Privacy Policy

Last updated: 2 July 2026

VoyaMed ("VoyaMed", "we", "us") connects international patients with independent specialist doctors and clinics in Egypt and coordinates their care. This policy explains what personal data we collect, why, the legal basis for processing, who we share it with, and the rights you have under the EU/UK General Data Protection Regulation (GDPR).

1. Who we are (data controller)

VoyaMed is the data controller for the personal data described in this policy. For any privacy question, or to exercise your rights, contact our privacy team at privacy@voyamed.co. Where required, we will identify a Data Protection Officer or EU/UK representative; their contact details will be published here.

2. What data we collect

We do not store full payment card or bank details — payments are processed by our payment provider (see §4).

3. Why we process your data and the legal basis

4. Who we share data with

We do not sell your personal data.

5. International transfers

Because our patients are international and our specialists are in Egypt, your data may be transferred across borders. Where data is transferred outside the EEA/UK, we rely on appropriate safeguards (such as Standard Contractual Clauses) or your explicit consent, and we take steps to ensure your data remains protected.

6. How long we keep your data

We keep your data for as long as your account is active and as needed to provide the service. When you delete your account, we immediately erase your health information (medical history, allergies, medications, and related profile fields), scrub your name/email/contact details, and delete your uploaded medical documents from storage. Messages you sent or received have their content erased; the surrounding record is kept only so the other party's conversation isn't broken.

Payment records are the one exception: we keep them, as required by law, for the duration of our accounting and tax record-keeping obligation (GDPR Art. 17(3)(b)) — we do not delete or anonymise them on request, because we are legally required to retain them. No other category of your data is kept for this reason.

Backups follow our storage provider's normal rotation and are not separately queried to serve user data.

7. Your rights — and how to exercise them in-product

Under the GDPR you have the right to:

Doctor, clinic, and admin accounts: self-service export/erasure is not yet available for these roles — email privacy@voyamed.co and we will action the request. For any right not yet self-service, or any question, email the same address. We respond within the timeframes required by law.

8. How we protect your data

We use encryption in transit and at rest for sensitive data, role-based access controls so users can only see their own data, and audit logging of changes to records. No system is perfectly secure, but we work to protect your information and to detect and respond to incidents.

9. Patients — additional information

Your medical information is processed only to coordinate your care with the doctor or clinic you choose. VoyaMed is a referral and coordination platform: the treating doctor or clinic is solely responsible for clinical decisions, treatment, and outcomes. VoyaMed is not responsible for the medical outcome of any procedure.

10. Doctors & clinics — additional information

We collect your professional and tax-registration documents to verify your account and meet legal requirements; these documents are private to you and authorised VoyaMed administrators. The relationship between you and VoyaMed is that of an independent practitioner — VoyaMed is not your employer and refers patients to you while you act on your own professional responsibility (including clinical decisions, regulatory compliance, taxes, insurance, and licensing).

11. Changes to this policy

We may update this policy from time to time. We will post the new version here and update the "last updated" date. Material changes affecting how we use your data will be communicated where appropriate.