Skip links

Last updated: July 16, 2026

This Privacy Policy describes the policies and procedures of MedSyntra Inc. regarding the collection, use, disclosure and protection of information when You use the Service. It also explains Your privacy rights and how applicable laws may protect You.

MedSyntra provides healthcare artificial intelligence infrastructure for institutional deployment, including controlled data environments, secure data ingestion, de-identification, governance and permission-based access. We use Personal Data to provide, maintain, secure and improve the Service. By using the Service, You acknowledge the practices described in this Privacy Policy.

Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

  • Account means a unique account created for You to access our Service or parts of our Service.
  • Company (referred to as either “the Company”, “We”, “Us” or “Our” in this Privacy Policy) refers to MedSyntra Inc., 16192 Coastal Highway, Lewes, Delaware 19958, County of Sussex, United States.
  • Customer means a healthcare institution, hospital network, government authority, research organization, pharmaceutical organization, approved technology provider or other entity that enters into an agreement with MedSyntra or uses the Service.
  • Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
  • Country refers to the State of Delaware, United States.
  • Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
  • Personal Data is any information that relates to an identified or identifiable individual.
  • Service refers to the MedSyntra Website, software, platform, institutional infrastructure, applications and related services.
  • Service Provider means any natural or legal person that processes information on behalf of the Company or provides services supporting the operation, hosting, security, maintenance, analysis or delivery of the Service.
  • Usage Data refers to data collected automatically through the use of the Service or generated by the Service’s technical infrastructure, such as access, performance, diagnostic, security and activity information.
  • Website refers to MedSyntra, accessible from https://www.medsyntra.com.
  • You means the individual accessing or using the Service, or the company, institution or other legal entity on behalf of which that individual accesses or uses the Service, as applicable.

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

The Personal Data We collect depends on how You interact with MedSyntra and which parts of the Service You use. When You contact Us, request information or a demonstration, create an Account, use the Service, request support or enter into a business relationship with Us, We may collect information including, but not limited to:

  • Contact and professional information, including Your name, business email address, telephone number, job title, employer or institution, country or region, and the content of messages or requests You send to Us.
  • Account and authentication information, including account identifiers, login information, authentication tokens, organization or tenant details, user roles, permissions, preferences and security logs.
  • Marketplace and subscription information, where applicable, including Microsoft tenant or directory identifiers, Marketplace subscription identifiers, offer or plan details, provisioning status and information required to activate, administer, support or cancel the Service.
  • Commercial and support information, including meeting details, deployment requirements, licensing or procurement information, support communications and other information You choose to provide.

Institutional and Healthcare-Related Data

Depending on the applicable Customer agreement and deployment, the Service may process healthcare, clinical, medical-imaging, operational, research or other regulated information supplied or controlled by Customers. The exact categories of information, purposes of processing, permitted users, retention periods, security requirements and responsibilities of the parties are defined by the applicable agreements, deployment documentation and law.

Where appropriate, institutional data may be de-identified, pseudonymized, encrypted, aggregated or access-restricted before it is made available for an authorized purpose. MedSyntra does not acquire ownership of Customer data merely because it is processed through the Service. Please do not submit patient records, medical images or other sensitive healthcare information through public Website forms unless MedSyntra has expressly provided an authorized secure method.

Usage Data

Usage Data is collected automatically when You access or use the Service.

Usage Data may include Your Device’s Internet Protocol address, browser type and version, Device type, operating system, language and regional settings, pages or features accessed, the date and time of access, time spent on the Service, referring source, session or Device identifiers, and application, performance, diagnostic, audit or security information.

When You access the Service through a mobile Device, We may automatically collect information such as the type of mobile Device, mobile operating system, mobile browser, IP address, unique Device identifiers and diagnostic information.

We may also collect information that Your browser, Device, identity provider or institutional environment sends when You visit or use the Service.

Tracking Technologies and Cookies

We use Cookies and similar technologies to operate, secure, analyze and improve the Service. Depending on Your choices and applicable law, these technologies may include browser Cookies, tags, scripts, pixels and local storage.

  • Cookies or Browser Cookies. A Cookie is a small file placed on Your Device. You can instruct Your browser to refuse Cookies or indicate when a Cookie is being sent. If You do not accept certain Cookies, some parts of the Service may not function correctly.
  • Similar Technologies. Certain parts of the Service or Our communications may use tags, scripts, pixels or similar technologies to support security, measure performance, understand use of the Service and verify system integrity.

Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.

We use both Session and Persistent Cookies for the purposes set out below:

  • Necessary / Essential Cookies

Type: Session Cookies

Administered by: Us

Purpose: These Cookies are required to provide the Website and Service, maintain security, authenticate users, manage sessions, prevent fraudulent activity and enable essential functionality.

  • Cookies Policy / Notice Acceptance Cookies

Type: Persistent Cookies

Administered by: Us

Purpose: These Cookies record whether users have accepted, rejected or configured their Cookie preferences.

  • Functionality Cookies

Type: Persistent Cookies

Administered by: Us

Purpose: These Cookies allow Us to remember choices You make, such as login information, language preferences, regional settings or other Service preferences, so You do not need to re-enter them each time You use the Service.

Where required by law, non-essential Cookies are activated only after You provide consent. You can manage Your choices through the Cookie banner or Your browser settings.

Use of Your Personal Data

The Company may use Personal Data for the following purposes:

  • To provide and maintain Our Service, including operating institutional infrastructure, enabling authorized access, monitoring availability, security, performance and use, and supporting approved deployments.
  • To manage Your Account: to register and authenticate users, administer roles and permissions, manage organization or tenant access and provide the functions available to authorized users.
  • For the performance of a contract: to provide requested demonstrations, pilot programs, infrastructure deployments, subscriptions, licensing, support and other services under an agreement with You or Your organization.
  • To contact You: to respond by email, telephone, online meeting or other appropriate communication methods regarding inquiries, Account activity, deployment matters, support, security notices and important Service updates.
  • To provide relevant information: to send news or information about Our services where permitted by law and where You have not opted out of such communications.
  • To manage Your requests: to respond to inquiries, meeting requests, support cases, privacy requests, complaints and feedback.
  • For business transfers: to evaluate or complete a merger, financing, acquisition, restructuring, reorganization, sale of assets or similar corporate transaction in which Personal Data may be among the transferred assets.
  • For other purposes: to analyze usage, identify trends, troubleshoot technical issues, maintain security and audit records, improve functionality and user experience, conduct internal research and quality assurance, comply with legal obligations, and establish, exercise or defend legal claims.

We may share Your personal information in the following situations:

  • With Service Providers: We may share Personal Data with providers of cloud infrastructure, hosting, identity and authentication, cybersecurity, storage and backup, customer support, communications, scheduling, analytics, software development and professional services. They may process information only for authorized purposes and subject to appropriate obligations.
  • With Microsoft: if the Service is offered through Microsoft Marketplace or uses Microsoft Entra ID, Microsoft Azure or related Microsoft services, information may be exchanged with Microsoft where necessary for authentication, hosting, provisioning, subscription management, security, support or Marketplace operations.
  • For business transfers: We may share or transfer Personal Data in connection with, or during negotiations concerning, a merger, financing, acquisition, reorganization, sale of Company assets or similar corporate transaction.
  • With Affiliates: We may share information with Our parent company, subsidiaries or entities under common control, provided they protect the information consistently with this Privacy Policy and applicable law.
  • With business and institutional partners: We may share limited information where necessary to provide a requested Service, manage an approved partnership or deployment, or fulfil a contractual obligation.
  • With Customers and authorized administrators: if You use the Service through Your employer, institution or another Customer, authorized administrators may have access to relevant Account, role, subscription, access and activity information. Institutional data is made available only according to applicable agreements, permissions and governance controls.
  • With Your consent: We may disclose Personal Data for another purpose when You have instructed Us or provided Your consent.

Retention of Your Personal Data

The Company retains Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing and supporting the Service, maintaining Accounts and subscriptions, meeting contractual obligations, maintaining security and audit records, complying with legal requirements, resolving disputes and enforcing agreements.

The applicable retention period depends on the category of information, the nature of the Service, Customer instructions, contractual requirements, security needs and applicable law. Institutional and healthcare-related data is retained according to the relevant Customer agreement and deployment configuration. When information is no longer required, it may be deleted, anonymized, aggregated or securely isolated, as appropriate.

Transfer of Your Personal Data

Personal Data may be processed in locations where the Company, its Customers or its Service Providers operate. This means information may be transferred to or maintained in a jurisdiction with privacy laws that differ from those in Your location.

Where required by applicable law, MedSyntra uses appropriate safeguards for international transfers, which may include data-processing agreements, standard contractual clauses, contractual security obligations or other recognized transfer mechanisms.

Institutional deployments may also be configured to support Customer requirements concerning local hosting, national data boundaries, data residency, access limitations and security controls. The Company takes reasonable steps designed to ensure that Personal Data is treated securely and in accordance with this Privacy Policy.

Your Privacy Rights and Deletion of Personal Data

Depending on Your location and applicable law, You may have the right to request access to, correction of, deletion of, restriction of or portability of Your Personal Data, to object to certain processing, to withdraw consent and to lodge a complaint with a competent data-protection authority.

The Service may allow You to update or delete certain information directly through Your Account settings.

You may also contact Us to exercise an applicable privacy right. We may request information necessary to verify Your identity and authority. Where MedSyntra processes Personal Data solely on behalf of a Customer, We may refer Your request to that Customer or ask You to contact the relevant institution directly.

We may retain certain information where necessary to comply with a legal obligation, fulfil a contractual requirement, maintain security records, prevent fraud, resolve disputes or enforce Our agreements. Deleting an individual Account may not require deletion of information controlled by an institutional Customer.

Disclosure of Your Personal Data

Business Transactions

If the Company is involved in a merger, acquisition, financing, restructuring or asset sale, Personal Data may be transferred as part of that transaction. Where required, We will provide notice before Personal Data becomes subject to a materially different Privacy Policy.

Law enforcement

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Other legal requirements

The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of the Company
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of Users of the Service or the public
  • Protect against legal liability

Security of Your Personal Data

The security of Personal Data is important to Us. We use administrative, technical, organizational and physical safeguards designed to protect Personal Data against unauthorized access, use, disclosure, alteration, loss, misuse or destruction. Depending on the Service and deployment, these safeguards may include encryption, identity and access management, role-based permissions, logging, monitoring, audit trails, backups, data minimization and de-identification or pseudonymization. No method of Internet transmission or electronic storage is completely secure, and We cannot guarantee absolute security.

Children’s Privacy

The public Website and general business services are intended for organizations, institutions and adult professional users and are not directed to children under the age of 18. We do not knowingly collect Personal Data directly from children through the public Website or general business communications.

Healthcare or institutional data relating to minors may be processed through an authorized Customer deployment where permitted by law and governed by the applicable agreements, permissions, safeguards and privacy notices. If You believe a child has provided Personal Data directly to MedSyntra without appropriate authorization, please contact Us.

Links to Other Websites

The Service may contain links to websites or services that are not operated or controlled by Us. If You follow a third-party link, You will be directed to that third party’s website or service. We encourage You to review its privacy policy before providing Personal Data.

We have no control over and assume no responsibility for the content, privacy policies, security or practices of independent third-party websites or services.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to Our services, processing practices, technology, legal requirements, regulatory obligations or organizational structure.

We will publish the updated Privacy Policy on this page and revise the “Last updated” date. Where required by law, We may also provide notice of material changes through the Website, the Service, email or another appropriate communication method.

You are advised to review this Privacy Policy periodically. Changes become effective when they are published on this page unless otherwise stated.

Contact Us

If You have any questions, requests or concerns about this Privacy Policy or the way MedSyntra processes Personal Data, You can contact Us:

MedSyntra Inc., 16192 Coastal Highway, Lewes, Delaware 19958, County of Sussex, United States

By email: info@medsyntra.com