Privacy Policy
Last updated: 2025. This Privacy Policy explains how MedEscort China ("we", "us", "our") collects, uses, stores and shares personal data — including the medical information you share with us as part of a medical concierge engagement.
We take this seriously. We are not a medical provider, but we handle sensitive medical information on behalf of patients and their treating hospitals, and we apply the standards of major data-protection frameworks (including GDPR and China's Personal Information Protection Law) regardless of where you live.
1. Who we are
MedEscort China is a medical concierge service that helps international patients access treatment at hospitals in China. We are the data controller for the personal information you give us directly. When we forward records to a hospital you have selected, that hospital becomes an independent controller of the data they receive — please review their privacy practices too.
2. What data we collect
We collect three categories of data:
- Contact data — name, email, phone, WhatsApp number, country of residence.
- Medical data — reports, imaging, prior diagnoses, treatment history, current medications, allergies, and any other health information you choose to share with us for the purpose of arranging care.
- Engagement data — the services you book, communications with your coordinator, payment records, and feedback after your case closes.
We do not collect special categories of data beyond what is strictly necessary for your case, and we never collect data from third parties about you without telling you.
3. Why we use your data (purposes & legal basis)
- To reply to your enquiry and provide a quote — based on your consent or our legitimate interest in operating our business.
- To arrange and coordinate your care — based on the contract you enter with us, and on your explicit consent to share relevant medical data with your chosen hospital.
- To provide interpreting, escort and travel services — based on the contract.
- To send service-related messages (appointment reminders, family updates) — based on the contract and your consent.
- To comply with legal obligations — accounting, tax, anti-money-laundering record-keeping.
- To improve our service — based on legitimate interest, using aggregated or de-identified data wherever possible.
4. How long we keep your data
We retain data only as long as needed for the purposes above:
- Active case data — for the duration of your engagement, plus a reasonable handover period.
- Post-return follow-up — typically 30 days (Standard) or 90 days (Premium) for the post-return remote follow-up window.
- Accounting and tax records — for the period required by local law (typically 5–10 years).
- Marketing data — until you withdraw consent, which you can do at any time.
After these periods, data is either deleted or fully de-identified. We do not retain medical records "just in case".
5. International data transfers
Your data may be transferred between the country you live in and China. We protect these transfers by:
- Using contracts that require recipients to apply data-protection standards equivalent to GDPR, regardless of local law.
- Encrypting data in transit (TLS 1.2+) and at rest where technically possible.
- Sharing only the minimum data necessary with any given recipient.
If you are in the EEA, UK or Switzerland, we rely on Standard Contractual Clauses for transfers outside your jurisdiction. If you are in mainland China, we comply with the PIPL cross-border transfer rules, including security assessments and standard contracts where applicable.
6. Your rights
Subject to your local law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete data we are not required to keep for legal reasons.
- Restrict or object to certain processing (e.g. for marketing).
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, without affecting processing already carried out on the basis of that consent.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, contact our DPO using the details below. We respond within 30 days.
7. Sharing your data
We share your data only with the people who need it for your case:
- Your chosen hospital and treating clinical team.
- Your assigned coordinator, interpreter and, where applicable, escort.
- Booking partners (hotels, transport providers) — but only the minimum needed to confirm a booking.
- Payment processors and our accountants.
- Authorities, when legally required.
We do not sell your data. We do not share it with marketing companies. We do not hand it to a third party you have not approved.
8. Third-party processors
We use a small number of vetted third-party processors to operate our service. Examples include cloud hosting, email, payment processing, and (with your consent) WhatsApp. Each is bound by a data-processing agreement. A current list of processor categories is available on request.
9. Cookies and similar technologies
Our website uses only the minimum cookies needed to operate:
- Strictly necessary cookies for the language preference and form session.
- Analytics (anonymized, IP-truncated) only if you accept — we never use advertising cookies.
You can clear cookies in your browser at any time. The site will still work; only your preferences may reset.
10. Security
We protect your data with a combination of technical and organizational measures: encryption in transit, access controls limited to staff on a need-to-know basis, two-factor authentication on internal systems, regular backups, and staff training on confidentiality. No system is perfect, but we work hard to keep yours safe.
11. Children
We only collect data about children with the consent of a parent or legal guardian. If you believe we have collected data about a child without proper consent, please contact our DPO and we will delete it.
12. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email to active clients and posted on this page with a new "last updated" date.
13. Contact our DPO
For any privacy question, request or complaint, contact our Data Protection Officer:
- Email: privacy@example.com
- Postal: Data Protection Officer, MedEscort China, XX Road, Pudong, Shanghai
- Response time: within 30 days.
If you are unhappy with our response, you may also lodge a complaint with your national data-protection authority.