Back to home
Data protection

Privacy policy

Protection of personal data — applicable to all services of Medcare Sarl-S and its applications

Version 1.0Last updated: May 2026
Contents

Preamble and company overview

Medcare Sarl-S (hereinafter "the Company" or "Medcare") is a simplified private limited liability company under Luxembourg law, with its registered office at 44, Rue de l'Industrie, L-8069 Strassen, Luxembourg. Registered with the Luxembourg Trade and Companies Register, Medcare specialises in the design, development, deployment, maintenance and management of IT solutions and digital applications.

Medcare's activity is mainly oriented towards the digital health sector, with the mission of giving healthcare professionals more time to care by automating and simplifying administrative tasks through AI-native solutions. The Company develops and operates the following applications in particular:

  • Nobesick (nobesick.com): an online health platform that facilitates medical appointment booking and connects patients with healthcare professionals;
  • MedReport (medreport-vocal.mercy4cameroon.com): a voice-based medical reporting tool for patient monitoring and management;
  • Prep-EVC (prepa-evc.com): a platform for preparing medical examinations (anatomy, neurology, radiology, cardiology, pharmacology, etc.) intended for medical students and healthcare professionals;
  • Mercy Tensio: an application for monitoring and tracking medical data;
  • Medi Scan: a digital medical scanning and analysis solution.

In addition to these products, Medcare offers custom development, system integration, IT infrastructure management and information technology consulting services for clients operating in the healthcare and education sectors.

In carrying out these activities, Medcare processes personal data belonging to various categories of people: patients, healthcare professionals, students, business clients, employees and partners. The purpose of this Privacy Policy is to inform these people transparently about the processing carried out and about their rights.

2. Data collected per application and service

2.1 Nobesick — Online health platform (nobesick.com)

Nobesick is a platform connecting patients with healthcare professionals, in particular for online appointment booking. The following data is collected:

  • Patients: surname, first name, date of birth, gender, contact details (e-mail, phone, address), social security number or equivalent, health insurance data, reason for consultation, appointment history, notification preferences;
  • Healthcare professionals: professional identity, professional identification number, speciality, professional contact details, practice or institution, calendar and availability, billing data;
  • Connection data: account identifiers, hashed passwords, IP addresses, access logs, in-platform browsing data, date and time of connections.
Sensitive data

Data relating to the medical speciality consulted and the reason for the appointment is considered indirectly health-related. Medcare applies the highest level of protection to it.

2.2 MedReport — Medical reporting tool

MedReport is a patient monitoring and management solution enabling the creation of voice-based medical reports. The data processed includes:

  • Patient data: identity, state of health, clinical status (stable, in progress, critical), vital signs (heart rate, etc.), monitoring history;
  • Professional data: identity of the caregiver or responsible doctor, record access rights, activity within the application;
  • Voice data: voice recordings used for the automatic generation of medical reports, processed using artificial intelligence technologies.
Health data (Art. 9 GDPR)

MedReport processes health data in the strict sense. This data benefits from the highest level of protection and is hosted on secure infrastructure compliant with the applicable requirements.

2.3 Prep-EVC — Medical examination preparation platform (prepa-evc.com)

Prep-EVC is an educational platform for medical students and healthcare professionals wishing to train for or prepare for assessments in medical specialities (anatomy, neurology, radiology, cardiology, immunology, pharmacology, paediatrics, emergency medicine, etc.). The data collected is:

  • Learner data: surname, first name, e-mail, affiliated institution, level of study, specialities followed, exercise results, learning progress, connection history;
  • Payment data: information required to access paid content, processed through secure providers (Stripe, PayPal) with no banking data stored by Medcare;
  • Usage data: modules viewed, time spent, scores obtained, anonymised analytics data.

2.4 Mercy Tensio and Medi Scan

These medical monitoring applications process health data (blood pressure readings, medical scan data) on behalf of the healthcare professionals and institutions that deploy them. Medcare acts as a data processor in this context. The exact data processed is defined contractually with each client acting as data controller.

2.5 The www.mcare.lu website

  • Contact form: name, e-mail address, subject and message of people wishing to contact Medcare;
  • Browsing data: IP address, browser type, pages visited, visit duration, cookies (see section 8).

2.6 Data relating to clients and business partners

As part of commercial relationships (development services, IT consulting, maintenance), Medcare processes the professional contact details of client representatives, contractual information, billing data and the history of exchanges.

2.7 Data relating to employees

Identification data, contractual information, remuneration data, access to internal systems, appraisals and training data of Medcare Sarl-S employees, freelancers and contractors.

3. Purposes and legal bases of processing

  • Provision and operation of the Medcare applications (Nobesick, MedReport, Prep-EVC, Mercy Tensio, Medi Scan) → Performance of the contract;
  • Medical appointment booking and introductions (Nobesick) → Performance of the contract / Explicit consent;
  • Processing of health data (MedReport, Mercy Tensio, Medi Scan) → Explicit consent of the data subject / Healthcare purposes (Art. 9(2)(h) GDPR) / Legal obligation;
  • Medical training and examination preparation (Prep-EVC) → Performance of the contract;
  • Processing of voice data for AI report generation → Explicit consent / Performance of the contract;
  • Custom software development for clients → Performance of the contract (Medcare acts as processor);
  • Continuous product improvement (anonymised or aggregated data) → Legitimate interest;
  • Technical support and user assistance → Performance of the contract / Legitimate interest;
  • Payment management (Prep-EVC and other paid services) → Performance of the contract / Legal obligation;
  • System security and incident detection → Legitimate interest;
  • Marketing and promotional communication → Consent / Legitimate interest (existing clients);
  • Human resources management → Performance of the contract / Legal obligation;
  • Compliance with legal and regulatory obligations → Legal obligation.

4. Data retention periods

  • Health data and medical records: the legal period applicable according to the country and type of data (generally 10 to 20 years under Luxembourg and European regulations);
  • Nobesick user data: the duration of the contractual relationship + 3 years for evidential purposes;
  • MedReport and Mercy Tensio data: defined contractually with the client acting as data controller;
  • Voice data used for report generation: processed for the time required for generation, then deleted within 30 days unless there is a contractual or legal obligation;
  • Prep-EVC learner data: the duration of access to the platform + 2 years;
  • Payment data: transaction references are kept for 10 years (accounting obligation); no banking data is stored by Medcare;
  • www.mcare.lu contact form data: 3 years from the date of the last contact;
  • Client and business partner data: the duration of the contract + 10 years (legal accounting obligation);
  • Employee data: the duration of the employment contract + 5 years;
  • Security and connection logs: 12 months.

At the end of these periods, data is securely erased or irreversibly anonymised in accordance with documented internal procedures.

5. Data security

Given the sensitive nature of the data processed, in particular health data, Medcare Sarl-S applies the following security measures:

5.1 Technical measures

  • End-to-end encryption of data in transit (TLS 1.2 minimum) and encryption at rest of sensitive data (AES-256);
  • Secure hosting of health data on infrastructure compliant with the regulatory requirements in force (certifications applicable according to the countries of deployment);
  • Multi-factor authentication (MFA) for access to systems containing health or sensitive data;
  • Pseudonymisation of data as soon as the purposes allow it;
  • Compartmentalised architecture: strict separation of development / test / production environments and of each client's data;
  • Comprehensive logging of access to sensitive data, with traceability of operations;
  • Native integration of artificial intelligence in secure environments, without exposing raw data to third-party models that are not under contract;
  • Regular security audits, penetration tests and code reviews.

5.2 Organisational measures

  • The principle of least privilege applied to all data access;
  • Mandatory training of all employees in security and data protection best practices;
  • Privacy by Design and Privacy by Default built into the design phase of every new product or feature;
  • Data Protection Impact Assessments (DPIAs) carried out for any high-risk processing, in particular the processing of health data;
  • Business continuity and disaster recovery plans guaranteeing the availability and integrity of data.

6. Data sharing and processors

6.1 Technical providers

Medcare uses carefully selected technical providers (hosts, cloud providers, monitoring tools, AI providers) bound by processing agreements compliant with Article 28 of the GDPR. The main types of provider include cloud infrastructure providers, artificial intelligence services for the generation of voice reports (MedReport), and secure payment platforms (Stripe, PayPal for Prep-EVC).

6.2 Clients acting as data controllers

When Medcare develops and operates solutions on behalf of clients (healthcare institutions, clinics, educational institutions), those clients are the data controllers. The processing terms are defined contractually in a Data Processing Agreement (DPA) signed before any service begins.

6.3 Declared third-party integrations

The Medcare applications integrate third-party technologies for the following purposes:

  • Twilio: communication services (SMS, notifications) within the health platforms;
  • OpenAI: artificial intelligence technologies for the automatic generation of medical reports (MedReport);
  • Stripe / PayPal: secure payment processing (Prep-EVC and paid services). These providers have their own privacy policies, to which Medcare expressly refers.

6.4 Competent authorities

Medcare may be required to disclose data to the competent judicial, health or regulatory authorities in the cases strictly provided for by law.

6.5 Transfers outside the EEA

Any transfer of personal data outside the European Economic Area is governed by appropriate safeguards: an adequacy decision of the European Commission, standard contractual clauses (SCCs) or binding corporate rules (BCRs). Medcare informs data subjects of any transfer to a third country in the information notices specific to each application.

7. Rights of data subjects

In accordance with the GDPR and the Luxembourg law of 1 August 2018, anyone whose data is processed by Medcare Sarl-S has the following rights:

  • Right of access (Art. 15): obtain confirmation that your data is being processed and receive a copy of it;
  • Right to rectification (Art. 16): have inaccurate data corrected or incomplete data completed;
  • Right to erasure / right to be forgotten (Art. 17): request the deletion of your data under the conditions set out in the GDPR;
  • Right to restriction of processing (Art. 18): request the temporary suspension of processing;
  • Right to data portability (Art. 20): receive your data in a structured, commonly used and machine-readable format;
  • Right to object (Art. 21): object to the processing of your data on legitimate grounds, in particular for direct marketing;
  • Right not to be subject to automated decision-making (Art. 22): not be subject to a decision based solely on automated processing producing legal effects;
  • Right to withdraw consent: withdraw your consent at any time, without affecting the lawfulness of prior processing.

To exercise these rights, contact our data controller:

E-mail
contact@mcare.lu
Post
Medcare Sarl-S, 44, Rue de l'Industrie, L-8069 Strassen, Luxembourg
Response time
30 days from receipt of your request (extendable to 3 months for complex requests, with prior notice)

If you are not satisfied, you have the right to lodge a complaint with the National Commission for Data Protection (CNPD) of Luxembourg: cnpd.public.lu — 15, Boulevard du Jazz, L-4370 Belvaux.

8. Cookies and similar technologies

The www.mcare.lu website and the Medcare applications may use cookies and similar technologies:

  • Strictly necessary cookies: essential to the operation of the service (authentication, security, session). No consent required;
  • Analytics cookies: audience measurement and service improvement (aggregated and anonymised data). Subject to consent;
  • Functional cookies: storage of your preferences (language, display settings). Subject to consent;
  • Communication cookies (Twilio): management of notifications and contact preferences within the health applications.

A cookie management banner is built into the website and the platforms concerned, allowing you to express your choices freely, to change them or to withdraw them at any time.

See the cookie policy

9. Data processing by artificial intelligence

Some Medcare applications (in particular MedReport) integrate artificial intelligence technologies for the automatic generation of medical reports from voice data. Medcare undertakes to:

  • Use voice and medical data solely for the declared purposes and with the explicit consent of the data subjects;
  • Not share health data with third-party AI models beyond what is necessary to deliver the contracted service;
  • Guarantee that every medical decision remains under the control and responsibility of the healthcare professional, AI playing only a supporting role;
  • Clearly inform users when a feature of the application relies on automated processing.

10. Data breach management

In the event of a personal data breach, Medcare Sarl-S applies the following procedure:

  1. Detection, qualification and containment of the incident as quickly as possible;
  2. Notification to the CNPD within 72 hours of becoming aware of the breach, where it is likely to result in a risk to the rights and freedoms of individuals (Article 33 GDPR);
  3. Information of the data subjects without delay where the breach is likely to result in a high risk (Article 34 GDPR);
  4. Information of the clients acting as data controllers without delay so that they can fulfil their own obligations;
  5. Documentation of each breach in the dedicated internal register (nature, likely effects, measures taken).

11. Data controller and point of contact

At this stage of its development, Medcare Sarl-S has not yet appointed a Data Protection Officer (DPO). The Company's applications (Nobesick, MedReport) do not yet process health data on a large scale within the meaning of Article 37(1)(c) of the GDPR, as their volume of active users remains limited to date.

Medcare Sarl-S undertakes to appoint a DPO as soon as the volume of personal data processing, in particular health data, reaches a threshold justifying this obligation under the GDPR and the recommendations of the National Commission for Data Protection (CNPD) of Luxembourg. This policy will be updated accordingly.

In the meantime, the Company itself, as data controller, is your direct point of contact for any question, request to exercise your rights or complaint relating to your personal data:

Company
Medcare Sarl-S
E-mail
contact@mcare.lu
Address
44, Rue de l'Industrie, L-8069 Strassen, Luxembourg
Phone
+352 691 123 456
Website
www.mcare.lu

Medcare Sarl-S undertakes to handle any request relating to personal data within 30 days of receipt, in accordance with Article 12 of the GDPR (extendable to 3 months for complex requests, with prior notice).

12. Updates to this policy

This Privacy Policy may change to take account of legal or regulatory amendments, developments in Medcare's services and applications, or CNPD recommendations. Any substantial change will be communicated by notification within the applications concerned, by e-mail or by publication on www.mcare.lu.

Effective date
May 2026
Next scheduled review
July 2027
Version
1.0
Document applicable to
Nobesick, MedReport, Prep-EVC, Mercy Tensio, Medi Scan, www.mcare.lu

Document drawn up by the management of Medcare Sarl-S and approved by the data controller.

Authoritative version. The French version of this document is the binding one. Translations are provided for information purposes only. In the event of any discrepancy in interpretation, the French version prevails. Medcare Sarl-S — 44, Rue de l'Industrie, L-8069 Strassen, Luxembourg.