Privacy Policy
This policy has been prepared for legal review. It describes CureAbroad's data practices as of the last updated date below and should be confirmed with qualified counsel before publication in each operating jurisdiction.
Last updated: August 7, 2026
CureAbroad ("we", "us") operates a marketplace that connects patients with verified clinics and practitioners offering medical treatment abroad. This Privacy Policy explains what personal and health information we collect, why we collect it, how it is used, and the rights you have over it.
1. Information we collect
- • Account data: name, email, and authentication details when you register.
- • Health data: medical history, current medications, chronic conditions, and intake photos you submit for specialist triage.
- • Booking & payment data: procedure selected, treatment dates, and escrow transaction records. Card data is handled by our payment processor; we do not store full card numbers.
- • Communications: messages exchanged between you and clinics through the platform.
- • Usage data: device, browser, and interaction data used to improve search relevance and platform security.
2. How we use your information
- • To route intake assessments to the appropriate verified specialists for triage.
- • To operate milestone escrow — holding and releasing funds as booking milestones are confirmed.
- • To facilitate booking, scheduling, transfers, and recovery coordination between you and the clinic.
- • To verify clinics and surgeons and prevent fraud on the marketplace.
- • To provide support and respond to disputes.
3. Sharing with providers
We share your health data and intake photos only with the specific clinic or surgeon assigned to your assessment or booking, and only to the extent necessary to deliver the service. Providers are contractually restricted from using your data for any other purpose.
4. Data security
Health data is stored in encrypted, access-controlled environments. Access is role-based and audited. We process data in line with HIPAA safeguards for protected health information and GDPR lawful-processing principles for residents of the European Economic Area.
5. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal and health data. EU/EEA residents have additional rights including objection, restriction, and data portability. To exercise any right, contact us through the platform's support channels.
6. Retention
We retain health and booking data for as long as needed to provide the service and for the longer of the period required by law or our records-retention policy. Escrow and transaction records are retained for the period required by financial regulations.
7. Changes to this policy
We will update this policy as our practices evolve. Material changes will be notified through the platform. Continued use after a change constitutes acceptance of the updated policy.
Prepared for legal review. Confirm jurisdiction-specific requirements (e.g., HIPAA, GDPR, Turkish KVKK, Mexican LFPDPPP) with qualified counsel before publication.