Skip to main content
ME

MedaSystems

GDPR evidence

medasystems.comLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

MedaSystems and GDPR

CertReports found no public GDPR evidence for MedaSystems as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
28 Jun 2024
Expires or valid through
26 May 2027
Scope
Purpose of Collecting Data: 1. Providing Products and Services: To deliver and enhance our software solutions and services to our customers, including continuous processing and transfers of personal data as required. 2. Communication: To communicate with business partners and clients about business matters, updates, and new features of our services. 3. Customer Support: To provide robust customer support, address user inquiries, troubleshoot issues, and improve customer service experiences. 4. Data Processing on Behalf of Customers: To process data on behalf of our customers in accordance with their instructions and our contractual obligations, as detailed in our agreements. This includes continuous processing and transfers to sub-processors in line with the subject matter, nature, and duration of the processing. 5. Product Improvement: To analyze usage trends, gather feedback, and conduct research to enhance our products and services. 6. Security and Fraud Prevention: To ensure the security of our systems, diagnose problems, prevent fraudulent activities, and protect our users and company from malicious activities. 7. Compliance and Legal Obligations: To comply with legal and regulatory requirements, including maintaining records as required by law. Types of Personal Data Processed: • Customer Personnel Data: Information inputted by customer personnel into the SaaS services. • Physician Data: Information provided by physicians, including name, contact details, medical specialty, professional licensure, and professional affiliations, in connection with submitting requests and subsequent interactions. • Patient and Caregiver Data: De-identified information provided by patients, their caregivers, or physicians, including medical history, diagnosis, copies of medical imaging tests, lab test results, and results of other medical tests, related to requests and subsequent interactions. Category of Data Subjects: • Users of the services, including physicians, patients, and caregivers who submit requests through the services for access to investigational products of the customer. • Customer personnel. Disclosure to Third Parties: We may disclose personal data to third parties, including service providers who assist us in providing our services, legal authorities to comply with legal obligations, and business partners for legitimate business purposes. All third-party disclosures are conducted in accordance with applicable data protection laws and our contractual obligations.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026MedaSystems, Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 6adcc9ea31
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is MedaSystems GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.

No same-category vendor has GDPR evidence in the index yet.