Medinformics

Privacy Policy

Last updated: July 2026 | Compliant with GDPR & Austrian DPA

1. Data Controller

Roi Shternin-Martini
1180 Vienna, Austria
Email: privacy@medinformics.com

2. Data We Collect

  • Account data: Email, name, password (hashed)
  • Learning data: Lesson progress, exercise submissions, scores
  • Technical data: IP address, user agent, device type
  • Usage data: Pages visited, time spent, interactions (via PostHog)
  • Payment data: Processed by Stripe (we never store card details)
  • Consent data: GDPR, privacy, marketing, analytics (with timestamps)
  • Community content: Discussion threads and replies you post are visible to other learners and platform moderators. Do not include patient names, medical record numbers, or other identifying health information in community posts.
  • Organization data (if you join a team account): If you accept an invitation to join an organization on Medinformics, your lesson completion percentage, exam scores, earned certificates, and domain mastery scores become visible to that organization's managers. This sharing only happens after you explicitly consent when accepting the invitation.

3. Legal Basis for Processing

Contract (GDPR Article 6(1)(b)): Account creation, purchase processing

Legitimate Interest (6(1)(f)): Analytics, fraud prevention

Consent (6(1)(a)): Marketing, analytics (opt-in)

Legal obligation (6(1)(c)): Tax records, compliance

4. How Long We Keep Data

  • Account data: Until account deletion + 7 years (tax requirement)
  • Learning data: Until account deletion
  • Audit logs: 3 years (compliance)
  • Opt-in analytics: 13 months (PostHog default)

5. Your Rights (GDPR)

You have the right to:

  • Access (Article 15): Request a copy of your data
  • Rectification (16): Correct inaccurate data
  • Erasure (17): Delete your account & associated data
  • Restrict processing (18): Limit how we use your data
  • Data portability (20): Export your data in machine-readable format
  • Object (21): Opt out of marketing/analytics
  • Withdraw consent: Anytime, for any reason, no penalty

To exercise any right: privacy@medinformics.com with proof of identity.

6. Data Processors (Third Parties)

  • Stripe (payments): EU-based
  • Resend (email): EU-based
  • PostHog (analytics): EU cloud, privacy-first, EU data residency
  • Render (hosting): US-based, SOC 2 compliant
  • Anthropic (Claude API): US-based, data not used for training without consent

If you join an organization (team) account, the organization's designated managers are also recipients of your learning progress and results data as described in Section 2 above — this is a data-sharing purpose distinct from the third-party processors listed here, since organization managers are not Medinformics vendors.

All processors have Data Processing Agreements (DPAs) in place.

7. Cookies & Tracking

Essential: Authentication, session (always on)

Analytics (opt-in): PostHog (only if user consents)

Marketing (opt-in): None used currently

See our Cookie Policy for details.

Questions?

Email: privacy@medinformics.com
For complaints: Contact your national Data Protection Authority

We use essential cookies to keep you logged in. Analytics cookies are optional. Learn more