Privacy Policy
Last updated 16 August 2026
This policy explains what personal data PodiaScan processes, why we process it, and the rights available to you. PodiaScan is operated by GD Consultants, Greystones, Ireland.
1. Who we are
PodiaScan is provided by GD Consultants ("we", "us"). For account and clinic data we describe below, we act as the data controller. For patient clinical records entered by a clinic, the clinic is the controller and we act as its processor.
GD ConsultantsGreystones, Co. Wicklow, Ireland
privacy@podiascan.com
2. Data we process
- Account data — name, email address, clinic membership and role.
- Clinic data — clinic name, strap line, address, contact email and phone, logo and theme settings.
- Patient data — patient name or reference, date of birth, risk level, and thermal scan sessions (twelve zone temperatures, device model, timestamps and alert state). Health data is special-category data under Article 9 GDPR.
- Technical data — authentication tokens, session logs and error diagnostics needed to keep the service running securely.
3. Why we process it and our legal basis
- To provide accounts and secure sign-in — performance of a contract.
- To store and display clinical scans for the clinic — on the clinic's documented instructions as its processor.
- Health data is processed by the clinic under Article 9(2)(h) GDPR (healthcare provision) with professional secrecy obligations; the clinic is responsible for its own lawful basis and patient information notices.
- To keep the service secure and prevent misuse — legitimate interests.
- To meet legal and regulatory obligations — legal obligation.
4. Sharing
We do not sell personal data and we do not use it for advertising. Data is shared only with the infrastructure providers needed to run PodiaScan (application hosting, managed database, authentication and email delivery), each bound by a data processing agreement. Data is not shared between clinics: every record is scoped to the clinic that created it and enforced at the database level.
5. Retention
Clinical records are retained for as long as the clinic's account is active or as its own retention schedule requires, and are deleted or returned on request when the clinic leaves the service. Account and security logs are kept for a limited period for audit and troubleshooting purposes.
6. Your rights
Under GDPR you may request access, rectification, erasure, restriction, portability, and object to certain processing. Patients should contact their treating clinic first, as the clinic controls their record. You may also complain to the Irish Data Protection Commission (dataprotection.ie).
7. Security
Access requires authentication, and every query is restricted to the signed-in user's clinic through row-level security. Data is encrypted in transit and at rest by our infrastructure providers. Passwords are stored hashed and checked against known-breached password lists.
8. Changes and contact
We will update this page when our processing changes and revise the "last updated" date. Questions or requests: privacy@podiascan.com.