Privacy policy
How we handle your personal data, in compliance with the GDPR
Last updated : May 25, 2026
1. Identity of the data controller
MedQara- published by Fidèle M'PO, Biomedical Engineering student at ISIFC (University of Franche-Comté).
Contact: contact@veillemedqara.fr
2. Data collected
2.1 At account creation
- Email address (required) - legal basis: performance of the contract
- Full name (required) - email personalization
- Organization, role/function (optional) - adapting content
- Password - stored irreversibly (bcrypt hash by Supabase Auth)
2.2 When using the service
- Monitored source preferences
- Alerts marked as read
- Compliance tracking statuses (in progress, compliant, etc.)
- Enabled event reminders
2.3 Payment data (Pro users)
- Processed by Stripe (PCI-DSS Level 1). We never store your bank details on our servers.
- Stripe customer ID and subscription status only.
2.4 Technical data
- Cloudflare Web Analytics: anonymous visit statistics, cookieless, no individual tracking
- Server logs (IP address, user-agent, date) kept 30 days for security
3. Legal basis for processing
- Performance of the contract (Art. 6.1.b GDPR): account creation, service management, sending alerts
- Legitimate interest (Art. 6.1.f GDPR): platform security, fraud prevention
- Consent (Art. 6.1.a GDPR): sending non-essential emails (weekly digest, critical alerts) - revocable at any time in Settings
4. Retention period
- Account data: subscription duration + 3 years after account deletion
- Technical logs: 30 days
- Billing data: 10 years (French legal obligation)
5. Recipients and sub-processors
Your data is processed by:
- Supabase (database hosting) - Europe region (Frankfurt)
- Render (application hosting) - Europe region (Frankfurt)
- Resend (email sending) - GDPR compliant
- Stripe (payments) - Ireland (EU)
- Cloudflare (CDN + analytics + Turnstile) - GDPR compliant, anonymized data
- Groq (AI analysis of alerts) - transient processing only, no personal data sent
6. Transfers outside the EU
All our structural data (account, alerts, payments) is hosted and processed within the European Union. Only third-party APIs (Cloudflare, Groq, Stripe) may process technical metadata outside the EU, under GDPR contractual safeguards (Standard Contractual Clauses).
7. Your rights
At any time, you have the following rights (Art. 15 to 22 GDPR):
- Right of access: know the data we hold about you
- Right to rectification: correct your data from Settings
- Right to erasure: permanently delete your account
- Right to portability: retrieve your data in an open format
- Right to object: refuse certain processing (e.g. marketing emails)
- Right to restriction: temporarily freeze processing
To exercise these rights: contact@veillemedqara.fr. Response within 30 days maximum.
If we do not handle your request satisfactorily, you have the right to lodge a complaint with the CNIL (cnil.fr/fr/plaintes).
8. Security
We apply the following measures:
- TLS 1.3 encryption for all exchanges
- AES-256 encryption of data at rest (Supabase)
- Reinforced authentication (Cloudflare Turnstile CAPTCHA)
- Passwords stored as bcrypt hashes (impossible to reverse)
- Automatic encrypted backups
- Secure HTTP headers (CSP, HSTS, X-Frame-Options...)
Full details: Security policy
9. Cookies
MedQara uses only essential cookies for operation (authentication session, language preferences). No third-party marketing tracking cookies. Our analytics (Cloudflare Web Analytics) is cookieless.
10. Changes
We may update this policy. Users are notified by email in the event of a substantial change. The date of the last update is shown at the top of this page.