Legal
Privacy Policy
Last updated: August 2025
The Short Version
Asclevor processes no patient data. Ever. We provide medical reference data to developers via an API, which means the only personal data we hold is yours — the developer's — plus minimal technical data required to run the Service. This policy explains what we collect, why, and the rights you have under the GDPR.
1. Who We Are
Asclevor is the controller of the personal data described in this policy. You can reach us at privacy@asclevor.com for any privacy-related request.
2. What We Collect
- Account data: name, email address, and organization when you sign up for an API key.
- Billing data: handled by our payment processor (Stripe). We never store full card numbers.
- Usage data: API request metadata such as endpoint called, timestamp, response status, and rate-limit counters.
- Query analytics: aggregated patterns of which conditions, symptoms, and endpoints are queried most, used to improve dataset coverage and quality.
- Technical data: IP addresses in server logs for security and abuse prevention, retained for a limited period.
3. What We Do Not Collect
- No patient records, health records, or other sensitive health data;
- No end-user personal data from applications built on the API;
- No advertising or cross-tracking cookies on this website;
- No selling of personal data to third parties.
4. Why We Process Your Data (Legal Bases)
- Contract (Art. 6(1)(b) GDPR): to provide the API, authenticate requests, meter usage, and bill paid tiers.
- Legitimate interests (Art. 6(1)(f)): to secure the Service, prevent abuse, and improve dataset coverage based on aggregate query patterns.
- Consent (Art. 6(1)(a)): for optional communications such as changelog newsletters, which you can unsubscribe from at any time.
5. Where Your Data Lives
All infrastructure is hosted within the European Union. We do not transfer personal data outside the EU unless adequate safeguards under Chapter V GDPR are in place. As an EU-based vendor, we deliberately avoid exposing our customers to CLOUD Act jurisdiction risk.
6. Processors We Use
We rely on a small set of vetted sub-processors to operate the Service, including hosting providers, our payment processor, transactional email delivery, and privacy-first analytics. A current list is available on request. All processors are bound by data processing agreements consistent with Art. 28 GDPR.
7. Retention
Account and billing records are retained for the duration of your subscription and as required by commercial and tax law. Server logs containing IP addresses are rotated within 30 days. Aggregated, anonymized query statistics may be retained indefinitely since they do not constitute personal data.
8. Your Rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interests. To exercise any of these rights, email privacy@asclevor.com — we respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
9. Security
All API traffic is encrypted in transit via TLS. Access to internal systems follows the principle of least privilege, and we are working toward ISO 27001 certification as part of our enterprise readiness roadmap.
10. Changes
If we make material changes to this policy, we will notify you by email or through the Service before the changes take effect.