1. Data controller
MediTravel Solutions, with its head office at 23 Avenue Habib Bourguiba, Les Berges du Lac, Tunis 1053, Tunisia.
2. Data collected
In the course of providing our services, we collect the following categories of data :
- Identification data (last name, first name, date of birth)
- Contact data (email, phone, address)
- Medical data (history, treatments, allergies, reports)
- Uploaded medical documents (test results, imaging, prescriptions)
3. Processing purposes
Your data is processed exclusively for the following purposes :
- Preparing personalized medical quotes
- Coordinating with partner clinics and surgeons
- Organizing your stay (transfers, hotel, flights)
- Post-operative follow-up for at least 12 months
4. Hosting and security
Medical data is encrypted in transit (TLS 1.3) and at rest (AES-256), and hosted on HDS (Health Data Hosting) certified servers in France.
5. Your rights
In accordance with the GDPR, you have the right to access, rectify, erase, port and object. To exercise these rights, write to us at dpo@meditravelsolutions.tn.
6. Retention
Your medical data is retained for 20 years from the last action concerning you, in accordance with the legal obligations applicable to medical records.