Data protection at Mendai
Recovery is private. Our starting position is to collect as little as possible, keep it in Europe, and hold ourselves to health-grade safeguards even where the law does not force us to.
Two contexts, one posture
There are two places you might share data with us: this website, and — later — the Mendai application. The website is deliberately thin: no cookies, no third-party trackers, and a form you choose to fill in (details in the Privacy Policy). The application will handle far more sensitive material, and it is being designed for that from the start rather than patched afterwards.
GDPR
Mendai is built in Europe and the GDPR is our default frame, not an add-on for European visitors. In practice that means:
- Data minimization. We collect what a purpose requires and nothing more — the website's analytics cannot even recognize a returning visitor.
- EEA hosting. Our infrastructure runs on AWS in the EU (Stockholm, eu-north-1) [confirm all backend regions].
- Rights by design. Access, correction, deletion, and objection are handled at [privacy@mendai.tech] within one month.
- Health data handled as special category. When the application launches, any health-related data will be processed only with explicit consent (art. 9(2)(a)) after a completed data-protection impact assessment. [Internal: DPIA before launch; appoint DPO if required.]
HIPAA
HIPAA, the US health-privacy law, applies to "covered entities" — health plans, clearinghouses, and providers who bill electronically — and to their "business associates". A consumer product used directly by individuals is generally outside HIPAA's scope unless it is offered through such a partner.
We say "HIPAA-aligned", and we mean it precisely: we design our safeguards to the standard of the HIPAA Security Rule — encryption in transit and at rest, role-based access on a minimum-necessary basis, audit logging, and breach response procedures [confirm each with engineering] — without claiming a compliance status that would only attach through a healthcare partnership. If Mendai is offered through US healthcare partners, we will operate under business associate agreements and state our HIPAA status explicitly.
What we will not do
- Sell personal data, on the website or in the product.
- Run advertising trackers on surfaces where people talk about their recovery.
- Use identifiable therapeutic content to train models without separate, explicit, revocable consent.
Questions
Ask us anything about this at [privacy@mendai.tech]. If you are a clinician or partner with a due-diligence questionnaire, we are happy to complete it.