Medra Privacy Policy
Last updated: June 18, 2025
Medra ("Medra," "we," "us," or "our") is committed to protecting your privacy and handling personal information responsibly. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you interact with our websites, platform, and related services (collectively, the "Services").
This Policy is designed to comply with international privacy standards, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA/CPRA), and other global data protection frameworks.
1. Important Platform Deployment Context
Medra's software platform is deployed into each customer's own environment (e.g., their cloud infrastructure or on-premises environment). As a result:
- Medra does not store, access, or process customer production data within Medra's systems, unless explicitly agreed for support or troubleshooting.
- Customer data remains fully under the customer's control in their own environment.
- Medra acts as a Service Provider / Processor only with respect to limited diagnostic or support-related data, if provided by the customer.
Any personal information described in this Policy refers primarily to information related to:
- Visitors to our website
- Individuals who interact with Medra for sales, support, marketing, or account management
- Limited technical metadata related to use and operation of the platform (not customer production data)
2. Information We Collect
A. Information You Provide Directly
- Name, email address, phone number
- Company name and role
- Login or authentication-related information
- Communications sent to us (support tickets, emails, chats)
- Billing or invoicing information (handled by third-party processors)
B. Information Related to Website or Platform Usage
We may collect limited technical metadata such as:
- IP address and browser information
- Device type and operating system
- Interaction logs for our website or the Medra-controlled services
- Cookie and tracking information (for the website only)
We do not collect customer production data generated within the deployed platform inside the customer's own environment.
C. Information from Third Parties
We may receive limited information from:
- CRM and sales systems
- Analytics tools
- Business partners
- Identity verification or authentication solutions
D. Sensitive Personal Data
We do not intentionally collect sensitive personal data.
3. How We Use Personal Information
We use personal information only for:
- Delivering and supporting the Services
- Managing customer accounts and subscriptions
- Responding to inquiries, support requests, and feedback
- Improving our website, product experience, and documentation
- Conducting analytics to improve performance
- Communicating updates, announcements, and administrative information
- Ensuring security and compliance
- Fulfilling legal obligations
We do not use customer production data because we do not store or process it.
4. Legal Bases for Processing (GDPR)
If you are in the EEA/UK, we process personal data under:
- Contract performance
- Legitimate interests (product improvement, security, communication)
- Consent (marketing preferences)
- Legal obligations
5. How We Share Personal Information
We may share limited personal information with:
A. Service Providers / Subprocessors
For activities such as:
- Hosting for Medra's website and backend services
- Analytics
- Support tools
- Billing systems
- Communications systems
These providers do not receive any customer production data from the deployed platform.
B. Legal and Compliance
If required by applicable law or lawful request.
C. Business Transactions
If Medra undergoes a merger, acquisition, or asset transfer.
Medra does not sell personal information under CCPA/CPRA.
6. International Data Transfers
We may transfer personal information to regions outside your own (e.g., United States, Europe). To protect your data, we use appropriate safeguards such as:
- Standard Contractual Clauses
- Adequacy decisions
- Data Processing Agreements
- Technical and organizational security measures
7. Your Privacy Rights
Depending on your jurisdiction, you may have the right to:
- Access your personal information
- Correct inaccurate data
- Request deletion
- Object to certain processing
- Restrict processing
- Request portability
- Withdraw consent
- Opt out of marketing communications
California Residents (CCPA/CPRA)
You may also:
- Request to know what personal information we collect
- Request deletion
- Request correction
- Opt out of data sharing for cross-context behavioral advertising
- Exercise rights without discrimination
You can exercise any rights by contacting us at privacy@medra.ai.
8. Cookies and Tracking Technologies
We use cookies on Medra-controlled websites for:
- Essential functionality
- Analytics and performance
- Remembering preferences
You may manage cookies via your browser settings or applicable cookie banners.
The deployed platform inside customer environments uses only the cookies configured or controlled by the customer.
9. Data Retention
We retain personal information only as long as:
- Necessary to provide the Services
- Required by contract with customers
- Required by law
- Needed for security or compliance
We do not retain customer production data.
10. Data Security
We apply administrative, technical, and physical controls to protect personal information, including:
- Encryption
- Access control
- Security monitoring
- Vulnerability management
- Incident response capabilities
Customers are responsible for securing their own deployed environments.
11. Children's Privacy
Medra does not target or offer Services to children under 16 and does not knowingly collect personal data from minors.
12. Third-Party Websites and Integrations
Our website may contain links to external sites.
We are not responsible for their privacy practices and encourage reviewing their privacy notices.
13. Updates to This Privacy Policy
We may update this Privacy Policy periodically.
Updates will be posted with a new "Last Updated" date.
Significant changes will be communicated as required.
14. Contact Us
For questions about this Policy or your personal information:
Medra, Inc.
Email: privacy@medra.ai
Website: https://www.medra.ai
Address: 1301 Folsom Street, San Francisco, CA 94104, United States