Privacy Policy

Last updated: June 2026

This Privacy Policy describes how Toctive Ltd. (“MediSync”, “we”, “us”, or “our”) collects, uses, discloses, and safeguards information about you when you access or use the MediSync platform, including our website, web application, mobile applications, APIs, and any other services we provide (collectively, the “Service”). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.

Information we collect

We collect information in three ways. First, information you provide directly: when you register an account we collect your name, email address, job title, organisation name, and billing details. When you submit support requests or contact us, we collect the content of those communications. Second, information we collect automatically: we log your IP address, browser type, operating system, referring URLs, pages viewed, and timestamps when you interact with the Service. We use cookies and similar tracking technologies (see the Cookies section below). Third, clinical and operational data you store: any client records, appointment data, notes, or other health-related information you upload to the Service is processed on your behalf. We are the data processor for that data; you (the clinic or healthcare provider) are the data controller. We do not use clinical data for our own purposes beyond operating the Service.

How we use information

We use the information we collect to: (a) provide, operate, maintain, and improve the Service; (b) create and manage your account and authenticate your identity; (c) process payments and manage billing; (d) send you service-related notices, security alerts, and administrative messages; (e) respond to your comments, questions, and support requests; (f) send marketing communications where you have consented or where we have a legitimate interest and you have not opted out; (g) monitor and analyse usage patterns to improve functionality and user experience; (h) detect, investigate, and prevent fraudulent transactions, abuse, and other illegal activities; (i) comply with applicable legal obligations. We never sell your personal data to third parties.

Data sharing and disclosure

We share your information only in the following circumstances: (a) Service providers — we share data with carefully vetted third-party vendors (cloud infrastructure, payment processors, email delivery, analytics) who process data on our behalf under strict data processing agreements. A current list of sub-processors is available upon request. (b) Business transfers — if MediSync is involved in a merger, acquisition, or asset sale, we will provide notice before your data is transferred and becomes subject to a different privacy policy. (c) Legal requirements — we may disclose information if required to do so by law or in response to valid requests by public authorities (e.g. court orders, government agencies). (d) Protection of rights — we may disclose information where we believe it necessary to protect the rights, property, or safety of MediSync, our users, or the public. We do not share clinical client data with any party except as directed by you or required by law.

Data security

We implement industry-standard administrative, technical, and physical safeguards to protect your information. These include: AES-256 encryption at rest, TLS 1.2+ encryption in transit, strict role-based access controls, multi-factor authentication options, continuous intrusion monitoring, and regular third-party penetration testing. All clinical data is stored within isolated per-tenant database schemas with row-level security so that no tenant can access another's data. We maintain a written information security programme aligned with ISO 27001 principles and HIPAA administrative safeguards. Despite these measures, no method of electronic transmission or storage is 100% secure. If we become aware of a security breach that affects your data, we will notify you in accordance with applicable law.

Your rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data: (a) Access — request a copy of the personal data we hold about you. (b) Correction — ask us to correct inaccurate or incomplete data. (c) Erasure — request deletion of your personal data where there is no compelling reason for us to continue processing it. (d) Restriction — ask us to restrict processing in certain circumstances. (e) Portability — receive your data in a structured, machine-readable format and have it transmitted to another controller. (f) Objection — object to processing based on legitimate interests or for direct marketing. (g) Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing. To exercise any of these rights, please email [email protected]. We will respond within 30 days. In the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local supervisory authority.

Contact

If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact our Data Protection Officer at: Toctive Ltd., [email protected]. For EU/UK residents: our EU representative can be reached at the same address. We take privacy concerns seriously and will respond promptly.

Cookies and tracking technologies

We use cookies, web beacons, and similar tracking technologies to operate and improve the Service. Essential cookies are required for authentication and core functionality; they cannot be disabled. Analytics cookies help us understand how users interact with the Service (we use privacy-respecting analytics tools and do not share analytics data with advertising networks). Preference cookies remember your settings and language choices. You can control non-essential cookies through the cookie banner shown on your first visit or by adjusting your browser settings. Note that disabling cookies may affect certain features of the Service. We do not use cookies for targeted advertising on third-party sites.

Data retention

We retain your personal data for as long as necessary to provide the Service and fulfil the purposes described in this policy. Account data is retained for the duration of your subscription and for a reasonable period thereafter to handle billing disputes or legal claims. Clinical and operational data stored on behalf of a clinic is retained according to your account settings and any retention schedule you configure; upon account termination, we will securely delete or return such data within 90 days unless longer retention is required by law. Server logs are retained for 90 days for security and debugging purposes. You may request earlier deletion of your personal data subject to our legal and contractual obligations.

International data transfers

MediSync is operated from the United Kingdom. If you are accessing the Service from the European Economic Area, Switzerland, or other regions with laws governing data collection and use, please note that your data may be transferred to and processed in countries outside your jurisdiction, including the UK and the United States. Where we transfer personal data from the EEA or UK to countries not deemed adequate by the relevant authority, we use appropriate safeguards such as Standard Contractual Clauses approved by the European Commission or the UK ICO. By using the Service, you consent to such transfers in accordance with this policy.