GDPR Information

Last updated: 27 August 2026

Our role and lawful basis

Controller and processor

Med App acts in two different roles depending on how you use the platform.

  • Where your hospital or health service holds a Med App subscription, that organisation is the controller of your data and Med App is the processor. Your organisation determines what data is collected and why, under a subscription agreement that defines the scope of processing. Med App processes that data only on their documented instructions.
  • Where you register yourself directly on Open Access Med App, Med App is the controller of your registration data.

Lawful basis

For users in the EU and the UK, processing is carried out on the basis of legitimate interests under Article 6(1)(f) GDPR — providing clinician orientation, communication and assessment tools to health services and the clinicians who work in them. For users in Australia, collection is reasonably necessary for Med App’s functions and activities under Australian Privacy Principle 3.

Med App does not collect special category data or criminal offence data.

Records of processing and impact assessments

Med App maintains records of its processing activities and reviews them at least annually.

A Data Protection Impact Assessment covering the core platform is maintained and reviewed annually, most recently in April 2026. A DPIA is also completed whenever a new project may change or add to the data collected and processed through the platform; where a new implementation uses the standard Med App feature set, the existing assessment applies. The current DPIA is available on request through our Trust Centre.

Privacy policy

Our full privacy policy is at https://www.med.app/privacy-policy/ and is also presented when users register for or log in to the mobile app.

What we hold, and for how long

  • Registration information — email, phone number, first and last name. Used to confirm a real person, prevent duplicate profiles, enable password resets, provide support, and send critical notifications.
  • Usage data — for mobile app users this is anonymised, so people can read what is useful to them without feeling monitored; anonymised and aggregated usage is shared with hospital teams to improve the content on their site. For dashboard users who manage content and communications, usage is not anonymised, because governance and transparency require it.
  • Forms data (where a customer site uses the Forms feature) — assessment and accreditation information, configured to that hospital’s own forms.

Retention:

  • Registration data is retained while an account is active. Following account deletion, backups containing that data are superseded within 30 days.
  • Usage analytics data is retained for a maximum of two years.
  • Forms data is retained by the customer hospital in line with its own accreditation and record-keeping obligations.

Full detail is in our Data Retention Policy, available through our Trust Centre.

Where data is stored and transferred

Med App is an Australian company. Platform data is stored and processed in Australia, on Amazon Web Services infrastructure. Customer accounts cannot select an alternative processing region.

Australia is not the subject of an adequacy decision by the European Commission or the UK government. Where Med App holds data relating to individuals in the EU or the UK, the terms governing that data — including any transfer outside the country of collection — are set out in the subscription agreement with the customer organisation, alongside the data protection obligations Med App accepts as processor. Med App will enter into the European Commission’s Standard Contractual Clauses, or the UK International Data Transfer Addendum, where a customer requires them as part of that agreement.

Every sub-processor Med App engages is itself bound by a data processing agreement covering the personal data it handles. The current list, and where each one is located, is below.

Sub-processors

The vendors below process personal data on Med App’s behalf as part of delivering the platform. Each is engaged under a data processing agreement. Vendors used only for Med App’s internal business operations, which do not process platform user data, are not listed.

Sub-processor

Location

Purpose

Agreement

Amazon Web Services

Australia

Hosting and storage of platform data

aws.amazon.com/service-terms

Auth0 (Okta)

Australia

Authentication and user profile data

okta.com — DPA, January 2025

Twilio

United States

SMS delivery, including phone numbers

twilio.com/en-us/legal/data-protection-addendum

Twilio SendGrid

United States

Email delivery, including email addresses

Covered by the Twilio addendum

Intercom

EU / United States

In-app support conversations and profile data

intercom.com/legal/data-processing-agreement

OneSignal

United States

Push notification delivery and logs

onesignal.com — DPA

Amplitude

United States

Product analytics — anonymised for mobile users; identifiable for dashboard users

amplitude.com — DPA

Sentry

United States

Application error logging – no PII

sentry.io — DPA

Cloudflare

Global edge

Content delivery and network security

cloudflare.com — DPA

Data security

Certification and policies

Med App is certified to ISO 27001:2022 by an external auditor, and maintains a policy set mapped to that standard, reviewed on a regular cycle. Policies covering data protection, data retention, information security, secure development, passwords, physical security, access control, encryption, logging and vulnerability management are available on request through our Trust Centre: https://tools.med.app/sites/medapp-trust-centre/index.html

Encryption and anonymisation

Med App collects only the data needed to deliver the service. Data is encrypted in line with our Encryption Policy, available through the Trust Centre. Mobile app usage data is anonymised; dashboard user activity is not, because content and communication changes must remain attributable for governance purposes.

People

Staff and contractors complete criminal history background checks and undertake security awareness training annually.

Breach notification

Med App maintains an Incident Response Plan and a Disaster Recovery Plan governing notification of affected individuals, customers and regulators following a data breach. Both are available on request through the Trust Centre.

Accountability and governance

Responsible officers

  • Security Officer: Stefano Pezzino, Head of Engineering
  • Privacy Officer: Duncan Paradice, Chief Operating Officer

Both can be reached at [email protected].

Data Protection Officer

Med App does not meet the GDPR criteria requiring appointment of a Data Protection Officer. Responsibility for privacy and security sits with the officers named above.

EU and UK representative

Med App is an Australian company with no registered office in the EU or the UK. Our EU and UK user base is small relative to our Australian and New Zealand operations, and we have not appointed a representative under Article 27 GDPR. We will appoint EU and UK representatives if our footprint in those jurisdictions grows to the point where that is the right arrangement for the people whose data we hold.

In the meantime, individuals in the EU or the UK can contact us directly at [email protected]. We respond to all requests within the timeframes GDPR sets, and we do not treat the absence of a local representative as a reason to respond any differently.

Your rights

You can exercise any of the rights below through in-app, dashboard or website live chat, monitored by our Hospital Success and Support team, or by email to [email protected] or [email protected]. We respond within one month, as Article 12(3) requires. Where your hospital is the controller of the data in question, we will pass the request to them and tell you we have done so.

Access and a copy of your data

Most information can be exported directly from the mobile app. If you need more, or have questions about the format, contact us — data is provided in common formats such as spreadsheet, PDF or Word files.

Correction

Personal information can be updated in the app under the ‘more’ tab, then ‘edit details’. Information processed through the Forms workflow — such as workplace-based assessments or end-of-term assessments — is managed by your hospital, and corrections to it are made by them. Not all customer sites use the Forms feature.

Erasure

You can delete your Med App account from the mobile app, which removes your account and associated data from the database. Some records cannot be deleted this way: forms data linked to assessments, education session attendance, and orientation letter read receipts are held by hospitals to meet accreditation obligations. For those, your hospital is the controller and any erasure request is a matter for them.

Portability

Where processing is carried out by automated means, you can ask for the personal data you provided to us in a structured, commonly used, machine-readable format.

Restriction and objection

You can ask us to restrict processing where Article 18 applies, or object to processing where the relevant grounds apply.

Complaints

If you are not satisfied with how we have handled your data or your request, you can lodge a complaint with your supervisory authority — in the EU, the data protection authority in your member state; in the UK, the Information Commissioner’s Office; in Australia, the Office of the Australian Information Commissioner. We would rather hear from you first at [email protected], but that right is yours regardless.

Automated decision-making and AI

Med App does not make decisions about individuals by automated means, and does not carry out profiling that produces legal or similarly significant effects.

We do not currently deploy AI or machine learning features that process user data. Any such feature would be assessed as novel processing under our DPIA process before deployment, and this page would be updated before it went live.