Privacy Policy

Last updated: July 2026

1. Introduction

MedCite is a medical evidence search, synthesis and reference service for healthcare professionals and researchers. This Privacy Policy explains what personal data we process, why we process it, and your rights. We apply privacy-by-design principles and do not require an account to use the service.

2. Information We Process

We process the following categories of information:

  • Clinical questions you enter - the text you submit. Original queries are retained only briefly and are redacted before evidence retrieval.
  • Technical data - anonymised IP address, browser type, device type, access timestamps, and an anonymous session identifier.
  • Feedback data - ratings and quality feedback submitted voluntarily.
  • Published articles - content you choose to publish, including the question, answer and references.
  • Analytics data - anonymised information about feature usage and preferences. No clinical content is included.

3. Patient Identifiers

Do not enter identifiable patient information. MedCite applies automated redaction to obvious identifiers before evidence retrieval, but this redaction is pattern-based and may be incomplete. It is not a substitute for de-identification by you. De-identified clinical case descriptions may be entered.

If you believe identifiable patient information has been submitted, contact us immediately so we can assist with deletion.

4. Security

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure.

Limited staff access: Access is restricted to a designated authorised reviewer, who may view individual queries and the search results retrieved for them where necessary for quality and safety assurance. The reviewer is bound by confidentiality, and access is logged. Generated answers, chat histories and complete conversations are not stored and cannot be accessed.

5. Purposes and Legal Bases

We process personal data only where we have a valid legal basis under the GDPR. The main purposes and legal bases are set out below.

Providing answers to your clinical questions

Performance of a contract (Article 6(1)(b))

Yes

Maintaining service security, availability and abuse prevention

Legitimate interests (Article 6(1)(f))

Yes

Product analytics and service improvement

Legitimate interests (Article 6(1)(f)), with privacy-preserving configuration

No - you may object by contacting privacy@medcite.eu

Storing feedback and published articles you choose to submit

Legitimate interests (Article 6(1)(f)) and your consent for public publishing

No - voluntary

6. Data Retention

We retain personal data only as long as necessary for the purposes described. Generated answers are retained temporarily and deleted automatically. Feedback and published articles are retained until you request deletion. Technical logs are anonymised and retained for up to 30 days. Session identifiers are retained for up to one year. You may request deletion of your data at any time by contacting us.

7. Disclosure of Information

We only share personal data when necessary to provide our service or when required by law. Where external processors act on our behalf, we enter into data processing agreements that safeguard the security and confidentiality of the data.

8. International Transfers

Where personal data is transferred outside the EEA, we use safeguards required by applicable data protection law, including Standard Contractual Clauses where applicable.

9. Publishing and Public Articles

Review answers can be intentionally published at a public URL. Publishing is an explicit user action. Before you publish, you should understand that:

  • The article and potentially the underlying clinical question become publicly accessible.
  • Eligible articles may be indexed by search engines.
  • Published material remains stored until removed under our deletion policy.
  • You must ensure that the question, answer and article contain no patient identifiers, confidential information or third-party protected content.
  • The anonymous session identifier is retained so you can exercise export or deletion rights for the content you published.

You can request removal of published articles at any time through your Privacy Settings. Removing a MedCite page does not guarantee immediate removal from search-engine caches or third-party copies.

10. Your Rights

Under applicable data protection law, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate personal data
  • Erase your personal data, subject to legal obligations
  • Restrict processing of your personal data
  • Object to processing based on legitimate interests
  • Withdraw consent where consent is the legal basis
  • Receive your data in a structured, commonly used and machine-readable format
  • Complain to the Danish Data Protection Agency (Datatilsynet) or your local supervisory authority

To exercise these rights, contact us at privacy@medcite.eu. You may need your anonymous session identifier to request deletion or export of server-side data.

11. Automated Decision-Making

MedCite does not make automated decisions about you or any patient that produce legal or similarly significant effects. All clinical decisions remain with qualified healthcare professionals.

12. Data Breaches

If a data breach occurs that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours in accordance with Article 33 of the GDPR. If the breach poses a high risk to your rights, we will also notify you directly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be published on this page with an updated revision date.

14. Cookies

We use privacy-preserving product analytics to understand how the service is used and to improve its operation. Essential cookies are used for language selection, session management and security. No analytics cookies track you across sites or for advertising purposes.

You have the right to object to analytics processing under the GDPR by contacting privacy@medcite.eu.

15. Contact and Controller Details

If you have questions about this Privacy Policy or want to exercise your data protection rights, please contact us at privacy@medcite.eu. The data controller is Nordjysk Speciallægeklinik ApS, Sct. Catharinavej 3, 9900 Frederikshavn, Denmark.

privacy@medcite.eu

Supervisory Authority

If you believe we have not handled your personal data properly, you may lodge a complaint with the Danish Data Protection Agency (Datatilsynet) or your local data protection authority.

Privacy Policy | MedCite