MS
EN

MedicSort · Effective from 21. 8. 2026

Privacy and Data Protection

How MedicSort handles data across accounts, the social network, MedicSort and Angella AI.

1. Controller

The controller is the operator identified below. This notice covers all three connected services. External vendors may have their own roles and notices.

2. Data we process

Account data includes email, a one-way password hash, optional name, avatar, language, one-time hashed reset tokens and security records. Social data includes profile, posts, comments, reactions, relationships, messages and reports. Angella data includes prompts, answers, attachments and conversation context. MedicSort answers are normally evaluated in the browser; location is requested only when you start a facility search. We also process necessary device, IP, cookie and security logs.

3. Purposes and legal bases

Contract supports accounts and requested features; legitimate interests support security, abuse prevention, basic measurement and improvement; legal obligation supports mandatory records and authority requests; consent supports optional analytics and situations requiring permission for sensitive data. Consent can be withdrawn prospectively.

4. Health and sensitive data

An Angella conversation or post may contain health data under GDPR Article 9. Enter only what is necessary and do not publish another person’s health information without a lawful basis. Processing health data in a personal AI conversation must be supported by explicit consent before use; making data public still carries risk.

5. Recipients and international transfers

Vetted hosting, database, security, email and AI providers may act as processors. OpenStreetMap/Overpass receives approximate coordinates only after a search. Transfers outside the EEA require a valid safeguard such as adequacy or Standard Contractual Clauses. The operator must complete the actual vendor list before launch.

6. Retention

Account and content data is kept for the account’s lifetime, then deleted or anonymised without undue delay except for legal retention and temporary backup cycles. Security records and notices are kept only as needed for legal claims and duties. Exact production periods must be completed before launch.

7. Your rights

You may request access, correction, deletion, restriction, portability, object, withdraw consent and complain to a supervisory authority. The GDPR Rights page explains the process. For solely automated decisions with serious effects, you may request human intervention and contest the decision.

8. Security, children and changes

We use access controls, encrypted transport, secure sessions, minimisation and audit records, but no system is risk-free. The service is not directed to children below the applicable minimum age. We will explain material changes clearly.

EU legal framework