IntelMedica
Privacy Policy

Privacy Policy

How we handle information collected through this website. Plain-spoken, with the legal precision the law requires.

Effective date: May 1, 2026
1. Introduction and scope

Intel Medica LLC ("IntelMedica," "we," "our," or "us"), a Wyoming-registered limited liability company, operates this marketing website at intelmedica.ai (the "Site"). This privacy policy ("Policy") explains what we collect through the Site, how we use it, the lawful bases on which we rely, and the choices and rights you have.

This Policy covers the marketing website only. Our products (Doc Assist AI, RN Scribe, Open Medical Skills, OpenMedica, and others) are separate services with their own privacy notices and, where applicable, separate Business Associate Agreements (BAAs) and Data Processing Agreements (DPAs). If you are evaluating one of those products, ask us for the product-specific notice.

Our sister company, SECSOLS LLC, is a separate legal entity with its own privacy practices and is not governed by this Policy.

Our products are research tools. They are not medical devices and are not intended for clinical decision-making.

2. Information we collect

The table below summarises the categories of personal data we collect through the Site, the source, the purpose, the lawful basis under GDPR Article 6 (where applicable), the retention period, and the recipients.

Data TypeSourcePurposeLawful Basis (GDPR Art. 6)RetentionRecipients
Personal contact data (name, email, region, profession, role)Demo request formRespond to demo requests; relationship managementArt. 6(1)(b) contract / pre-contract steps; Art. 6(1)(f) legitimate interests; Art. 6(1)(a) consent where required24 months from last interactionCloudflare; email service provider
Technical / log data (IP, user-agent, request paths, timestamps)Cloudflare Workers operational logsSite operation, security, abuse preventionArt. 6(1)(f) legitimate interests; Art. 6(1)(c) legal obligations (security)90 days operational; longer where retained for security incidentsCloudflare
Analytics events (page views, referrer, approximate location, browser, device)Analytics provider scriptMeasure and improve the SiteArt. 6(1)(a) consent (EU/UK/EEA); Art. 6(1)(f) legitimate interests elsewhere14 months[ANALYTICS-PROVIDER-NAME]
Cookies (first-party, minimal)Site / analytics providerSee section 4 (cookies)Art. 6(1)(a) consent (EU/UK/EEA); Art. 6(1)(f) legitimate interests elsewhereSee section 4[ANALYTICS-PROVIDER-NAME]

What we do NOT collect

  • Patient health information or PHI
  • Medical records, lab results, imaging
  • Audio recordings of clinical encounters
  • Payment card or financial account data
  • Government-issued identifiers (SSN, NPI, etc.) through this Site
  • Special category data under GDPR Article 9 (health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation)
  • Sensitive Personal Information (SPI) as defined under California CPRA

Form data we receive is personal information (PII), not Protected Health Information (PHI).

3. How we use information

We use the information we collect to:

  • Respond to your demo request and follow up about IntelMedica products
  • Improve the Site (which pages people read, where the Site is slow, what is broken)
  • Detect, prevent, and respond to fraud, abuse, and security incidents
  • Comply with legal obligations and respond to lawful requests

We do not use the information you submit to train AI models. Product-side training data, where it exists, is governed by separate product privacy notices and contracts.

We do not engage in automated decision-making (including profiling) that produces legal effects concerning you or similarly significantly affects you.

4. Cookies and tracking

A cookie is a small text file stored on your device by your browser. We classify the cookies and similar technologies we use as follows.

CategoryExamplesPurposeRetentionConsent required (EEA/UK)
Strictly necessaryCloudflare security cookies (e.g. anti-bot, load-balancer affinity)Site delivery, security, fraud preventionSession to 12 monthsNo (necessary for service)
Analytics[ANALYTICS-PROVIDER-NAME] first-party cookieAggregate usage metrics; visitor countsUp to 14 monthsYes
FunctionalTheme / preference cookies (if used)Remember non-essential UI choicesUp to 12 monthsYes
Advertising / cross-site trackingNoneNot usedN/AN/A

Consent: in jurisdictions where consent is required for non-essential cookies (including the EU/UK/EEA under the ePrivacy Directive and PECR), non-essential cookies are not set until you provide consent via our cookie banner. You can withdraw consent at any time by clearing the cookie or revisiting the banner controls.

Browser opt-out instructions

  • Chrome: Settings > Privacy and security > Cookies and other site data
  • Firefox: Settings > Privacy & Security > Cookies and Site Data
  • Safari: Settings > Privacy > Manage Website Data
  • Edge: Settings > Cookies and site permissions

Do Not Track (DNT) signals: most current analytics providers do not act on DNT signals, and we do not currently make automatic adjustments based on DNT headers. We honour California "Global Privacy Control" (GPC) signals as a valid request to opt out of sale/sharing where applicable. We are evaluating privacy-respecting analytics alternatives, and this Policy will be updated if our handling changes.

5. How we share information — subprocessors

We do not sell your information. We share limited information only with the service providers (subprocessors) who help us run the Site, under written contract that requires confidentiality, security, and processing only on our documented instructions.

SubprocessorPurposeData CategoriesLocationTransfer Mechanism
Cloudflare, Inc.Hosting (Workers), CDN, edge security, DNSIP, request data, technical logs, form payload in transitGlobal edge (US-headquartered)Standard Contractual Clauses (SCCs) + Cloudflare DPA; EU–US Data Privacy Framework where Cloudflare is certified
[ANALYTICS-PROVIDER-NAME]Web analyticsPage views, anonymised identifiers, approximate location[ANALYTICS-PROVIDER-LOCATION][ANALYTICS-PROVIDER-DPA / SCCs as applicable]
Email service ([ANALYTICS-PROVIDER-NAME])Demo request notifications and repliesForm data (name, email, region, profession, role)[ANALYTICS-PROVIDER-LOCATION]DPA + SCCs (where applicable)

We may also disclose information when required by law, valid legal process, or to protect the rights, property, or safety of IntelMedica, our users, or the public.

If IntelMedica is involved in a merger, acquisition, reorganization, or sale of assets, your information may transfer to the successor entity, subject to this Policy or an equivalent successor policy. We will provide notice of such a transfer to the extent required by law.

6. How long we keep information

We do not retain personal data for longer than necessary for the purposes for which it was collected, save where a longer retention period is required or permitted by law.

Data TypeRetention PeriodTriggerDisposal Method
Demo form submissions24 monthsLast interaction or earlier on requestCryptographic erasure / deletion from inbox + CRM
Operational / server logs90 daysRolling windowLog rotation; secure overwrite
Analytics aggregates (anonymised)14 monthsRolling windowProvider-side rollover
Records of consentDuration of policy + 7 yearsLegal evidentiary requirementSecure archive; destruction at end of period
Records of subject access requests6 yearsRegulatory / accountabilitySecure archive; destruction at end of period
Information under legal holdAs requiredLitigation / regulatory holdSecure deletion once hold released
7. Your rights under EU/UK GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the EU General Data Protection Regulation 2016/679 (and equivalent UK / Swiss frameworks) applies to processing of your personal data through this Site. IntelMedica acts as the data controller for that processing.

Article 6 lawful bases

We rely on the following lawful bases for our processing activities. See the data table in section 2 for the basis applicable to each category.

  • Art. 6(1)(a) Consent — for non-essential cookies and analytics in EU/UK/EEA, and for any optional marketing communications.
  • Art. 6(1)(b) Contract / pre-contract — to take steps at your request prior to entering into a contract (e.g. responding to your demo request).
  • Art. 6(1)(c) Legal obligation — to comply with applicable legal, security, and accountability obligations.
  • Art. 6(1)(f) Legitimate interests — to operate, secure, and improve the Site; we balance these interests against your rights and freedoms.

We do not rely on Art. 6(1)(d) (vital interests) or Art. 6(1)(e) (public task) for Site processing.

Article 9 special category data

We do not process special category data (including health, biometric, genetic, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation) on this Site.

Your data subject rights

  • Right of access (Art. 15) — obtain confirmation of, and a copy of, the personal data we process about you.
  • Right to rectification (Art. 16) — have inaccurate or incomplete data corrected.
  • Right to erasure / right to be forgotten (Art. 17) — have your personal data deleted, subject to limited exceptions.
  • Right to restriction of processing (Art. 18) — have processing temporarily limited.
  • Right to data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21) — object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent — where processing relies on consent, withdraw it at any time without affecting prior lawful processing.
  • Rights related to automated decision-making (Art. 22) — we do not engage in automated decision-making producing legal or similarly significant effects through this Site.

How to exercise your rights

Email us at hello@intelmedica.ai with the subject line "Privacy Request." To protect your data, we will verify your identity (typically by confirming control of the email address you used with us, and where necessary additional non-document information). We respond within 30 days, extendable by a further 60 days for complex or numerous requests (we will notify you of any extension and the reasons within the initial 30 days). There is no charge for reasonable requests.

Right to lodge a complaint

You have the right to lodge a complaint with your local data protection supervisory authority. Selected major authorities:

  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
  • Ireland: Data Protection Commission (DPC) — dataprotection.ie
  • France: Commission Nationale de l'Informatique et des Libertés (CNIL) — cnil.fr
  • Germany: Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) and Länder authorities — bfdi.bund.de
  • Netherlands: Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl
  • Spain: Agencia Española de Protección de Datos (AEPD) — aepd.es
  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch

We would, however, appreciate the chance to address your concerns first — please contact us before approaching a regulator where possible.

8. California rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA/CPRA"), provides you with rights regarding your personal information. The categories below follow the statutory categories under California Civil Code § 1798.140.

CCPA CategoryCollected?ExamplesDisclosed to third parties?Sold / shared?
A. IdentifiersYesName, email, IP addressHosting, email, analytics providersNo
B. Customer records (Cal. Civ. Code § 1798.80(e))YesDemo form: name, emailHosting, email providersNo
C. Protected classificationsNoN/AN/A
D. Commercial informationNoN/AN/A
E. Biometric informationNoN/AN/A
F. Internet / network activityYesPage views, referrer, browser typeHosting, analytics providersNo
G. Geolocation dataYes (general region only, not precise)Country / region from IPHosting, analytics providersNo
H. Sensory dataNoN/AN/A
I. Professional / employment informationYesProfession, role from formEmail providerNo
J. Education informationNoN/AN/A
K. InferencesNo (none drawn for advertising purposes)N/AN/A

Sensitive Personal Information (SPI)

We do not collect Sensitive Personal Information as defined under the CPRA (e.g., government identifiers, account log-in credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, contents of mail/email/text messages, genetic data, biometric identifiers processed for unique identification, health information, sex life or sexual orientation). Because we do not collect SPI, the right to limit use and disclosure of SPI does not apply.

No sale, no sharing, no cross-context behavioral advertising

We do not sell personal information for monetary or other valuable consideration, and we do not share personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months and do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.

Your California rights

  • Right to know (categories, sources, purposes, recipients) and access
  • Right to delete personal information we have collected
  • Right to correct inaccurate personal information
  • Right to opt out of sale or sharing (we do neither, but you have the right)
  • Right to limit use of Sensitive Personal Information (N/A — we collect none)
  • Right to non-discrimination for exercising your rights

Authorized agents

California residents may designate an authorized agent to make a request on their behalf. We will require: (a) written, signed permission from the consumer designating the agent; (b) verification of the consumer's identity directly with us; and (c) confirmation from the consumer that they have authorized the agent. Send agent requests to hello@intelmedica.ai.

9. California "Shine the Light" Act

Under California Civil Code § 1798.83, California residents may request from businesses with which they have an established relationship a list of personal information disclosed to third parties for those third parties' direct marketing purposes during the preceding calendar year, and the names and addresses of those third parties.

IntelMedica does not disclose personal information to third parties for the third parties' direct marketing purposes. A "Shine the Light" request directed to us will return a no-disclosure response. Send any request to hello@intelmedica.ai.

10. Notice of financial incentives

We do not offer financial incentives, price differences, or service-level differences in exchange for the collection, retention, sale, or sharing of personal information.

11. Middle East jurisdictions

We honor data subject rights granted under the following regional frameworks. In each jurisdiction, processing through this Site is generally based on consent and/or legitimate interests, and cross-border transfers from those jurisdictions to the United States rely on legally permissible mechanisms (Standard Contractual Clauses with subprocessors, written controller–processor agreements, and where required, transfer impact assessments).

JurisdictionStatuteAuthorityCross-border transfers
UAE (federal)PDPL — Federal Decree-Law No. 45 of 2021UAE Data OfficeAdequacy or appropriate safeguards (SCCs / BCRs); explicit consent route available
Saudi ArabiaPDPL (2023) and implementing regulationsSDAIA (Saudi Data & AI Authority)Adequacy decision or appropriate safeguards; explicit consent for sensitive data
QatarPDPPL — Law No. 13 of 2016National Data Protection Office (NDPO), Ministry of Communications and Information TechnologyPermitted with adequate protection; consent and notification requirements apply
BahrainPDPL — Law No. 30 of 2018Personal Data Protection Authority (PDPA)Adequate-country list or PDPA authorisation / appropriate safeguards
OmanPDPL — Royal Decree No. 6/2022Ministry of Transport, Communications & Information Technology (MTCIT)Permit-based for international transfer; explicit consent required for sensitive data

Residents of these jurisdictions have rights including access, correction, erasure, objection or restriction of specific processing activities, withdrawal of consent (where processing relies on it), and the right to lodge a complaint with the relevant authority. Direct requests to hello@intelmedica.ai with "Privacy Request" in the subject line.

Where a regulator-approved transfer mechanism is not available for a specific case, we will work with you to find an acceptable alternative before processing.

12. International data transfers

IntelMedica is based in the United States and hosts the Site on Cloudflare's global edge network. Depending on your location, your data may be processed in the United States, the European Union, the United Kingdom, the Asia-Pacific region, or other countries where our subprocessors operate edge infrastructure.

  • EU/UK/EEA → United States: we rely on Standard Contractual Clauses (SCCs) under Article 46 GDPR (and the UK Addendum to the EU SCCs / UK IDTA), supplemented where applicable by the EU–US Data Privacy Framework (DPF) and UK Extension where the recipient is certified.
  • Middle East → United States: case-by-case mechanisms per jurisdiction, as outlined in section 11 (typically appropriate safeguards plus explicit consent where required).
  • Other jurisdictions: we rely on adequacy decisions where they exist and on contractual safeguards otherwise.

Where required, we conduct Transfer Impact Assessments (TIAs) for high-risk transfers, considering the legal context of the recipient country and any supplementary technical and organisational measures applied. Contact hello@intelmedica.ai for a copy of the relevant safeguards.

13. Children's privacy

The Site is directed to professional audiences and is not intended for children. We do not knowingly collect personal information from children below the applicable digital age of consent in the user's jurisdiction.

  • United States (COPPA): not directed at children under 13; we do not knowingly collect data from children under 13.
  • EU/UK/EEA: the digital age of consent under GDPR Art. 8 ranges from 13 to 16 depending on Member State law (e.g., 16 in Germany, the Netherlands, France, Hungary; 14 in Italy, Austria, Spain; 13 where set, including the UK and Belgium). We do not knowingly process the personal data of children below the applicable threshold without the authorisation of a holder of parental responsibility.
  • Middle East: requirements vary by jurisdiction; we apply local minimum-age standards per the applicable PDPL.

If you believe a child has submitted information through this Site, contact hello@intelmedica.ai and we will delete it within 24–72 hours of confirmation.

14. Security and incident response

We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.

Technical measures

  • Encryption in transit (TLS 1.2 or higher; HSTS)
  • Encryption at rest (Cloudflare R2 / KV defaults; provider-managed keys)
  • Network and edge security (DDoS protection, WAF, bot management)
  • Logging and monitoring with anomaly detection
  • Vulnerability management (dependency scanning, patching, regular review)
  • Hardened deployments via Cloudflare Workers; no PHI stored on Site infrastructure

Organisational measures

  • Role-based access controls and least-privilege principles
  • Multi-factor authentication on administrative accounts
  • Confidentiality obligations on staff and contractors
  • Privacy and security training for personnel handling personal data
  • Written contracts with all subprocessors (DPAs, SCCs where required)

Incident response

We are not a HIPAA-covered entity for this Site, and our security policy goes beyond statutory minimums. If we discover a personal data breach as defined under GDPR Article 4(12):

  • We will notify the competent supervisory authority within 72 hours of becoming aware where required (GDPR Art. 33).
  • Where the breach is likely to result in a high risk to the rights and freedoms of natural persons, we will notify affected individuals without undue delay (GDPR Art. 34).
  • Comparable notification timelines under UAE PDPL, Saudi PDPL, Qatar PDPPL, Bahrain PDPL, Oman PDPL, and applicable US state laws will be observed.
  • We will document all breaches, including remedial action, in a register.

No system is perfectly secure. We continually evaluate and improve our controls.

15. Healthcare-specific disclaimer

This Site is informational and lead-generation only. It is NOT a clinical service, NOT a medical device, and NOT a HIPAA-covered service.

This Site does not receive PHI. Do not submit patient information or Protected Health Information through any form on this Site. The demo request form is for business contact only. Any PHI inadvertently submitted will be deleted upon discovery without being used, processed, or disclosed.

Our products are research tools, not medical devices, and not intended for clinical decision-making. For IntelMedica products that do process clinical data on behalf of covered entities, separate Business Associate Agreements (BAAs) and product-specific privacy notices apply. Ask us for a BAA before any data exchange.

For research purposes only. Not a medical device. Not intended for clinical decision-making.

16. Limit on retention

We do not retain personal data for longer than is reasonably necessary for the purposes disclosed in this Policy or required by law. Where data is no longer necessary, we delete or anonymise it according to the schedule in section 6.

17. Third-party links

We link to third-party sites, including HuggingFace (for our open datasets), blog.intelmedica.ai, GitHub, and others. Those sites have their own privacy policies; this Policy does not apply to them. When you click through to a third-party site, you are subject to their terms.

Our open datasets are distributed on HuggingFace under CC-BY-NC-4.0 with manual gating (gated="manual"). Dataset access requests are handled at huggingface.co, not on this Site.

18. Updates to this Policy

We may update this Policy from time to time. The "Effective date" at the top reflects the most recent version.

  • Material changes: we will provide at least 30 days' advance notice via a prominent banner on the Site and, where we have your email and the change affects you, by direct email to demo-form contacts before the change takes effect.
  • Non-material changes: posted with a revised "Effective date".
  • Version history: available on request to hello@intelmedica.ai.
19. Contact us

Privacy questions and requests:

hello@intelmedica.ai

General inquiries:

hello@intelmedica.ai

Entity:

Intel Medica LLC, a Wyoming-registered limited liability company.

Mailing address:

Intel Medica LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA.

Email is preferred for routine privacy requests. Governing law: this Policy is governed by the laws of the State of Wyoming, without regard to conflict-of-laws principles, except where mandatory local data-protection law of your jurisdiction applies.

For research purposes only. Not a medical device. Not intended for clinical decision-making.