breach, it will assess the incident and apply the procedures required under applicable data protection law.
Where legally required, the relevant supervisory authority and/or affected individuals will be notified within the applicable regulatory timeframe.
INOQARE may engage service providers to process data on its behalf.
Where required by law, such providers are subject to contractual obligations regarding:
INOQARE periodically reviews the categories of service providers used by the Platform.
INOQARE may update this Privacy Policy to reflect:
The date shown at the top of this Policy indicates the latest revision.
Where appropriate, users may receive additional notice of material changes.
For any privacy or personal data matter:
Data Protection Officer – INOQARE
dpo@inoqare.com
Data controller, where applicable:
INOQARE
Simplified Joint-Stock Company with a Sole Shareholder
Share capital: EUR 500
980 324 511 R.C.S. Bobigny
45 Place Nicole Neuburger
93140 Bondy
France
See also our Legal Notice.
