Privacy Policy

Last Updated: 7 August 2025

Medi-Qore (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, protect, and share your information when you use our AI-powered fault response system (“System”).

  1. Definitions
  • Personal Data: Any information relating to an identified or identifiable individual, such as names, email addresses, device/IP data, or account identifiers, as defined by applicable law (e.g., UK/EU GDPR).
  • Processing: Any operation(s) performed on Personal Data, whether automated or manual (including collection, storage, use, disclosure, etc.).
  • User: Any individual or entity who accesses or uses the System.
  1. Data We Collect

Personal Data

We collect only the minimal personal data necessary to operate your account and the System, such as:

  • Account information (e.g., email address, login credentials, subscription details).
  • Usage data (e.g., chat history, query logs, system feedback for service improvement).

We do not intentionally collect or process any patient health or clinical data. We implement controls to prevent uploading of such data and require users to confirm compliance.

Technical and Non-Personal Data

  • Technical/device information (e.g., IP address, browser type, device information).
  • Anonymized and aggregated analytics data regarding usage patterns.
  1. Lawful Bases for Data Processing

We process your personal data only when permitted under data protection laws, including:

  • Contract necessity: To deliver and maintain the System and services you have requested.
  • Legitimate interests: For system improvement, security, customer support, and analytics, unless those interests are overridden by your rights and interests.
  • Legal obligations: To comply with laws, such as responding to lawful requests by public authorities.
  • Consent: For specific optional activities (e.g., feedback surveys), which you may withdraw at any time.
  1. How We Use Data
  • To register, authenticate, and manage your account.
  • To operate, maintain, and improve the System and our services.
  • To personalize user experience and develop the System (AI improvement, feature development).
  • To communicate with you, including notifying you of updates or changes.
  • To meet legal and regulatory obligations.

If any automated decision-making or profiling is performed, you will be informed of its nature, logic, and consequences, and have a right to request human intervention.

  1. Data Sharing and Disclosure

We do not sell or rent your personal data.

  • Service Providers: Your personal data may be shared with trusted third parties who process data on our behalf (e.g., AWS cloud hosting, Stripe or PayPal for payments). Such providers are contractually bound by Data Processing Agreements to protect your data in line with GDPR and perform regular compliance audits.
  • Change of Providers: You will be notified if we change essential third-party service providers (sub-processors).
  • Legal Compliance: Personal data may be disclosed to law enforcement or regulators if required by law or if necessary to defend our rights, safety, or property.
  • Third-Party Links: The System may contain links to external sites. We are not responsible for their content or privacy practices.
  1. International Data Transfers

Your data may be transferred to, or stored at, locations outside your country, including the United States (for data hosting on AWS). Where personal data is transferred outside the UK/EU, we implement appropriate safeguards to ensure equivalent levels of protection, such as Standard Contractual Clauses (SCCs) or adequacy decisions as required by law. By using our System, you consent to such transfers, where lawful.

  1. Data Security

We use robust and industry-standard security measures to protect your data, including:

  • AES-256 encryption at rest,
  • TLS 1.2/1.3 encryption for data transmission,
  • Role-based access and internal logging for administrative access,
  • Regular security monitoring, vulnerability assessments, and staff training.

While we are committed to protecting your data, no system can be completely secure. Users are encouraged to safeguard login credentials and notify us immediately in case of suspected unauthorized access.

  1. Data Retention

We keep personal data only as long as necessary:

  • For active accounts: as long as the account is in use and up to [X months/years] after closure, to comply with legal, contractual, or legitimate business requirements.
  • For analytics and AI improvement: usage data may be retained longer in de-identified, anonymized form.
  • Data is securely deleted or anonymized after its retention period.
  1. Your Rights

Depending on your jurisdiction (including the UK/EU), you have the right to:

  • Access your personal data;
  • Rectify inaccurate or incomplete data;
  • Request deletion (“right to be forgotten”);
  • Restrict or object to processing;
  • Data portability (receive your data in a structured, machine-readable format);
  • Withdraw consent at any time (where processing is based on consent);
  • Lodge a complaint with the relevant supervisory authority (see below).

You may exercise these rights by submitting a request using our Data Subject Request Form or by contacting us as detailed below. We will respond within legally required timeframes (usually one month) and may require verification of your identity.

Data Subject Request Form

  • Name:
  • Contact email:
  • Request type (circle one): Access / Correction / Deletion / Portability / Restriction / Objection
  • Details of Request:
    (Please specify the data you are requesting access to or the action you would like us to take)
  • Signature: _________________________
  • Date: _________________________

Please submit this form to: Contact@Medi-Qore.com

Some rights may be limited by applicable law (e.g., ongoing investigations/security).

  1. Cookies and Tracking

We use cookies or similar technologies strictly for session management and technical functionality—not for any advertising, profiling, or unrelated tracking purposes. You can manage cookie preferences in your browser. Details are provided in our separate Cookie Policy (if applicable).

  1. Children’s Privacy

Our System is not intended for children under 13 (or other applicable age under local laws). If we become aware that personal data has been collected from a child without parental consent, we will delete such data promptly.

  1. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, services, or legal requirements. Material updates will be clearly notified to you (e.g., by email or in-app notice). Your continued use after changes constitutes your acceptance.

  1. Contact Us

For privacy-related questions, please contact Medi-Qore using the email below:

  • Email: Contact@Medi-Qore.com