Privacy Policy
Last updated: May 2026
Who We Are
MedCite is operated by Nordjysk Speciallægeklinik ApS, Denmark. We provide a medical evidence search platform that retrieves and summarizes information from biomedical literature and clinical guidelines. For privacy inquiries:
Contact us at privacy@medcite.eu.
Data We Collect
- Query text — the medical questions you enter
- Account data (if you create one) — name, email, professional credentials
- Technical data — anonymised IP address, browser type, access timestamps
- Feedback data — ratings, comments, and citation quality feedback
- Usage analytics — anonymised feature usage and search patterns
How We Process Your Data
Your queries are processed by AI models to generate evidence summaries. We use data processors operating in the EU with appropriate data processing agreements. Queries are anonymised before transmission to literature databases.
We do not use your queries, feedback, or generated outputs to train AI models. Your data is used only to generate answers and improve retrieval quality.
Data Retention
Query logs and generated outputs are retained up to 90 days for quality monitoring. Account data is retained until you request deletion. Technical logs are retained up to 30 days.
Security & Compliance
MedCite maintains the following server certifications, audited by Sensiba LLP:
- SOC 2 Type 2—Annual audit — security, availability, and confidentiality controls verified.
- SOC 3—Public summary of SOC 2 Type 2 report. Available on request.
- HIPAA—Compliance assessment — administrative, physical, and technical safeguards for health information.
- GDPR—Full compliance. EU-US DPF and Swiss-US DPF. All data processed in EEA where possible.
Your Rights
Under applicable data protection law, you have the right to access, correct, delete, or port your personal data, and to object to or restrict processing. To exercise these rights, contact privacy@medcite.eu.
Cookies & Analytics
- Essential cookies — required for the website to function (e.g., language preferences).
- Analytics — we use SiteBehaviour for privacy-conscious product and session analytics. No clinical query text, answer text, source abstracts, or patient details are sent.