Privacy Policy

Last updated: 2026-06-18

This Privacy Policy explains how MDRpilot ("we", "us") processes personal data when you use the MDRpilot platform ("Service"). It applies to website visitors, account holders and invited users.

1. Data controller

MDRpilot is the controller for personal data processed through the Service. Contact: support@mdrpilot.com · Data protection enquiries: privacy@mdrpilot.com

2. Categories of data we process

Account and identity data

Company and regulatory workspace data

Technical data

We do not intentionally collect patient health data. Do not upload personal health information unless you have assessed lawful basis, necessity and appropriate safeguards.

3. Purposes and legal bases (GDPR / KVKK)

We process personal data to:

We do not sell personal data or use it for third-party advertising.

4. AI processing

When you use AI features, relevant document excerpts or prompts may be transmitted to configured sub-processors (e.g. OpenAI, Anthropic) strictly to generate the output you request. We configure providers not to use Customer Data to train public models where such contractual options exist.

You are responsible for ensuring AI processing is permitted under your internal policies, employment agreements and applicable medical-device confidentiality rules.

5. Recipients and sub-processors

Data may be shared with:

A current sub-processor list is available on request at privacy@mdrpilot.com.

6. International transfers

Where data is transferred outside your country, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions, as applicable.

7. Retention

We retain personal data while your account is active and for a limited period thereafter to resolve disputes, enforce agreements and meet legal obligations. Customer regulatory content is retained according to your subscription status and deletion requests, subject to backup cycles.

You may request deletion of your account by contacting support@mdrpilot.com. Some logs may be retained where required for security or compliance.

8. Security

We implement administrative, technical and organisational measures including encryption in transit, access controls, role-based permissions, audit logging and least-privilege access for personnel. No method of transmission or storage is completely secure; you must protect your credentials.

9. Your rights

Depending on your location, you may have the right to access, rectify, erase, restrict, object to processing, data portability and withdraw consent where processing is consent-based. You may lodge a complaint with your supervisory authority.

To exercise rights, contact privacy@mdrpilot.com. We respond within applicable statutory timeframes.

10. Cookies

We use essential session cookies for authentication and security. We do not use third-party advertising cookies.

11. Children

The Service is intended for business and professional users. It is not directed at children under 16.

12. Changes

We may update this Policy. Material changes will be indicated by updating the date above and, where appropriate, in-app notice.

13. Contact

Privacy requests: privacy@mdrpilot.com · General support: support@mdrpilot.com