Last updated: 27 August 2026
1. About this Privacy Policy
PrivateGP.ie respects your privacy and the confidentiality of your medical information.
This Privacy Policy explains how we collect, use, store and share personal data when you visit PrivateGP.ie, request or receive healthcare from us, communicate with us or otherwise use our services.
PrivateGP.ie provides remote healthcare services through doctors registered with the Medical Council of Ireland. Services may include GP consultations, video or telephone consultations, secure messaging and questionnaire-based clinical assessments, prescriptions and repeat-prescription reviews, sick certificates, medical letters, referrals, investigations and results follow-up, weight-management services and other remote GP services.
This Privacy Policy should be read alongside our Terms & Conditions and Cookie Policy.
2. Who is responsible for your information?
PrivateGP.ie is operated by:
Atlantic Maple Private Healthcare Limited
CRO Number: 799369
Atlantic Maple Private Healthcare Limited is the data controller for personal data processed through PrivateGP.ie, except where another organisation acts as an independent data controller for its own activities.
For privacy enquiries or requests relating to your personal data, please contact:
Privacy Contact
Email: privategp.ie@gmail.com- SEPARATE PRIVACY EMAIL TBC
We keep our data-protection arrangements under review, including whether appointment of a formal Data Protection Officer is required as the nature and scale of our services develops.
3. Information we collect
The information we collect depends on the service you request and what is necessary to provide safe and appropriate healthcare.
Identity and contact information
This may include:
- name;
- date of birth;
- sex or other information relevant to your care;
- address and Eircode;
- email address;
- telephone number;
- emergency-contact details;
- information required to verify your identity; and
- where relevant, information about a parent, guardian or person acting on your behalf.
We do not seek identifiers such as PPS numbers unless there is a genuine clinical, administrative or legal reason to do so.
Health and medical information
Health information is special-category personal data under the GDPR.
Depending on the service you use, this may include:
- symptoms and medical concerns;
- medical and surgical history;
- diagnoses and existing conditions;
- medications, prescriptions and prescribing history;
- allergies and adverse reactions;
- family history;
- mental, sexual or reproductive-health information where relevant;
- height, weight or other clinical measurements;
- questionnaire responses;
- photographs, test results, reports or documents supplied by you;
- consultation records and clinical notes;
- clinical assessments and treatment recommendations;
- prescriptions and decisions whether or not to prescribe;
- referrals, sick certificates and medical letters;
- investigation requests and results;
- follow-up information; and
- correspondence with pharmacies, laboratories, your usual GP, specialists or other healthcare professionals.
A request for a clinical service may itself generate a medical record even if the requested treatment, prescription, certificate or other service is ultimately not provided.
Children and young people
Where healthcare is provided to a child or young person, we may also process information concerning:
- the child or young person’s health;
- their parent or guardian;
- the relationship between the adult and the child;
- consent and decision-making;
- confidentiality; and
- safeguarding.
Payment and administrative information
We may process information concerning appointments, payments, refunds, transaction references and other information required to administer your use of our services.
Payments may be handled by a third-party payment provider.
Technical information
When you use our website or online services, we may process information such as:
- IP address;
- browser and device information;
- operating system;
- login and authentication information;
- dates and times of access;
- website activity;
- error or security logs; and
- cookie and analytics information where applicable.
Our separate Cookie Policy provides further information about cookies and similar technologies.
Communications
We may retain relevant communications with you, including email, SMS, secure messages, telephone communications, support requests and complaints.
Where a communication concerns your healthcare, it may form part of your medical record.
4. How we obtain information
Most information is provided directly by you when you:
- request a service;
- complete a medical questionnaire;
- attend a consultation;
- request a prescription or other clinical service;
- upload a photograph, report or document;
- provide follow-up information;
- communicate with us in any format; or
- make a payment.
We also create information during the provision of healthcare, including clinical notes, assessments, prescribing decisions and correspondence.
Where appropriate and lawful, we may receive relevant information from a parent or guardian, your usual GP, another healthcare professional, a pharmacy, laboratory, hospital, specialist or other healthcare provider.
5. Why we use your information and our legal bases
We only process personal data where we have a lawful reason to do so.
The applicable basis depends on the purpose for which the information is being used.
Providing and administering our services
We process information to:
- register and identify patients;
- arrange consultations;
- provide requested services;
- communicate with you;
- process payments;
- issue documents; and
- manage your account and requests.
The principal lawful basis is Article 6(1)(b) GDPR, where processing is necessary to enter into or perform our contract with you.
Providing healthcare
We process health information to:
- assess your symptoms and medical history;
- determine whether remote treatment is suitable;
- provide medical advice and treatment;
- make prescribing decisions;
- issue prescriptions;
- arrange referrals or investigations;
- review results;
- provide follow-up care; and
- maintain appropriate medical records.
Health information is special-category personal data.
The principal condition allowing us to process health data is Article 9(2)(h) GDPR, which permits processing necessary for medical diagnosis, the provision of healthcare or treatment and the management of healthcare services by or under the responsibility of healthcare professionals subject to duties of confidentiality.
Depending on the activity, the relevant Article 6 basis may include contractual necessity, compliance with legal obligations or our legitimate interests in providing and managing safe healthcare services.
Legal and professional obligations
We may process information where necessary to comply with Irish or EU law and with professional, regulatory and healthcare obligations applying to us or to doctors providing care through PrivateGP.ie.
The relevant basis may include Article 6(1)(c) GDPR.
Clinical governance and patient safety
We may process appropriate information for purposes such as:
- clinical governance;
- patient safety;
- clinical audit;
- investigating incidents;
- responding to complaints; and
- improving the quality and safety of our healthcare services.
We will use only information reasonably necessary for these purposes and anonymise or pseudonymise information where appropriate.
Legal and medico-legal matters
We may process information to obtain legal or professional advice, deal with complaints or regulatory matters, and establish, exercise or defend legal claims.
Where special-category information is required for legal claims, Article 9(2)(f) GDPR may apply.
Security, fraud and misuse
We may process appropriate administrative and technical information to protect patients and our services, secure our systems, prevent fraud and investigate suspected misuse.
Marketing
Where we send optional electronic marketing, we will normally do so only where you have chosen to receive it.
You may withdraw marketing consent at any time.
We do not use your diagnosis, medical history, medication or other clinical information to target advertising.
6. Consent, confidentiality and data protection
Consent to medical treatment and consent under the GDPR are not the same thing.
When you agree to receive medical care, this is clinical consent to treatment.
Doctors also owe patients an independent professional duty of medical confidentiality.
GDPR consent is one of several possible legal bases for processing personal data, but it is not the basis on which we ordinarily maintain your medical record or process information necessary to provide healthcare.
This means that withdrawing consent for an optional activity such as marketing does not require us to stop processing information that we are lawfully required or entitled to retain for healthcare, professional, legal or medico-legal purposes.
7. Sharing information for your healthcare
Safe healthcare sometimes requires relevant information to be shared with other healthcare professionals.
Where appropriate, we may share necessary information with:
- doctors and other healthcare professionals involved in your care;
- your usual GP;
- pharmacies;
- consultants and specialists;
- laboratories and diagnostic providers;
- hospitals or clinics; and
- other healthcare providers involved in your treatment.
Only information reasonably necessary for the relevant purpose should be shared.
Healthcare professionals receiving information are subject to their own professional and legal confidentiality obligations.
Your usual GP
Where appropriate for safe continuity of care, our doctors may recommend that relevant information is shared with your usual GP.
We will respect your wishes regarding such communication where possible. There may, however, be several circumstances where disclosure is required by law or justified based on patient-safety or safeguarding considerations or is deemed by the Doctor to be justified in line with professional and legal obligations.
8. Other organisations we may share information with
We may use carefully selected third parties to help us provide and operate our services.
These may include providers of:
- secure hosting and data storage;
- medical-record and practice-management services;
- telemedicine and communications services;
- email and SMS services;
- payment processing;
- cybersecurity and technical support;
- website services; and
- analytics, where permitted.
Where another organisation processes personal data on our behalf, we require appropriate contractual, confidentiality, data-protection and security safeguards.
We may also disclose relevant information where necessary to:
- medical indemnity providers or insurers;
- lawyers, accountants, auditors and professional advisers;
- the Medical Council;
- the Data Protection Commission;
- Tusla;
- An Garda Síochána;
- courts or coroners;
- the HSE or public-health authorities; or
- other competent regulatory or statutory authorities.
Such disclosures are made only where there is an appropriate legal, clinical, professional or patient-authorised basis.
We do not sell patient data and we do not disclose medical information to advertisers.
9. Children and young people
Children and young people have their own rights to privacy, confidentiality and data protection.
Personal data relating to a child belongs to the child. A parent or guardian does not automatically have an unrestricted right to the child’s medical information.
Children under 16
A parent or legal guardian will generally be involved in healthcare decisions for a child under 16.
We may take reasonable steps to verify the identity and authority of a parent or guardian.
Children should be involved in decisions about their care in a manner appropriate to their age and maturity.
Young people aged 16 and 17
Young people aged 16 or 17 can generally consent to medical treatment in their own right.
Where they receive healthcare in their own right, their confidentiality and data-protection rights will be respected accordingly.
It may often be beneficial to involve a parent or guardian, but this does not automatically entitle the parent to the young person’s medical information.
Access by parents or guardians
Where a parent or guardian requests a child’s information or seeks to exercise a data-protection right on their behalf, we will consider the circumstances individually, including:
- the child’s age and maturity;
- the child’s wishes;
- parental or guardianship authority;
- confidentiality;
- the child’s best interests; and
- any safeguarding considerations.
Safeguarding
Our doctors must comply with applicable child-protection and safeguarding requirements.
Where there are reasonable grounds for concern about abuse, neglect or a serious risk of harm, relevant information may be disclosed to Tusla, An Garda Síochána or another appropriate authority where required or justified.
10. Disclosures without your permission
Medical confidentiality is extremely important, but it is not absolute.
In limited circumstances, information may be disclosed without your permission where:
- disclosure is required by law;
- a court or competent authority lawfully requires it;
- mandatory reporting requirements apply;
- it is necessary for safeguarding;
- there is a serious risk of harm to you or another person; or
- another sufficiently important legal or public-interest justification applies.
Any disclosure should be limited to information reasonably necessary for the purpose.
11. Recordings, photographs and uploaded documents
Photographs, reports, test results and other documents provided for clinical assessment may become part of your medical record.
PrivateGP.ie does not treat this Privacy Policy as permission to secretly record consultations. If you want to record the consultation you should explicitly make this known to the Doctor.
The Doctor may make use temporary voice recording of consultations and part of our use of trusted AI technology to assist with clinical note taking and documentation processes. Relevant confidentiality and data-protection requirements will apply. AI transcripts are not maintained past the necessary period for the Doctor to appropriately document the clinical interaction or service.
12. Automated decision-making and AI
Clinical decisions about diagnosis, treatment and prescribing are made by appropriately qualified doctors and are not ordinarily made solely by automated systems.
Online questionnaires or other technology may assist in collecting, organising or reviewing information, but they do not replace professional clinical judgement where a doctor’s decision is required.
PrivateGP.ie may use AI-supported transcription, documentation or clinical-support tools in line with what is appropriately in use in Irish healthcare systems and in line with the laws of data-protection and clinical-governance.
13. Where information is stored and processed
PrivateGP.ie is an Irish healthcare service and processes patient information in accordance with Irish and EU data-protection law.
We may use carefully selected third-party providers to securely process or transmit information on our behalf, including processing and storage of clinical records. Clinical record are stored in the EU within Ireland.
At the time of writing no data is processed outside of the EU. Where limited processing of personal data takes place in the future outside the EEA, we will ensure that an appropriate legal mechanism and safeguards are in place as required by the GDPR.
14. How long we keep information
We keep information only for as long as there is an appropriate clinical, professional, legal, regulatory, security or business reason to do so.
Medical records
Medical records are different from ordinary website or account information.
Doctors registered with the Medical Council are professionally required to maintain appropriate medical records.
Medical Council guidance requires doctors to keep medical records for as long as required by law or for as long as they remain clinically relevant. Retention must also take account of continuity and transfer of care and legitimate medico-legal requirements.
PrivateGP.ie therefore retains medical records in accordance with an appropriate healthcare records-retention policy, having regard to Medical Council requirements, applicable Irish law and relevant national healthcare records guidance.
Medical records may consequently be retained for a substantial period after your last interaction with PrivateGP.ie.
Unsuccessful clinical requests
A request for a prescription, certificate, referral or other treatment may itself involve a clinical assessment.
Where a doctor has considered a request, the information supplied, assessment and decision may form part of your medical record even if the requested prescription, treatment or document is not provided.
It will then be retained as part of the clinical record.
Other information
Administrative, website and support information that does not need to form part of the medical record will be retained only for as long as reasonably necessary.
Financial information will be kept for applicable accounting and taxation requirements.
Information relevant to complaints, regulatory matters, patient-safety incidents or actual or potential legal claims may be retained for longer where necessary.
15. Deletion of medical records
You have a right under Article 17 GDPR to request deletion of personal data in certain circumstances.
However, the right to erasure is not absolute.
In particular, medical records cannot ordinarily be treated in the same way as an unused online account or marketing record.
Doctors have professional obligations to maintain medical records and may need to retain them for:
- continuity and safety of care;
- clinical reasons;
- professional record-keeping requirements;
- legal or regulatory obligations;
- clinical governance;
- safeguarding;
- complaints or investigations; and
- legitimate medico-legal purposes.
For these reasons, closing your PrivateGP.ie account or making a GDPR erasure request will not ordinarily result in deletion of a legitimate medical record.
Before any medical record is destroyed, we must consider whether there remains a clinical, professional, legal or medico-legal reason for retaining it.
Where such a reason exists, we may refuse an erasure request in whole or in part.
You are still entitled to make an erasure request and we will consider it properly. Information that can lawfully and appropriately be deleted will be deleted.
16. Correcting medical records
You may ask us to correct personal data that is factually inaccurate.
Medical records must also preserve an accurate history of the care provided.
A clinical opinion, assessment or diagnosis recorded by a doctor does not become inaccurate simply because a different opinion is reached later.
Clinical notes will therefore not ordinarily be overwritten or retrospectively altered.
Where a genuine error needs to be corrected or information requires clarification, an appropriate correction, supplementary statement or subsequent clinical entry may be added while preserving the integrity of the original record.
17. Security and confidentiality
We take appropriate technical and organisational measures to protect personal and medical information against unauthorised access, disclosure, alteration, loss or destruction.
Access to patient information is limited to people who require it for an appropriate clinical, administrative, technical or legal purpose.
Doctors and relevant staff are subject to confidentiality obligations.
Third parties processing information on our behalf are required to provide appropriate data-protection and security safeguards.
No electronic system can be guaranteed to be completely secure, and we therefore do not make unrealistic guarantees of absolute security.
If a personal-data breach occurs, we will investigate and manage it in accordance with applicable data-protection law, including notifying the Data Protection Commission and affected individuals where legally required.
18. Your data-protection rights
Depending on the circumstances, you may have the following rights under the GDPR.
Access
You can request a copy of personal data we hold about you, including your medical information.
There are limited circumstances in which access to particular health information may lawfully be restricted, including where the applicable legal test concerning a serious risk of harm is met.
Rectification
You can ask us to correct factually inaccurate or incomplete personal data, subject to the principles relating to clinical records explained above.
Erasure
You can request deletion in circumstances where Article 17 GDPR applies.
As explained above, this does not create an automatic entitlement to have legitimate medical records destroyed.
Restriction
You may ask us to restrict processing in certain circumstances.
Objection
You may object to processing based on legitimate interests.
We will consider whether there are compelling legitimate grounds requiring the processing to continue.
You have a right to object to direct marketing at any time.
Data portability
Where the relevant GDPR conditions are met, you may request certain information you provided to us in a structured, commonly used and machine-readable format.
Withdrawal of consent
Where processing genuinely relies on your consent, you may withdraw that consent at any time.
Withdrawal does not affect processing already lawfully carried out and does not prevent processing that relies on another lawful basis.
19. Exercising your rights
To exercise a data-protection right or make a privacy enquiry, contact:
[privategp@gmail.com TBC INSERT PRIVACY EMAIL]
We may request reasonable evidence of identity before disclosing personal or medical information.
If another person is acting on your behalf, we may request evidence of their authority.
We will respond without undue delay and ordinarily within one month, subject to any extension permitted by the GDPR.
20. Service communications and marketing
Messages necessary to provide your healthcare are not marketing.
These may include:
- appointment information;
- consultation links;
- messages from your doctor;
- prescription notifications;
- requests for clinical information;
- results and follow-up;
- security messages; and
- important service communications.
You may not be able to opt out of communications that are necessary to safely provide a service you have requested.
Marketing communications are handled separately and can be stopped at any time.
21. Cookies
PrivateGP.ie may use cookies and similar technologies for necessary website operation, security, preferences and analytics.
Where consent is legally required for non-essential cookies, they will not be used unless the appropriate consent has been obtained.
Further information is contained in our separate Cookie Policy.
22. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to our services, legal requirements or data-processing practices.
The current version and date will be published on PrivateGP.ie.
Where a change materially affects how patient information is used, we will take appropriate steps to bring it to the attention of affected users.
23. Complaints
If you have concerns about how we use your personal data, please contact our Privacy Contact so that we can investigate the matter.
You also have the right to raise a concern or lodge a complaint with the Data Protection Commission:
Data Protection Commission
6 Pembroke Row
Dublin 2
D02 X963
Ireland
24. Contact us
For privacy enquiries, requests to exercise your GDPR rights or concerns regarding the use of your personal data:
Privacy Contact
Atlantic Maple Private Healthcare Limited
CRO Number: 799369
Email: [privategp@gmail.com- TBC INSERT PRIVACY EMAIL]