Privacy Policy
Last updated 10 October 2026
Protecting your personal data is a priority for us. This Privacy Policy describes how we collect, use, store and protect your personal data on medoteca.com, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Romanian law.
1. Definitions
- “Website” means the public website medoteca.com, operated by Kodrium S.R.L.
- “Controller” means Kodrium S.R.L., the legal entity operating the Website.
- “User” means any natural or legal person who accesses or uses the Website.
- “Personal data” means any information by which a natural person can be identified, directly or indirectly (e.g. name, email, IP address, phone number).
- “Processing” means any operation performed on personal data: collection, storage, use, transmission, deletion and so on.
- “GDPR” means Regulation (EU) 2016/679 on the protection of personal data.
- “Consent” means the freely given, specific and explicit agreement of the data subject to the processing of their data.
- “Anonymisation” means irreversibly altering data so that the person can no longer be identified by any reasonable means.
2. This policy covers the website, not the software platform
There are two very different things called “Medoteca”, and they have different rules.
| This website (medoteca.com) | The Medoteca software platform | |
|---|---|---|
| What it is | Public marketing pages | The portal your organisation signs in to |
| Who controls the data | We do | Your organisation does |
| Governed by | This policy | The agreement between us and your organisation |
If you use the software platform through an employer, a clinic or any other organisation, that organisation decides what is held about you and why. We process it on their instructions. Send access, correction and deletion requests to them first; if they need us, they will ask.
Exception: platform usage analytics
For one purpose, Kodrium S.R.L. is also a controller inside the software platform: analysing how the platform is used, through a third-party analytics service, to improve it and diagnose errors.
| What data | Interactions (clicks, scrolling, pages visited, errors), device and browser type, approximate location derived from the IP address, pseudonymous cookie identifiers |
| What is not recorded | Text you type and data shown on screen - the service runs with content masking |
| Lawful basis | Your consent (GDPR Art. 6(1)(a) and Romanian Law 506/2004), given in the platform’s cookie banner |
| Recipient | The analytics provider, acting as a processor; the provider currently in use is named in the platform’s cookie banner |
| Transfers | The provider may process the data outside the EEA; if so, only with appropriate safeguards (an adequacy decision or standard contractual clauses) |
| Retention | At most 13 months; the cookies expire as listed in the Cookie Policy |
The analytics service loads only after you accept. You can withdraw consent at any time from the platform’s cookie settings, without affecting processing that took place before.
Apart from this subsection, everything below is about the public website only.
3. How we process personal data
This website has no accounts, sets no cookies, runs no analytics and embeds no third-party tracking. We only process personal data when you send us a form or an email, or when our hosting provider serves the pages. The purposes are: providing the website, keeping it secure, arranging demos and trial workspaces, answering your messages and fixing reported problems.
We do not profile visitors, build audiences, send marketing, or make automated decisions about anyone.
4. Purposes, data categories and lawful bases
| Purpose | Data | Lawful basis |
|---|---|---|
| Keeping the website working and secure, preventing abuse | IP address, user agent, requested URL, timestamp - held briefly by our hosting provider | Our legitimate interests |
| Arranging a demo and, if you ask for one, setting up a trial workspace | Business name, tax ID (CUI), sector, type of business, country, number of locations, team size, suites of interest; your name, role, work email, phone and message | Steps taken at your request before entering into a contract; our legitimate interest in replying to business enquiries |
| Answering a message sent through the contact form or by email | Topic, name, email address, organisation, message content | Our legitimate interest in maintaining contact with you and resolving your request |
| Preventing form abuse and fraud, and verifying where a submission came from | Your IP address and a one-way salted hash of it, browser user agent, approximate country derived from the IP address, and the page the form was sent from, stored with the form submission | Our legitimate interests |
| Diagnosing and fixing reported problems | The report’s content, browser and screen size (if you leave them in the report) | Our legitimate interests |
| Understanding how the website is used, to improve it (only if you accept analytics) | Pages visited, clicks, scrolling and errors; device and browser type; approximate location derived from the IP address; pseudonymous cookie identifiers. Text you type and data shown on the page are masked and not recorded | Your consent (GDPR Art. 6(1)(a) and Romanian Law 506/2004), given in the cookie banner and withdrawable at any time |
We do not process payment data, account data or marketing data, because the website offers none of those features.
5. Our forms
The demo request and contact forms send what you type to our server, where it is stored in a database and forwarded to our inbox. Only the fields listed above are sent; nothing is stored in your browser.
Report a bug works differently, and it is worth being precise about what it does, because it is not what most forms do.
- It does not submit anything. There is no endpoint behind it and no request leaves the page when you press the button.
- Pressing Open the email assembles what you typed into a
mailto:link and hands it to whichever mail application your device is set up to use. That application, not this website, then sends it - and you can read and edit the draft first. - Copy the report instead puts the same text on your clipboard and sends nothing at all.
- Nothing you type is stored in your browser, and nothing is retained if you navigate away.
- Your browser and screen size are filled in automatically as a convenience. They are ordinary text in a field you can edit or clear before sending.
Once you send the email, we hold it the same way we hold any other correspondence. Please do not put passwords, access tokens or other people’s personal data in a bug report - a record’s reference is enough for us to find it.
6. Browser storage
Three values may be stored in your browser. None is a cookie, none is transmitted to any server, and none contains personal data. If you accept analytics, Microsoft Clarity also sets the cookies listed in the Cookie Policy:
theme- whether you chose the light or dark colour schemeconsent- whether you accepted or rejected optional analyticskdr-status- the public system status shown in the header, kept for one minute and deleted when you close the tab
See the Cookie Policy for detail.
7. If you do not provide data
You do not need to give us any data to read the website. If you request a demo or contact us, we need your name and an email address to reply; without them we cannot act on your request. The tax ID and other optional fields only help us prepare; you can leave them empty.
8. How long we keep it
Data is kept only as long as the purpose requires:
- connection logs are kept by our hosting provider for its standard, short period;
- demo requests and contact form messages are deleted 24 months after our last contact with you, unless you become a customer, in which case our contract with your organisation applies;
- website analytics data is kept by Microsoft Clarity for at most 13 months, and session recordings for 30 days unless we mark one to keep;
- correspondence and bug reports are kept for the duration of our contact with you and then for any applicable limitation period or legal retention obligation, but no longer than the purpose requires.
9. Recipients and transfers
Your data may be accessed by:
- our employees and collaborators, only as far as necessary;
- technical service providers acting as processors, under appropriate contractual safeguards:
- Cloudflare - hosting, content delivery and the database that stores form submissions;
- Microsoft - email (anything you send to our published addresses, and the notification we receive for each form submission) and, only if you accept analytics, Microsoft Clarity usage analytics;
- public authorities, where the law requires it.
Both providers operate outside the European Economic Area in part. Transfers rely on the safeguards those providers offer for EU personal data, including standard contractual clauses.
We do not sell or trade your personal data.
10. Your rights
Under the GDPR you have the following rights:
- Access: to confirm whether we process your data and obtain a copy;
- Rectification: to have inaccurate data corrected or incomplete data completed;
- Erasure: to have your data deleted, under the conditions set by law;
- Restriction: to limit how we use your data;
- Portability: to receive the data you gave us in a structured format;
- Objection: to object to processing based on legitimate interests;
- Withdrawing consent: at any time, without affecting earlier lawful processing;
- Complaint: to the National Supervisory Authority for Personal Data Processing (ANSPDCP).
To exercise any right, see GDPR requests. We respond within 30 days at most.
11. Security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss or destruction. If a security breach affects your rights, we will notify you as the law requires.
Where possible, we anonymise or pseudonymise the personal data we process, so the people it relates to can no longer be identified.
12. Children
The website is not intended for anyone under 16. We do not knowingly collect children’s personal data. If we find we have collected such data without parental consent, we delete it promptly.
13. Changes to this policy
This policy may be updated from time to time. Material changes will be announced on the website. The date of the last update is shown at the top of the page.
14. Contact and controller
For any question, request or complaint about how we process your personal data, write to privacy@medoteca.com.
Personal data controller:
- Full name: Kodrium S.R.L.
- Trade Register no. / tax ID (CUI): being assigned
- Website: medoteca.com
- Email: privacy@medoteca.com