Your privacy is not a legal footnote — it is our promise

Doctiplus is a healthcare platform. We understand that the information you share with us — about your health, your doctors, your appointments — is deeply personal. This policy explains exactly what we collect, why we collect it, what we never do with it, and how you stay in control.

Who We Are

Doctiplus is a global online doctor directory and healthcare platform operated at docti-plus.com. We connect patients with verified, licensed doctors across 130+ countries through our website and mobile applications. For the purposes of this Privacy Policy, “Doctiplus”, “we”, “us”, and “our” refer to the operators of docti-plus.com.

Doctiplus is an independent platform. We are not affiliated with, and are not responsible for, any other website or platform operating under a similar name, including doctiplus.co, doctiplus.net, doctiplus.com, or doctipluss.com. This Privacy Policy applies exclusively to docti-plus.com and the official Doctiplus mobile applications.

Data controller contact

For all privacy-related enquiries, email us at editorial.doctiplus@gmail.com We respond to all privacy requests within 30 days.

What data we collect — and why

We only collect data that is genuinely necessary to provide the Doctiplus service. We do not collect data speculatively or “just in case”. Here is every category of data we collect, and the specific reason we collect it:

Account information

When you create a free Doctiplus account: your name, email address, and password (stored encrypted). Optional: phone number for appointment reminders.

Why: to identify your account, send confirmations and reminders, and give you access to your booking history.
 

Booking information

When you book an appointment: the doctor selected, appointment type (in-person or telehealth), date and time, and optional reason for visit you provide.

Why: to confirm your booking, send you reminders, and allow you to manage or reschedule appointments.

Search queries

Specialty, condition, location, and filter preferences you enter into the Doctiplus search bar.

Why: to return relevant search results. We do not build advertising profiles from your health searches.

Reviews you submit

IP address, browser type, device type, operating system, and pages visited on doctiplus.com. Collected automatically when you use the platform.

Why: to ensure the platform works correctly on your device and to diagnose technical issues. Not used for individual profiling.

Device and technical data

Star rating and written review text submitted after a confirmed appointment. Linked to your account and the specific booking record.

Why: to display verified patient reviews on doctor profiles and maintain our review integrity standards.

Contact form messages

Name, email address, and message content submitted through our contact forms.

Why: to respond to your enquiry. Messages are stored for up to 12 months and then deleted unless an ongoing relationship exists

How we use your data

We use your data only for the purposes listed below. We do not use your data in ways you would not reasonably expect from a healthcare directory platform.

  1. To create and manage your Doctiplus patient account.
  2. To process and confirm your appointment bookings and send reminders.
  3. To display relevant doctor search results based on your filters and location.
  4. To enable and facilitate telehealth video consultations through our platform.
  5. To allow you to submit verified patient reviews after confirmed appointments.
  6. To respond to enquiries submitted through our contact forms.
  7. To maintain and improve platform security, performance, and functionality.
  8. To send you service-related emails (booking confirmations, reminders, account security alerts) — these are not marketing emails and cannot be unsubscribed from while your account is active.
  9. To send you optional newsletter and health content emails if you have subscribed — you can unsubscribe at any time with one click.
  10. To comply with our legal obligations under applicable data protection law
 

What we never do with your data

These are absolute commitments — not aspirational guidelines. They apply regardless of any commercial pressure or third-party requests:

  1. We never sell your personal data to any third party — advertiser, data broker, pharmaceutical company, or anyone else.
  2. We never use your health search queries to build advertising profiles or target you with advertisements.
  3. We never share your booking details or consultation notes with any party other than the specific doctor or clinic you have booked.
  4. We never allow pharmaceutical companies, insurance companies, or hospital groups to access your individual patient data.
  5. We never use your data to make automated decisions that have significant effects on you without human review.
  6. We never retain your data longer than necessary — see our retention periods in Section 7
 
 
 
 
 

Cookies and tracking

Doctiplus uses a small number of cookies — small text files stored on your device — to make the platform work properly and improve your experience. We do not use advertising cookies or sell cookie data.

Essential cookies:

Required for the platform to function. Includes session cookies that keep you logged in and security cookies that protect against fraud. Cannot be disabled.

Analytics cookies:

We use Google Analytics to understand how patients use Doctiplus — which pages are most visited, how searches are performed. All data is anonymised before processing. You can opt out.

 
Preference cookies:

Remember your language preference, search filter settings, and other choices so you do not have to set them every visit. Optional but improve your experience.

 

You can manage cookie preferences through the Doctiplus cookie banner shown on your first visit, or through your browser settings at any time. Disabling essential cookies will prevent you from logging in or booking appointments.

Data sharing — Who We Share Your Data With

We share your data with third parties only in the following limited and specific circumstances:

  1. Your booked doctor or clinic — when you book an appointment, we share your name, contact information, appointment type, and optional reason for visit with the doctor or clinic you have selected. This is necessary to fulfill your booking.
  2. Payment processors — if a consultation involves a fee, payment is processed by a secure third-party payment provider. Doctiplus does not store your card details. The payment processor’s own privacy policy applies to payment data.
  3. Video consultation technology providers — for telehealth sessions, we use an encrypted video platform. Your name and meeting details are shared only with the video provider to generate your secure meeting link. No consultation content is recorded without your explicit consent.
  4. Legal obligations — we may be required to share data with law enforcement or regulatory authorities if compelled by law. We will notify you where legally permitted to do so.
  5. Service providers — we use a small number of trusted technical service providers (hosting, email delivery, analytics) who process data on our behalf under strict data processing agreements. They may only use your data to provide services to Doctiplus and are prohibited from using it for their own purposes.

Data security and retention

Docti-Plus takes the security of your personal and health-related data seriously. We apply the following technical and organisational measures:

  1. All data transmitted between your device and Docti-Plus is encrypted using TLS (Transport Layer Security) — the same technology used by banks.
  2. All stored data is encrypted at rest using AES-256 encryption.
  3. Passwords are stored using one-way cryptographic hashing — we cannot see your password.
  4. Access to patient data within Docti-Plus is restricted on a strict need-to-know basis
  5. We conduct regular security reviews and apply security patches promptly.
 

Data retention periods

Active Patient Accounts

Retained until you delete your account

Booking Records

Retained for 3 years after the appointment date

Contact Form Messages

Retained for 3 years after the appointment date

Analytics Data

Anonymised and retained for 24 months

Deleted Accounts

All personal data deleted within 30 days of account deletion request

Legal Compliance Records

Retained for the period required by applicable law

Your rights

Under GDPR and applicable data protection laws, you have the following rights regarding your personal data. To exercise any of these rights, contact us at editorial.doctiplus@gmail.com

We will respond within 30 days.

Right of Access

Request a copy of all personal data we hold about you.

Right to Rectification

Ask us to correct any inaccurate data we hold about you.

Right to Erasure

Request deletion of your personal data. We will delete all data within 30 days, subject to legal retention obligations.

Right to Portability

Receive a copy of your data in a commonly used, machine-readable format (CSV or JSON).

Right to Restrict Processing

Ask us to limit how we use your data while you dispute its accuracy or our right to process it.

Right to Object

Object to processing of your data for specific purposes including marketing communications.

Children's privacy

Docti-Plus does not knowingly collect personal data from children under the age of 13. Our platform is intended for use by adults and by parents or legal guardians acting on behalf of children seeking medical care. If you are a parent or guardian booking an appointment for a child, you are responsible for ensuring the information provided is accurate and appropriate.

If we become aware that we have collected personal data from a child under 13 without verifiable parental consent, we will delete that data immediately. If you believe we may hold data from a child under 13, please contact us at 

Contact us and complaints

If you have any questions about this Privacy Policy, how we handle your data, or wish to exercise any of your rights — contact our privacy team directly.

 

Privacy Enquiries

Response Time

Within 2-3 days

Complaints

You may also complain to your national data protection authority