DRAFT — NOT LEGALLY REVIEWED. DO NOT PUBLISH AS-IS.
This document was drafted as a working starting point. It has not been reviewed by a solicitor, and it contains [[CONFIRM: …]] placeholders wherever a fact was not available. Every placeholder must be filled and the whole document reviewed by a qualified adviser before OlaDoc.ie accepts a single order. Publishing this unchanged would misstate your legal position to patients.
Last updated: [[CONFIRM: date]] · Version: draft
1. Who we are
OlaDoc.ie is operated by IE HEALTHNOW LIMITED, a company registered in Ireland (company number 805729), registered office 5 St Patrick’s Close, Kilkenny, Ireland [[CONFIRM: Eircode]].
IE HEALTHNOW LIMITED is the data controller for the personal data described here. The same company operates DocOnCall.ie and DoxOnCall.ie.
Data protection contact: [[CONFIRM: DPO or data protection contact email]].
[[CONFIRM: whether a Data Protection Officer is formally required. Art. 37(1)(c) GDPR requires a DPO where core activities consist of large-scale processing of special category data. A home testing service processing health data at scale may well cross this threshold — take advice.]]
2. What data we collect
Information you give us
- Name, email address, phone number, delivery address and date of birth
- Payment details (processed by Stripe — we do not store card numbers)
- Health information you provide when registering a kit: symptoms, medication, supplements, relevant history, and for some tests menstrual cycle information
Information generated by the service
- Your kit’s unique reference number, and the link between it and you
- Laboratory results returned against that reference number
- The reviewing GP’s interpretation, notes and any advice issued
- Order, dispatch and delivery records
Information collected automatically
- IP address, browser and device information, and pages visited
- Cookies and similar technologies — see our Cookie Policy
3. Special category data
Health data is special category personal data under Article 9 of the UK/EU General Data Protection Regulation and the Irish Data Protection Act 2018. It carries stronger protections, and we treat it accordingly.
4. Our lawful bases
| Purpose | Lawful basis (Art. 6) | Condition for health data (Art. 9) |
|---|---|---|
| Providing the testing service and GP review | Contract | Art. 9(2)(h) — provision of health care and treatment by a health professional under a duty of confidentiality |
| Taking payment | Contract | n/a |
| Meeting legal and regulatory duties, including notifiable-disease reporting | Legal obligation | Art. 9(2)(i) — public interest in public health |
| Marketing emails, where you have opted in | Consent | n/a — we do not use health data for marketing |
| Service security, fraud prevention and improvement | Legitimate interests | n/a |
Where we rely on consent you may withdraw it at any time. Withdrawing consent does not affect processing carried out before withdrawal.
5. Who we share your data with
- Our partner laboratory — [[CONFIRM: laboratory name, country of processing, accreditation, and whether it acts as processor or joint controller]]. The laboratory receives your sample identified by reference number.
- Reviewing clinicians — GPs registered with the Irish Medical Council, bound by professional confidentiality.
- Stripe — payment processing.
- Delivery partners — [[CONFIRM: courier/postal partner]], who receive delivery details only, never health data.
- Public health authorities — where a result is a notifiable infection under the Infectious Diseases Regulations, the reviewing clinician has a statutory reporting duty. See section 9.
- [[CONFIRM: hosting, email and analytics processors, and whether a processor list will be published]]
We do not sell your data. We do not share health data with advertisers, and we do not use it to target advertising.
6. International transfers
[[CONFIRM: whether any processor — laboratory, hosting, email — processes data outside the EEA. If so, name the safeguard relied on: adequacy decision, Standard Contractual Clauses, or a derogation.]]
7. How long we keep your data
[[CONFIRM: retention periods. These must be set deliberately, not by default. Relevant considerations: Irish Medical Council guidance on retention of patient records; the general position that adult medical records are retained for a minimum of 8 years; statutory limitation periods; and the separate, shorter retention appropriate for marketing data and web analytics.]]
We keep data only as long as necessary for the purposes set out here, then delete or anonymise it.
8. Your rights
Under GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you
- Rectification — have inaccurate data corrected
- Erasure — have data deleted, subject to our legal and clinical retention duties
- Restriction — limit how we process your data
- Portability — receive your data in a portable format
- Object — object to processing based on legitimate interests
- Withdraw consent — where consent is the basis
To exercise any of these, contact [[CONFIRM: data rights contact email]]. We respond within one month, extendable by two further months for complex requests.
Note on erasure: the right to erasure is not absolute. Where we are required to retain clinical records under professional or statutory obligations, we cannot delete them on request, and we will explain why if that applies.
9. Notifiable infections
Chlamydia, gonorrhoea, syphilis and HIV are notifiable infectious diseases in Ireland. Where a test returns a positive result for a notifiable infection, the reviewing clinician has a legal duty to report it to public health authorities. This duty exists independently of your consent and cannot be opted out of.
We will always tell you when this applies and explain what is reported. [[CONFIRM: exact notification workflow agreed with the laboratory and the reporting clinician — who notifies, to whom, and what identifiers are included.]]
10. Security
We use encryption in transit, access controls, and restrict access to health data to clinicians and staff who need it. Samples are identified to the laboratory by reference number rather than by name.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours, and notify you directly where the risk is high.
11. Children
[[CONFIRM: minimum age. Most at-home testing services restrict to 18+. If under-18s are to be accepted, consent, capacity and safeguarding requirements change materially — take advice before allowing it.]]
12. Complaints
If you are unhappy with how we handle your data, contact us first at [[CONFIRM: complaints email]]. You also have the right to complain to the Irish supervisory authority:
Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 — dataprotection.ie
13. Changes
We will post any changes here and update the date at the top. Material changes affecting how we use health data will be notified to you directly.