Privacy Policy
Last updated: July 2026 | Compliant with GDPR & Austrian DPA
1. Data Controller
Roi Shternin-Martini
1180 Vienna, Austria
Email: privacy@medinformics.com
2. Data We Collect
- Account data: Email, name, password (hashed)
- Learning data: Lesson progress, exercise submissions, scores
- Technical data: IP address, user agent, device type
- Usage data: Pages visited, time spent, interactions (via PostHog)
- Payment data: Processed by Stripe (we never store card details)
- Consent data: GDPR, privacy, marketing, analytics (with timestamps)
- Community content: Discussion threads and replies you post are visible to other learners and platform moderators. Do not include patient names, medical record numbers, or other identifying health information in community posts.
- Organization data (if you join a team account): If you accept an invitation to join an organization on Medinformics, your lesson completion percentage, exam scores, earned certificates, and domain mastery scores become visible to that organization's managers. This sharing only happens after you explicitly consent when accepting the invitation.
3. Legal Basis for Processing
Contract (GDPR Article 6(1)(b)): Account creation, purchase processing
Legitimate Interest (6(1)(f)): Analytics, fraud prevention
Consent (6(1)(a)): Marketing, analytics (opt-in)
Legal obligation (6(1)(c)): Tax records, compliance
4. How Long We Keep Data
- Account data: Until account deletion + 7 years (tax requirement)
- Learning data: Until account deletion
- Audit logs: 3 years (compliance)
- Opt-in analytics: 13 months (PostHog default)
5. Your Rights (GDPR)
You have the right to:
- Access (Article 15): Request a copy of your data
- Rectification (16): Correct inaccurate data
- Erasure (17): Delete your account & associated data
- Restrict processing (18): Limit how we use your data
- Data portability (20): Export your data in machine-readable format
- Object (21): Opt out of marketing/analytics
- Withdraw consent: Anytime, for any reason, no penalty
To exercise any right: privacy@medinformics.com with proof of identity.
6. Data Processors (Third Parties)
- Stripe (payments): EU-based
- Resend (email): EU-based
- PostHog (analytics): EU cloud, privacy-first, EU data residency
- Render (hosting): US-based, SOC 2 compliant
- Anthropic (Claude API): US-based, data not used for training without consent
If you join an organization (team) account, the organization's designated managers are also recipients of your learning progress and results data as described in Section 2 above — this is a data-sharing purpose distinct from the third-party processors listed here, since organization managers are not Medinformics vendors.
All processors have Data Processing Agreements (DPAs) in place.
7. Cookies & Tracking
Essential: Authentication, session (always on)
Analytics (opt-in): PostHog (only if user consents)
Marketing (opt-in): None used currently
See our Cookie Policy for details.
Questions?
Email: privacy@medinformics.com
For complaints: Contact your national Data Protection Authority