1. Controller
The controller is the operator identified below. This notice covers all three connected services. External vendors may have their own roles and notices.
2. Data we process
Account data includes email, a one-way password hash, optional name, avatar, language, one-time hashed reset tokens and security records. Social data includes profile, posts, comments, reactions, relationships, messages and reports. Angella data includes prompts, answers, attachments and conversation context. MedicSort answers are normally evaluated in the browser; location is requested only when you start a facility search. We also process necessary device, IP, cookie and security logs.
3. Purposes and legal bases
Contract supports accounts and requested features; legitimate interests support security, abuse prevention, basic measurement and improvement; legal obligation supports mandatory records and authority requests; consent supports optional analytics and situations requiring permission for sensitive data. Consent can be withdrawn prospectively.
4. Health and sensitive data
An Angella conversation or post may contain health data under GDPR Article 9. Enter only what is necessary and do not publish another person’s health information without a lawful basis. Processing health data in a personal AI conversation must be supported by explicit consent before use; making data public still carries risk.
5. Recipients and international transfers
Vetted hosting, database, security, email and AI providers may act as processors. OpenStreetMap/Overpass receives approximate coordinates only after a search. Transfers outside the EEA require a valid safeguard such as adequacy or Standard Contractual Clauses. The operator must complete the actual vendor list before launch.
6. Retention
Account and content data is kept for the account’s lifetime, then deleted or anonymised without undue delay except for legal retention and temporary backup cycles. Security records and notices are kept only as needed for legal claims and duties. Exact production periods must be completed before launch.
7. Your rights
You may request access, correction, deletion, restriction, portability, object, withdraw consent and complain to a supervisory authority. The GDPR Rights page explains the process. For solely automated decisions with serious effects, you may request human intervention and contest the decision.
8. Security, children and changes
We use access controls, encrypted transport, secure sessions, minimisation and audit records, but no system is risk-free. The service is not directed to children below the applicable minimum age. We will explain material changes clearly.
