Ultrasound IrelandMedical & Maternity Ultrasound Centers
Legal

Privacy Policy

This policy explains how we collect, use, share and protect your personal and health information, whether you are a patient at one of our clinics or a visitor to our website.

Effective Date: 7 September 2026

Introduction

Ultrasound Dimensions Ltd, trading as Ultrasound Ireland ("we", "us"), provides diagnostic and pregnancy ultrasound services at our clinics in Dublin. We are the data controller for the personal information we hold about you. This policy applies to patients, to people who book or enquire on behalf of a patient, and to visitors to our website.

Because we provide healthcare, much of the information we hold about you is health data, which is a special category of personal data under the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. This policy explains what we hold, why, who we share it with, how long we keep it, and your rights.

Data Controller:

Ultrasound Dimensions Ltd
21 Main St, Blackrock
Co. Dublin, Ireland

Data Protection Officer:

Kyle Bolton, hello@ultrasound.ie

Information We Collect

When you book or attend a scan

When you book an appointment, complete our online intake form, or attend a scan, we collect:

  • Your name, date of birth, address and Eircode, phone number and email address
  • Details of your referring doctor or GP, and any referral letter they provided
  • For pregnancy scans, your maternity hospital and pregnancy details
  • Your medical history and the reason for your scan, as given on your intake form or at your appointment
  • The consents and acknowledgements you give on your intake form, including your signature
  • The ultrasound images, measurements and recordings taken during your scan
  • The report written by our sonographer or reporting doctor, and any clinical notes
  • For children, the name and signature of the parent or legal guardian who consents on their behalf
  • Invoice and payment records. Card payments are processed by our payment provider and we do not store full card numbers.

When you use our website or contact us

  • Your name, email address, phone number and the content of any message you send us
  • Technical information such as your IP address and browser type, collected automatically
  • Cookie data as described in our Cookie Policy

Our online intake forms are hosted by our practice management provider, not on this website. Health information you enter on an intake form goes directly into your patient record.

How We Use Your Information

We use your information to:

  • Perform your scan safely and write your report
  • Send your report to your referring doctor and, where you have asked for it, to you
  • Share your images and report with other healthcare professionals involved in your care
  • Create and maintain the medical record we are required by law and professional standards to keep
  • Schedule and manage your appointments, and send appointment confirmations and reminders
  • Take payment and issue receipts, including receipts you may use for an insurance claim
  • Respond to your enquiries
  • Carry out clinical audit and quality assurance of our scanning and reporting
  • Improve our website and services, and monitor how the website is used
  • Comply with our legal and regulatory obligations

We do not use your health information for marketing, and we do not sell your information to anyone.

Legal Basis for Processing

Data protection law requires us to have a legal basis for each use of your information. For health data we also need a further condition under Article 9 of the GDPR. The bases we rely on are:

  • Providing your care. Performing your scan, writing your report, sending it to your referring doctor and sharing it with other healthcare professionals treating you is necessary for medical diagnosis and the provision of healthcare (Article 9(2)(h)), carried out under the responsibility of professionals bound by a duty of confidentiality. It is also necessary to perform our contract with you (Article 6(1)(b)).
  • Keeping medical records. We are required to keep a record of your care for set periods. This is a legal obligation (Article 6(1)(c)) together with Article 9(2)(h).
  • Health insurance claims. If your insurer needs information from us to process a claim you have made, we share it on the basis of your explicit consent (Article 9(2)(a)), which you normally give to your insurer on the claim form.
  • Running our clinic and website. Appointment reminders, payment, audit, security and website analytics rely on our legitimate interests (Article 6(1)(f)) in running a safe and efficient service, or on your consent for non-essential cookies.
  • Legal requirements. Where we must disclose information to a court, regulator or public health body, we rely on a legal obligation (Article 6(1)(c)) and, for health data, the relevant public interest or legal claims conditions in Article 9.

We do not rely on your consent as the legal basis for providing your care. This means we do not need to ask you to consent to your care each time, and it means you cannot withdraw from record keeping that the law requires. Your rights, described below, still apply.

Who We Share Your Information With

Healthcare professionals involved in your care

Your report is sent to your referring doctor or GP as a normal part of your care. If another healthcare provider treating you asks us for your images or report, for example a maternity hospital, an emergency department, a consultant or a fertility clinic, we will provide them. This is how care is shared between providers, and it means you do not have to collect and carry your own images between appointments.

Before we share, we:

  • Check that the request comes from a healthcare provider that is treating you, through an official hospital or clinic channel
  • Confirm that the details in the request match your record
  • Send the images and report by a secure route, not by ordinary email attachment
  • Keep a record of what was shared, with whom, and when

If you do not want us to share your images or report with other providers without checking with you first, email us at hello@ultrasound.ie and we will note this on your record.

Health insurers

You normally submit an insurance claim yourself using the receipt we give you. We only share information with your insurer in connection with a claim you have made, and only the information the insurer needs to process that claim. We do not share your images or medical history with an insurer for any other reason.

Service providers who work for us

We use specialist companies to host and run our systems. They process your information only on our instructions and under a written contract, and cannot use it for their own purposes. They include:

  • Our practice management and intake form provider, which holds your patient record
  • Our medical imaging archive, which stores your ultrasound images and reports and is hosted in the European Union
  • Email, SMS and secure link providers used to send confirmations, reminders and reports
  • Our payment processor
  • Website hosting, analytics and support providers

Legal and safety

We may disclose information where the law requires it, for example to a court, the Data Protection Commission, a health regulator, or a public health authority, or where it is necessary to protect someone's life or safety.

Where Your Information Is Stored

Your ultrasound images and reports are stored in the European Union. Our practice management provider, which holds your patient record and intake forms, stores data in Australia. Australia is outside the European Economic Area, so this transfer is protected by the European Commission's Standard Contractual Clauses and the provider's data processing agreement with us. Some of our website and email providers may also process data outside the EEA under the same kind of safeguards. You can ask us for details of these safeguards at any time.

How Long We Keep Your Information

We keep medical records for the periods set out in Irish healthcare record retention standards. In summary:

  • Adult medical scans, including images and reports: 8 years after your last attendance
  • Pregnancy and maternity scans: 25 years after the birth
  • Children’s scans: until the child’s 25th birthday, or 26th birthday if the child was 17 at their last attendance
  • Invoices and payment records: 7 years, as required by Revenue
  • Website enquiries and contact form messages: up to 2 years

When a retention period ends, records are securely deleted or destroyed.

Your Rights

Under GDPR and Irish data protection law, you have the following rights:

Right of Access

Request a copy of your personal data, including your images and report. There is no charge for a first copy.

Right to Rectification

Ask us to correct inaccurate personal details such as your name, address or date of birth

Right to Erasure

Ask us to delete your data. This does not apply to medical records we are legally required to keep for the periods above.

Right to Object

Object to processing based on our legitimate interests, such as appointment reminders or analytics

Right to Restriction

Ask us to limit how we use your data while a query about it is resolved

Right to Data Portability

Receive the data you gave us in a machine-readable format, or have it sent to another provider

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent, such as an insurance claim or non-essential cookies

To exercise any of these rights, contact us at hello@ultrasound.ie. We will respond within one month. You also have the right to lodge a complaint with the Data Protection Commission at dataprotection.ie.

Cookies

Our website uses cookies to enhance your browsing experience. Cookies are small text files stored on your device that help us understand how you use our site.

For detailed information about the cookies we use and how to manage them, please see our Cookie Policy.

Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit and at rest
  • Secure access controls and authentication, with access limited to staff who need it for your care
  • Encrypted, off-site backups of your images and records
  • Regular security assessments
  • Staff training on data protection and confidentiality
  • A record of every disclosure of images or reports to another provider

In the event of a data breach, we will notify affected individuals and the Data Protection Commission as required by law.

Children

We provide scans for children and young people. A parent or legal guardian completes the intake form and gives consent on the child's behalf, and their name and signature are kept with the child's record. A child's images and report may be shared with the child's GP, paediatrician or hospital in the same way as an adult's.

Our website is not intended for use by children under 16. We do not knowingly collect personal information from children through the website. If you believe we have, please contact us.

Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. Where a change affects how we use patient information, we will also update the data protection notice on our intake forms.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Ultrasound Dimensions Ltd

21 Main St, Blackrock
Co. Dublin, Ireland

Email: hello@ultrasound.ie

Phone: 01 210 0232