Medoteca
RORequest a demo

GDPR and Your Data Rights

Last updated 10 October 2026

This page explains how to exercise the rights described in our Privacy Policy.

First: work out who to ask

This is the part people get wrong, so it is worth thirty seconds.

If your data is in the Medoteca platform - because your employer, your clinic or another organisation put it there - then that organisation is the controller, not us. They decide what is held and why; we hold it on their instructions. Send your request to them. They can reach us if they need to, and we are contractually required to help them answer you.

If your data is with us directly - because you emailed us, or sent a bug report from this website - then we are the controller and the rest of this page applies.

What we are likely to hold

This website has no accounts. In practice the only personal data we hold about a visitor is:

  • a demo request or contact form you chose to send us, with a salted hash of your IP address used to limit abuse,
  • an email you chose to send us, including a bug report you sent from the Report a bug page,
  • plus short-lived connection logs held by our hosting provider.

The bug report page never submits anything by itself - it opens a draft in your own mail application, and you decide whether to send it. We hold what you actually sent, nothing more.

Your rights

Right What it means here
Access A copy of what we hold, which is normally your correspondence with us
Rectification Correction of anything inaccurate
Erasure Deletion, where one of the Article 17 grounds applies
Restriction Processing paused while something is disputed
Portability Data you gave us, in a machine-readable format
Objection Object to processing based on legitimate interests
Automated decisions We make none - there is no profiling on this site

Making a request

Write to privacy@medoteca.com and tell us what you want. Include enough detail for us to find the data and to be confident it is yours.

You do not need to use a particular form of words, quote an article number, or explain why.

What we will do

  • We acknowledge the request.
  • We may ask you to confirm your identity, so we do not disclose your data to someone else.
  • We respond within one month. If a request is complex, we may extend by up to two further months and will tell you why inside the first month.
  • Requests are free. We would only charge or refuse where a request is manifestly unfounded or excessive, and we would explain why.
  • If we conclude we are not the controller for the data you are asking about, we say so, and we say who is, rather than simply declining.

If you are unhappy

You can complain to your supervisory authority. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro.

Complaining to a supervisory authority does not stop you also raising it with us, and you do not have to come to us first.

The controller

Kodrium S.R.L. (Trade Register no. / tax ID: being assigned), privacy@medoteca.com.