Privacy and Data Protection Policy
Rules for processing personal data, infrastructure security, and ensuring the integrity of regulatory data within the NexiMed system.
This document is undergoing legal review and may change.
Data Protection at a Life Sciences Standard
- GDPR Compliance: We process personal data only on the legal bases set out in this policy.
- Quality Record Integrity: Records related to quality and regulatory documentation are subject to specific retention rules arising from industry regulations (ISO 13485, MDR).
- Data Minimization: We collect only the data necessary to achieve the stated processing purposes.
1. Data Controller and Contact Details
The data controller within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR) is NexiMed Sp. z o.o.
For all matters relating to the processing of personal data and the exercise of rights under the GDPR, please contact us directly at the email address above.
2. Scope and Categories of Data Processed
As part of operating the NexiMed website and platform, we distinguish two main data processing channels:
- • Identification data: first name, last name, job title/role
- • Business data: business email address, employer/client name, department
- • Authentication: password (encrypted), login identifiers
- • Activity log: system action history, electronic signatures on document approvals
- • Contact inquiries: first name, last name, business email, company, message content
- • Newsletter: email address, language preferences
- • Telemetry data: IP address, browser type, operating system, visit timestamps
3. Legal Bases and Purposes of Processing
We process personal data only where permitted by applicable law:
Providing access to the platform, handling login and system notifications.
Obligations arising from tax and accounting regulations, and, for client quality documentation, from industry standards such as ISO 13485 or MDR.
Ensuring platform security, preventing abuse, and pursuing or defending against claims.
Sending newsletters and optional marketing and analytics cookies.
4. Quality Documentation and Regulatory Requirements
Detailed rules governing audit trail records depend on the configuration deployed for a given client and are described in separate documentation and the Data Processing Agreement (DPA).
Given the legal requirements on documentation integrity in the Life Sciences sector:
- Records constituting validation evidence for a quality process may be subject to restrictions on deletion or modification.
- When exercising the right to delete an account, the user's profile data is anonymized or deactivated, subject to retention periods arising from industry regulations and the agreement with the client.
5. Data Security and Hosting
We apply standard security measures aimed at protecting the confidentiality, integrity and availability of data. Details regarding the infrastructure provider, server location, and held security certifications are pending confirmation and will be added once verified.
Data transmission is secured using an encrypted protocol (TLS).
Access to data is restricted in accordance with the principle of least privilege.
6. Data Processing Agreement (DPA)
In our relationship with clients who upload data about their employees and collaborators to the platform, the client acts as the Data Controller, and NexiMed Sp. z o.o. acts as the Data Processor.
Before granting access to the production environment, we enter into a Data Processing Agreement (DPA) with the client, in accordance with Art. 28 GDPR, specifying the subject matter, duration, nature and purposes of processing, and the technical and organizational measures applied.
7. Sub-processors and Data Transfers
The list of technology sub-processors involved in data processing is currently under review and will be published once approved.
| Entity / Provider | Role / Service | Data location |
|---|---|---|
| Pending confirmation | Cloud infrastructure / hosting | — |
8. Rights of Data Subjects (GDPR Rights)
Every natural person whose data is processed has the following rights:
10. Policy Changes and Contact
The Privacy Policy may be updated to reflect changes in the law, guidance from supervisory authorities, or the technologies used. We will inform you of any material changes via the website.
Have questions?
Let's talk about your processes.
Not sure which package to choose? Or maybe you need a custom integration? Our engineers will be happy to help.