Privacy Policy
This site collects very little on purpose: no cookies, no third-party trackers, and a contact form you choose to fill in. Here is exactly what we process and why.
1. Who is responsible
The controller for personal data collected on mendai.tech is MendAI AS. Contact: privacy@mendai.tech.
2. What this policy covers
This policy covers the mendai.tech website and its preview form. It does not cover the Mendai application: the app will have its own privacy notice, presented before first use, covering any health-related data it processes.
This website does not ask for health information. The message field on the preview form is free text — please do not include details about your health or anyone else's. If you do, we treat them as confidential, use them only to respond to you, and delete them on request.
3. What we collect and why
Preview form. Name, email address, the topic you pick, and your message. We use these to respond and, if you asked for early access, to contact you about the preview program. Legal basis: taking steps you request before entering a contract (GDPR art. 6(1)(b)) and our legitimate interest in responding to inquiries (art. 6(1)(f)). Marketing beyond that happens only with your consent (art. 6(1)(a)), which you can withdraw at any time.
First-party analytics. Our own analytics records the page path, referring page, a coarse viewport size (small / medium / large), any utm_ campaign tags in the link you clicked, and a random session id that lives only in your browser tab's memory. It sets no cookies, stores nothing on your device, does not fingerprint, and cannot recognize you when you return. It also respects your browser's Global Privacy Control and Do Not Track signals. Legal basis: our legitimate interest in understanding aggregate site usage (art. 6(1)(f)).
Server and delivery logs. Our hosting infrastructure (AWS) records standard technical logs — IP address, user agent, timestamps, requested URLs — for security, abuse prevention, and service delivery. Legal basis: legitimate interest (art. 6(1)(f)). Retention: [30–90 days — confirm with engineering].
4. Cookies
The Site sets no cookies and stores nothing in your browser — no analytics cookies, no advertising cookies, no local storage. That is why there is no cookie banner.
5. Who receives your data
We do not sell personal data and we do not share it with advertisers. Our processors are: Amazon Web Services (hosting and form processing in the EU, Stockholm region eu-north-1; content delivery via its global edge network) and [email / CRM provider — to be confirmed]. Processors act under data-processing agreements and only on our instructions.
6. International transfers
Form submissions and analytics are received and stored in the EEA ([confirm backend region and any sub-processors outside the EEA]). Public website files are cached on CDN edge servers worldwide; these contain no personal data. Where any transfer outside the EEA occurs, we rely on adequacy decisions or standard contractual clauses.
7. How long we keep data
Preview-form data: until you ask us to delete it, and at most [12 months] after our last contact. Analytics: kept as aggregate statistics; raw events are deleted after [x months]. Logs: [30–90 days]. [All retention periods to be confirmed internally.]
8. Your rights
Under the GDPR you can ask for access to your data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time. Write to [privacy@mendai.tech]; we respond within one month. You can also complain to your supervisory authority — for us, [Datatilsynet (Norway) — confirm lead authority].
9. Children
The Site is not directed at anyone under 18, and we do not knowingly collect children's data. If you believe a minor has submitted the form, contact us and we will delete the data.
10. Security
All traffic is encrypted in transit (TLS). Access to submitted data is limited to the people who need it, and hosting runs in the EEA. [Confirm encryption at rest and access-control specifics with engineering before publication.]
11. Changes and contact
We will update this policy as the Site changes and revise the effective date above. Questions: [privacy@mendai.tech]. See also Data protection at Mendai for our GDPR and HIPAA posture.