Privacy Policy
Last updated: 2026-06-08
Effective date: 2026-01-01. Updated date: 2026-06-08. This Privacy Policy is issued by Yihe Jinrun International Limited (Simplified Chinese name: 颐和金润国际健康咨询有限公司; Traditional Chinese name: 頤和金潤國際有限公司), company registration number 79265162-000-11-25-9. Our registered address is FLAT/RM B32 11/F, WONG KING INDUSTRIAL BUILDING, NO.2 TAI YAU STREET, KL.
MedToChina provides international medical intermediary, coordination, and concierge services. We understand the importance of personal information, especially medical and health information, and we are committed to protecting your privacy and information security. This Privacy Policy explains how we collect, use, store, share, disclose, and protect your personal information, and what rights you may have.
1. Applicable Laws and Jurisdiction
If you are a resident of mainland China, or if your personal information is collected or processed in mainland China, this policy is interpreted primarily according to the Personal Information Protection Law of the People's Republic of China and related laws and regulations.
If you are a resident of the Hong Kong Special Administrative Region, or if your personal data is collected or processed in Hong Kong, this policy is interpreted primarily according to the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong and related guidance.
If there is a conflict between applicable privacy laws, we aim to apply the rule that provides the stronger protection for your personal information where reasonably required by law. Disputes should first be resolved through friendly negotiation. Depending on the circumstances, you may also contact the relevant mainland China regulator, the Office of the Privacy Commissioner for Personal Data in Hong Kong, or another competent authority.
2. Information We Collect
2.1 Information You Provide
- Basic personal information, such as name, gender, age, date of birth, nationality, passport number, identity document number, phone number, email address, residential address, and emergency contact information.
- Medical and health information, such as symptoms, current illness, past medical history, examination reports, imaging reports, pathology reports, diagnosis certificates, medical records, medication history, treatment plans, allergies, surgery history, and family history.
- Service-related information, such as treatment goals, preferred appointment or travel time, accommodation needs, meal needs, transport needs, language support needs, service comments, and feedback.
- Payment information, such as payment records, invoice information, and bank account information where applicable.
2.2 Information Generated During Services
We may collect service records, communication records, visit accompaniment records, medical translation records, service logs, and other records generated while providing services. These records may contain medical or health information.
2.3 Information From Third Parties
With your explicit authorization or where permitted by law, we may obtain information from hospitals, clinics, examination centers, insurers, translation providers, local support providers, or other service providers involved in your case.
3. How We Use Information
We use personal information for the following purposes:
- Medical service arrangement, including hospital appointments, doctor visit arrangements, examination coordination, surgery schedule coordination, medical report transfer, and report explanation coordination.
- Identity verification and service security.
- Service delivery and improvement, including translation and companion support, accommodation and transport coordination, itinerary planning, customer support, complaint handling, and service quality improvement.
- Medical communication support, including doctor-patient communication translation, medical instruction communication, and report explanation support.
- Legal compliance, regulatory cooperation, fraud prevention, and protection of lawful rights.
- Statistical analysis after irreversible anonymization, where the information can no longer identify you.
4. Sensitive Personal Information
Passport numbers, identity document numbers, medical and health information, payment information, bank account information, and similar information may be treated as sensitive personal information under applicable law. For sensitive personal information, we will explain the purpose, method, and scope of processing and seek your separate consent where required. We limit processing to the minimum scope necessary to provide the service or comply with law.
5. Information Sharing and Disclosure
We do not sell, rent, or trade your personal information to unrelated third parties. We may share information only in the following situations:
- Medical service necessity, such as providing your medical records, examination reports, and relevant case information to hospitals, physicians, departments, or examination institutions that directly support your care.
- Service delivery necessity, such as sharing necessary information with translation agencies, local companion providers, hotels, airlines, transport providers, or other service providers after authorization.
- Legal requirement, such as disclosure required by law, regulation, court, arbitration institution, government authority, or law enforcement authority.
- Your separate explicit consent for any sharing outside the situations described above.
Where we share information with service providers, we require confidentiality or data processing obligations, use limitation, appropriate security measures, and deletion or irreversible anonymization after the service purpose is completed where required by law and practical for the service relationship.
6. Storage Period and Location
We retain personal information only for the minimum period necessary for the purposes described in this policy, unless a longer period is required for legal, financial, tax, audit, medical, dispute handling, or compliance reasons.
- Client profile information: generally retained for 5 years after service completion.
- Medical records and health-related service materials: generally retained for up to 10 years after service completion where needed for service continuity, dispute handling, or medical industry practice.
- Service records: generally retained for 3 years after service completion.
Personal information may be stored or processed in mainland China, Hong Kong, the United States, or other locations where our website infrastructure, cloud service providers, hospitals, support providers, or business systems operate. Our website infrastructure may use cloud hosting outside mainland China. Where cross-border transfer is necessary, we will explain the purpose, recipient, destination, and transfer arrangement where required by law, obtain separate consent where required, and adopt appropriate safeguards such as contractual commitments, encryption, access control, or other lawful transfer mechanisms.
7. Security Measures
We use reasonable technical, organizational, and physical measures to protect personal information, including:
- Encrypted transmission such as SSL/TLS where technically applicable.
- Encryption or restricted access for sensitive records where appropriate.
- Access controls, identity verification, security logging, and monitoring.
- Staff confidentiality training, information classification, and permission management.
- Security incident response procedures and periodic security review.
- Office area security, document storage security, and device management.
No internet transmission or storage method is completely secure. If a data incident occurs, we will take reasonable remedial measures and provide notice where required by applicable law.
8. Your Rights
Subject to applicable law, you may have the right to:
- Access personal information we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion in legally permitted situations.
- Object to processing that is not necessary for core service delivery, such as certain statistical analysis.
- Request portability of information you provided where technically feasible and legally required.
- Withdraw specific consent previously given.
- Request account cancellation where applicable.
We normally respond to lawful rights requests within 15 business days after receiving a valid request and completing identity verification. We generally provide rights request handling free of charge unless a request is manifestly unreasonable, excessive, repetitive, or otherwise chargeable under applicable law.
9. Minors
We attach special importance to the protection of minors. If you are under 18, you should read this policy with a parent or guardian and use our services only with explicit guardian consent. We collect minors' information only where permitted by law, with guardian consent where required, and where necessary for service delivery or protection of the minor.
10. Cookies and Analytics
We may use cookies, similar technologies, server logs, and privacy-conscious analytics tools to maintain website functions, understand how visitors use the website, measure marketing performance, improve forms, and protect security. We do not intentionally send medical details, diagnostic information, or direct contact details to analytics providers.
11. Policy Changes
We may update this policy from time to time. For material changes, we may provide notice through website announcement, email, SMS, or other appropriate methods. The updated policy takes effect when published unless the notice states otherwise.
12. Information Collection Summary
| Category | Main items | Purpose | Sensitive |
|---|---|---|---|
| Basic personal information | Name, gender, age | Identity recognition and service contact | No |
| Identity documents | Passport number, identity document number | Identity verification and cross-border compliance | Yes |
| Contact information | Phone, email, address | Service contact and travel arrangement | No |
| Medical and health information | Symptoms, reports, medical records | Medical service arrangement and care coordination | Yes |
| Payment information | Payment records, account information | Settlement and compliance audit | Yes |
| Service records | Communication records and service logs | Service delivery and quality improvement | May be sensitive if medical details are included |
13. Contact
Privacy contact: [email protected]
General support: [email protected]
Phone: +8613716151862
Address: FLAT/RM B32 11/F, WONG KING INDUSTRIAL BUILDING, NO.2 TAI YAU STREET, KL
If you believe our handling of personal information violates applicable law, you may first contact us. If you are not satisfied with our response, you may complain to a competent regulator, such as the relevant mainland China authority or the Office of the Privacy Commissioner for Personal Data in Hong Kong, depending on the circumstances.