GDPR Notice
How we comply with EU General Data Protection Regulation requirements.
๐ช๐บ
GDPR Compliant Architecture
Bondmedic has been built from the ground up to exceed European data protection standards.
1. Your Data Rights
Under GDPR, you have the following rights regarding your data:
- Right to Access: Request a copy of your personal/medical data.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure: Request deletion of your data ("Right to be forgotten").
- Right to Portability: Request your data in a machine-readable format.
- Right to Object: Object to processing of your personal data.
- Right to Withdraw Consent: Withdraw consent for data processing at any time.
2. Legal Basis for Processing
We process your data based on your explicit, informed consent (Art. 6 GDPR) and for the necessity of medical diagnosis and healthcare provision (Art. 9 GDPR).
3. Data Retention
Medical records and reports are retained for the minimum period required by clinical governance standards in our jurisdiction, typically 7โ10 years, unless you request erasure earlier (subject to legal requirements).
Data Subject Access Request (DSAR)
To exercise any of your GDPR rights, please submit a DSAR through our contact form or by emailing our DPO directly.
dpo@bondmedic.com