How we handle information collected through this website. Plain-spoken, with the legal precision the law requires.
Intel Medica LLC ("IntelMedica," "we," "our," or "us"), a Wyoming-registered limited liability company, operates this marketing website at intelmedica.ai (the "Site"). This privacy policy ("Policy") explains what we collect through the Site, how we use it, the lawful bases on which we rely, and the choices and rights you have.
This Policy covers the marketing website only. Our products (Doc Assist AI, RN Scribe, Open Medical Skills, OpenMedica, and others) are separate services with their own privacy notices and, where applicable, separate Business Associate Agreements (BAAs) and Data Processing Agreements (DPAs). If you are evaluating one of those products, ask us for the product-specific notice.
Our sister company, SECSOLS LLC, is a separate legal entity with its own privacy practices and is not governed by this Policy.
Our products are research tools. They are not medical devices and are not intended for clinical decision-making.
The table below summarises the categories of personal data we collect through the Site, the source, the purpose, the lawful basis under GDPR Article 6 (where applicable), the retention period, and the recipients.
| Data Type | Source | Purpose | Lawful Basis (GDPR Art. 6) | Retention | Recipients |
|---|---|---|---|---|---|
| Personal contact data (name, email, region, profession, role) | Demo request form | Respond to demo requests; relationship management | Art. 6(1)(b) contract / pre-contract steps; Art. 6(1)(f) legitimate interests; Art. 6(1)(a) consent where required | 24 months from last interaction | Cloudflare; email service provider |
| Technical / log data (IP, user-agent, request paths, timestamps) | Cloudflare Workers operational logs | Site operation, security, abuse prevention | Art. 6(1)(f) legitimate interests; Art. 6(1)(c) legal obligations (security) | 90 days operational; longer where retained for security incidents | Cloudflare |
| Analytics events (page views, referrer, approximate location, browser, device) | Analytics provider script | Measure and improve the Site | Art. 6(1)(a) consent (EU/UK/EEA); Art. 6(1)(f) legitimate interests elsewhere | 14 months | [ANALYTICS-PROVIDER-NAME] |
| Cookies (first-party, minimal) | Site / analytics provider | See section 4 (cookies) | Art. 6(1)(a) consent (EU/UK/EEA); Art. 6(1)(f) legitimate interests elsewhere | See section 4 | [ANALYTICS-PROVIDER-NAME] |
Form data we receive is personal information (PII), not Protected Health Information (PHI).
We use the information we collect to:
We do not use the information you submit to train AI models. Product-side training data, where it exists, is governed by separate product privacy notices and contracts.
We do not engage in automated decision-making (including profiling) that produces legal effects concerning you or similarly significantly affects you.
A cookie is a small text file stored on your device by your browser. We classify the cookies and similar technologies we use as follows.
| Category | Examples | Purpose | Retention | Consent required (EEA/UK) |
|---|---|---|---|---|
| Strictly necessary | Cloudflare security cookies (e.g. anti-bot, load-balancer affinity) | Site delivery, security, fraud prevention | Session to 12 months | No (necessary for service) |
| Analytics | [ANALYTICS-PROVIDER-NAME] first-party cookie | Aggregate usage metrics; visitor counts | Up to 14 months | Yes |
| Functional | Theme / preference cookies (if used) | Remember non-essential UI choices | Up to 12 months | Yes |
| Advertising / cross-site tracking | None | Not used | N/A | N/A |
Consent: in jurisdictions where consent is required for non-essential cookies (including the EU/UK/EEA under the ePrivacy Directive and PECR), non-essential cookies are not set until you provide consent via our cookie banner. You can withdraw consent at any time by clearing the cookie or revisiting the banner controls.
Do Not Track (DNT) signals: most current analytics providers do not act on DNT signals, and we do not currently make automatic adjustments based on DNT headers. We honour California "Global Privacy Control" (GPC) signals as a valid request to opt out of sale/sharing where applicable. We are evaluating privacy-respecting analytics alternatives, and this Policy will be updated if our handling changes.
We do not sell your information. We share limited information only with the service providers (subprocessors) who help us run the Site, under written contract that requires confidentiality, security, and processing only on our documented instructions.
| Subprocessor | Purpose | Data Categories | Location | Transfer Mechanism |
|---|---|---|---|---|
| Cloudflare, Inc. | Hosting (Workers), CDN, edge security, DNS | IP, request data, technical logs, form payload in transit | Global edge (US-headquartered) | Standard Contractual Clauses (SCCs) + Cloudflare DPA; EU–US Data Privacy Framework where Cloudflare is certified |
| [ANALYTICS-PROVIDER-NAME] | Web analytics | Page views, anonymised identifiers, approximate location | [ANALYTICS-PROVIDER-LOCATION] | [ANALYTICS-PROVIDER-DPA / SCCs as applicable] |
| Email service ([ANALYTICS-PROVIDER-NAME]) | Demo request notifications and replies | Form data (name, email, region, profession, role) | [ANALYTICS-PROVIDER-LOCATION] | DPA + SCCs (where applicable) |
We may also disclose information when required by law, valid legal process, or to protect the rights, property, or safety of IntelMedica, our users, or the public.
If IntelMedica is involved in a merger, acquisition, reorganization, or sale of assets, your information may transfer to the successor entity, subject to this Policy or an equivalent successor policy. We will provide notice of such a transfer to the extent required by law.
We do not retain personal data for longer than necessary for the purposes for which it was collected, save where a longer retention period is required or permitted by law.
| Data Type | Retention Period | Trigger | Disposal Method |
|---|---|---|---|
| Demo form submissions | 24 months | Last interaction or earlier on request | Cryptographic erasure / deletion from inbox + CRM |
| Operational / server logs | 90 days | Rolling window | Log rotation; secure overwrite |
| Analytics aggregates (anonymised) | 14 months | Rolling window | Provider-side rollover |
| Records of consent | Duration of policy + 7 years | Legal evidentiary requirement | Secure archive; destruction at end of period |
| Records of subject access requests | 6 years | Regulatory / accountability | Secure archive; destruction at end of period |
| Information under legal hold | As required | Litigation / regulatory hold | Secure deletion once hold released |
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the EU General Data Protection Regulation 2016/679 (and equivalent UK / Swiss frameworks) applies to processing of your personal data through this Site. IntelMedica acts as the data controller for that processing.
We rely on the following lawful bases for our processing activities. See the data table in section 2 for the basis applicable to each category.
We do not rely on Art. 6(1)(d) (vital interests) or Art. 6(1)(e) (public task) for Site processing.
We do not process special category data (including health, biometric, genetic, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation) on this Site.
Email us at hello@intelmedica.ai with the subject line "Privacy Request." To protect your data, we will verify your identity (typically by confirming control of the email address you used with us, and where necessary additional non-document information). We respond within 30 days, extendable by a further 60 days for complex or numerous requests (we will notify you of any extension and the reasons within the initial 30 days). There is no charge for reasonable requests.
You have the right to lodge a complaint with your local data protection supervisory authority. Selected major authorities:
We would, however, appreciate the chance to address your concerns first — please contact us before approaching a regulator where possible.
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA/CPRA"), provides you with rights regarding your personal information. The categories below follow the statutory categories under California Civil Code § 1798.140.
| CCPA Category | Collected? | Examples | Disclosed to third parties? | Sold / shared? |
|---|---|---|---|---|
| A. Identifiers | Yes | Name, email, IP address | Hosting, email, analytics providers | No |
| B. Customer records (Cal. Civ. Code § 1798.80(e)) | Yes | Demo form: name, email | Hosting, email providers | No |
| C. Protected classifications | No | — | N/A | N/A |
| D. Commercial information | No | — | N/A | N/A |
| E. Biometric information | No | — | N/A | N/A |
| F. Internet / network activity | Yes | Page views, referrer, browser type | Hosting, analytics providers | No |
| G. Geolocation data | Yes (general region only, not precise) | Country / region from IP | Hosting, analytics providers | No |
| H. Sensory data | No | — | N/A | N/A |
| I. Professional / employment information | Yes | Profession, role from form | Email provider | No |
| J. Education information | No | — | N/A | N/A |
| K. Inferences | No (none drawn for advertising purposes) | — | N/A | N/A |
We do not collect Sensitive Personal Information as defined under the CPRA (e.g., government identifiers, account log-in credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, contents of mail/email/text messages, genetic data, biometric identifiers processed for unique identification, health information, sex life or sexual orientation). Because we do not collect SPI, the right to limit use and disclosure of SPI does not apply.
We do not sell personal information for monetary or other valuable consideration, and we do not share personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months and do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.
California residents may designate an authorized agent to make a request on their behalf. We will require: (a) written, signed permission from the consumer designating the agent; (b) verification of the consumer's identity directly with us; and (c) confirmation from the consumer that they have authorized the agent. Send agent requests to hello@intelmedica.ai.
Under California Civil Code § 1798.83, California residents may request from businesses with which they have an established relationship a list of personal information disclosed to third parties for those third parties' direct marketing purposes during the preceding calendar year, and the names and addresses of those third parties.
IntelMedica does not disclose personal information to third parties for the third parties' direct marketing purposes. A "Shine the Light" request directed to us will return a no-disclosure response. Send any request to hello@intelmedica.ai.
We do not offer financial incentives, price differences, or service-level differences in exchange for the collection, retention, sale, or sharing of personal information.
We honor data subject rights granted under the following regional frameworks. In each jurisdiction, processing through this Site is generally based on consent and/or legitimate interests, and cross-border transfers from those jurisdictions to the United States rely on legally permissible mechanisms (Standard Contractual Clauses with subprocessors, written controller–processor agreements, and where required, transfer impact assessments).
| Jurisdiction | Statute | Authority | Cross-border transfers |
|---|---|---|---|
| UAE (federal) | PDPL — Federal Decree-Law No. 45 of 2021 | UAE Data Office | Adequacy or appropriate safeguards (SCCs / BCRs); explicit consent route available |
| Saudi Arabia | PDPL (2023) and implementing regulations | SDAIA (Saudi Data & AI Authority) | Adequacy decision or appropriate safeguards; explicit consent for sensitive data |
| Qatar | PDPPL — Law No. 13 of 2016 | National Data Protection Office (NDPO), Ministry of Communications and Information Technology | Permitted with adequate protection; consent and notification requirements apply |
| Bahrain | PDPL — Law No. 30 of 2018 | Personal Data Protection Authority (PDPA) | Adequate-country list or PDPA authorisation / appropriate safeguards |
| Oman | PDPL — Royal Decree No. 6/2022 | Ministry of Transport, Communications & Information Technology (MTCIT) | Permit-based for international transfer; explicit consent required for sensitive data |
Residents of these jurisdictions have rights including access, correction, erasure, objection or restriction of specific processing activities, withdrawal of consent (where processing relies on it), and the right to lodge a complaint with the relevant authority. Direct requests to hello@intelmedica.ai with "Privacy Request" in the subject line.
Where a regulator-approved transfer mechanism is not available for a specific case, we will work with you to find an acceptable alternative before processing.
IntelMedica is based in the United States and hosts the Site on Cloudflare's global edge network. Depending on your location, your data may be processed in the United States, the European Union, the United Kingdom, the Asia-Pacific region, or other countries where our subprocessors operate edge infrastructure.
Where required, we conduct Transfer Impact Assessments (TIAs) for high-risk transfers, considering the legal context of the recipient country and any supplementary technical and organisational measures applied. Contact hello@intelmedica.ai for a copy of the relevant safeguards.
The Site is directed to professional audiences and is not intended for children. We do not knowingly collect personal information from children below the applicable digital age of consent in the user's jurisdiction.
If you believe a child has submitted information through this Site, contact hello@intelmedica.ai and we will delete it within 24–72 hours of confirmation.
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.
We are not a HIPAA-covered entity for this Site, and our security policy goes beyond statutory minimums. If we discover a personal data breach as defined under GDPR Article 4(12):
No system is perfectly secure. We continually evaluate and improve our controls.
This Site is informational and lead-generation only. It is NOT a clinical service, NOT a medical device, and NOT a HIPAA-covered service.
This Site does not receive PHI. Do not submit patient information or Protected Health Information through any form on this Site. The demo request form is for business contact only. Any PHI inadvertently submitted will be deleted upon discovery without being used, processed, or disclosed.
Our products are research tools, not medical devices, and not intended for clinical decision-making. For IntelMedica products that do process clinical data on behalf of covered entities, separate Business Associate Agreements (BAAs) and product-specific privacy notices apply. Ask us for a BAA before any data exchange.
For research purposes only. Not a medical device. Not intended for clinical decision-making.
We do not retain personal data for longer than is reasonably necessary for the purposes disclosed in this Policy or required by law. Where data is no longer necessary, we delete or anonymise it according to the schedule in section 6.
We link to third-party sites, including HuggingFace (for our open datasets), blog.intelmedica.ai, GitHub, and others. Those sites have their own privacy policies; this Policy does not apply to them. When you click through to a third-party site, you are subject to their terms.
Our open datasets are distributed on HuggingFace under CC-BY-NC-4.0 with manual gating (gated="manual"). Dataset access requests are handled at huggingface.co, not on this Site.
We may update this Policy from time to time. The "Effective date" at the top reflects the most recent version.
Privacy questions and requests:
hello@intelmedica.ai
General inquiries:
hello@intelmedica.ai
Entity:
Intel Medica LLC, a Wyoming-registered limited liability company.
Mailing address:
Intel Medica LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA.
Email is preferred for routine privacy requests. Governing law: this Policy is governed by the laws of the State of Wyoming, without regard to conflict-of-laws principles, except where mandatory local data-protection law of your jurisdiction applies.
For research purposes only. Not a medical device. Not intended for clinical decision-making.