PRIVACY
Privacy Policy
How we process the personal data of those who request access to Medars and of those who are already members, in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
LAST UPDATED: AUGUST 2026
1. Data controller
NEOHYAL OÜ is responsible for the processing of personal data collected via this website and the app Med-ars.com.
Contact email address for data protection matters: info@med-ars.com
The company’s full identification details will be included once the incorporation and registration procedures have been completed.
2. Data we process
Access request details: full name, registration number, medical association, specialism, years of practice, clinic or place of work, town or city, telephone number, email address and professional social media profile.
Verification details: supporting documentation proving membership of a professional body and, where applicable, an identity document provided to confirm the applicant’s identity.
Membership and billing details: membership tier, subscription history, courses purchased and data required for issuing invoices. Card details are processed directly by the payment provider and Med-ars.com It does not store them.
Usage data: technical information relating to navigation and activity within the application, as set out in the cookie policy.
Med-ars.com it does not request or process patients’ health data. Professional registration details do not constitute special categories of data within the meaning of Article 9 of the GDPR, but are processed with enhanced safeguards due to their nature as proof of professional status.
3. Purposes and legal bases
Check your status as a healthcare professional and to process the request for access. Legal basis: the performance of pre-contractual measures at the request of the data subject (Article 6(1)(b) of the GDPR) and a legitimate interest in ensuring the integrity of a closed professional community (Article 6(1)(f)).
Provide the membership service, to manage access to content, the community, the shop and concierge services. Legal basis: performance of the contract (Art. 6.1.b).
Manage collections, invoicing and tax obligations. Legal basis: performance of the contract and compliance with legal obligations (Articles 6(1)(b) and 6(1)(c)).
Send operational communications relating to membership, changes to services or security notices. Legal basis: performance of the contract.
Send marketing communications regarding new masterclasses, events or services. Legal basis: consent of the data subject, which may be withdrawn at any time (Art. 6(1)(a)).
Analysing website and app usage to improve the service. Legal basis: consent for non-essential cookies and legitimate interest in improving the product.
4. Retention periods
Data relating to rejected applications are retained for a maximum of twelve months from the date of the decision, unless the data subject requests their erasure before then.
Member data is retained for as long as membership remains active and, following termination, for the duration of the limitation periods applicable to legal, tax and accounting obligations.
Verification documents are retained only for as long as is necessary to demonstrate that due care has been taken in verifying membership of the professional body.
5. Recipients and data processors
Med-ars.com It works with suppliers who act as data processors, under a contract in accordance with Article 28 of the GDPR: infrastructure and databases, video hosting, payment gateways, transactional email and analytics.
The core data infrastructure is hosted on servers located in the European Union. Where a supplier involves international data transfers, these are covered by adequacy decisions or standard contractual clauses approved by the European Commission.
Med-ars.com It does not sell or pass on personal data to third parties for advertising purposes.
6. Rights of data subjects
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and data portability at any time, as well as withdraw any consent you have given, by writing to info@med-ars.com.
If you believe that the processing does not comply with the regulations, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
7. Safety
Med-ars.com It implements technical and organisational measures to protect data against unauthorised access, loss or alteration, including encryption in transit, role-based access control and security policies at database level.
Access to the verification documentation is restricted to the staff responsible for carrying out such checks.
8. Minors
The services of Med-ars.com are intended exclusively for registered healthcare professionals and, therefore, adults. They are not intended for or provided to minors.
9. Changes to this policy
This policy may be updated to reflect changes in regulations or to the service. Members will be notified of any substantial changes by email.