Privacy & GDPR
Your medical record belongs to you
Built to Irish and EU GDPR standards, with encryption and audit logging on every clinical record.
Who we are
NOVAGP.IE is an Irish online general practice service and is the data controller for the personal and health data you provide through this platform. Queries: admin@novagp.ie.
What we collect
Identity and contact details, your past medical history, current medications and drug allergies, consultation notes and outcomes, prescriptions, certificates and referral letters, uploaded documents and images, and payment records held by our payment processor.
Why we hold it
To provide medical care, to keep the clinical record the law requires of a general practice, to process payments, and to meet our regulatory obligations. We do not sell your data or use it for advertising.
How it is protected
Data is encrypted in transit (TLS) and at rest, with additional application-level encryption on sensitive clinical fields. Access is restricted by role — a GP sees only the patients assigned to them — and every access to a record is logged in an audit trail.
Where it lives
Your data is hosted within the European Union. Where a processor operates outside the EU, transfers are governed by Standard Contractual Clauses.
How long we keep it
Clinical records are retained in line with Irish medical record retention guidance. Payment records are retained as required by Revenue. Data no longer needed for either purpose is deleted.
Your rights
You may request access to, correction of, or deletion of your data, object to processing, or ask for your record to be exported. Most of this is available directly from your patient portal; anything else, email admin@novagp.ie. You may also complain to the Data Protection Commission (dataprotection.ie).
