MedControl Privacy Policy

Last updated: June 12, 2025

1. Introduction

Welcome to MedControl. Your privacy is fundamental to us. This Privacy Policy explains what personal data we collect from our users («you»), how we use it, with whom we share it, and the rights you have over your data.

By using the MedControl application («the App»), you agree to the practices described in this policy.

Data Controller:

For the purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, the data controller for your data is:

SHELBY CODE SL Calle Rio Duero 33, 1C, 28913, Leganés, Spain. Contact email for privacy matters: appmedcontrol@gmail.com

2. Personal Data We Collect

We collect information to provide you with an effective and personalized service. The data can be grouped into the following categories:

a) Information You Provide Directly:

  • Account Registration Data: When you create an account in MedControl, we collect information such as your name, email address, and optional demographic data like gender, date of birth, weight, and height, which are necessary to calculate metrics like BMI.
  • Health and Wellness Data: This is the main information you record in the App and includes, among others:
    • Medication, dosage, and frequency.
    • Reminders and intake confirmations.
    • Measurements of vital signs (blood pressure, blood glucose, temperature, heart rate, oxygen saturation).
    • Symptom logging, including intensity and associated notes.
    • Laboratory analysis results that you enter manually.
    • Information about medical appointments and check-ups.
    • Medical files and documents you upload to the library.
  • Communications: If you contact us via email, we will keep a record of that correspondence.

b) Information We Collect Automatically:

  • Usage and Technical Data: We collect information about your interaction with the App, such as the features you use, the pages you visit, and technical data like device type, operating system, unique device identifiers, and crash data. This information is collected in an aggregated and anonymous form whenever possible.

3. Purpose and Legal Basis for Processing Your Data

We use your personal data for the following purposes, based on a legal justification (legal basis) according to the GDPR:

Purpose of Processing Types of Data Used Legal Basis (GDPR)
Providing and managing the MedControl service Registration Data, Health Data Performance of a contract (the Terms of Use you agree to when using the App).
Improving and personalizing the App Usage and Technical Data, Health Data (anonymized and aggregated) Legitimate interest to improve our service and user experience.
Communicating with you (technical support, important service notifications) Registration Data (email) Performance of a contract and Legitimate interest.
Sending marketing communications and newsletters (optional) Registration Data (email) Explicit consent (only if you actively subscribe).
Analysis and statistical studies Usage and Technical Data, Health Data (anonymized and aggregated) Legitimate interest to understand App usage and make business decisions.
Complying with legal obligations All relevant data Legal obligation.

4. How We Share Your Personal Data

Your trust is our priority. We do not sell or rent your personal data to third parties. We only share your information in the following limited circumstances:

  • Service Providers: We may share data with companies that provide services to us, such as cloud hosting providers (e.g., Google Firebase, AWS) or performance analysis tools. These providers are contractually obligated to protect your data and can only use it for the specific purposes we entrust to them.
  • Legal Requirements: We may disclose your information if required by law, court order, or a valid governmental request, or to protect our rights, property, or safety, as well as those of our users.
  • Business Transactions: If the company is involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice before your personal data is transferred and becomes subject to a different Privacy Policy.

5. Your Data Protection Rights (GDPR Rights)

As a user in the European Union, you have the following rights over your personal data:

  • Right of Access: You have the right to request a copy of the personal data we hold about you.
  • Right to Rectification: You have the right to request the correction of inaccurate or incomplete personal data.
  • Right to Erasure (‘Right to be Forgotten’): You have the right to request the deletion of your personal data under certain circumstances.
  • Right to Restriction of Processing: You have the right to request that we restrict the processing of your data under certain conditions.
  • Right to Data Portability: You have the right to receive your data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
  • Right to Object: You have the right to object to the processing of your personal data based on our legitimate interest.
  • Right to Withdraw Consent: If processing is based on your consent, you can withdraw it at any time.

To exercise any of these rights, please contact us at appmedcontrol@gmail.com. You also have the right to lodge a complaint with a data protection authority, such as the Spanish Data Protection Agency (AEPD).

6. Data Security and Retention

  • Security: We implement technical and organizational security measures to protect your data against unauthorized access, alteration, disclosure, or destruction. This includes data encryption in transit and at rest. However, no method of transmission over the Internet or method of electronic storage is 100% secure.
  • Retention: We will retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. When you delete your account, we will initiate a process to securely and completely delete your information from our systems.

7. International Data Transfers

Your information may be transferred to — and maintained on — computers located outside of your state, province, or country, where data protection laws may differ. If we transfer personal data outside the European Economic Area (EEA), we will ensure that appropriate safeguards are applied, such as the Standard Contractual Clauses approved by the European Commission. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

8. Children’s Privacy

Our services are not directed to anyone under the age of 16 (or the minimum applicable age in your jurisdiction) without parental consent. We do not knowingly collect personally identifiable information from children without such consent. If you are a parent or guardian and you are aware that your child has provided us with personal data without your consent, please contact us so that we can take the necessary steps.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and, if the changes are significant, we will provide a more prominent notice (such as an in-app notification).

10. Medical Disclaimer

MedControl is a support tool to help you manage your health information. It does not provide medical advice, diagnosis, or treatment. It should not be used as a substitute for professional medical consultation. The data and charts presented should be interpreted by a qualified physician or healthcare professional. The use of the App is the sole responsibility of the user. If in any doubt, YOU MUST CONSULT A DOCTOR. The developer is not liable for any loss or damage resulting from the use of the application.

11. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, you can contact us at: appmedcontrol@gmail.com

en_USEnglish