MEDrecord B.V. is committed to safeguarding the privacy of all users of its platforms, services, and websites. Personal data is handled with the utmost care, secured, and processed in accordance with this Privacy Statement and applicable laws and regulations, including the General Data Protection Regulation (GDPR).

This Privacy Statement explains:

  • what categories of personal data we collect and process when you use our services;

  • how your data is used, shared, and protected;

  • your rights concerning your personal data;

  • how you can contact us regarding data protection.

Who is responsible for your personal data?

MEDrecord B.V. is the data controller for the processing of your personal data.
Address: Mendelweg 32, 2333CS Leiden, The Netherlands
Chamber of Commerce (KvK): 60601140
Email: info@medrecord.io

We provide digital healthcare services and platforms that enable patients, healthcare providers, and stakeholders to collaborate in delivering personalized care, supported by certified technology and infrastructure.

What personal data do we collect?

Depending on your interaction with our services, we may collect the following categories of personal data:

  • Contact information: name, email address, phone number, physical address

  • Account credentials: username, password

  • Personal characteristics: gender, date of birth, place of residence

  • Health data: medical history, vital signs (e.g., weight, blood pressure, cholesterol, heart rate)

  • Activity data: data from connected devices such as step counters or wearables

  • Payment information: if you use paid services

  • Media content: any images, photos, or videos you upload

  • Communication records: emails or messages exchanged with our support desk

Why and how do we use your personal data?

Your data may be used for the following purposes:

  • Account access and platform use: to create a personal account, log in securely, and provide access to our services and features.

  • Customer support and communication: to respond to your inquiries or provide technical assistance.

  • Service delivery and transactions: when purchasing products or using specific health-related modules.

  • Health insights and personal tracking: to display your health metrics and progress in dashboards or reports.

  • Research and development: anonymized data may be used for scientific research or product improvement.

  • Security and fraud prevention: to monitor and maintain the integrity of our systems.

Scientific Research

Data derived from the use of our services may be used for anonymized scientific studies or quality evaluations. If specific consent is required (e.g., for interviews or additional surveys), it will always be requested in advance. You may withdraw your consent at any time.

Data Security

MEDrecord B.V. is certified for:

  • NEN-7510: Information Security in Healthcare

  • ISO27001: International Standard for Information Security

All connections use modern encryption standards (SHA-256 with RSA), and data is stored on secure servers within the European Economic Area (EEA). Only authorized staff can access personal data and only when necessary.

Please note: although we use strong security measures, transmitting sensitive data over public networks may carry risks beyond our control.

Data Retention

We retain your personal data only for as long as needed for the purposes outlined above, unless a longer retention period is required by law.

Your Rights

You have the right to:

  • Access your personal data

  • Request correction of inaccurate or incomplete data

  • Request deletion (“right to be forgotten”)

  • Object to data processing based on your specific situation

  • Withdraw your consent at any time

  • Request data portability

You may also request the deletion of your account. Anonymized health data may still be retained for research purposes.

Contact: info@medrecord.io

Third-party Services and Integrations

Our platforms may integrate with third-party services such as fitness trackers or external health record systems. When connecting to these services, their own privacy policies may apply.

We are not responsible for the content or privacy practices of external websites or apps we link to.

Cookies

Our websites use cookies for purposes such as:

  • Session management

  • User preference storage

  • Device-specific display optimization

  • Abuse prevention

  • Site performance monitoring

  • Login convenience (optional)

  • Enabling interactive elements

Common cookies include:

  • Google Analytics (_GA / _GAT): for usage statistics (2 years)

  • PHPSESSID: session management (expires upon browser closure)

You can delete or disable cookies via your browser settings, though this may impact site functionality.

Third-party Cookies

Some embedded content (e.g., videos or documents) may include third-party cookies. If you have questions, please contact us at info@medrecord.io.

Minors

We do not knowingly collect personal data from individuals under the age of 18 without parental or legal guardian consent. If you suspect your child has submitted data, please contact us immediately.

Changes to this Privacy Statement

This Privacy Statement may be updated in response to legal developments or service changes. The latest version is always available on our website.

Contact Information

For questions, access requests, or complaints regarding your personal data, please contact:

MEDrecord B.V.
Mendelweg 32
2333CS Leiden
The Netherlands
KvK: 60601140
Email: info@medrecord.io

You may also submit a complaint to the supervisory authority in the Netherlands:
Autoriteit Persoonsgegevens (Dutch Data Protection Authority) via dit formulier.