Privacy Policy

Last updated: 12 September 2026

This Privacy Policy explains how INOQARE collects, uses, shares, stores and protects personal data when individuals use the INOQARE website, Platform and related healthcare access services.

These services may include video consultations, medical second opinions, international healthcare navigation, access to healthcare professionals and institutions, medical document management and other digital healthcare services.

Because INOQARE services may involve health data, additional safeguards may apply.

1. Who Is Responsible for Your Personal Data?

For processing activities where INOQARE determines the purposes and essential means of processing, the data controller is:

INOQARE
Simplified Joint-Stock Company with a Sole Shareholder
Share capital: EUR 500
Registered office: 45 Place Nicole Neuburger, 93140 Bondy, France
Registration: 980 324 511 R.C.S. Bobigny

Depending on the service concerned, a healthcare professional, clinic or hospital may act as an independent data controller in relation to personal data processed for the provision of medical care.

The respective legal role of INOQARE and each healthcare provider depends on the actual purpose and means of each processing activity.

2. Data Protection Officer

INOQARE's data protection contact is:

Data Protection Officer – INOQARE
Email: dpo@inoqare.com

You may contact the DPO regarding:

  • privacy questions;
  • access requests;
  • rectification;
  • deletion requests;
  • objections;
  • restriction;
  • portability;
  • concerns regarding health data;
  • international transfers;
  • other personal data matters.

3. Who Does This Policy Apply To?

This Privacy Policy may apply to:

  • patients;
  • users;
  • parents or legal guardians;
  • authorised family members or representatives;
  • doctors;
  • healthcare professionals;
  • clinics;
  • hospitals;
  • healthcare institution representatives;
  • business partners;
  • professional prospects;
  • visitors to the INOQARE website.

4. Personal Data We May Collect

The exact categories of personal data processed depend on the service being used.

INOQARE may process:

Identity and contact details

  • first name;
  • last name;
  • date of birth;
  • age;
  • sex where medically or legally relevant;
  • nationality where necessary;
  • country of residence;
  • physical location where required for healthcare eligibility;
  • postal address;
  • email address;
  • phone number;
  • profile information;
  • user account identifiers.

5. Health Data

When necessary for healthcare-related services, INOQARE may process health-related personal data including:

  • medical history;
  • declared symptoms;
  • medical conditions;
  • previous diagnoses;
  • treatments;
  • medication;
  • allergies;
  • laboratory results;
  • medical reports;
  • prescriptions;
  • specialist letters;
  • hospital discharge reports;
  • surgical reports;
  • pathology reports;
  • previous consultations;
  • medical images;
  • X-rays;
  • ultrasound images;
  • MRI examinations;
  • CT scans;
  • DICOM files where supported;
  • healthcare professional reports;
  • information relating to ongoing or previous care;
  • information submitted as part of a medical second opinion request.

Health data receives enhanced protection under applicable data protection law.

6. Healthcare Professional Data

INOQARE may process information relating to healthcare professionals including:

  • legal name;
  • professional contact details;
  • country of practice;
  • profession;
  • specialty;
  • subspecialty;
  • professional photograph;
  • spoken languages;
  • healthcare institution affiliation;
  • professional registration number;
  • professional licence number;
  • regulatory authority;
  • jurisdiction of registration;
  • licence status;
  • licence expiration date where applicable;
  • qualifications;
  • diplomas;
  • certifications;
  • professional credentials;
  • professional indemnity information where appropriate;
  • availability;
  • services offered;
  • consultation fees;
  • payment information.

The information required may vary by jurisdiction.

7. Healthcare Institution Data

For clinics, hospitals and medical partners, INOQARE may process:

  • organisation details;
  • authorised representative details;
  • contact information;
  • specialties;
  • treatments or services;
  • associated practitioners;
  • accreditations;
  • supporting documentation;
  • service capacity;
  • available languages;
  • pricing;
  • billing information;
  • contractual information.

8. Payment and Transaction Information

When a user purchases a service, information may include:

  • service purchased;
  • price;
  • currency;
  • date;
  • payment status;
  • transaction reference;
  • invoice information;
  • billing details;
  • refund information where applicable.

Full payment card information may be processed directly by the relevant payment provider rather than being stored by INOQARE.

9. Technical, Security and Usage Data

INOQARE may collect technical information such as:

  • IP address;
  • browser type;
  • operating system;
  • device information;
  • authentication logs;
  • access timestamps;
  • security logs;
  • session information;
  • account activity;
  • platform events;
  • fraud or anomaly indicators.

Such information may be necessary for cybersecurity, authentication, fraud prevention and system integrity.

10. Purposes of Processing

Depending on the relevant service, INOQARE may process personal data to:

  • create and manage user accounts;
  • authenticate users;
  • provide the Platform;
  • facilitate healthcare professional search;
  • match patients with professionals;
  • determine service eligibility;
  • arrange appointments;
  • facilitate video consultations;
  • transmit information to healthcare professionals;
  • manage medical second opinion requests;
  • allow patients to upload medical records;
  • organise medical files;
  • provide healthcare navigation;
  • coordinate international care;
  • facilitate contact with hospitals or clinics;
  • manage Medical Tourism-related services;
  • process payments;
  • issue invoices and receipts;
  • provide documentation supporting insurance claims;
  • provide customer support;
  • send operational communications;
  • maintain security;
  • detect fraud;
  • investigate incidents;
  • comply with legal obligations;
  • exercise or defend legal rights;
  • improve the Platform;
  • create permitted statistics;
  • manage healthcare professional and partner relationships.

11. Legal Bases for Processing

The legal basis depends on the relevant processing activity.

INOQARE may rely on:

Performance of a contract

Where processing is necessary to provide a service requested by the user.

For example:

  • account creation;
  • appointment booking;
  • payment processing;
  • provision of Platform services.

Legal obligations

Where processing is necessary to comply with legal, tax, accounting, regulatory or judicial obligations.

Legitimate interests

Where appropriate, INOQARE may process data for legitimate interests including:

  • cybersecurity;
  • fraud prevention;
  • service security;
  • platform improvement;
  • legal defence.

Such processing is subject to an assessment of the rights and freedoms of the individuals concerned.

Consent

Where applicable law requires consent.

Where processing relies on consent, the user may withdraw that consent subject to applicable legal conditions.

12. Special Category Health Data

Health data constitutes a special category of personal data.

Where the GDPR applies, processing of health data requires both:

  • a lawful basis under Article 6 GDPR; and
  • a valid condition under Article 9 GDPR.

Depending on the processing activity, this may include explicit consent or another legally permitted condition relating to healthcare services.

INOQARE does not assume that every health-data processing activity is automatically based on consent.

The appropriate legal basis is assessed according to the specific processing activity.

13. Video Consultation Data

For video consultations, relevant information may be made available to the healthcare professional providing the service.

This may include:

  • patient identity;
  • reason for consultation;
  • relevant medical history;
  • medical records;
  • information submitted through the Platform;
  • messages exchanged in relation to the consultation.

The healthcare professional remains responsible for clinical decisions and may have independent legal obligations relating to maintenance of medical records.

14. Medical Second Opinion Data

Where a patient requests a second medical opinion, INOQARE may process information including:

  • existing diagnosis;
  • treatment recommendation;
  • surgery recommendation;
  • main medical question;
  • medical history;
  • medications;
  • laboratory results;
  • imaging;
  • pathology reports;
  • specialist reports;
  • supporting documentation.

INOQARE may organise these records to facilitate review by the appropriate healthcare professional.

INOQARE does not itself issue the medical second opinion.

15. Artificial Intelligence

INOQARE may use artificial intelligence or automated technologies to support certain features.

Such systems may assist with:

  • healthcare navigation;
  • matching;
  • classification;
  • document organisation;
  • extraction of relevant information;
  • chronology creation;
  • medical file structuring;
  • administrative support;
  • translation support;
  • customer support;
  • security and fraud prevention.

For example, technology may help structure documents submitted as part of a second medical opinion request.

Such tools are not intended to independently make a medical diagnosis or replace a healthcare professional's clinical judgment.

Where a legally significant decision is made solely through automated processing, INOQARE will apply the protections required by applicable law.

16. Who May Receive Personal Data?

Depending on the service and only where necessary, personal data may be shared with:

  • authorised INOQARE personnel;
  • healthcare professionals;
  • doctors;
  • clinics;
  • hospitals;
  • healthcare institutions;
  • cloud infrastructure providers;
  • IT providers;
  • video consultation providers;
  • payment providers;
  • authentication providers;
  • cybersecurity providers;
  • messaging providers;
  • email/SMS providers;
  • translation providers;
  • technical support providers;
  • legal advisers;
  • auditors;
  • insurers where the user requests or authorises transmission;
  • regulators, courts or public authorities where required by law.

Access should be limited to the data reasonably necessary for the relevant purpose.

17. Amazon Web Services

INOQARE uses services provided by Amazon Web Services (AWS) as part of its technical infrastructure.

The relevant EMEA entity may include:

Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy
L-1855 Luxembourg
Luxembourg

18. International Data Transfers

INOQARE provides international healthcare access services.

Personal data may therefore in certain circumstances need to be accessed or transferred internationally.

This may occur, for example, where a patient asks to consult a healthcare professional or healthcare institution located in another country.

Where the GDPR applies and personal data is transferred outside the European Economic Area, INOQARE uses an appropriate legal transfer mechanism where required.

Depending on the destination, this may include:

  • an adequacy decision;
  • Standard Contractual Clauses;
  • another valid safeguard permitted under applicable law;
  • a lawful derogation in circumstances permitted by law.

Additional security measures may be used where appropriate.

Questions regarding international transfers may be sent to: dpo@inoqare.com

19. International Patients

The laws applicable to a healthcare interaction may differ depending on:

  • patient's country of residence;
  • patient's physical location;
  • healthcare professional's location;
  • healthcare professional's licensing jurisdiction;
  • healthcare institution location;
  • nature of the medical service.

INOQARE may therefore apply different privacy or compliance requirements depending on the relevant jurisdiction.

20. Data Security

INOQARE applies technical and organisational measures intended to protect personal information according to its sensitivity and associated risks.

Measures may include, where applicable:

  • access controls;
  • role-based permissions;
  • authentication;
  • encryption in transit;
  • encryption at rest;
  • secure credential management;
  • logging;
  • audit trails;
  • security monitoring;
  • backup procedures;
  • vulnerability management;
  • incident response;
  • infrastructure security;
  • segregation of environments;
  • least privilege access;
  • vendor risk management.

For security reasons, INOQARE does not publicly disclose technical details that could weaken the security of its systems.

21. Data Retention

INOQARE retains personal data only for as long as reasonably necessary for the purposes for which it was collected and as required or permitted by law.

Retention periods may depend on:

  • purpose of processing;
  • contractual relationship;
  • type of information;
  • medical requirements;
  • professional obligations;
  • regulatory requirements;
  • accounting and tax requirements;
  • limitation periods;
  • legal defence requirements.

Different categories of personal data may therefore have different retention periods.

INOQARE maintains internal retention rules which may be updated to reflect applicable legal requirements.

22. Account Deletion

Users may request deletion of their account by contacting: dpo@inoqare.com

Deletion of a user account does not necessarily result in immediate deletion of every associated record.

Certain information may need to be retained where required or permitted for:

  • medical obligations;
  • legal obligations;
  • regulatory obligations;
  • accounting;
  • taxation;
  • fraud prevention;
  • establishment, exercise or defence of legal claims.

Where retention is no longer necessary, information will be deleted or anonymised in accordance with applicable law.

23. Your Data Protection Rights

Where the GDPR applies and subject to legal conditions, users may have rights including:

Right of access

You may request confirmation as to whether your data is processed and obtain access to relevant personal data.

Right to rectification

You may request correction of inaccurate or incomplete personal information.

Right to erasure

You may request deletion of certain personal data where the applicable legal requirements are met.

Right to restriction

You may request restriction of processing in certain circumstances.

Right to object

You may object to certain processing based on legitimate interests.

Right to portability

Where applicable, you may request certain personal data in a structured, commonly used and machine-readable format.

Withdrawal of consent

Where processing relies on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Automated decision-making rights

Where applicable, you may have rights relating to decisions based solely on automated processing.

24. How to Exercise Your Rights

Requests should be sent to:

Data Protection Officer – INOQARE
dpo@inoqare.com

INOQARE may request additional information where reasonably necessary to verify the identity of the requester and protect personal data against unauthorised disclosure.

25. Complaints

If you believe that your personal data is being processed unlawfully, you may contact INOQARE's DPO: dpo@inoqare.com

Where the GDPR applies, you also have the right to lodge a complaint with the competent supervisory authority.

26. Children and Minors

Certain INOQARE services may be used in connection with a minor's healthcare.

Where applicable, INOQARE may process information concerning:

  • the minor;
  • parent;
  • guardian;
  • person with parental responsibility.

INOQARE may request information necessary to verify whether an adult is legally entitled to act for the minor.

Healthcare professionals remain subject to the medical, ethical and legal requirements governing treatment of minors in their jurisdiction.

27. Cookies and Similar Technologies

INOQARE may use cookies and similar technologies for purposes including:

  • authentication;
  • session management;
  • security;
  • user preferences;
  • website operation;
  • permitted analytics;
  • performance measurement.

Where legally required, non-essential cookies are activated only after consent.

Users can manage cookie preferences through INOQARE's consent management interface.

Further details are available in the Cookie Policy.

28. Communications

INOQARE may send service-related communications concerning:

  • appointment confirmations;
  • video consultations;
  • second opinion cases;
  • medical documents;
  • account security;
  • payments;
  • requests requiring action;
  • support;
  • operational information.

These communications may be necessary for providing the requested service and are not necessarily marketing communications.

Marketing communications are sent only where permitted under applicable law.

Users may unsubscribe from marketing messages through the mechanism provided in those communications.

29. Insurance Reimbursement Documents

INOQARE may provide documents intended to help users submit claims to insurers.

Such documents may include:

  • itemised invoice;
  • receipt;
  • proof of payment;
  • consultation confirmation;
  • healthcare professional details;
  • medical report where actually issued by the practitioner.

INOQARE does not guarantee reimbursement.

Whether reimbursement is provided depends on the relevant insurer, insurance contract, policy conditions and eligibility rules.

30. Information Received from Third Parties

INOQARE may receive personal data from:

  • healthcare professionals;
  • healthcare institutions;
  • legal representatives;
  • authorised family members;
  • partners;
  • other lawful sources.

Where applicable data protection law requires it, individuals will be provided with the appropriate information regarding indirect collection.

31. Confidentiality of Health Information

Users should use the secure features provided by INOQARE for medical information whenever available.

Users are encouraged not to send unnecessary sensitive health information through unsecured communication channels.

Access to medical information is limited according to user permissions, professional roles and legitimate service requirements.

32. Personal Data Breaches

Where INOQARE becomes aware of a personal data breach, it will assess the incident and apply the procedures required under applicable data protection law.

Where legally required, the relevant supervisory authority and/or affected individuals will be notified within the applicable regulatory timeframe.

33. Third-Party Processors

INOQARE may engage service providers to process data on its behalf.

Where required by law, such providers are subject to contractual obligations regarding:

  • confidentiality;
  • data protection;
  • security;
  • authorised processing;
  • incident management;
  • deletion or return of data;
  • international transfers;
  • sub-processing.

INOQARE periodically reviews the categories of service providers used by the Platform.

34. Changes to This Privacy Policy

INOQARE may update this Privacy Policy to reflect:

  • legal developments;
  • regulatory requirements;
  • new services;
  • new technologies;
  • changes to data processing;
  • changes to service providers;
  • security developments;
  • changes to international operations.

The date shown at the top of this Policy indicates the latest revision.

Where appropriate, users may receive additional notice of material changes.

35. Contact Details

For any privacy or personal data matter:

Data Protection Officer – INOQARE
dpo@inoqare.com

Data controller, where applicable:

INOQARE
Simplified Joint-Stock Company with a Sole Shareholder
Share capital: EUR 500
980 324 511 R.C.S. Bobigny
45 Place Nicole Neuburger
93140 Bondy
France

See also our Legal Notice.

Image