Privacy policy

What personal data MedCoord processes, why, who receives it and how you exercise your rights.

Last updated: 20 Sept 2026

1. Who is responsible for your data

MedCoord is operated by MEDCOORD (“we”). You can write to us about anything in this policy at cosmina.palade@gmail.com.

For the accounts of the people who use MedCoord and for the operation of the service, MEDCOORD is the data controller. When a clinic, a hospital or an independent care coordinator uses MedCoord to manage patient files, that organisation or person decides why and how the patient data is processed and is the controller of those files; MEDCOORD then acts as its processor, under a data processing agreement.

2. What data we process

MedCoord processes only what is needed to coordinate care. It does not collect location, contacts, advertising identifiers or analytics about your behaviour, and it does not sell or share data for advertising.

  • Account data of coordinators and staff: name, email address, role and the time of the last sign-in. Sign-in uses a one-time code sent by email; only a hash of the code is stored.
  • Access requests sent from the public page: the email address and the optional note you typed.
  • Patient file data, entered or uploaded by the coordinator: name, date of birth, gender, blood type, allergies, conditions, medication, consultations and interventions with what was decided, measured values (for example INR or blood pressure), costs if recorded, uploaded medical documents (PDF files or photos), the text extracted from them and the summaries built from the file. This is data concerning health, a special category under Article 9 GDPR.
  • Patient portal data: a hash of the access code, the time of the last visit, the count of failed sign-in attempts, and the conversation with the assistant (the questions, the answers and the replies written by the coordinator).
  • Links for physicians: the label, the expiry date and the number of views of each link.
  • Security and audit data: a log of who opened which patient file, document or export and when, including the IP address; short-lived counters, stored as hashes, that limit repeated sign-in attempts.
  • Cookies and storage on your device: see section 8.

3. Why we process it and on what legal basis

  • To provide the service to coordinators and their organisations: performance of a contract (Article 6(1)(b) GDPR).
  • To answer access requests and messages: steps taken at your request before entering into a contract (Article 6(1)(b)).
  • To keep the service secure, prevent abuse and keep the access log: our legitimate interest (Article 6(1)(f)) and the security obligations of Article 32 GDPR.
  • Health data in patient files: only on behalf of the organisation or coordinator that manages the file and under the legal basis they have established: the provision of health or social care under professional secrecy (Article 9(2)(h)) or the patient's explicit consent (Article 9(2)(a)).
  • To comply with legal obligations that apply to us (Article 6(1)(c)).

4. Artificial intelligence

MedCoord can use an AI model provided by Kimi (Moonshot) to propose a structured reading of an uploaded document, to draft summaries, to translate the content of a file and to answer questions in the patient portal. Before any text is sent to the model, the patient's first and last name, 13-digit personal identification numbers and phone numbers are replaced with neutral placeholders. Free text can still contain other details, for example the name of a physician or of a hospital. Uploaded images are never sent to the model unless the operator has explicitly switched that option on.

What the model returns is a proposal: a coordinator reviews it before it becomes part of a file, and the portal assistant gives general information only. It does not diagnose and does not decide treatment. We do not use patient data for advertising, for profiling or for automated decisions that produce legal effects. When no AI key is configured, these features work with fixed rules and no text leaves the service.

5. Who receives the data

Inside MedCoord a patient file is visible to the coordinator who owns it, to the colleagues it was shared with, to the patient through the portal and to the physicians who receive a read-only link from the coordinator. We disclose data to public authorities only when the law requires it.

We use the following processors, each bound by a data processing agreement and used only for the purpose shown:

  • Netlify: hosting of the application and storage of the uploaded documents.
  • Neon: the managed PostgreSQL database that holds the accounts and the patient files.
  • Resend: delivery of the sign-in code emails; it receives the recipient's email address and the message.
  • Kimi (Moonshot): processing of de-identified text by the AI model, as described in section 4.

6. Transfers outside the European Economic Area

Some of these providers are established, or may process data, outside the European Economic Area (for example in the United States or, for the AI provider, in Asia). Such transfers take place only with the safeguards required by Chapter V GDPR, such as the European Commission's standard contractual clauses, and, for the AI provider, only for text from which the identifiers listed in section 4 were removed. You can ask for a copy of the safeguards at cosmina.palade@gmail.com.

7. How long we keep the data

  • Patient files: until the coordinator who owns the file deletes it, or until the contract with the organisation ends. Deleting a file removes its records, uploaded documents, cached translations, portal conversation and access log entries.
  • Accounts: while the account is in use; deleted on request or when the contract ends (see “Account and data deletion”).
  • Sign-in codes are valid for 10 minutes and can be used once. A sign-in lasts 7 days for coordinators and 30 days in the patient portal.
  • Access requests: until the request has been handled; you can ask us to delete yours at any time.
  • Counters that limit repeated attempts: deleted shortly after their time window has passed.
  • Backups made by our hosting providers expire on their own schedule, within the restore window of the hosting plan.

8. Cookies and storage on your device

MedCoord uses only cookies that are strictly necessary for the service. There are no analytics or advertising cookies, which is why no consent banner is shown.

  • medcoord_session: keeps a coordinator signed in (7 days, not readable by scripts).
  • medcoord_portal: keeps a patient signed in to the portal (30 days, not readable by scripts).
  • medcoord_portal_seen: remembers the last message you read in the portal (30 days).
  • medcoord_locale: remembers the language you chose (1 year).
  • Offline copies: the coordinator pages you open are kept on your device for at most 7 days, so that they remain readable without a connection. Signing out removes them. Pages of the patient portal and of the links for physicians are never kept.

9. How we protect the data

Connections are encrypted (HTTPS). Sessions are signed and kept in cookies that scripts cannot read. Codes are stored only as hashes. A patient file can be opened only by its owner and by the people the owner shared it with, every access is logged, repeated sign-in attempts are limited, and identifiers are removed from text before it reaches the AI model.

10. Your rights

Under GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format and to withdraw consent at any time, without affecting what was done before the withdrawal.

If your data is in a patient file managed by a clinic or a coordinator, address your request to them first: they are the controller, and we will help them answer. For everything else write to cosmina.palade@gmail.com. We answer within one month.

You can lodge a complaint with the Romanian supervisory authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), www.dataprotection.ro, or with the authority of the country where you live.

11. Children

MedCoord is intended for professionals and for adult patients. The file of a minor is managed by the coordinator together with the parent or legal guardian; the portal is not meant to be used by children on their own.

12. Changes to this policy

We publish every change on this page and update the date at the top. We inform account holders by email about changes that matter.

Contact

Operator
MEDCOORD
Email
cosmina.palade@gmail.com