Intel e-medix Systems ("we", "us", "our") respects your privacy. This Policy explains what personal and medical data we collect, why we collect it, how it is protected, and the rights you have over it. Our practices are aligned with HIPAA, GDPR, and PDPL, and we make a Business Associate Agreement (BAA) available to covered entities.
1. Data We Collect
- Account data: name, email, organisation (if applicable), authentication tokens.
- Uploaded reports: medical documents and images you choose to upload for analysis.
- Derived data: structured findings, plain-English summaries, and translations generated from your reports.
- Operational data: audit logs (who accessed what, and when), IP address, user-agent, and basic device metadata for security and abuse prevention.
- Payment data: handled by our PCI-DSS-compliant payment processor. We never see or store full card numbers.
2. How We Use Data
- To deliver the report-explanation service you requested.
- To maintain account security, fraud prevention, and a tamper-evident audit log.
- To improve service quality (on aggregated, de-identified data only).
- To process payments and meet tax/accounting obligations.
- To send transactional emails (receipts, account notices). Marketing emails only with explicit opt-in.
We do not sell personal data, and we do not use uploaded medical content to train third-party AI models.
3. Retention & Auto-Purge
Uploaded files and their derived analyses are cryptographically purged within 48 hours of upload by default. Enterprise customers may configure a longer retention under contract. Audit-log entries are retained for the period required by applicable healthcare regulation (typically 6 years).
4. Security
- TLS 1.3 in transit, AES-256 at rest, FIPS 140-2 validated KMS.
- Role-based access control, least-privilege service accounts.
- Continuous monitoring, change management, and incident-response procedures aligned with SOC 2 and ISO/IEC 27001 controls.
- Tamper-evident audit logging on all access to protected health information.
5. Sharing & Sub-processors
We share personal data only with:
- Payment processor / Merchant of Record — Lemon Squeezy, LLC (a Stripe company). When you make a purchase, checkout is handled by Lemon Squeezy, which collects and processes your name, billing address, email, payment-method details, IP address, and device metadata to authorize the transaction, prevent fraud, calculate and remit applicable taxes (VAT/GST/sales tax), issue invoices, and process refunds and chargebacks. Lemon Squeezy acts as an independent controller for tax and anti-fraud purposes. See the Lemon Squeezy Privacy Policy and Terms.
- Cloud infrastructure & email sub-processors (hosting, transactional email delivery, error monitoring) bound by data-protection agreements and, where applicable, HIPAA Business Associate Agreements.
- Your designated clinicians or organisation, when you explicitly grant access.
- Authorities, when required by valid legal process and only to the extent strictly required.
We do not sell personal data. We do not share personal data with advertising networks or data brokers.
6. Cookies & Tracking
We use strictly-necessary cookies for authentication, session security, and load balancing. We use a minimal set of first-party analytics cookies to understand aggregate site usage; these are anonymized and do not build a cross-site profile. Payment pages hosted by Lemon Squeezy may set their own cookies for fraud prevention and PCI compliance — governed by Lemon Squeezy's cookie policy. We honor Global Privacy Control (GPC) signals as a valid opt-out of any non-essential data sale/share under CCPA/CPRA.
7. Your Rights
Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, PDPL, and similar laws), you have rights to:
- Access, correct, or delete your personal data.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time (without affecting prior lawful processing).
- Lodge a complaint with your data-protection authority.
To exercise any right, email privacy@intelemedix.com. We respond within 30 days.
8. International Transfers
Where data is transferred across borders, we use approved safeguards (Standard Contractual Clauses, UK IDTA, and equivalent regional mechanisms) to ensure protection consistent with this Policy. Lemon Squeezy processes payment data in the United States under its own approved transfer safeguards.
9. Children
The Service is not directed to children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes
We may update this Policy. Material changes will be notified by email or in-app notice at least 14 days before they take effect.
11. Contact
Data Protection Officer · privacy@intelemedix.com
Compliance · compliance@intelemedix.com
Billing (via Merchant of Record) · help@lemonsqueezy.com (Lemon Squeezy, LLC)