M Medora
How it works Modules Security Pricing
Sign in Book a demo ↗
Legal

Privacy Policy

Last updated: [DATE] · Version 1.0

1. Who we are 2. Controller and processor 3. What we collect 4. Why we use it 5. Legal bases 6. Patient data 7. Who we share with 8. International transfers 9. How long we keep it 10. Security 11. Your rights 12. Cookies 13. Children 14. Changes 15. Contact
The short version. If you are a hospital using Medora, the patient records you put into the system belong to you — we hold them on your behalf and we do not use them for anything except running the service for you. This policy explains that in full, and covers the separate, much smaller set of data we collect about you as our customer.

1. Who we are

Medora is hospital management software provided by [LEGAL ENTITY NAME], a company registered in [COUNTRY] under company number [NUMBER], with its registered office at [ADDRESS] ("Medora", "we", "us").

This policy explains how we handle personal data. It applies to our website, our sales process, and the Medora application.

2. Controller and processor — an important distinction

We handle two very different categories of data, and our responsibilities differ for each.

CategoryOur role
Customer data
Your staff's names, work emails, phone numbers, billing details, support conversations, usage logs.
We are the controller. We decide why and how this is processed, and this policy governs it.
Patient data
Everything your hospital records about patients: demographics, clinical notes, prescriptions, results, invoices.
We are the processor. Your hospital is the controller. We act only on your documented instructions under the Data Processing Agreement.

In plain terms: we decide how we handle your account manager's email address. We do not decide anything about your patients' records — you do.

3. What we collect

3.1 When you visit the website

  • Pages viewed, referring site, approximate location derived from IP address
  • Device and browser type
  • Anything you type into the demo request form

3.2 When you become a customer

  • Names, work email addresses, phone numbers and job titles of the staff you give logins to
  • Hospital name, address and billing details
  • Payment information, handled by our payment provider — we do not store full card numbers
  • Support requests and correspondence

3.3 When your team uses Medora

  • Authentication events: sign-ins, sign-outs, failed attempts
  • Audit records: which user changed which record, when, and from which IP address
  • Technical logs needed to keep the service running and diagnose faults

The audit trail is a deliberate feature, not surveillance: in a clinical system it must be possible to establish who recorded or altered a record.

4. Why we use it

  • To provide the service — creating your workspace, authenticating users, storing your records.
  • To support you — answering questions, investigating faults.
  • To bill you — invoicing and collecting payment.
  • To keep the service secure — detecting unauthorised access and abuse.
  • To improve the product — using aggregate, non-identifying usage patterns.
  • To meet legal obligations — tax, accounting and lawful requests.

We do not sell personal data. We do not use patient data to train machine learning models. We do not serve advertising.

5. Legal bases

Where data protection law requires a legal basis, we rely on:

  • Contract — to deliver the service you have signed up for.
  • Legitimate interests — to secure the service, prevent abuse and improve the product, where those interests are not overridden by your rights.
  • Legal obligation — where a law requires us to retain or disclose something.
  • Consent — for marketing email, which you may withdraw at any time.

6. Patient data

This is the part that matters most, so we will be direct about it.

  • Patient records entered into Medora belong to your hospital.
  • We store and process them only to provide the service.
  • Our staff do not browse patient records. Support access requires your request, is limited in time and scope, and is logged.
  • We do not disclose patient data to third parties except the infrastructure providers listed below, or where compelled by law — and we will tell you if that happens unless legally prohibited.
  • Each hospital's workspace is logically isolated. Data is not pooled or shared between customers.
  • You can export your data at any time, in an open format.

7. Who we share with

We use a small number of sub-processors. Each is bound by contract to protect the data.

ProviderPurposeLocation
[HOSTING PROVIDER]Application and database hosting[REGION]
[BACKUP PROVIDER]Encrypted backups[REGION]
[EMAIL PROVIDER]Transactional email[REGION]
[PAYMENT PROVIDER]Subscription billing[REGION]

A current list is maintained at Compliance. We give notice before adding a sub-processor that handles patient data.

8. International transfers

We sell internationally, so data may be processed outside your country. Where that happens we rely on appropriate safeguards — Standard Contractual Clauses, adequacy decisions, or equivalent local mechanisms.

If your hospital must keep data inside a particular country, tell us before you sign. Data residency is available on request in [LIST REGIONS].

9. How long we keep it

DataRetention
Patient dataFor as long as your subscription runs, then deleted [30] days after termination unless you ask for it sooner or law requires longer
Account and billing records[7] years, for tax and accounting
Support correspondence[3] years
Security and audit logs[12] months
Backups[35] days on a rolling cycle

Clinical records are often subject to statutory retention periods that are longer than a software contract. Those obligations sit with your hospital as controller, and you should export accordingly before termination.

10. Security

  • Encryption in transit (TLS) and at rest
  • Role-based access control inside the application
  • Passwords stored using industry-standard one-way hashing — never in readable form
  • Audit logging of clinical and financial changes
  • Daily encrypted backups with tested restores
  • Least-privilege access for our own staff, reviewed regularly

No system is perfectly secure. If a breach affects your data we will notify you without undue delay and, where required, within [72] hours of becoming aware, with what we know and what we are doing about it.

11. Your rights

Depending on where you live you may have the right to access, correct, delete, port, restrict or object to processing of your personal data, and to complain to a regulator.

For customer data, contact us and we will respond within [30] days.

For patient data, the request should go to the hospital holding the record — they are the controller. If a patient contacts us directly we will refer them to the hospital and tell you.

12. Cookies

The application uses strictly necessary cookies for sign-in and security. These cannot be switched off without breaking the service.

The marketing website uses [analytics/no analytics]. [If analytics are used, describe them and how to opt out.]

13. Children

Our service is sold to healthcare organisations, not individuals, and is not directed at children. Hospitals do of course record data about child patients; that data is patient data and is handled under section 6 and the Data Processing Agreement.

14. Changes

We may update this policy. Material changes will be notified by email to account administrators at least [30] days before they take effect. The version and date at the top always reflect the current text.

15. Contact

Privacy questions: [PRIVACY EMAIL]
Data Protection Officer: [NAME / EMAIL, if appointed]
Post: [REGISTERED ADDRESS]

If you are in the EU or UK and we do not have an establishment there, our representative is [NAME AND ADDRESS, if required].

© 2026 Medora. All rights reserved. Designed, built and supported by TaskMinions