Last Updated: [01-06-2026]
At Doctor247, protecting your privacy, confidentiality, and personal data is one of our highest priorities.
We are committed to ensuring that all personal information and health information collected through our platform is processed lawfully, fairly, transparently, and securely in accordance with:
As a healthcare service provider, Doctor247 processes health information, which is classified as Special Category Personal Data under Article 9 of the GDPR and is subject to enhanced legal protection.
The General Data Protection Regulation (GDPR) is the primary data protection law governing the collection, use, storage, and sharing of personal data within the European Union and European Economic Area.
GDPR gives individuals greater control over their personal information and imposes strict obligations on organizations that process personal data.
Doctor247 follows the core GDPR principles when processing personal information:
We only collect and process personal data where we have a lawful basis for doing so and we explain clearly how your information is used.
Your information is collected only for specific, legitimate, and clearly defined purposes.
We only collect information that is necessary to provide healthcare services, comply with legal obligations, and operate our platform effectively.
We take reasonable steps to ensure that personal information remains accurate and up to date.
Personal data is retained only for as long as necessary to fulfil legal, regulatory, medical, and operational requirements.
We implement appropriate technical and organisational security measures to protect personal information against unauthorized access, disclosure, alteration, or destruction.
Doctor247 maintains internal processes, policies, and safeguards designed to demonstrate compliance with GDPR requirements.
As part of providing healthcare services, Doctor247 processes health information including:
Under Article 9 GDPR, health information is classified as Special Category Personal Data and receives enhanced protection because of its sensitive nature.
Doctor247 only processes personal information where a valid legal basis exists under Article 6 GDPR.
Depending on the circumstances, our legal basis may include:
Processing necessary to provide healthcare services requested by you.
Processing necessary to comply with applicable healthcare, regulatory, tax, and legal obligations.
Processing necessary for platform security, fraud prevention, service improvement, and operational management where such interests are not overridden by your rights.
Processing necessary to protect an individual’s life or physical safety in emergency situations.
Where required, we obtain your explicit consent before processing certain categories of personal information.
Because health information is classified as Special Category Personal Data, GDPR requires an additional legal basis under Article 9.
Doctor247 may process health information where processing is necessary for:
Healthcare services frequently rely on legal healthcare exemptions under Article 9 GDPR in addition to Article 6 lawful processing grounds.
We may collect the following categories of personal data:
Payment card information is generally processed by secure third-party payment providers.
Your information may be used for:
Under GDPR, you may have the following rights:
You may request a copy of the personal data we hold about you.
You may request correction of inaccurate or incomplete personal information.
You may request deletion of your personal data where applicable under law.
You may request that processing of your personal data be limited under certain circumstances.
You may request a copy of your data in a structured, commonly used, machine-readable format.
You may object to certain processing activities where permitted by law.
Where processing is based on consent, you may withdraw that consent at any time.
You have the right to lodge a complaint with the Irish Data Protection Commission if you believe your data protection rights have been violated.
Doctor247 does not sell personal information.
We may share personal data only where necessary with:
All third parties are required to implement appropriate data protection and security measures.
Where personal data is transferred outside the European Economic Area (EEA), Doctor247 ensures that appropriate safeguards are implemented, including:
Doctor247 retains personal data only for as long as necessary to:
Retention periods may vary depending on the nature of the information and applicable legal requirements.
Doctor247 implements appropriate technical and organisational security measures including:
While we strive to protect personal information, no internet-based transmission or storage system can be guaranteed to be completely secure.
Doctor247 uses cookies and similar technologies to:
Where required, consent is obtained before non-essential cookies are placed on your device.
Doctor247 does not make clinical decisions solely through automated processing.
Healthcare decisions are made by qualified healthcare professionals exercising independent clinical judgment.
Doctor247 services are intended primarily for adults.
Where services are provided to minors through a parent or legal guardian, personal data is processed in accordance with applicable GDPR requirements and Irish law concerning children’s data.
Doctor247 maintains procedures for identifying, investigating, and responding to personal data breaches.
Where required under GDPR:
For GDPR-related requests or privacy questions, please contact:
Data Protection Team
Email: privacy@doctor247.ie
Website: https://doctor247.ie
If you believe your personal information has been processed unlawfully, you may lodge a complaint with:
Website: Data Protection Commission
The Data Protection Commission is Ireland’s independent supervisory authority responsible for enforcing GDPR and data protection laws.
Doctor247 is committed to maintaining the highest standards of privacy, confidentiality, security, and GDPR compliance in the delivery of healthcare services.
GDPR provides additional protection for health information because health data is classified as Special Category Personal Data under Article 9 GDPR and may only be processed under specific legal conditions with appropriate safeguards.