Data Processing & Sharing Terms

Last updated: June 6, 2026 | Version 1.0 | For partner hospitals

1. Roles of the Parties

CureMeridian (a US company) and the partner hospital are each independent data controllers. CureMeridian determines the means and purposes of collecting and matching patient inquiries; the hospital independently determines how it uses a patient's data once it accepts a qualified introduction. This is a controller-to-controller data sharing arrangement, not a processor relationship.

2. Purpose Limitation

Data shared through CureMeridian may be used only to respond to the patient's inquiry, to provide a quote, arrange a consultation, and deliver the requested care. It may not be used for unrelated marketing, sold or onward-disclosed, or processed in any way the patient has not been told about.

3. Lawful Basis & Consent

CureMeridian shares a patient's data with a hospital only after the patient gives explicit consent to that sharing, including explicit consent to any cross-border transfer (GDPR Art. 49(1)(a)). The hospital must rely on its own lawful basis for any further processing and must honor the scope of the patient's consent.

4. Cross-Border Transfers

Where patient data originates in the EU/UK and is shared with a hospital outside an adequacy decision, the transfer relies on the patient's explicit, informed consent to that specific transfer. Where applicable, the parties will put EU Standard Contractual Clauses and supplementary measures in place.

5. Security

Each party must apply appropriate technical and organizational measures to protect the data, including encryption in transit and at rest, access controls, and staff confidentiality obligations, consistent with GDPR Art. 32.

6. Data-Subject Rights & Withdrawal

If a patient withdraws consent, requests erasure, or restricts processing, CureMeridian will notify the hospital under GDPR Art. 19, and the hospital must promptly stop processing and delete or restrict the patient's data unless it has an independent legal obligation to retain it. Each party will cooperate to fulfil data-subject requests.

7. Breach Notification

Each party must notify the other without undue delay (and in any event within 24 hours) of becoming aware of a personal-data breach affecting shared data, and cooperate on notification to authorities and affected individuals.

8. Retention & Deletion

The hospital may retain shared data only as long as necessary for the patient's care and its own legal obligations, and must delete it on request where no such obligation applies.

9. Categories of Data Shared

The data shared with a hospital through a qualified introduction is limited to what it needs to respond to the patient: the patient's name and contact details, the procedure and destination they are considering, the health information they chose to provide for matching (such as conditions, history, and relevant details), and their stated preferences. We do not share payment-card data or login credentials.

10. US Consumer Health Laws

For patients in US states with consumer-health-privacy laws (such as Washington's My Health My Data Act), health-linked data is shared only under a valid authorization the patient has given. The hospital must use that data only within the scope of that authorization, must not sell or further share it, and must honor any withdrawal of authorization we communicate.

11. Sub-Processors

If the hospital uses its own service providers to process shared data, it must impose data-protection obligations on them at least equivalent to those in these terms, and it remains responsible for their compliance.

12. Audit and Cooperation

On reasonable request, the hospital will provide the information necessary to demonstrate its compliance with these terms and will cooperate with reasonable assessments of how shared data is handled.

13. Liability and Indemnification

Each party is responsible for its own compliance with applicable data-protection law and for losses caused by its own breach of these terms. The hospital will indemnify CureMeridian against claims, fines, and losses arising from the hospital's misuse of shared data or breach of these terms, to the extent permitted by law.

14. Governing Law, Term, and Termination

These terms are governed by the laws of the State of Delaware, USA, without regard to conflict-of-laws rules, and without limiting any mandatory data-protection law that applies to a party. Either party may terminate these terms on notice. On termination, the hospital must stop processing and delete the shared data unless it has an independent legal obligation to retain it. The sections on purpose limitation, security, breach notification, US consumer health laws, and liability survive termination.

15. Contact

Questions about these terms: contact@curemeridian.com.