Privacy Policy

Last updated: 3 July 2026

This policy explains how NexWell handles your personal data when you use thenexwell.com and our patient-coordination services.

1. Who we are (Data Controller)

Nexwell Global Solutions FZCO(“NexWell”, “we”, “us”) is the controller of the personal data described in this policy.

  • Registered entity: NEXWELL GLOBAL SOLUTIONS FZCO
  • Licence: Dubai Integrated Economic Zones Authority (IFZA), Licence No. 53266
  • Registered address: IFZA Properties, Dubai Silicon Oasis, Dubai, UAE
  • Contact: info@thenexwell.com

Our role.NexWell is a medical-tourism coordination platform, not a clinic. We connect patients with independent partner clinics in Türkiye. For the treatment itself, each partner clinic is a separate data controller for the clinical data it holds. NexWell is the controller for the coordination data described here.

2. What data we collect

Data you give us (enquiry / quote forms):

  • Identity & contact: name, email address, phone number, country of residence.
  • Health-related information (special category): the treatment or procedure you are interested in, and any medical details you choose to share in your message or supporting documents.

Payment data: where a deposit or payment is processed, it is handled by our payment processor Stripe; NexWell does not store full card numbers.

Data collected automatically: IP address, device / browser information, pages viewed, and cookie / analytics identifiers (see Section 8).

3. Why we use it, and our legal basis

We process health data and share it with a clinic only with your explicit consent, which you may withdraw at any time (Section 6).

PurposeLegal basis (GDPR)Legal basis (KVKK)
Respond to your enquiry and prepare a coordination quoteArt. 6(1)(b) / 6(1)(f)Md. 5
Process health data to match you with a suitable clinicArt. 9(2)(a) explicit consentMd. 6 explicit consent
Share your details with the relevant partner clinicArt. 6(1)(b) + 9(2)(a)Md. 5–6
Payments / depositsArt. 6(1)(b)Md. 5
Marketing & analytics (only with consent)Art. 6(1)(a)Md. 5

4. Who we share data with

  • Partner clinics in Türkiye — to arrange and deliver treatment (only with your explicit consent).
  • GoHighLevel / LeadConnector — enquiry and CRM management.
  • Stripe — payment processing.
  • Google Analytics (GA4) & Google Tag Manager — website analytics (with consent).
  • Meta (Facebook) Pixel — advertising measurement (with consent).
  • Cookiebot — cookie-consent management.
  • Sentry — application error monitoring.

We put data-processing agreements in place with our processors.

5. International data transfers

Your data — including health data — may be transferred between the United Arab Emirates (where NexWell is established), Türkiye (where partner clinics deliver treatment) and the EU / UK (where many patients are located). Where we transfer EU / UK personal data to countries without an adequacy decision, we rely on appropriate safeguards, namely Standard Contractual Clauses (SCCs), together with your explicit consent for health-data sharing.

6. Your rights

Under GDPR / UK GDPR you have the right to access; rectification; erasure; restriction; data portability; to object; to withdraw consent at any time; and not to be subject to solely automated decisions. Under KVKK (Türkiye) you have equivalent rights.

To exercise any right, contact info@thenexwell.com. We respond within the legal timeframe (one month under GDPR / 30 days under KVKK).

7. How long we keep your data

We keep personal data only as long as necessary for the purposes described above and as required by law. Health data is minimised and deleted or anonymised once the coordination of your treatment is complete, unless a longer period is legally required (for example, statutory accounting retention for payment records).

8. Cookies

We use strictly necessary, analytics and marketing cookies. Non-essential cookies are set only with your consent, managed through our cookie banner (Cookiebot). You can change your preferences at any time via the cookie settings.

9. Data security

We apply appropriate technical and organisational measures (encryption in transit, access controls, HTTPS / HSTS, vetted processors). No method of transmission is 100% secure; we work to protect your data and to notify you and the relevant authority of a breach where legally required.

10. Complaints

If you believe we have mishandled your data you may complain to a supervisory authority — the ICO (UK), your local Data Protection Authority (EU), or the Kişisel Verileri Koruma Kurumu (KVKK, Türkiye). We ask that you contact us first at info@thenexwell.com so we can try to resolve it.

11. Changes to this policy

We may update this policy; the “Last updated” date above shows the latest version. Material changes affecting how we use health data will be notified where required.