MedaSystems and GDPR
CertReports found no public GDPR evidence for MedaSystems as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 28 Jun 2024
- Expires or valid through
- 26 May 2027
- Scope
- Purpose of Collecting Data: 1. Providing Products and Services: To deliver and enhance our software solutions and services to our customers, including continuous processing and transfers of personal data as required. 2. Communication: To communicate with business partners and clients about business matters, updates, and new features of our services. 3. Customer Support: To provide robust customer support, address user inquiries, troubleshoot issues, and improve customer service experiences. 4. Data Processing on Behalf of Customers: To process data on behalf of our customers in accordance with their instructions and our contractual obligations, as detailed in our agreements. This includes continuous processing and transfers to sub-processors in line with the subject matter, nature, and duration of the processing. 5. Product Improvement: To analyze usage trends, gather feedback, and conduct research to enhance our products and services. 6. Security and Fraud Prevention: To ensure the security of our systems, diagnose problems, prevent fraudulent activities, and protect our users and company from malicious activities. 7. Compliance and Legal Obligations: To comply with legal and regulatory requirements, including maintaining records as required by law. Types of Personal Data Processed: • Customer Personnel Data: Information inputted by customer personnel into the SaaS services. • Physician Data: Information provided by physicians, including name, contact details, medical specialty, professional licensure, and professional affiliations, in connection with submitting requests and subsequent interactions. • Patient and Caregiver Data: De-identified information provided by patients, their caregivers, or physicians, including medical history, diagnosis, copies of medical imaging tests, lab test results, and results of other medical tests, related to requests and subsequent interactions. Category of Data Subjects: • Users of the services, including physicians, patients, and caregivers who submit requests through the services for access to investigational products of the customer. • Customer personnel. Disclosure to Third Parties: We may disclose personal data to third parties, including service providers who assist us in providing our services, legal authorities to comply with legal obligations, and business partners for legitimate business purposes. All third-party disclosures are conducted in accordance with applicable data protection laws and our contractual obligations.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | MedaSystems, Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 6adcc9ea31 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is MedaSystems GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.