Privacy Policy

Privacy Policy

Last updated: 22 August 2026

1. Who We Are

This website (medicalcert.co.uk) is operated by Nobel Medical LLC, a limited liability company registered in the State of Delaware, United States, with its registered office at 131 Continental Drive, Suite 305, Newark, DE 19713, USA.

Nobel Medical LLC (“we”, “us”, “our”) acts as the data controller for personal data collected through this website. There is no separate UK company. Because we offer a service to people in the United Kingdom, the UK GDPR applies to our processing under Article 3(2).

MedicalCert operates as a digital service connecting patients with GMC-registered doctors for private medical consultations and the issuance of medical documentation where clinically appropriate.

2. UK Representative

As Nobel Medical LLC is established outside the United Kingdom, we have appointed a UK Representative under Article 27 of the UK GDPR.

UK-based individuals and the Information Commissioner’s Office (ICO) may contact our UK Representative directly regarding any matter relating to the processing of their personal data:

GDPRLocal Ltd. Attn: Adam Brogden 1st Floor Front Suite, 27-29 North Street Brighton, England, BN1 1EB United Kingdom

Email: contact@gdprlocal.com Privacy request submission page: https://nobelmedicalllc.gdprlocal.com/uk

You may contact our UK Representative as an alternative to contacting us directly. They will forward your enquiry to us and we will respond as required by law.

3. What Information We Collect

We collect the following categories of personal data:

  • Identity information: name, date of birth
  • Contact information: email address, postal address, telephone number where provided
  • Medical information: symptoms, medical history, and other clinical details you provide during the consultation process, together with any supporting documents or images you upload
  • Consultation records: details of the consultation, clinical decisions made, and any documentation issued
  • Technical data: IP address, approximate location derived from that IP address, browser type, device information, and usage data, including identifiers set by cookies and similar technologies as described in Section 8
  • Payment information: processed directly by Stripe; we do not store full card details

Medical information constitutes special category health data under UK GDPR and is handled with enhanced safeguards.

4. Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Performance of a contract (Article 6(1)(b) UK GDPR), to provide the consultation service you have requested
  • Legal obligation (Article 6(1)(c) UK GDPR), where we are required to retain or disclose data by law
  • Legitimate interests (Article 6(1)(f) UK GDPR), for service improvement, fraud prevention, and security, balanced against your rights

Health information is special category data under Article 9(1) UK GDPR. It needs a condition under Article 9(2) in addition to a lawful basis under Article 6. We rely on:

  • Article 9(2)(h) UK GDPR, processing necessary for medical diagnosis and for the provision of health care or treatment, carried out pursuant to a contract with a health professional. That condition applies subject to Article 9(3), which requires the data to be processed by or under the responsibility of a person bound by an obligation of secrecy. The matching condition in domestic law is paragraph 2 of Part 1 of Schedule 1 to the Data Protection Act 2018, health or social care purposes, read with section 11(1) of that Act.
  • Article 9(2)(f) UK GDPR, where health data is needed to establish, exercise or defend a legal claim.

Providing the identity, contact and clinical information requested in the consultation form is a requirement of the contract between us. If you do not provide it, we cannot arrange a clinical review and cannot issue any documentation.

5. How Your Information Is Used

We use your information to:

  • Connect you with a GMC-registered doctor for clinical review
  • Facilitate the issuance of medical documentation where the doctor determines it is clinically appropriate
  • Process payments securely via Stripe
  • Communicate with you about your consultation
  • Maintain the security and integrity of our service
  • Comply with applicable legal, regulatory, and professional obligations
  • Maintain accurate clinical records as required by professional standards

6. Clinical Confidentiality

Medical information is accessed only by the GMC-registered doctor assigned to your consultation and by authorised personnel involved in delivering the service.

Our doctors are bound by the duty of confidentiality that applies to every GMC-registered practitioner. Non-clinical personnel who need access in order to deliver the service are bound by equivalent contractual duties of confidentiality. This satisfies the requirement in Article 9(3) UK GDPR, supplemented by section 11(1) of the Data Protection Act 2018, that health data be processed by or under the responsibility of a person subject to an obligation of secrecy.

7. Automated Decisions

No decision about your consultation, and no decision about whether a document is issued to you, is made solely by automated means. Every consultation is read and assessed by a GMC-registered doctor, who decides what is clinically appropriate.

Automated checks are applied in two limited places. Our payment processor may apply automated fraud screening to a card payment, which can result in a payment being declined. We also filter obviously automated or duplicated submissions. Neither affects the clinical assessment.

Articles 22A to 22D UK GDPR restrict significant decisions taken solely by automated processing, and Article 22B restricts them further where health data is involved. We do not take decisions of that kind.

8. Cookies and Similar Technologies

Our website stores information on your device, and reads information already stored there, using cookies and similar technologies. This is governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, which permits it only where one of the exceptions in Schedule A1 to those Regulations applies. Regulation 6 was substituted with effect from 5 February 2026 by the Data (Use and Access) Act 2025.

The technologies used on this site fall into the following groups:

  • Strictly necessary. These keep the consultation form and the payment session working, hold your place in the process, and protect the site against attack and fraudulent submissions. They fall within paragraph 4 of Schedule A1, which covers storage and access strictly necessary for an information society service you have requested.
  • Security and delivery. Cloudflare provides content delivery and protection against malicious traffic, and NitroPack serves optimised and cached pages. Both set identifiers used to route and serve your request.
  • Analytics. PostHog, hosted in the European Union, and Google Analytics 4 record which pages are viewed, which site referred you, your approximate location derived from your IP address, your device and browser type, and how far you get through a consultation form. We use this to find and fix the points where the service fails people. Analytics is not strictly necessary to deliver the service.
  • Embedded content. Some pages embed a reviews widget supplied by Elfsight. The widget loads a script from that provider, which receives your IP address and browser information as a result.
  • Payments. Stripe sets the identifiers it needs to process a card payment securely and to detect fraud.

You can block or delete cookies through your browser settings, and most browsers let you do this for one site at a time. Blocking strictly necessary cookies will stop the consultation form and the payment step from working.

9. Sharing of Information

We do not sell your personal data. We share personal data only with:

  • GMC-registered doctors providing your consultation
  • Stripe, our payment processor
  • Our hosting and infrastructure providers, who process data on our behalf under written data processing terms. These are WP Engine, which hosts the website, Cloudflare, which provides content delivery and security, and Railway, which hosts the application that handles consultations
  • Our analytics providers, PostHog and Google, as described in Section 8
  • Our UK Representative (see Section 2), where contacted by you or the ICO
  • Regulatory or law enforcement authorities, where legally required

10. International Transfers

Nobel Medical LLC is established in the United States, and there is no UK establishment. Personal data you give us is therefore processed in the United States, and our hosting and application infrastructure is located in the Asia Pacific region.

Chapter V of the UK GDPR governs transfers of personal data to countries outside the UK. It was substantially rewritten with effect from 5 February 2026 by the Data (Use and Access) Act 2025. Under Article 44A, a transfer may be made only where it is approved by regulations under Article 45A, is made subject to appropriate safeguards under Article 46, or falls within a derogation under Article 49.

The United States is the subject of UK adequacy regulations, but only for transfers to an organisation that is listed as participating in the UK Extension to the EU-US Data Privacy Framework. Where a recipient is not on that list, we do not rely on those regulations.

For transfers to our processors we rely on appropriate safeguards under Article 46 UK GDPR, in the form of the standard data protection clauses issued by the Information Commissioner, being the International Data Transfer Agreement or the International Data Transfer Addendum to the European Commission’s standard contractual clauses.

You can obtain a copy of the safeguards that apply to a particular transfer by emailing us at the address in Section 17, or by contacting our UK Representative.

11. Data Retention

We retain personal and medical information only for as long as necessary to:

  • Deliver the consultation service
  • Maintain clinical records in line with professional and regulatory standards
  • Comply with legal, tax, and accounting obligations
  • Resolve disputes and enforce agreements

For clinical records we follow the retention schedule in the NHS England Records Management Code of Practice, published August 2021 and updated August 2023. That schedule sets a minimum of 8 years for adult health records, running from the point at which the record stops being operational. Records relating to children and young people, and a small number of other categories, carry longer minimum periods under the same schedule. A period can be extended where there is a documented reason, such as an unresolved complaint or claim.

Payment records are kept for as long as we are required to keep them for tax, accounting and chargeback purposes. Correspondence about a consultation is kept for as long as the clinical record it relates to. Analytics data is kept for the period configured in each analytics tool and is deleted automatically at the end of that period.

Once a retention period expires, data is securely deleted or anonymised.

12. Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectification of inaccurate or incomplete data
  • Erasure of your data, subject to legal and clinical retention obligations
  • Restrict or object to processing in certain circumstances
  • Object to direct marketing at any time under Article 21(2) UK GDPR. This right is absolute, and we will stop
  • Data portability where applicable
  • Withdraw consent at any time, where processing is based on consent
  • Not be subject to a significant decision based solely on automated processing, as described in Section 7

To exercise any of these rights, you can:

We will respond without undue delay, and normally within one month of receiving your request. If your request is complex, or if you have made a number of requests, we may need longer. We will tell you within one month if that is the case, and why.

13. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, secure authentication, and regular review of our security practices.

While no system can guarantee absolute security, we apply commercially reasonable safeguards proportionate to the sensitivity of the data we process.

14. Data Breaches

In the event of a personal data breach we will notify the Information Commissioner without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to people’s rights and freedoms. That obligation is in Article 33 UK GDPR.

Where a breach is likely to result in a high risk to your rights and freedoms, we will tell you about it without undue delay, under Article 34 UK GDPR.

15. Complaints

If you think we have handled your personal data in a way that breaches your rights, you can complain to us. Section 164A of the Data Protection Act 2018, in force from 19 June 2026, requires us to make complaints easy to lodge, to acknowledge your complaint within 30 days of receiving it, and to respond without undue delay and tell you the outcome. Email us at support@medicalcert.co.uk, or use the form provided by our UK Representative.

You can also complain to the Information Commissioner’s Office (ICO), the UK data protection regulator. That right is in section 165 of the Data Protection Act 2018. You do not have to complain to us first.

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

The ICO is a regulator, not a certifier. Nothing on this website is an endorsement, approval or accreditation by the ICO.

16. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent version. Material changes will be notified through the website or by direct communication where appropriate.

17. Contact

Nobel Medical LLC 131 Continental Drive, Suite 305 Newark, DE 19713, USA Email: support@medicalcert.co.uk

UK Representative: see Section 2 above.

Avatar

Reviewed by Dr Maria Knobel

Medical Director, MedicalCert · GMC 7495073 · Last updated: 25 August 2026