HearMed Acoustic Healthcare
GDPR and Data Protection Policy
Effective date: 4 September 2026
Last updated: 4 September 2026 at 09:09 UTC
HearMed Acoustic Healthcare (“HearMed”, “we”, “us” or “our”) is committed to protecting the privacy, confidentiality and security of the personal information entrusted to us.
This policy explains how HearMed complies with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Data Protection Act 2018 and other applicable Irish data-protection and privacy laws.
This policy should be read alongside our Privacy Notice, which explains in more detail what personal information we collect, why we use it and who we may share it with.
1. Who is responsible for your information?
HearMed Acoustic Healthcare is the data controller for personal information that we collect and use in connection with our healthcare services, websites, appointments, communications and business activities.
Our details are:
HearMed Acoustic Healthcare
Company Registration Number: 742968
HearMed Medical Centre
Patrick Street
Tullamore
Co. Offaly
R35 F2X0
Ireland
Email: getintouch@hearmed.ie
Telephone: 0818 058 058
Website: hearmed.ie
For data-protection matters, you may contact us using the details above.
2. Our data-protection principles
HearMed processes personal information in accordance with the principles set out in GDPR.
We aim to ensure that personal data is:
- processed lawfully, fairly and transparently; - collected for specific, legitimate purposes; - limited to what is necessary for those purposes; - accurate and kept up to date where necessary; - retained only for as long as required; - protected against unauthorised or unlawful processing, loss, destruction or damage; and - handled in a way that allows HearMed to demonstrate compliance with its obligations.
3. The information we process
HearMed provides audiology and hearing healthcare services and therefore processes a range of personal information.
This may include:
- names and contact details; - dates of birth; - addresses and Eircodes; - appointment information; - patient numbers and internal identifiers; - referral information; - communications and correspondence; - payment, invoice and account information; - PRSI, grant or insurance information where applicable; - website enquiry and booking information; - marketing preferences; - website and advertising attribution information; and - information about interactions with our clinics and services.
Because we provide healthcare, we also process special category health information.
This may include:
- audiological case histories; - hearing test results; - audiograms; - medical history relevant to hearing care; - clinical notes; - diagnoses and clinical impressions; - hearing-aid prescriptions and fittings; - hearing-device serial numbers and repair information; - referral information; - reports; - clinical forms; - treatment and follow-up information; - consultation transcripts; and - other information required to provide appropriate hearing healthcare.
Where required for public schemes or benefits, we may also process identifiers such as a PPS number.
4. Our lawful bases for processing
HearMed does not rely on one single lawful basis for every type of processing.
Different activities are carried out under different provisions of GDPR.
Providing healthcare and services
We may process ordinary personal data where it is necessary:
- to provide services you have requested; - to take steps at your request before providing a service; - to perform our contract with you; or - to comply with our legal obligations.
This may include processing under Articles 6(1)(b) and 6(1)(c) GDPR.
Health information
Health information receives additional protection under GDPR.
Where HearMed processes health information for the provision or management of healthcare, we rely on the appropriate condition under Article 9 GDPR, including Article 9(2)(h), together with applicable Irish law, including the Data Protection Act 2018.
Legitimate interests
In some circumstances, we may rely on our legitimate interests under Article 6(1)(f), provided that those interests do not override your rights and interests.
This may include activities necessary to operate, secure and improve our healthcare practice.
Consent
Where the law requires consent, HearMed will obtain it before carrying out the relevant processing.
Consent may be used for matters such as:
- optional direct marketing; - certain website cookies and advertising technologies; - optional consultation recording; - optional AI-supported transcription; or - other processing that is not required for the ordinary provision of healthcare.
Consent can be withdrawn at any time.
Withdrawing consent does not affect processing that has already taken place lawfully and does not affect information that HearMed must retain under another lawful basis.
5. Clinical care is not dependent on marketing consent
HearMed does not require patients to agree to marketing in order to receive healthcare.
Consent for marketing, cookies, advertising, consultation recording and other optional processing is treated separately from the processing necessary to provide clinical care.
Patients may refuse or withdraw optional consent without affecting their ability to access HearMed's normal healthcare services.
6. Our use of Clinear
HearMed uses Clinear, a clinic-management and electronic health-record platform, to manage many of our clinical and administrative activities.
This includes areas such as:
- patient records; - appointments; - clinical notes; - audiology information; - hearing-aid records; - documents; - communications; - invoices; - reports; and - other clinic-management functions.
For HearMed's patient information, HearMed remains the data controller.
Clinear Limited acts as a data processor and processes HearMed information on our instructions under a written data-processing agreement.
Clinear may use approved subprocessors to provide infrastructure, hosting, communications, storage and other technical services.
Clinear is required to control those subprocessors in accordance with GDPR and its agreement with HearMed.
7. Data processors
HearMed uses carefully selected organisations to provide services that may involve personal data.
Depending on the service, these may include providers of:
- clinical software; - cloud hosting; - secure data storage; - email services; - telecommunications; - SMS; - website hosting; - website forms; - IT support; - accounting; - payroll; - marketing technology; and - other business services.
Where an organisation processes personal information only on HearMed's instructions, we require appropriate contractual protections in accordance with Article 28 GDPR.
These contracts require processors to protect personal information, restrict how it is used, maintain confidentiality and assist HearMed with its GDPR obligations.
8. Other healthcare providers and organisations
Some organisations that receive information from HearMed are not processors.
They may act as independent data controllers because they have their own legal or professional reasons for using information.
These may include:
- GPs; - hospitals; - other healthcare professionals; - insurers; - government departments; - the Department of Social Protection; - hearing-aid manufacturers; - laboratories; - payment providers; - professional advisers; - regulatory bodies; - courts; and - law-enforcement authorities.
Where information is shared, HearMed aims to provide only what is necessary for the relevant purpose.
9. Hearing-aid manufacturers and laboratories
Where we order, fit, repair or service hearing aids or related products, it may be necessary to provide information to the relevant manufacturer, supplier or laboratory.
We apply data-minimisation principles and provide only the information reasonably needed for the order, fitting, manufacture, repair or warranty process.
10. PRSI, grants, schemes and insurers
Where a patient asks HearMed to process a PRSI benefit, grant, insurance claim or other scheme entitlement, we may process and share the information necessary to verify eligibility and administer the claim.
The relevant public body, insurer or scheme administrator may process that information under its own legal responsibilities.
11. Website enquiries
HearMed operates websites including hearmed.ie and hearmed.app.
Our website forms and advertising pages are intended to collect enough information to:
- respond to enquiries; - arrange a callback; - facilitate a booking; - identify the clinic or service requested; and - understand how people find our services.
Our general website forms are not intended to be used to submit detailed medical history or other sensitive clinical information.
Once a person becomes a patient, relevant clinical information should be recorded in the approved HearMed clinical system rather than stored unnecessarily in website systems.
12. Cookies and tracking technologies
HearMed uses cookies and similar technologies on its websites.
Some are necessary for the website to function properly.
Other technologies may be used for:
- analytics; - advertising; - campaign attribution; - conversion measurement; and - understanding how people use our websites.
Non-essential cookies and advertising technologies will be used only where the required consent has been obtained.
Users can reject optional cookies and can change or withdraw their choices.
Where advertising attribution is used, it may include information such as campaign parameters and advertising click identifiers.
HearMed does not consider advertising tracking to be “strictly necessary” simply because it is commercially useful.
13. Google Ads and advertising data
HearMed uses Google Ads to advertise our services.
We may use website-level advertising measurement to understand whether advertising generates enquiries or bookings.
HearMed does not intentionally send medical records, clinical notes, audiograms, diagnoses or other detailed health information to Google Ads.
We will not use customer-data or patient-level conversion functionality where doing so would breach data-protection law, applicable advertising-platform rules or the person's privacy choices.
Where optional advertising measurement requires consent, that measurement will remain disabled until valid consent has been obtained.
14. Telephone communications
HearMed uses telephone systems to communicate with patients and prospective patients.
Telephone systems may process information such as:
- caller numbers; - call times; - call duration; - missed-call information; - staff extension information; and - call outcomes.
Telephone systems are not intended to replace the clinical patient record.
Where information discussed during a call is clinically relevant, the appropriate information should be recorded in HearMed's clinical system.
HearMed will not introduce routine clinical call recording without first ensuring that the appropriate legal, contractual, transparency and security requirements are satisfied.
15. SMS, email and WhatsApp
HearMed may communicate with patients by SMS, email, telephone and approved messaging services.
These channels may be used for:
- appointment confirmations; - appointment reminders; - service communications; - recalls; - follow-up; - enquiries; and - marketing where permitted.
We aim to minimise sensitive information contained in ordinary SMS or other short messages.
Detailed clinical information should be communicated through an appropriate secure method where necessary.
Patients should avoid sending unnecessary sensitive clinical information through social-media or general messaging platforms.
16. Direct marketing
HearMed may send information about services, offers, events or other relevant healthcare services where permitted by law.
Where consent is required, we will obtain it.
Every person has the right to object to direct marketing at any time.
Marketing preferences can be changed by:
- using an unsubscribe option where provided; - contacting the clinic; or - emailing getintouch@hearmed.ie.
Opting out of marketing does not prevent HearMed from sending necessary service communications such as appointment reminders or important information relating to your care.
17. AI-assisted clinical documentation
HearMed may use approved AI-assisted tools to help clinicians prepare or organise clinical documentation.
Where raw consultation audio is recorded or transmitted for transcription, the required explicit consent will be obtained before recording begins.
Patients do not need to agree to consultation recording or optional AI transcription in order to receive ordinary HearMed clinical care.
AI tools are intended to assist the clinician.
They do not replace clinical judgement.
Information generated by AI should be reviewed by an authorised clinician before it becomes part of the patient's final clinical record.
HearMed does not permit patient clinical information to be used for general-purpose AI model training unless this has been specifically assessed, approved and lawfully implemented.
18. Data minimisation
HearMed aims to collect only the information that is reasonably necessary.
We regularly review forms, systems and workflows so that unnecessary information is not requested or retained.
Our staff are encouraged to avoid placing sensitive information in systems that do not need it.
19. Access to information
Access to HearMed systems and patient information is limited according to role and legitimate need.
Measures may include:
- individual user accounts; - role-based permissions; - clinic-level restrictions; - password controls; - multi-factor authentication; - access logging; - session security; and - administrative restrictions.
Staff should only access patient information where they have a genuine work-related reason to do so.
20. Confidentiality
HearMed staff and authorised users are required to maintain confidentiality.
Patient information must not be disclosed to unauthorised persons.
Information should not be discussed in public areas where it can be overheard.
Devices, screens, files and documents containing personal information must be handled securely.
Personal accounts and personal devices should not be used to store patient information unless specifically authorised and appropriately secured.
21. Information security
HearMed takes appropriate technical and organisational measures to protect personal data.
Depending on the system and type of information, these measures may include:
- encryption; - role-based access; - access logging; - secure cloud hosting; - multi-factor authentication; - encrypted communications; - secure backups; - staff training; - processor due diligence; - data minimisation; - breach-response procedures; and - secure deletion.
While no internet-connected system can be guaranteed to eliminate every risk, HearMed reviews its security arrangements and the organisations that process data on its behalf.
22. International transfers
HearMed aims to keep health and clinical information within the European Economic Area where reasonably possible.
Some providers or their subprocessors may nevertheless be based outside the EEA or may access systems from other countries.
Where personal data is transferred outside the EEA and an adequacy decision does not apply, HearMed or the relevant processor will use an appropriate transfer mechanism.
This may include:
- European Commission Standard Contractual Clauses; - transfer-impact assessments; - supplementary security measures; or - another lawful GDPR transfer mechanism.
23. How long information is retained
HearMed keeps personal information only for as long as there is a legitimate or legal reason to retain it.
Different categories of data have different retention periods.
Clinical records may need to be retained for extended periods because of healthcare, professional, legal, insurance or limitation requirements.
Financial and accounting information is retained for periods required by law.
Website lead and advertising-site information that has not become part of the patient record is generally intended to be retained only for a shorter period.
Information stored specifically on hearmed.app is ordinarily scheduled for deletion after approximately 90 days, unless there is another lawful reason to retain it.
Consultation audio used solely to produce an approved transcript or clinical document should be deleted once its approved purpose has been completed, subject to the applicable HearMed retention procedure.
24. Your GDPR rights
Depending on the circumstances, you may have the right to:
- access your personal data; - obtain a copy of your personal data; - correct inaccurate information; - request completion of incomplete information; - request erasure; - request restriction of processing; - object to processing; - receive certain personal data in a portable format; - withdraw consent; - object to direct marketing; and - complain to the Data Protection Commission.
These rights are subject to the conditions and exceptions contained in GDPR and Irish law.
25. Access requests
You may ask HearMed for access to the personal data that we hold about you.
We may need to verify your identity before releasing information.
HearMed will normally respond without undue delay and within one month of receiving a valid request.
Where GDPR allows additional time because a request is particularly complex or numerous, we will inform you within the original one-month period.
26. Erasure
The right to erasure is not absolute.
Some information can be deleted when it is no longer required.
However, HearMed may need to retain information where there is a legal, clinical, professional or other lawful reason to do so.
For example, we may not be able to erase parts of a clinical record where retaining the record remains necessary for healthcare, legal obligations or the establishment, exercise or defence of legal claims.
Where information can lawfully be deleted, HearMed will take reasonable steps to remove it from relevant systems.
27. Rectification
If you believe that information HearMed holds about you is incorrect, you can ask us to correct it.
Clinical records sometimes need to preserve the historic entry together with a correction rather than simply deleting or overwriting the original record.
This helps maintain an accurate clinical audit trail.
28. Restriction and objection
You may have the right to ask HearMed to restrict certain processing or to object to processing carried out under particular lawful bases.
We will consider the circumstances and explain our decision.
You have an unconditional right to object to processing for direct-marketing purposes.
29. Data portability
Where the requirements of GDPR are met, you may have the right to receive certain information in a structured, commonly used and machine-readable format or request that it is transferred to another provider where technically feasible.
This right does not apply to every category of information held by HearMed.
30. Withdrawing consent
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawal does not affect processing that occurred before the withdrawal.
It also does not require HearMed to delete information that must lawfully be retained for another reason.
31. Personal data breaches
HearMed maintains procedures for identifying, containing, investigating and documenting personal data breaches.
A personal data breach can include:
- loss of information; - unauthorised access; - accidental disclosure; - sending information to the wrong person; - compromised accounts; - stolen devices; - malicious access; - inappropriate system access; or - accidental destruction of information.
Where a breach is likely to result in a risk to individuals, HearMed will notify the Data Protection Commission in accordance with GDPR.
Where feasible, this notification will be made within 72 hours of HearMed becoming aware of the breach.
Where a breach is likely to result in a high risk to affected individuals, HearMed will also inform those individuals where required.
32. Data Protection Impact Assessments
HearMed assesses privacy risks when introducing processing that may create a high risk to individuals.
A Data Protection Impact Assessment (“DPIA”) may be carried out where appropriate, including for significant processing involving:
- large volumes of health data; - new technologies; - AI; - consultation recording; - significant data matching; - new advertising technologies; - major changes to clinical systems; or - other high-risk processing.
Our use of Clinear and its clinical-data architecture forms part of HearMed's wider data-protection risk assessment.
33. Children and people requiring assistance
HearMed provides services to children and to adults who may require help with communication or decision-making.
Where appropriate, we may interact with parents, guardians, carers or authorised representatives.
We will take reasonable steps to confirm the person's authority where necessary.
The patient's privacy rights and interests remain important regardless of who assists them.
34. Automated decision-making
HearMed does not intend to make clinical decisions about patients solely through automated processing where those decisions would have legal or similarly significant effects.
Technology, algorithms and AI may assist clinicians and staff, but human review remains part of significant clinical decision-making.
35. Changes to our systems and processors
HearMed reviews the privacy implications of new systems, integrations and service providers before using them for personal information.
Where appropriate, this includes reviewing:
- the provider's legal role; - data-processing terms; - security; - subprocessors; - processing location; - international transfers; - retention; - deletion arrangements; and - the types of personal data involved.
We may update this policy where our technology, providers or processing activities materially change.
36. Complaints
If you have concerns about how HearMed has handled your personal information, please contact us first so that we can investigate the matter.
You also have the right to complain to the Irish Data Protection Commission.
Data Protection Commission
6 Pembroke Row
Dublin 2
D02 X963
Ireland
Website: dataprotection.ie
37. Contact HearMed
For GDPR queries or to exercise your rights, contact:
HearMed Acoustic Healthcare
HearMed Medical Centre
Patrick Street
Tullamore
Co. Offaly
R35 F2X0
Ireland
Email: getintouch@hearmed.ie
Telephone: 0818 058 058
Please include “Data Protection” in the subject line of written requests where possible.
38. Updates to this policy
We may update this GDPR & Data Protection Policy from time to time to reflect changes in our services, technology, legal obligations or data-processing activities.
The most recent version will be published on our website.
Created: 4 September 2026 at 09:09 UTC
