1. Who we are
Medora is hospital management software provided by [LEGAL ENTITY NAME], a company registered in [COUNTRY] under company number [NUMBER], with its registered office at [ADDRESS] ("Medora", "we", "us").
This policy explains how we handle personal data. It applies to our website, our sales process, and the Medora application.
2. Controller and processor — an important distinction
We handle two very different categories of data, and our responsibilities differ for each.
| Category | Our role |
|---|---|
| Customer data Your staff's names, work emails, phone numbers, billing details, support conversations, usage logs. |
We are the controller. We decide why and how this is processed, and this policy governs it. |
| Patient data Everything your hospital records about patients: demographics, clinical notes, prescriptions, results, invoices. |
We are the processor. Your hospital is the controller. We act only on your documented instructions under the Data Processing Agreement. |
In plain terms: we decide how we handle your account manager's email address. We do not decide anything about your patients' records — you do.
3. What we collect
3.1 When you visit the website
- Pages viewed, referring site, approximate location derived from IP address
- Device and browser type
- Anything you type into the demo request form
3.2 When you become a customer
- Names, work email addresses, phone numbers and job titles of the staff you give logins to
- Hospital name, address and billing details
- Payment information, handled by our payment provider — we do not store full card numbers
- Support requests and correspondence
3.3 When your team uses Medora
- Authentication events: sign-ins, sign-outs, failed attempts
- Audit records: which user changed which record, when, and from which IP address
- Technical logs needed to keep the service running and diagnose faults
The audit trail is a deliberate feature, not surveillance: in a clinical system it must be possible to establish who recorded or altered a record.
4. Why we use it
- To provide the service — creating your workspace, authenticating users, storing your records.
- To support you — answering questions, investigating faults.
- To bill you — invoicing and collecting payment.
- To keep the service secure — detecting unauthorised access and abuse.
- To improve the product — using aggregate, non-identifying usage patterns.
- To meet legal obligations — tax, accounting and lawful requests.
We do not sell personal data. We do not use patient data to train machine learning models. We do not serve advertising.
5. Legal bases
Where data protection law requires a legal basis, we rely on:
- Contract — to deliver the service you have signed up for.
- Legitimate interests — to secure the service, prevent abuse and improve the product, where those interests are not overridden by your rights.
- Legal obligation — where a law requires us to retain or disclose something.
- Consent — for marketing email, which you may withdraw at any time.
6. Patient data
This is the part that matters most, so we will be direct about it.
- Patient records entered into Medora belong to your hospital.
- We store and process them only to provide the service.
- Our staff do not browse patient records. Support access requires your request, is limited in time and scope, and is logged.
- We do not disclose patient data to third parties except the infrastructure providers listed below, or where compelled by law — and we will tell you if that happens unless legally prohibited.
- Each hospital's workspace is logically isolated. Data is not pooled or shared between customers.
- You can export your data at any time, in an open format.
7. Who we share with
We use a small number of sub-processors. Each is bound by contract to protect the data.
| Provider | Purpose | Location |
|---|---|---|
| [HOSTING PROVIDER] | Application and database hosting | [REGION] |
| [BACKUP PROVIDER] | Encrypted backups | [REGION] |
| [EMAIL PROVIDER] | Transactional email | [REGION] |
| [PAYMENT PROVIDER] | Subscription billing | [REGION] |
A current list is maintained at Compliance. We give notice before adding a sub-processor that handles patient data.
8. International transfers
We sell internationally, so data may be processed outside your country. Where that happens we rely on appropriate safeguards — Standard Contractual Clauses, adequacy decisions, or equivalent local mechanisms.
If your hospital must keep data inside a particular country, tell us before you sign. Data residency is available on request in [LIST REGIONS].
9. How long we keep it
| Data | Retention |
|---|---|
| Patient data | For as long as your subscription runs, then deleted [30] days after termination unless you ask for it sooner or law requires longer |
| Account and billing records | [7] years, for tax and accounting |
| Support correspondence | [3] years |
| Security and audit logs | [12] months |
| Backups | [35] days on a rolling cycle |
Clinical records are often subject to statutory retention periods that are longer than a software contract. Those obligations sit with your hospital as controller, and you should export accordingly before termination.
10. Security
- Encryption in transit (TLS) and at rest
- Role-based access control inside the application
- Passwords stored using industry-standard one-way hashing — never in readable form
- Audit logging of clinical and financial changes
- Daily encrypted backups with tested restores
- Least-privilege access for our own staff, reviewed regularly
No system is perfectly secure. If a breach affects your data we will notify you without undue delay and, where required, within [72] hours of becoming aware, with what we know and what we are doing about it.
11. Your rights
Depending on where you live you may have the right to access, correct, delete, port, restrict or object to processing of your personal data, and to complain to a regulator.
For customer data, contact us and we will respond within [30] days.
For patient data, the request should go to the hospital holding the record — they are the controller. If a patient contacts us directly we will refer them to the hospital and tell you.
12. Cookies
The application uses strictly necessary cookies for sign-in and security. These cannot be switched off without breaking the service.
The marketing website uses [analytics/no analytics]. [If analytics are used, describe them and how to opt out.]
13. Children
Our service is sold to healthcare organisations, not individuals, and is not directed at children. Hospitals do of course record data about child patients; that data is patient data and is handled under section 6 and the Data Processing Agreement.
14. Changes
We may update this policy. Material changes will be notified by email to account administrators at least [30] days before they take effect. The version and date at the top always reflect the current text.
15. Contact
Privacy questions: [PRIVACY EMAIL]
Data Protection Officer: [NAME / EMAIL, if appointed]
Post: [REGISTERED ADDRESS]
If you are in the EU or UK and we do not have an establishment there, our representative is [NAME AND ADDRESS, if required].