GO Medics

Privacy Policy

Effective: June 2026

1. Controller

Go Medics FlexCo

Nikolaiplatz 4, 8020 Graz, Austria

Company Register Number: FN637661m

Phone: +43 316 30 01 19

Email: office@go-medics.eu

www.go-medics.eu

Data Protection Officer: Mag. Ewald Felbar
Contact: ewald.felbar@go-medics.eu

2. Role of the Company

The company is an intermediary and organisational contact, but not a medical service provider, clinic, medical practice or any other treating entity. No diagnoses are made, no medical therapies are performed and no medical decisions are made for patients.

The processing of data is therefore primarily for the initiation, organisation and execution of the intermediary service as well as for communication with the clinics or practitioners desired by the Customer. The medical treatment itself is carried out exclusively by the respective clinic or doctor abroad.

3. Scope

This privacy policy applies to:

  • visiting the website,
  • contact via form, email, telephone, messenger or other means,
  • uploads of documents, images and medical records,
  • the initiation, execution and documentation of intermediary services,
  • communication with clinics, doctors, interpreters and other recipients,
  • enabling direct contact by clinics with the Customer, provided corresponding authorisation has been granted.

4. Data Processed

4.1 Master and Contact Data: Name, date of birth, gender, address, telephone number, email address, language, nationality, accessibility data, contract and transaction data.

4.2 Intermediation and Organisation Data: desired treatment, desired country, desired clinic or practitioner, appointment requests, travel and accommodation information, communication content, correspondence and conversation notes.

4.3 Health Data and Sensitive Documents: medical certificates, doctor's letters, diagnoses, findings and laboratory values, information on complaints, pre-existing conditions, allergies and medication, surgical reports, before/after photos, other medical documents.

5. May Health Data be Collected by the Intermediary?

An intermediary may not process health data automatically, but may do so lawfully if a valid data protection legal basis exists. For a non-treating intermediary company, the explicit consent of the data subject is in practice regularly the safest and often necessary basis. Consent must be given voluntarily, for specific purposes, in an informed manner and unambiguously; explicit consent is required for sensitive data. For evidentiary reasons, GO Medics FlexCo obtains written or electronic confirmation for such consents (Declaration of Consent).

6. Separate Consent for Processing Health Data

Insofar as health data is processed, this is done only on the basis of a separate explicit consent of the Customer. This consent covers: receipt and storage of medical documents, review and organisational processing of the documents, forwarding to selected clinics, doctors or medical facilities, inquiries with clinics on the basis of the transmitted documents, organisational communication about the requested treatment, documentation of the intermediary process.

7. Power of Attorney / Communication Authorisation

In order for the Intermediary to communicate with clinics, the Customer expressly authorises the Intermediary: to transmit medical and organisational documents to clinics, to make inquiries with clinics, to obtain offers, appointment options and organisational information, to receive communications from the clinic and forward them to the Customer.

8. Authorisation for Contact by Clinics

If the Customer wishes for the selected clinic or doctor to contact them directly, they expressly confirm this.

9. Purposes of Processing

Data processing is carried out for the following purposes: processing of inquiries, initiation and execution of the intermediary contract, selection and contacting of suitable clinics, transmission of documents to clinics, obtaining appointment options and cost estimates, organisation and documentation of communication, enabling direct contact between clinic and Customer, invoicing and administration, enforcement of legal claims, IT security and abuse prevention.

10. Legal Bases

Depending on the processing operation, the following legal bases come into consideration: contract performance and pre-contractual measures (Art. 6(1)(b) GDPR) for master data and organisational processes, legal obligations (Art. 6(1)(c) GDPR) for accounting and retention, legitimate interests (Art. 6(1)(f) GDPR) for IT security and legal enforcement, explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) for health data and communication authorisation.

11. Recipients of Data

Data is only passed on to the extent necessary to: selected clinics and doctors, interpreters or service partners, IT, hosting, form and upload service providers (esp. Vercel Inc., USA — EU-U.S. DPF), tax consultants, payment service providers and legal advisors, authorities, courts or insurers, insofar as legally required.

12. Communication via Email and Telephone

Communication with the Customer as well as — after corresponding authorisation — with clinics may take place via email and telephone. The Customer expressly confirms that organisational messages, inquiries and appointment coordination may take place via these communication channels. Insofar as sensitive documents are sent by email, appropriate security measures are taken.

13. Storage Period

Personal data is only stored for as long as is necessary for the stated purposes or as required by statutory retention obligations. For tax and company law relevant documents, statutory retention periods apply (7 years pursuant to § 132 BAO). Health data based exclusively on consent is generally deleted after the purpose ceases to apply or upon revocation, unless statutory retention obligations conflict.

14. Data Subject Rights

Data subjects have in particular the right to information (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), objection (Art. 21 GDPR) as well as the right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR). The withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

15. Right to Complain

Data subjects have the right to lodge a complaint with the Austrian Data Protection Authority: Data Protection Authority, Barichgasse 40–42, 1030 Vienna, Email: dsb@dsb.gv.at, Web: www.dsb.gv.at.

16. Google Analytics & Cookies

This website uses Google Analytics 4 (Google Ireland Ltd.) only with explicit consent. IP anonymisation is activated. Data retention: 14 months. Data transfer to the USA is based on the EU-U.S. Data Privacy Framework (DPF). Details and opt-out: see cookie settings.

Essential cookies (session, cookie preferences) are technically necessary and cannot be deactivated. Analysis and marketing cookies are only set after active consent.

17. Data Security

Appropriate technical and organisational measures (TOMs) are taken to protect personal data and in particular health data against loss, unauthorised access, unlawful disclosure or manipulation. These include access controls, role and authorisation concepts, secure transmission channels (SSL/TLS), encryption, password policies, logging and privacy-friendly default settings (Privacy by Design / Privacy by Default).