Legal Document

Privacy Policy

We value your trust and are committed to protecting your privacy. Learn how we collect, use, and safeguard your information.

Effective DateJune 2026
Applies ToAll LumieraMed Services
Sections20 Clauses

At LumieraMed, we value your trust and are committed to protecting your privacy. This Privacy Policy explains how LumieraMed Ltd (company number 16668686, registered in England and Wales) collects, uses, stores, shares and protects your personal information when you visit our website at https://lumieramed.com or engage our placement services. It should be read alongside our Terms and Conditions. We process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Who We Are & What We Collect
01

Who We Are

LumieraMed Ltd is the data controller responsible for your personal data. If you have any questions about this policy or how we handle your information, please contact us at support@lumieramed.com.

02

Information We Collect

We collect personal information in the following categories:

Information you provide to us:

  • Contact details: your name, email address, phone number, and country of residence.
  • Account and application information: login credentials, preferred placement dates, availability, and placement preferences.
  • Professional and academic documents: your CV, academic transcript, letter of good standing or enrolment, personal statement, and proof of language proficiency.
  • Identity and travel documents: passport copy, photographs, and related identification.
  • Health and immunisation records: where required by a Host Hospital or destination country (see Clause 4 regarding special category data).
  • Communications: any details you provide when contacting us by email, through contact or enquiry forms, or through our Client Portal.

Information collected automatically:

  • Technical data: browser type, device type, operating system, IP address, and website usage data collected via cookies and similar technologies (see Clause 7).
  • Usage data: pages visited, time spent on the website, and interaction patterns, collected to help us improve our services.

Information collected via your account and Client Portal:

  • Account registration data: your name, email address, and login credentials created when you register for an account.
  • Portal activity: login timestamps, document uploads, application status interactions, and messages sent through the Portal.
  • Application progress data: records of your placement search progress, correspondence with us, and any notes or updates recorded during the facilitation process.
How & Why We Use Your Data
03

Lawful Basis for Processing

Under the UK GDPR, we are required to have a lawful basis for processing your personal data. We rely on the following:

  • Contract: to process your placement application, communicate with you about your enquiry, collect and submit documents on your behalf, and fulfil our obligations under our Terms and Conditions.
  • Legitimate interests: to improve our website and services, analyse usage trends, maintain the security of our systems, and promote our services, where these interests are not overridden by your rights.
  • Legal obligation: to comply with applicable laws, regulatory requirements, or lawful requests from authorities.
  • Consent: where you have given us specific consent, for example, to use your testimonial or photographs in our marketing materials, or to receive marketing communications from us. You may withdraw consent at any time by contacting us at support@lumieramed.com, although withdrawal does not affect the lawfulness of processing carried out before withdrawal.
04

Special Category Data (Health Information)

Health and immunisation records are classified as special category data under the UK GDPR, which carries additional legal protections. We collect this information solely where it is required by a Host Hospital or destination country as a condition of your Placement.

We process this data on the following additional legal bases:

  • Explicit consent: by providing your health and immunisation records to us, you give your explicit consent to our processing and sharing of that data with the relevant Host Hospital for the purpose of facilitating your Placement.
  • Vital interests: in circumstances where sharing health information is necessary to protect your vital interests or those of others during a Placement.

We will only share health data with Host Hospitals where it is strictly necessary and required by them. You may withdraw consent to the processing of your health data at any time by contacting support@lumieramed.com, although this may affect our ability to arrange your Placement.

05

How We Use Your Information

We use the personal information we collect to:

  • Respond to your enquiries and communicate with you about our services.
  • Create and manage your account and Client Portal access.
  • Process and manage your placement application, including matching you with suitable Host Hospitals, collecting and submitting your documents, and tracking progress through the Client Portal.
  • Share your professional and academic documents (including your CV, transcript, personal statement and supporting documents) with Host Hospitals and relevant third parties solely for the purpose of facilitating your placement.
  • Provide general guidance on related processes such as visa applications (noting that this is not immigration or legal advice).
  • Send you service-related communications, including placement updates, document requests, and confirmations.
  • Send you marketing communications where you have given consent, and manage your communication preferences.
  • Maintain and improve the performance and security of our website and Client Portal.
  • Analyse usage trends and visitor behaviour to improve user experience.
  • Comply with our legal and regulatory obligations.
  • Use your testimonial, name, and photographs in our marketing and on our website and social media channels, where you have given consent.

We only use your information for purposes that are relevant and necessary, and will not use it in a way that is incompatible with the purpose for which it was collected.

06

Data Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, alteration, or disclosure. These measures include:

  • Password-protected access to our Client Portal and internal systems.
  • Secure transmission of data using encryption where appropriate.
  • Limiting access to your personal data to those members of our team who need it to perform their role.
  • Regularly reviewing our data handling practices and security measures.

No method of electronic transmission or storage is completely secure. Whilst we take all reasonable steps to protect your information, we cannot guarantee absolute security. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately at support@lumieramed.com.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) and, where required, you, in accordance with our obligations under the UK GDPR.

Sharing & International Transfers
07

Cookies and Similar Technologies

Our website uses cookies and similar tracking technologies to improve functionality and user experience. Cookies help us understand how visitors interact with our site and allow us to remember preferences for future visits.

You can control or disable cookies through your browser settings. Please note that disabling cookies may affect certain features of the website. For more information about the cookies we use, please refer to any cookie notice displayed on our website.

08

Sharing and Disclosure of Information

We do not sell or rent your personal information. We may share your information in the following circumstances:

Host Hospitals and placement partners:

As a core part of our service, we share your professional, academic and personal documents with Host Hospitals (including partner hospitals in China) for the purpose of assessing and facilitating your placement. This is necessary to perform our contract with you.

Third-party service providers:

We use trusted third-party tools to operate our services (see Clause 9). These providers process data on our behalf and are required to keep it secure and use it only for the purposes we specify.

Legal and regulatory requirements:

We may disclose your information where required to comply with a legal obligation, court order, or lawful request from a regulatory authority, or to protect the rights, safety, or property of LumieraMed or others.

Business transfers:

In the event of a merger, acquisition, or transfer of all or part of our business, your information may be transferred to the relevant third party, subject to equivalent privacy protections.

09

Third-Party Service Providers

We use the following categories of third-party service providers to help us operate our business. Each processes your data only as necessary for the specified purpose and is bound by appropriate data processing obligations:

  • Analytics providers: to help us understand how visitors use our website (e.g. Google Analytics or equivalent). Usage data such as pages visited and session duration may be collected.
  • Email and communication platforms: to send and manage email communications with you.
  • Payment processors: to securely process payment of the Placement Deposit and Hospital Fee. We do not store your full payment card details.
  • Website hosting and infrastructure providers: to host and maintain the LumieraMed website and Client Portal.

We will update this clause as our technology stack develops. If you have questions about a specific provider, please contact us at support@lumieramed.com.

10

International Data Transfers

Because we facilitate placements at hospitals in China, your personal data (including your CV, academic documents, identity documents, and where applicable health records) will be transferred to and processed by recipients located outside the United Kingdom and the European Economic Area. Where we transfer your data outside the UK, we take steps to ensure that appropriate safeguards are in place to protect your information, in accordance with UK GDPR requirements. By engaging our services and providing your information, you acknowledge that your data will be shared with Host Hospitals in China as described in this policy. If you have questions about the safeguards in place, please contact us at support@lumieramed.com.

Accounts, Retention & Children
11

Your Account & Client Portal

When you create an account with LumieraMed, we collect and store the registration information and activity data described in Clause 2. Your Client Portal is used to manage your placement application, upload documents, and communicate with our team.

Account activity logging:

We log account activity including login timestamps and document uploads for security purposes and to maintain an accurate record of your application progress. This data is not shared with third parties except as described in Clause 8.

Account suspension or termination:

We reserve the right to suspend or terminate your account where required under our Terms and Conditions. Upon termination of your engagement with us, we may retain your account data for the period set out in Clause 12, after which it will be securely deleted or anonymised. You will not be able to access the Client Portal after your account has been terminated.

Closing your account:

If you wish to close your account or request deletion of your Portal data, please contact us in writing at support@lumieramed.com. We will process your request in accordance with your rights under Clause 15, subject to any legal obligation we have to retain certain records.

12

Data Retention

We retain your personal information only for as long as is necessary to fulfil the purposes set out in this policy, or as required by law. In practice:

  • Placement application records (including documents, correspondence, and Client Portal data) are retained for a period of up to 6 years following the conclusion of your engagement with us, in line with standard UK limitation periods.
  • Account data is retained for the duration of your engagement and for up to 6 years thereafter, unless you request earlier deletion and we are not legally required to retain it.
  • Marketing consent records are retained until you withdraw consent.
  • Technical and usage data collected via cookies is typically retained for a shorter period in line with the relevant cookie settings.

Once information is no longer needed, we take reasonable steps to securely delete or anonymise it.

13

Children's Privacy

Our website and services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that personal data has been collected from a child without appropriate consent, we will take steps to delete it promptly.

14

Automated Decision-Making and Profiling

We do not make any decisions about you solely by automated means (including profiling) that produce legal or similarly significant effects. All placement matching and eligibility assessments are carried out manually by our team, taking into account the information you provide and the requirements of the relevant Host Hospital.

Your Rights & Communications
15

Your Data Protection Rights

Under UK data protection law, you have the following rights in relation to your personal data:

  • Right of access: you may request a copy of the personal data we hold about you (a Subject Access Request).
  • Right to rectification: you may ask us to correct any inaccurate or incomplete personal data.
  • Right to erasure: you may ask us to delete your personal data in certain circumstances (the "right to be forgotten").
  • Right to restrict processing: you may ask us to limit how we use your data in certain circumstances.
  • Right to data portability: you may ask us to provide your personal data in a structured, commonly used, machine-readable format.
  • Right to object: you may object to processing based on legitimate interests, or to direct marketing.
  • Right to withdraw consent: where processing is based on your consent, you may withdraw it at any time.
  • Right to complain: you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk if you believe we have not handled your data in accordance with the law.

To exercise any of these rights, please contact us in writing at support@lumieramed.com. We will respond within one month. We may need to verify your identity before fulfilling your request.

16

Marketing & Communications Preferences

From time to time, we may send you marketing communications about our services, new placement opportunities, or updates we think may be of interest to you. We will only do this where you have given your consent.

You can opt out of marketing communications at any time by:

  • Clicking the unsubscribe link in any marketing email we send you.
  • Contacting us directly at support@lumieramed.com and requesting to be removed from our mailing list.

Please note that opting out of marketing communications does not affect service-related communications, such as placement updates, document requests, payment confirmations, or other messages necessary to manage your application. These will continue for as long as you are engaged with us.

Updates & Contact
17

Third-Party Websites

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to read the privacy policies of any third-party services you use.

18

Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services or legal requirements. The current version will always be available at https://lumieramed.com/privacy-policy. Where changes are material, we will take reasonable steps to bring them to your attention. Continued use of our website or services after any update constitutes acceptance of the revised policy.

19

Closing Your Account & Requesting Data Deletion

If you wish to close your LumieraMed account or request that we delete your personal data, please follow these steps:

  • Step 1 — Contact us: send a written request to support@lumieramed.com with the subject line "Account Closure / Data Deletion Request". Please include your full name and the email address associated with your account.
  • Step 2 — Identity verification: we may ask you to verify your identity before processing your request, to ensure we do not delete data at the request of an unauthorised person.
  • Step 3 — Processing: we will confirm receipt of your request within 5 working days and aim to complete it within one month. Where we are legally required to retain certain records (for example, for a period of up to 6 years under UK law), we will inform you of this and explain what data we must keep and why.

Closing your account will result in the termination of your Client Portal access. Any active placement engagement will also be terminated, and the refund terms set out in our Terms and Conditions will apply.

20

Contact Us

If you have any questions or concerns about this Privacy Policy, or about how we handle your personal information, please contact us:

If you are not satisfied with our response, you have the right to contact the Information Commissioner's Office (ICO) at www.ico.org.uk or by calling 0303 123 1113.

Have questions about your privacy?

Contact us at support@lumieramed.com or reach the ICO at www.ico.org.uk.

Contact Us →