GDPR Statement

    Last updated: 18 May 2026

    Connected Medics, operated by Get Connected Limited, complies with the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR as supplemented by the Data Protection Act 2018. This statement summarises how we apply those rules.

    1. Data controller

    Get Connected Limited is the data controller for personal data processed via the Connected Medics platform. For all data protection matters contact hello@connectedmedics.com.

    2. Principles we follow

    • Lawfulness, fairness, transparency — clear notices and lawful bases for every processing activity.
    • Purpose limitation — data is used only for the purposes set out in our Privacy Policy.
    • Data minimisation — we ask only for what we need.
    • Accuracy — you can update your data at any time from your profile.
    • Storage limitation — retention periods are documented and enforced.
    • Integrity and confidentiality — encryption in transit and at rest, role-based access, audit logs.
    • Accountability — records of processing, DPIAs for high-risk processing, vendor due diligence.

    3. Your rights under GDPR

    • Right of access (Article 15)
    • Right to rectification (Article 16)
    • Right to erasure / "right to be forgotten" (Article 17)
    • Right to restriction of processing (Article 18)
    • Right to data portability (Article 20)
    • Right to object (Article 21)
    • Rights related to automated decision-making (Article 22) — we do not make solely automated decisions with legal effect.
    • Right to withdraw consent at any time
    • Right to lodge a complaint with a supervisory authority (e.g. the UK ICO, Irish DPC, CNIL).

    To exercise any right, email hello@connectedmedics.com. We respond within one month.

    4. Special category data

    Information about your medical specialty or clinical interests is not in itself "health data" about you as a patient, but we treat profession-related information that could reveal sensitive details with extra care. We do not process patient data on the platform — see our Medical Disclaimer.

    5. International transfers

    Where data is transferred outside the UK / EEA we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision.

    6. Sub-processors

    We engage carefully vetted sub-processors for hosting, email delivery and analytics. A current list is available on request.

    7. Breach notification

    In the unlikely event of a personal data breach likely to result in risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay.

    8. Contact

    Data Protection enquiries: hello@connectedmedics.com.