DocumentationSupportCosta Rica · Contact

Last updated:

Who processes your data

Meddyg Sociedad Anónima is the controller of the personal data collected at www.meddyg.com. Any request about this policy or about your data reaches the address below and is answered the same way.

DetailValue
ControllerMeddyg Sociedad Anónima
Company registration (Costa Rica)3-101-753619
AddressSan Francisco, Heredia, Costa Rica
Contact emailhola@meddyg.com

What we collect

There is only one way to give us personal data on this site: the contact form. Everything else is traffic measurement, which never asks for your name and is covered further down.

When you submit the form we collect exactly the fields you see on screen: name, role, email address, organisation, type of organisation, country, project stage, expected timeline, the services and products you tick, and your message. Phone number and preferred channel are optional. Alongside that travel the page you wrote from and the language you were reading it in, so we know what prompted you.

On the technical side, the web server logs what any web server logs: your IP address, the date, the URL requested, your browser and the page you came from. The service that receives the form holds your IP in memory for ten minutes to throttle automated submissions, and writes the organisation and email address of each successful send to its operational log.

There is no database. The form is not stored in any system of ours: it becomes an email, it is sent, and that is where its path through our infrastructure ends.

What we use it for, and on what legal basis

PurposeDataLegal basis
Answering your enquiry and preparing a possible proposalThe form fieldsPre-contractual steps taken at your request (GDPR art. 6(1)(b))
Keeping the form from being abused by scriptsIP address, verification tokenLegitimate interest in protecting the service (art. 6(1)(f))
Keeping the site up and diagnosing failuresWeb server logsLegitimate interest in site security and continuity (art. 6(1)(f))
Knowing how many visits there are and where they come from, without identifying anyoneAggregate cookieless measurementLegitimate interest in knowing the site's reach (art. 6(1)(f))
Understanding which content works and where navigation stallsAudience analytics and session recordingYour consent (art. 6(1)(a))

We do not sell personal data, do not pass it to advertising networks, do not build commercial profiles and take no automated decision that affects you. We also do not send marketing email to anyone who has not asked for it.

Cookies and storage on your device

Without your consent this site stores exactly one thing in your browser: the answer you gave to the cookie notice. We keep it precisely so we do not have to ask again, which is why it needs no permission.

What is storedProviderPurposeDurationConsent required?
meddyg.consent (local storage)MeddygRemembering your cookie decisionUntil you clear the site's dataNo
Temporary verification identifierCloudflare TurnstileTelling a person from a script when the form is submittedThe sessionNo: without it the form cannot be sent
No cookiesCloudflare Web AnalyticsCounting visits without identifying the visitorNo
No cookiesAhrefs AnalyticsCounting visits without identifying the visitorNo
_ga, _ga_KE9N7PNSWKGoogle AnalyticsDistinguishing visitors and sessions2 yearsYes
_clck, _clsk and other Microsoft identifiersMicrosoft ClarityReconstructing the path through the page_clck 1 year, _clsk 1 dayYes

Cloudflare Web Analytics and Ahrefs Analytics measure every visit because they write nothing to your device, read nothing from it and do not follow you to other sites. Google Analytics and Microsoft Clarity do all three, which is why they wait for you to say yes.

Until you accept, Google Analytics runs in denied consent mode: the library is present, sends signals without cookies or identifiers, and writes nothing. Microsoft Clarity does not even load.

Who else is involved

We do not own every link in the chain, so these providers process data on our behalf or, in the case of analytics, as controllers of their own service:

ProviderRoleWhereTheir policy
Akamai / LinodeHosts the site and the contact APIUnited Stateslinode.com
ResendDelivers the emails the form producesUnited Statesresend.com
CloudflareAnti-abuse verification and cookieless measurementUnited States and global networkcloudflare.com
GoogleGoogle Analytics 4United States and other countriespolicies.google.com
MicrosoftMicrosoft ClarityUnited Statesprivacy.microsoft.com
AhrefsAhrefs AnalyticsSingapore and European Unionahrefs.com

International transfers

Meddyg Sociedad Anónima operates from Costa Rica and its servers are in the United States, so if you write from the European Economic Area, the United Kingdom or Switzerland, your data leaves your jurisdiction. The providers in the table above support those transfers with the European Commission's Standard Contractual Clauses and, for the American ones, with their certification under the EU-U.S. Data Privacy Framework.

Costa Rica does not hold an adequacy decision from the European Commission. The volume of data at stake is that of a professional contact form, but you should know it before you write.

How long we keep it

DataRetention
Email produced by the form24 months from the last contact, unless the conversation is still live
Web server logs14 days, after which they are deleted automatically
Contact API operational logRotated automatically by size; never archived or analysed
IP used for rate limiting10 minutes, in memory only
Your cookie decisionIn your browser, until you change it or clear the site's data
Google Analytics14 months at user and event level
Microsoft ClarityPer Microsoft's retention period for the service

Your rights

Wherever you live, you can ask us what we hold about you, have it corrected, have it deleted, have us stop using it, or receive it in a readable format. You can also withdraw consent at any time, without that affecting anything done beforehand.

Write to the address in the first section. We answer within 30 calendar days at the latest, and sooner when the case is straightforward. We may ask for something extra to confirm it is you, but only the minimum.

What your country's law adds

European Economic Area and United Kingdom. The GDPR and the UK GDPR also give you the right to object to processing based on legitimate interest and to complain to the supervisory authority where you live.

United States. The laws of California, Colorado, Connecticut, Virginia, Utah and those that have joined them give you the right to know, correct, delete and not be discriminated against for exercising those rights. We neither sell nor share personal data in the sense those laws give those words, and we run no targeted advertising, so there is nothing to opt out of. We honour your browser's Global Privacy Control signal all the same: if it is on, we treat your visit as a refusal and do not show you the notice.

Brazil. On top of the above, the LGPD gives you the right to have unnecessary data anonymised or blocked, to know who we have shared it with, and to revoke consent. The competent authority is the ANPD.

Costa Rica. Law 8968 and its regulations give you rights of access, rectification and deletion, and let you turn to the Agencia de Protección de Datos de los Habitantes (Prodhab) if our answer does not satisfy you.

Rest of Latin America. Colombia, Chile, Mexico, Argentina, Peru, Ecuador and Uruguay have laws with equivalent rights. They are exercised through the same channel and, if our answer does not convince you, before your country's data protection authority.

Changing or withdrawing your consent

The “Cookie preferences” link in the footer opens the same panel you saw the first time, with your current choice ticked. You can change it or withdraw it entirely, and the effect is immediate: analytics cookies stop being written, and if you switch off session recording the page reloads so the script actually stops running rather than merely appearing to.

Your browser can also block or delete cookies on its own, from the site settings. If you clear this site's data, your decision goes with it and we will ask again.

Automatic browser signals

If your browser sends the Global Privacy Control signal, we take it as a refusal before the page finishes loading: nothing that requires consent is activated and the notice is not shown. We do not store it, so if you ever turn the signal off, we will ask you again.

The Do Not Track header has no agreed meaning across browsers and we base no decision on it. Global Privacy Control does, which is why that is the one we honour.

Security

  • The whole site travels encrypted over HTTPS, and the bare domain redirects to the main one in a single hop.
  • The form posts to the same domain. The email provider's key lives only on the server and is never included in the code that reaches your browser.
  • Every submission passes a Cloudflare anti-abuse check that also verifies the token came from our own domain.
  • The service rate-limits submissions per IP address and rejects any request body outside the expected size or shape.
  • The site is published as static files: there is no admin panel, no database and no user session to compromise.

No system is impregnable. If we detect a breach affecting your data, we will tell you and notify the relevant authority within the deadlines the applicable law sets.

Children

This site addresses health professionals and institutions. We do not knowingly request or collect data from minors. If you believe a minor has sent us data, write to us and we will delete it.

Changes to this policy

When what we do changes, this page changes, and the date at the top with it. If the change affects the tools that need your permission, the cookie notice appears again: consent given for one set of tools is not consent for a different one.

Contact and complaints

Write to us first: it is faster and almost always enough. If you are not satisfied, you can turn to your country's data protection authority.