Menu
Home/Privacy Policy
GDPR & ISO 13485 Compliance

Privacy and Data Protection Policy

Rules for processing personal data, infrastructure security, and ensuring the integrity of regulatory data within the NexiMed system.

Document version
v0.1 (draft)
Last updated
September 2026
Data residency
Pending confirmation
Data protection contact
kontakt@neximed.pl

This document is undergoing legal review and may change.

Key principles at a glance

Data Protection at a Life Sciences Standard

  • GDPR Compliance: We process personal data only on the legal bases set out in this policy.
  • Quality Record Integrity: Records related to quality and regulatory documentation are subject to specific retention rules arising from industry regulations (ISO 13485, MDR).
  • Data Minimization: We collect only the data necessary to achieve the stated processing purposes.
Section 1

1. Data Controller and Contact Details

The data controller within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR) is NexiMed Sp. z o.o.

Entity: NexiMed Sp. z o.o.
Address: Biała 4, 80-180 Jankowo Gdańskie, Poland
Registration details: NIP: 604 027 27 42 | KRS: 0001261505 | REGON: 54552056500000
General contact: kontakt@neximed.pl

For all matters relating to the processing of personal data and the exercise of rights under the GDPR, please contact us directly at the email address above.

Section 2

2. Scope and Categories of Data Processed

As part of operating the NexiMed website and platform, we distinguish two main data processing channels:

A. Platform Users
  • • Identification data: first name, last name, job title/role
  • • Business data: business email address, employer/client name, department
  • • Authentication: password (encrypted), login identifiers
  • • Activity log: system action history, electronic signatures on document approvals
B. Website Visitors and Contact Form Users
  • • Contact inquiries: first name, last name, business email, company, message content
  • • Newsletter: email address, language preferences
  • • Telemetry data: IP address, browser type, operating system, visit timestamps
Section 3

3. Legal Bases and Purposes of Processing

We process personal data only where permitted by applicable law:

Art. 6(1)(b) GDPR
Performance of the service agreement

Providing access to the platform, handling login and system notifications.

Art. 6(1)(c) GDPR
Compliance with legal obligations

Obligations arising from tax and accounting regulations, and, for client quality documentation, from industry standards such as ISO 13485 or MDR.

Art. 6(1)(f) GDPR
Legitimate interest of the controller

Ensuring platform security, preventing abuse, and pursuing or defending against claims.

Art. 6(1)(a) GDPR
User's voluntary consent

Sending newsletters and optional marketing and analytics cookies.

Section 4

4. Quality Documentation and Regulatory Requirements

Note for the regulated sector (Pharma / MedTech):

Detailed rules governing audit trail records depend on the configuration deployed for a given client and are described in separate documentation and the Data Processing Agreement (DPA).

Given the legal requirements on documentation integrity in the Life Sciences sector:

  • Records constituting validation evidence for a quality process may be subject to restrictions on deletion or modification.
  • When exercising the right to delete an account, the user's profile data is anonymized or deactivated, subject to retention periods arising from industry regulations and the agreement with the client.
Section 5

5. Data Security and Hosting

We apply standard security measures aimed at protecting the confidentiality, integrity and availability of data. Details regarding the infrastructure provider, server location, and held security certifications are pending confirmation and will be added once verified.

Data Encryption

Data transmission is secured using an encrypted protocol (TLS).

Access Control

Access to data is restricted in accordance with the principle of least privilege.

Section 6

6. Data Processing Agreement (DPA)

In our relationship with clients who upload data about their employees and collaborators to the platform, the client acts as the Data Controller, and NexiMed Sp. z o.o. acts as the Data Processor.

Before granting access to the production environment, we enter into a Data Processing Agreement (DPA) with the client, in accordance with Art. 28 GDPR, specifying the subject matter, duration, nature and purposes of processing, and the technical and organizational measures applied.

A DPA template is available on request for legal and quality departments.Request a DPA →
Section 7

7. Sub-processors and Data Transfers

The list of technology sub-processors involved in data processing is currently under review and will be published once approved.

Entity / ProviderRole / ServiceData location
Pending confirmationCloud infrastructure / hosting—
Section 8

8. Rights of Data Subjects (GDPR Rights)

Every natural person whose data is processed has the following rights:

Right of access (Art. 15 GDPR)Obtaining confirmation of processing and a copy of the stored records.
Right to rectification (Art. 16 GDPR)Requesting correction of inaccurate or completion of incomplete personal data.
Right to erasure (Art. 17 GDPR)Subject to legal restrictions arising from retention obligations.
Right to restriction (Art. 18 GDPR)Suspending operations on data in cases specified under GDPR.
Right to data portability (Art. 20 GDPR)Receiving data in a structured, machine-readable format.
Right to object (Art. 21 GDPR)Objecting to processing based on the controller's legitimate interest.
Right to lodge a complaint with a supervisory authority: you have the right to lodge a complaint with the competent supervisory authority – in Poland, this is the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw.
Section 9

9. Cookie Policy and System Logs

The NexiMed website uses cookies for the following purposes:

NecessaryHandling a secure user session and remembering the selected language.
FunctionalRemembering interface preferences.
Analytics (optional)Anonymous usage statistics for the website, only with the user's prior consent.

You can change your cookie settings in your web browser at any time, or block them from being saved entirely.

Section 10

10. Policy Changes and Contact

The Privacy Policy may be updated to reflect changes in the law, guidance from supervisory authorities, or the technologies used. We will inform you of any material changes via the website.

Data protection contact
We respond to requests regarding personal data within a reasonable timeframe, in accordance with GDPR requirements.

Have questions?
Let's talk about your processes.

Not sure which package to choose? Or maybe you need a custom integration? Our engineers will be happy to help.