Privacy Policy
Please scroll through and read how we manage, protect, and handle your data.
Last updated July 2026
1. Commitment to Your Privacy
At MediBuddy LTD, we know your personal health schedules and tracking logs are deeply private. This Privacy Policy outlines exactly how we collect, safeguard, store, and process your information when you access our app, explore our website, or sign up for our waitlist. We comply with all regional frameworks, including the UK Data Protection Act 2018, UK GDPR, and EU GDPR guidelines.
2. Information We Actively Collect
To maintain an active account and deliver personal updates, our platform handles a variety of data streams:
- Account & Registration Details: Your name, email address, secure password hashes, account type profile configurations (such as indicating whether you are a patient or carer), and status verification timestamps.
- Special Category Data (Health Metrics): This covers any information you choose to log yourself. This includes medication names, logging histories, dose schedules, doctor or clinical appointment tracking details, medical notes summaries, and caregiver assignments.
- Age Verification Records: Parental consent data fields, date logs verifying you meet our minimum threshold requirements, and communication tracking for minor status confirmation profiles.
3. Network Logs, IP Monitoring, & Security Audits
When you open our app or connect to our website, our security layers continuously look at technical information from your device. We use this data to spot unusual connections, stop automated platform manipulation, and defend our health ecosystem from software vulnerabilities.
Our analytics, server monitors, and application firewalls actively track the following metrics:
- Internet Protocol (IP) Addresses: Collected to flag sudden location changes, evaluate account sign-in validity, prevent brute-force entry attempts, and mitigate distributed denial-of-service (DDoS) network threats.
- Device Fingerprinting & Tech Parameters: Operating system versions, device models, web browser types, system crash dumps, unique hardware identifiers, and active API application versions.
- Session Activity Records: Access times, specific page routes, server interactions, clicked links, and verification attempts.
We process this system data based on our legitimate interest in securing our applications, keeping user dashboards safe, and verifying that registration lines are not abused by automated spam tools.
4. Data Retention & Law Enforcement Overrides
We keep our operational system files and network log data lean and secure under standard conditions:
- Standard 60-Day Expiry: All routine system logs, connection history logs, and collected IP analytics are automatically scrubbed and permanently deleted from our primary tracking systems after 60 days.
- Law Enforcement & Legal Holds: If specific logs or network histories become subject to an official active legal query, criminal investigation, warrant, or formal request by law enforcement authorities or court orders, we will bypass the 60-day deletion routine.
- Extended Detention Windows: In such legal or regulatory scenarios, the required information may be safely isolated and retained for up to 5 years, or for whatever extended duration is legally mandated or required to resolve the legal action.
5. The Absolute Anti-Monetization Promise
Your data is only processed to provide you and your permitted caregivers with a personal planning tool. It is never used to run ads against you, and we do not profile your health details for commercial target markets.
6. Legal Bases for Processing Data
Under data protection laws, we have clear legal pillars that justify how we use your information:
- Contractual Performance: To set up your account, process waitlist entries, and coordinate the specific logging and reminder tools you configure.
- Explicit User Consent: Required under GDPR Article 9 guidelines before we handle the sensitive, special category medical organizer notes and pill lists you input.
- Legal Obligations: Fulfilling our statutory age verification duties, registering explicit guardian permission, complying with official judicial inquiries, and keeping records up to date.
- Legitimate Interests: Running real-time firewall checks, monitoring network logs, preserving server health, and defending our applications against malicious intrusions.
7. Shared Access Protocols (Split-Login Models)
Our system features explicit caregiver login configurations. If you opt to link your account dashboard with a caregiver, relative, or trusted partner, they are granted immediate system clearance to view your logged health notes, medication reminder logs, and calendar updates. You maintain full control over these links, can view active connection statuses, and can revoke caregiver access instantly inside your dashboard profile settings.
8. System Architecture & Data Erasure Timeline
We guard your details using industry-grade tools. All communication lines running between our application software and server databases are secured behind Transport Layer Security (TLS) data pipelines. Information records are securely stored using advanced encryption layers at rest inside dedicated data centers in the UK and European economic territories.
We keep your account setup details only as long as your profile remains active. If you request account closure, your health organizer records are deleted from our primary storage systems within 30 days.
Security Retention Clause: If our engineering team issues a formal platform ban against an individual for system abuse, endpoint manipulation, or scraping, we retain that user's email hash, associated IP address logs, and security violation details indefinitely. This specific data is kept inside our network firewall lists to block future registration attempts and preserve platform security.
9. Your Statutory Rights
Regardless of your global location, we respect your strict rights regarding your personal information under UK and EU data protection frameworks. You have the right to request:
- Access & Portability: A clear copy of all digital files we maintain on you inside an accessible layout.
- Rectification: Immediate correction of erroneous or outdated identity details.
- Erasure (The Right to be Forgotten): Full deletion of your entire account history and tracking records from our operational networks.
- Withdrawal of Consent: Stopping our use of your health data inputs by deleting records or canceling account setups.
To act on any of these rights, contact our privacy desk directly through our secure contact portal.
Privacy Compliance Support
For managing explicit subject access queries, processing minor parental consent paperwork, or sending formal notices, connect directly with our compliance desk.
Contact Privacy Representative