Privacy Policy

Last updated: June 6, 2026 | Version 1.1

Summary: We collect data to match you with international hospitals. When you choose to share your case, we introduce you to hospitals and those hospitals pay us a fee for the introduction, under some US state laws this counts as a “sale” or “sharing,” and you can opt out at any time. We do not sell your data to data brokers or for unrelated purposes. You have full GDPR rights including erasure, and our AI processes de-identified health information only.

Do Not Sell or Share My Personal Information (CCPA/CPRA)

If you are a California resident (or otherwise covered by US state privacy law), you have the right to opt out of the “sale” or “sharing” of your personal information. When you opt out, your inquiry is never shared or sold to clinics. We also honor browser Global Privacy Control (GPC) signals as a valid opt-out.

Loading your preference…

Limit the Use of My Sensitive Personal Information

Health information is “sensitive personal information” under CCPA/CPRA. We use it only to provide the matching, estimate, and introduction services you ask for, we do not use it to infer characteristics about you, and we do not disclose it for purposes that would require a separate right to limit. If you exercise the opt-out above, we stop sharing your sensitive information with hospitals. You can also contact contact@curemeridian.com to limit its use.

1. Who We Are (Controller Identity)

CureMeridian (“we”, “our”, “us”), a United States company, is the data controller for personal data collected through this platform. Contact: contact@curemeridian.com. Data Protection Officer: contact@curemeridian.com.

EU / UK representatives (GDPR Art. 27): As a controller based outside the EU and UK that offers services to individuals there, we have appointed representatives who can be contacted on data-protection matters at contact@curemeridian.com (EU) and contact@curemeridian.com (UK). The representatives' registered names and addresses are available on request.

2. Data We Collect and Why

Account Data:

Name, email address, password (hashed). Collected to provide account access. Legal basis: Art. 6(1)(b), contract performance.

Health Information:

Procedure interests, medical conditions, treatment history (entered voluntarily). Used to match you with suitable clinics. Legal basis: Art. 9(2)(a), explicit consent. Processed in de-identified form only for AI operations.

Usage Data:

Pages visited, search queries, features used. Used to improve the platform. Legal basis: Art. 6(1)(f), legitimate interests. You may object at any time.

Communications:

Messages sent via our platform, support tickets, chatbot conversations. Legal basis: Art. 6(1)(b), contract performance.

3. How We Use Your Data

  • Matching you with international medical clinics
  • Providing algorithm-based cost estimates and AI-assisted triage
  • Sending you relevant information about procedures and clinics (with consent)
  • Improving our platform and AI models (anonymized data only)
  • Complying with legal obligations
  • Fraud prevention and security

4. Data Sharing and Paid Introductions

When you ask to be introduced to hospitals and give your explicit consent, we share your inquiry with the partner hospitals you select. Those hospitals pay CureMeridian a fee for a qualified introduction. Because money changes hands, under California (CCPA/CPRA) and some other US state laws this may be considered a “sale” or “sharing” of personal information, which is why we give you the opt-out below and honor Global Privacy Control signals.

We do not sell your information to data brokers or for purposes unrelated to matching you with care. We also share data with our processors (cloud infrastructure, AI providers) under strict data processing agreements and GDPR-compliant safeguards including EU Standard Contractual Clauses.

We may also disclose your information where required to comply with applicable law, a court order, or a lawful request from a public authority, or where necessary to protect our rights, our users, or the public.

Business transfers: if CureMeridian is involved in a merger, acquisition, financing, reorganization, or sale of assets, or in the event of insolvency, your information may be transferred as part of that transaction. We will notify you by email or a prominent in-app notice before your personal data becomes subject to a different privacy policy.

5. International Transfers

CureMeridian operates from the United States, and some of our processors are US-based. Transfers to our processors are protected by EU Standard Contractual Clauses (Module 2) with supplementary technical safeguards including encryption and data minimization.

When you choose to share your case with a hospital, your data is transferred to the hospital in the destination country you selected. Many destination countries do not have an EU adequacy decision and may not offer the same level of data protection as your home country. We make these transfers on the basis of your explicit, informed consent to that specific transfer (GDPR Art. 49(1)(a)). You can withhold or withdraw this consent at any time without affecting your matches or estimate.

6. Data Retention

Account data: retained while your account is active, plus 30-day deletion grace period. Health information: retained as long as needed for matching, maximum 2 years from last activity. Audit logs: 7 years (HIPAA requirement). You may request deletion at any time.

7. Your Rights (GDPR Articles 15 to 21)

  • Access (Art. 15): Request a copy of all data we hold about you
  • Rectification (Art. 16): Correct inaccurate data
  • Erasure (Art. 17): “Right to be forgotten”, delete your account and data
  • Restriction (Art. 18): Limit how we process your data
  • Portability (Art. 20): Download your data in machine-readable format
  • Object (Art. 21): Object to legitimate-interest processing
  • Withdraw consent: Withdraw any consent given at any time

To exercise your rights, visit your account settings or email contact@curemeridian.com. To protect your data, we may need to verify your identity before acting on a request. We respond within 30 days.

8. Automated Decision-Making

We use automated systems (including AI) for clinic matching, lead scoring, and cost estimation. These are explained in our AI Transparency page. You have the right to request human review of any automated decision affecting you.

9. Cookies

We use essential cookies for authentication and analytics cookies (with consent). See our Cookie Policy for full details.

10. Complaint Rights

If you believe we have processed your data unlawfully, you have the right to lodge a complaint with your local data protection authority. EU residents may contact their national DPA or the lead supervisory authority.

11. Special Categories of Data

Health data is a special category under GDPR Art. 9. We process it only with your explicit consent and using enhanced security measures including AES-256 encryption and strict access controls.

12. Children

Our platform is for adults 18 and older. We do not knowingly collect data from minors. If you believe we have inadvertently collected data from a minor, contact us immediately.

13. Security

We protect your data with AES-256-GCM encryption, TLS in transit, bcrypt password hashing, and strict access controls. We undergo regular security audits. No method of transmission or storage is completely secure, so while we use industry-standard safeguards we cannot guarantee absolute security.

14. Third-Party Links

Our platform may link to third-party websites and services. We are not responsible for their privacy practices or content, and we encourage you to review the privacy policy of any site you visit.

15. Policy Changes

We will notify you by email or prominent in-app notice at least 30 days before any material changes to this policy. Continued use after notice constitutes acceptance.