Privacy Policy
Effective date: 22 July 2026
Version: 3
1. Introduction
Mediora is an AI-powered tool that helps adults understand their personal lab test results.
The service is operated by SLAtech Ltd, an Israeli company (company number 515518926)
with registered offices at HaShayetet 8, Rishon LeZion, Israel. References in this policy
to "we", "us", "Mediora", or "the service" mean SLAtech Ltd acting as the controller of
your personal data.
This policy explains what personal data we collect when you use Mediora, why we process it,
who we share it with, and which rights you have under the EU General Data Protection
Regulation (GDPR) and the Israeli Privacy Protection Law, 5741-1981 (PPL).
2. What data we collect
Account data. Email address, preferred language, optional first / last name, date of
birth, sex, phone number, chronic conditions and medications you choose to share in your
profile. Your date of birth is required by our 18+ age gate.
Health data (GDPR special category under Article 9). Lab reports you upload
(PDF / images), lab markers we extract from them, AI-generated analyses and trend
narratives, messages you exchange with the AI assistant, and the record of whether a
message triggered one of our safety filters.
Technical data. IP address, browser user agent, browser language, approximate
geolocation inferred from IP, and the session cookies listed in our Cookies Policy.
Usage data. Which features you use (uploads, report views, chat interactions), email
delivery history (welcome, analysis-ready, critical-alert), and admin audit log entries
that relate to your account when a staff member interacts with it.
Funnel and abandonment data. When you begin one of our forms — in particular the doctor
application — and enter an email address but do not complete and submit it, we retain that email
address together with the step you reached and the language you used. We use this only to
understand where people stop, to send a single short "what got in the way" survey, and to improve
the flow. You can ask us to delete it at any time (see Section 8).
Study materials (section for medics). If you create a student account and upload
study material — lecture notes, a summary, a handout — we store the file itself, the text
extracted from it, the fragments that text is split into, and the numeric vector
representations of those fragments used for search. The file is kept in a storage bucket
separate from medical reports, because the two have different retention periods and
different grounds for processing. Your material is visible only to you: it is not
published, not shown to other users, and never added to a shared question bank. No health
data is involved unless you choose to upload a lab report, which is covered above.
3. Legal basis for processing (GDPR Article 6 + Article 9)
We process your personal data on the following legal bases:
- Contract performance — Art. 6(1)(b). Delivering the core product: parsing your
reports, generating analyses, emailing you when they're ready, maintaining your history. - Consent — Art. 6(1)(a). Analytics cookies, marketing emails (opt-in in Profile),
non-essential features such as similar-case comparison, and early-access signup for the
section for medics — given by its own checkbox and confirmed through a link we email you. - Vital interests — Art. 6(1)(d). Sending "critical marker" alerts when one of your
results is clinically significant — we treat these as a safety issue, not a marketing
channel. - Special-category explicit consent — Art. 9(2)(a). Processing your health data
requires a separate affirmative consent, captured on signup as part of the "I accept
the Privacy Policy" checkbox. You can withdraw this consent at any time by deleting
your account (see Section 8).
Under the Israeli PPL we rely on §11 for processing with the data subject's consent and on
§2(9) for processing that is necessary to provide the service you requested.
4. How we use your data
- Run the analysis pipeline that processes your lab reports and produces the report you
see in the app. - Send transactional emails: account welcome, analysis-ready notification, critical-marker
alert, re-engagement nudge if you never returned after signup. - Track longitudinal trends across multiple uploads for the same marker.
- Improve the service using aggregated, de-identified metrics. We do not use your
identifiable data to train AI models. - Detect abuse (rate limits, spam, repeated safety-filter triggers).
5. Recipients of your data (processors)
We share the minimum necessary personal data with the following processors to provide the
service. This is the full list of recipients required by GDPR Article 13:
| Processor | Purpose | Location | Safeguards |
|---|---|---|---|
| OpenAI | AI analysis of lab reports, chat responses, and reading the text out of study material you upload | United States | Data Processing Agreement with a no-training-on-your-data clause; Standard Contractual Clauses for EU personal-data transfers |
| Amazon Web Services — S3 | Secure storage of your uploaded files — lab reports and study materials, in separate buckets | United States (AWS, us-east-1) | Server-side encryption at rest; Data Processing Agreement; Standard Contractual Clauses |
| Amazon Web Services — Textract | Redaction of patient identifiers before AI processing | United States (AWS, us-east-1) | Data Processing Agreement; Standard Contractual Clauses |
| Amazon Web Services — SES | Delivery of transactional email | United States (AWS, us-east-1) | Data Processing Agreement; Standard Contractual Clauses |
| Qdrant (vector search) | Semantic similarity search over the text of your reports, your analysis history and your study materials | Germany (Contabo GmbH) | Data Processing Agreement + Standard Contractual Clauses (Module 3); stored and processed within the EU (Germany); user-level isolation — every query is strictly filtered to your data |
| Primary application database, application and background processing | Storing and processing your account and analysis data | United States (Contabo Inc., US-East) | Data Processing Agreement + Standard Contractual Clauses (Module 3); access controls, encryption at rest |
| Cloudflare | Content delivery, DDoS protection and cookieless aggregate performance analytics | United States (Cloudflare, Inc.; global edge network) | Data Processing Addendum; Standard Contractual Clauses |
All processors are contractually bound to:
- Process your data only to provide the service to you.
- Implement appropriate technical and organisational security measures.
- Never use your health data to train AI models.
- Return or delete your data when our contract with them ends.
We do not sell personal data, and we do not share it with advertisers.
6. International data transfers
When we use processors located outside your country, we apply the safeguards required
by GDPR and the Israeli Privacy Protection Law:
- EU users: transfers to the United States are covered by the European Commission's
Standard Contractual Clauses (SCCs). - All users: Israel is currently recognised by the European Commission as providing
an adequate level of data protection (Decision 2011/61/EU). - Processors in other countries: bound by our Data Processing Agreement with
equivalent safeguards.
You can request the specific transfer mechanisms in use by emailing support@mediora.ai.
7. Retention
- Account active: we retain your data while your account is active.
- Account deleted (user-initiated): 30-day grace period during which you can cancel,
then permanent hard delete (see Section 8). The only data we retain after hard delete
are aggregated, irreversibly de-identified metrics. - Chat history: retained while your account is active; you can soft-delete
individual messages from the sidebar. - Early-access signups: retained while we prepare the launch of the educational
section. There is no scheduled auto-deletion — we delete the record when you ask us to
(support@mediora.ai) or when you create an account. - Study materials: retained while your account is active. Deleting a material
removes the file, the text extracted from it, its fragments and their search vectors.
Deleting your account removes all of them. - Backups: rolling 90-day encrypted backups; hard deletes propagate into the current
backup within 24 hours and drop out of rotation within 90 days.
8. Your GDPR rights
You can exercise the following rights at any time, free of charge:
- Access (Art. 15). The Profile page includes a "Download my data" button that
exports a machine-readable JSON bundle of everything we hold about you, including
the specific names of the processors we have shared data with. - Rectification (Art. 16). Edit your profile directly; lab-marker values can be
corrected in the analysis editor. - Erasure (Art. 17). The Profile page includes a "Delete my account" button that
triggers the 30-day deletion flow described in Section 7. - Restriction (Art. 18). Contact support@mediora.ai.
- Portability (Art. 20). Same export button as for Access.
- Object (Art. 21). Contact support@mediora.ai.
- Withdraw consent. Any consent you gave (analytics cookies, marketing emails) can
be withdrawn from the Profile page without affecting the lawfulness of prior processing.
9. Israeli PPL rights
Israeli data subjects have equivalent access rights under §13 of the PPL and may request
correction of inaccurate data under §14. To exercise these rights, email
support@mediora.ai from the address on your Mediora account.
10. Security measures
Transport: industry-standard encryption in transit for every browser-to-server
connection.Authentication: short-lived session tokens + one-time-passcode login (no password
stored on your device).Infrastructure: private network segmentation, firewalled database, least-privilege
service accounts, encrypted logs.Chat safety: a multi-layer content filter (input screening, refusal templates,
output review) so the assistant cannot produce prescriptions or diagnoses.Encryption at rest: extracted patient identifiers (name, date of birth, ordering
doctor) are encrypted at rest in our primary database under a managed-key scheme.
11. Children
Mediora is a service for adults. We do not knowingly collect personal data from anyone
under 18. You must tick an explicit "I am 18 or older" checkbox on signup, and the
service will refuse to save a profile whose date of birth corresponds to an under-18 age.
If you believe a minor has created an account, please email support@mediora.ai and we
will delete it.
12. Changes to this policy
We will notify you by email at least 30 days before a material change takes effect. For
changes that affect the legal basis of processing or add a new category of data, we will
ask for your fresh consent before continuing to process your data under the new terms.
13. Contact
- Controller: SLAtech Ltd, company number 515518926, HaShayetet 8, Rishon LeZion, Israel.
- Privacy contact: support@mediora.ai.
14. Supervisory authority
EU-based users have the right to lodge a complaint with the national data-protection
authority where they live or work.
Israeli users may contact the Privacy Protection Authority (Ministry of Justice).