SkyCare Assistance Discuss a Case

Legal & Privacy

Privacy Policy

How SkyCare Assistance collects, uses, shares, retains and protects personal information.

Last updated: 4 October 2026

SkyCare Assistance is operated by SkyCare Repatriation Ltd. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, retain and protect personal information when you use skycareassistance.uk, use our secure customer forms, contact us, request medical assistance, enquire about or arrange case management, medical review, hospital liaison, cost containment, travel assistance or medical transport, or otherwise interact with us.

SkyCare Assistance may process particularly sensitive information, including information about a patient’s health, when this is necessary to assess, plan, coordinate or provide medical assistance, case management, patient transport or repatriation services. We handle this information with additional safeguards.

1. Who We Are

SkyCare Repatriation Ltd is responsible for the personal data described in this policy where we determine why and how that data is processed. SkyCare Assistance is a service operated by SkyCare Repatriation Ltd.

SkyCare Repatriation Ltd
Office 4, Hangar 1, Passenger Terminal
London Biggin Hill Airport (EGKB)
Biggin Hill, Bromley, Kent TN16 3BH
United Kingdom

Email: [email protected]
Telephone: +44 (0)203 150 3999

2. Personal Data We May Collect

Depending on how you interact with us, we may collect:

  • name, address and contact details;
  • identity, nationality and travel information where required for a case or journey;
  • details about the patient, accompanying relatives, representatives or other contacts;
  • enquiry, case, quotation, booking, payment and correspondence information;
  • patient location, treating and receiving hospital or clinic details and travel arrangements;
  • technical and usage information such as IP address, browser, device information and pages visited;
  • cookie and consent preferences; and
  • other information you choose to provide to us.

3. Health and Medical Information

Information concerning health is special category personal data under UK data protection law. When necessary for medical assistance, case management, transport or repatriation, we may process information such as:

  • medical condition, diagnosis and relevant medical history;
  • mobility, oxygen, stretcher, medication, monitoring or clinical support requirements;
  • medical reports, clinical updates, fit-to-fly information and clinical assessments;
  • details of treating and receiving hospitals, clinics, doctors or other healthcare professionals;
  • information required to review treatment, monitor progress, plan discharge or determine an appropriate medical crew, equipment, aircraft or ground ambulance; and
  • other health information necessary to assess, coordinate or manage safe care and continuity of treatment.

We seek to collect only the medical information reasonably necessary for the relevant purpose.

4. How We Receive Personal Data

We may receive information directly from you or from someone acting on behalf of a patient. We may also receive information, where appropriate, from family members, representatives, hospitals, clinics, doctors, healthcare professionals, insurers, assistance companies, brokers, employers, embassies, consulates, government organisations, ambulance providers, aviation providers or other organisations involved in arranging the patient’s care, assistance or transport.

If you provide us with information about another person, you should ensure that you are authorised to provide it and, where appropriate, that the individual understands how their information may be used.

5. Why We Use Personal Data and Our Lawful Bases

We process personal data only where we have an appropriate lawful basis. Depending on the circumstances, this may include:

  • Contract: where processing is necessary to take steps at your request before entering into a contract or to perform a contract for medical assistance, case management, medical transport or related services.
  • Legal obligation: where processing is necessary to comply with a legal or regulatory requirement.
  • Legitimate interests: where necessary for legitimate business purposes such as responding to enquiries, coordinating cases and services, protecting our systems, maintaining records and improving our services, provided those interests are not overridden by an individual’s rights.
  • Consent: where we ask for consent for a specific purpose, including certain cookies or advertising technologies where required.
  • Vital interests: in limited circumstances where processing is necessary to protect someone’s life and the relevant legal requirements are met.

We may use personal data to respond to enquiries, assess assistance requirements, gather and review medical information, liaise with hospitals, monitor treatment, provide medical case management, plan discharge, prepare quotations, coordinate medical and non-medical transport, manage approved medical costs and payments, communicate with relevant parties, maintain service and regulatory records, protect our website and systems, deal with complaints and legal matters, and improve our services.

6. Additional Conditions for Health and Other Special Category Data

Because health information receives additional protection, an Article 6 lawful basis alone is not sufficient. Where we process special category data, we also identify an applicable condition under Article 9 of the UK GDPR and, where required, the Data Protection Act 2018.

The condition used depends on the particular circumstances and may include explicit consent, vital interests, or processing that is necessary for the provision or management of health or social care where the legal requirements for that condition are satisfied. We document the appropriate basis and condition for the relevant processing activity.

We do not use health information for general advertising or unrelated marketing.

7. Information Governance and the Caldicott Principles

SkyCare’s approved Information Governance and Caldicott framework governs how confidential patient and service-user information is handled across our services. Patient confidentiality, information security and appropriate information sharing are organisational priorities, with relevant information-governance matters escalated through our management and governance arrangements.

We apply the eight Caldicott Principles when using or sharing confidential information:

  1. Justify the purpose: the purpose for using or transferring confidential information should be clearly defined and kept under review.
  2. Use confidential information only when necessary: identifiable information should not be used where the purpose can reasonably be achieved without it.
  3. Use the minimum required: only the information necessary for the particular function or decision should be used or disclosed.
  4. Strict need-to-know access: access to patient-identifiable information is limited to authorised people who need it for their role and only to the information they need.
  5. Everyone understands their responsibilities: staff and providers handling confidential information are expected to understand and comply with their confidentiality and information-security responsibilities.
  6. Understand and comply with the law: uses of patient-identifiable information must have an appropriate lawful basis and comply with applicable data-protection and confidentiality requirements.
  7. The duty to share for individual care is as important as the duty to protect confidentiality: appropriate information may be shared in a patient’s best interests where this is necessary for safe and effective care.
  8. Inform patients and service users: we aim to provide clear information about how and why confidential information is used and the choices available to individuals.

These principles are particularly important in international medical assistance. Safe assessment, case management, treatment planning and continuity of care can require timely information exchange between SkyCare Assistance, treating and receiving clinicians, hospitals, insurers, assistance companies and medical transport providers. We seek to ensure that such use and disclosure is necessary, proportionate and limited to the information required for the relevant purpose.

Where practical and appropriate, information is anonymised or otherwise de-identified when an individual’s identity is not required for the purpose. Staff and providers are expected to use approved systems and information-sharing procedures and to take care to avoid inadvertent disclosure of confidential information.

8. Confidential Communications, Complaints and Investigations

Confidential patient information should be exchanged only through communication methods approved by SkyCare for the relevant purpose. Patients, representatives and business partners should not send medical records or other sensitive clinical information to ordinary or unapproved email addresses where a secure method has been provided. Where secure customer forms or other approved channels are available, these should be used for sensitive case information.

Complaints and investigations are handled confidentially. Information may nevertheless be used or disclosed where this is necessary and lawful for investigating a complaint or incident, protecting patient safety, meeting clinical-governance or regulatory obligations, responding to lawful requests from public authorities, or establishing, exercising or defending legal rights. Any disclosure is limited according to the circumstances and applicable law.

9. Patient Safety and Clinical Governance

Where a patient-safety incident, complaint or clinical-governance matter arises, SkyCare may record, review and share relevant personal and clinical information with appropriately authorised people where necessary for patient safety, incident investigation, clinical governance, risk management, complaints handling, regulatory obligations and organisational learning.

Information is handled confidentially and disclosures are limited according to the circumstances, applicable data-protection law, professional confidentiality requirements and SkyCare’s information-governance controls.

10. Who We May Share Personal Data With

Where necessary and proportionate for the relevant purpose, we may share information with:

  • treating and receiving hospitals, clinics, doctors and healthcare professionals;
  • air ambulance operators, airlines, aviation providers, airports and ground-handling providers;
  • road ambulance providers and medical escort personnel;
  • insurers, medical assistance companies, brokers, case managers and corporate travel-risk teams;
  • embassies, consulates, government bodies or public authorities where relevant and lawful;
  • IT, website, communications, secure-form, payment, professional and administrative service providers;
  • companies within our group or associated organisations where there is a legitimate and lawful reason;
  • regulators, law-enforcement bodies, courts or other authorities where disclosure is legally required; and
  • professional advisers or parties involved in a business restructuring, claim or legal dispute.

We limit disclosures to information that is reasonably necessary for the relevant purpose and expect organisations handling personal data on our behalf to protect it appropriately.

11. International Transfers

International medical assistance is inherently cross-border. A patient’s information may need to be communicated to hospitals, clinicians, insurers, assistance partners, medical transport providers, aviation providers or other relevant organisations outside the United Kingdom to assess, manage or arrange an international medical case or transfer.

Where UK data protection law restricts an international transfer of personal data, we use an appropriate transfer mechanism or safeguard where required, which may include UK adequacy regulations, contractual safeguards or another lawful mechanism available under UK data protection law.

12. Website Analytics, Cookies and Advertising

Our website uses cookies and similar technologies for essential functions and, where permitted, analytics and other purposes. Non-essential technologies are managed through our consent mechanism where consent is required.

You can accept, deny or manage your cookie preferences through the consent controls provided on the website. Further information is available in our Cookie Policy.

We may use Google services, including Google Analytics, Google Tag Manager and Google Ads, subject to the consent and configuration applied on our website. Google advertising is used to promote the SkyCare Assistance website and our services; it is not used to market to patients using their health information. Where required, advertising and measurement technologies are activated in accordance with the consent choices made through our consent-management system.

13. Customer Forms and Enquiries

When you contact us or submit an enquiry or secure customer form, we may collect your name, email address, telephone number, message and information relevant to the requested service. A form relating to a medical case may also contain health information about a patient.

Our customer forms may be provided through dedicated form services, including the SkyCare Assistance form domain at form.skycareassistance.uk. Please provide only information reasonably necessary for us to assess, manage or respond to the case. Medical information should not be submitted for unrelated purposes.

14. How Long We Keep Personal Data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide services and meet legal, regulatory, accounting, insurance, clinical-governance, complaints and dispute-resolution requirements.

Retention periods vary according to the type of information and the circumstances of the case. We consider the amount, nature and sensitivity of the information, the risk of harm from unauthorised use or disclosure, the purposes for which it is processed and applicable legal requirements when determining retention periods.

Information that is no longer required is deleted, anonymised or otherwise securely disposed of in accordance with our retention practices.

15. Security

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, authentication, encryption where appropriate, firewalls, system monitoring, backups, staff controls and security procedures.

No internet or electronic storage system can be guaranteed to be completely secure. If a personal data breach occurs, we assess it and make notifications to affected individuals and the Information Commissioner’s Office where required by law.

16. Your Data Protection Rights

Depending on the circumstances, UK data protection law may give you the right to:

  • request access to personal data we hold about you;
  • request correction of inaccurate or incomplete personal data;
  • request erasure of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • request transfer of certain personal data in a portable format;
  • withdraw consent where processing is based on consent, without affecting processing carried out before withdrawal; and
  • raise a complaint with the Information Commissioner’s Office.

These rights are not absolute and exemptions may apply. We may need to verify your identity before acting on a request.

To exercise a data protection right, contact us at [email protected].

You can find further information about your rights from the Information Commissioner’s Office.

17. Automated Decision-Making

We do not currently make solely automated decisions about individuals using personal data that produce legal or similarly significant effects. If this changes, we will update this policy and provide the information required by law.

18. Children and Patients Who Cannot Act for Themselves

Medical assistance and transport may sometimes involve a child or a patient who is unable to manage their own affairs. In those circumstances, information may be provided by a parent, guardian, attorney, representative, healthcare professional or another person lawfully involved in the patient’s care. We take account of the circumstances, the patient’s interests and applicable legal requirements when handling that information.

19. Third-Party Websites and Services

Our website and customer forms may link to or use services operated by other organisations. We do not control third-party websites and their privacy practices are governed by their own policies. We encourage you to review relevant privacy information before providing personal data to a third party.

20. Changes to This Privacy Policy

We may update this Privacy Policy when our services, technologies, providers or legal obligations change. The latest version will be published on this page and the date at the top will be updated.

21. Contact Us

For questions about this Privacy Policy, our use of personal data or a data protection request, contact:

SkyCare Repatriation Ltd
SkyCare Assistance
Email: [email protected]
Telephone: +44 (0)203 150 3999
Office 4, Hangar 1, Passenger Terminal
London Biggin Hill Airport (EGKB)
Biggin Hill, Bromley, Kent TN16 3BH
United Kingdom

This Privacy Policy explains SkyCare Assistance’s general approach to personal data. The lawful basis and special-category condition applicable to a particular processing activity depend on the facts and legal context of that activity.

Region UK not activated for privacy-statement.