Privacy Policy
Last updated: 3 August 2026
This Privacy Policy explains how Kinesin Health (“Kinesin”, “we”, “us”) collects, uses and protects your personal data when you use the Kinesin Patient Portal (the “Portal”). We are committed to protecting your privacy and handling your data — including health data — in line with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
1. Who is responsible for your data
Kinesin acts as a data controller (and, for some processing carried out on behalf of your practice, as a data processor). Where your practice determines how your clinical data is used, the practice is the controller for that data. If you have questions, contact our Data Protection Officer using the details in section 11.
2. Personal data we collect
Depending on how you use the Portal, we may collect:
- Account data: your email address and password (stored in hashed form).
- Identity data: first and last name, sex, date of birth and PPS number.
- Contact data: phone number and address (address lines, city, county and Eircode).
- Verification data: the one-time codes used to verify your email address.
- Sign-in data: identifiers from a third-party provider if you sign in with Microsoft or Google.
- Care data: information related to appointments, secure messages, prescriptions, medical records and billing that you access through the Portal.
- Technical data: device, browser and log information, and limited analytics needed to run and secure the service.
3. Health and other special-category data
Some of the data we process (such as medical records, prescriptions and information about your care) is special-category health data. We only process it where we have a lawful basis to do so, such as your explicit consent, the provision of health care, or another basis permitted under Article 9 GDPR.
4. How and why we use your data
We use your personal data to:
- create and manage your account, including email verification and account approval;
- provide the Portal’s features — appointments, messages, prescriptions, records and billing;
- keep the Portal secure, prevent fraud and troubleshoot problems;
- communicate with you about your account and the service; and
- comply with our legal and regulatory obligations.
Our lawful bases include: performance of a contract with you; your consent (which you can withdraw at any time); compliance with a legal obligation; the provision of health care; protection of vital interests; and our legitimate interests in operating and securing the Portal.
5. Account approval
New accounts are reviewed and approved before they can access patient features. This helps us confirm that access is granted to the right person and protect the confidentiality of health data.
6. Who we share your data with
We do not sell your personal data. We may share it with:
- your practice and its clinicians, so they can provide your care;
- service providers (processors) who host and support the Portal, under contracts that protect your data; and
- public authorities or regulators where required by law.
7. International transfers
We aim to store and process your data within the European Economic Area (EEA). Where data is transferred outside the EEA, we put appropriate safeguards in place, such as European Commission standard contractual clauses.
8. How long we keep your data
We keep your personal data only for as long as necessary for the purposes described in this Policy, including to meet legal, regulatory and clinical record-keeping obligations, after which it is securely deleted or anonymised.
9. How we protect your data
We use technical and organisational measures — including encryption in transit, access controls, email verification and two-factor authentication — to protect your data against unauthorised access, loss or misuse.
10. Your rights
Subject to conditions in data-protection law, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to certain processing;
- data portability; and
- withdraw consent at any time, without affecting processing carried out before withdrawal.
To exercise these rights, contact us using the details below. You also have the right to lodge a complaint with the Irish Data Protection Commission at www.dataprotection.ie.
11. Cookies
The Portal uses cookies and similar technologies that are necessary to sign you in, keep your session secure and remember your preferences. Where required, we ask for your consent to non-essential cookies.
12. Children
The Portal is intended for adults. We do not knowingly create accounts for children without appropriate authority and safeguards.
13. Changes to this Policy
We may update this Policy from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, notify you.
14. Contact us
For any privacy question or to contact our Data Protection Officer, email privacy@kinesin.health.