Privacy policy
How we collect, use, and protect your personal and medical data.
1. Who we are
SickCert is an Irish online service that connects patients with Irish-registered doctors for the assessment and issuance of sick certificates. For the purposes of data protection law, SickCert is the data controller for the personal data described in this policy.
2. What data we collect
Account data: your name, email address, and login credentials.
Application data: your date of birth, contact details, employment context, and the answers you give in the medical questionnaire, including information about your symptoms and medical history.
Clinical data: the reviewing doctor's notes, decisions, and any certificate issued to you.
Payment data: payment amounts, statuses, and transaction references. Card details are processed by our payment provider and are never stored on our servers.
Technical data: log information needed to keep the service secure, including a record of who accessed your records and when.
3. Why we use your data
To provide the service: reviewing your application, making a clinical decision, issuing certificates, and processing payments and refunds.
To meet legal obligations: doctors must keep accurate clinical records, and we must keep financial records for accounting purposes.
To keep the service secure: audit logs let us detect and investigate unauthorised access to medical records.
We do not sell your data, and we do not use your medical information for advertising.
4. Who can see your data
Doctors reviewing your application can see your questionnaire answers and clinical history on SickCert.
Support staff can see application status, payment, and delivery information to help you, but cannot see clinical notes or influence clinical decisions.
Service providers who process data on our behalf (such as our payment processor and hosting provider) are bound by data processing agreements.
Every access to your records is logged and auditable.
5. How long we keep your data
Patient records are retained for 8 years from your last activity on the service, in line with clinical record-keeping practice in Ireland. A record may be held longer where there is a legal or clinical reason to do so.
Financial records are kept for the period required by Irish accounting and tax law.
When a retention period ends, the record is securely deleted or anonymised.
6. Your rights
Under GDPR you have the right to access your data, correct inaccuracies, request erasure (subject to our legal obligation to retain clinical records), restrict or object to processing, and request a copy of your data in a portable format.
To exercise any of these rights, contact us at privacy@sickcert.ie. You also have the right to complain to the Data Protection Commission.
7. Security
We use encryption in transit and at rest, role-based access controls, and comprehensive audit logging. Access to medical data is limited to the people who need it to provide your care.
8. Changes to this policy
If we change this policy, we'll post the updated version here and, for significant changes, notify you by email. The date of the latest version is shown below.
Last updated: October 2026