Privacy policy
This site collects little, and says all of it: what comes in, who processes it, for how long, and how to ask for it to be gone.
Last updated:
Who processes your data
Meddyg Sociedad Anónima is the controller of the personal data collected at www.meddyg.com. Any request about this policy or about your data reaches the address below and is answered the same way.
| Detail | Value |
|---|---|
| Controller | Meddyg Sociedad Anónima |
| Company registration (Costa Rica) | 3-101-753619 |
| Address | San Francisco, Heredia, Costa Rica |
| Contact email | hola@meddyg.com |
What we collect
There is only one way to give us personal data on this site: the contact form. Everything else is traffic measurement, which never asks for your name and is covered further down.
When you submit the form we collect exactly the fields you see on screen: name, role, email address, organisation, type of organisation, country, project stage, expected timeline, the services and products you tick, and your message. Phone number and preferred channel are optional. Alongside that travel the page you wrote from and the language you were reading it in, so we know what prompted you.
On the technical side, the web server logs what any web server logs: your IP address, the date, the URL requested, your browser and the page you came from. The service that receives the form holds your IP in memory for ten minutes to throttle automated submissions, and writes the organisation and email address of each successful send to its operational log.
There is no database. The form is not stored in any system of ours: it becomes an email, it is sent, and that is where its path through our infrastructure ends.
What we use it for, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Answering your enquiry and preparing a possible proposal | The form fields | Pre-contractual steps taken at your request (GDPR art. 6(1)(b)) |
| Keeping the form from being abused by scripts | IP address, verification token | Legitimate interest in protecting the service (art. 6(1)(f)) |
| Keeping the site up and diagnosing failures | Web server logs | Legitimate interest in site security and continuity (art. 6(1)(f)) |
| Knowing how many visits there are and where they come from, without identifying anyone | Aggregate cookieless measurement | Legitimate interest in knowing the site's reach (art. 6(1)(f)) |
| Understanding which content works and where navigation stalls | Audience analytics and session recording | Your consent (art. 6(1)(a)) |
We do not sell personal data, do not pass it to advertising networks, do not build commercial profiles and take no automated decision that affects you. We also do not send marketing email to anyone who has not asked for it.
Who else is involved
We do not own every link in the chain, so these providers process data on our behalf or, in the case of analytics, as controllers of their own service:
| Provider | Role | Where | Their policy |
|---|---|---|---|
| Akamai / Linode | Hosts the site and the contact API | United States | linode.com |
| Resend | Delivers the emails the form produces | United States | resend.com |
| Cloudflare | Anti-abuse verification and cookieless measurement | United States and global network | cloudflare.com |
| Google Analytics 4 | United States and other countries | policies.google.com | |
| Microsoft | Microsoft Clarity | United States | privacy.microsoft.com |
| Ahrefs | Ahrefs Analytics | Singapore and European Union | ahrefs.com |
International transfers
Meddyg Sociedad Anónima operates from Costa Rica and its servers are in the United States, so if you write from the European Economic Area, the United Kingdom or Switzerland, your data leaves your jurisdiction. The providers in the table above support those transfers with the European Commission's Standard Contractual Clauses and, for the American ones, with their certification under the EU-U.S. Data Privacy Framework.
Costa Rica does not hold an adequacy decision from the European Commission. The volume of data at stake is that of a professional contact form, but you should know it before you write.
How long we keep it
| Data | Retention |
|---|---|
| Email produced by the form | 24 months from the last contact, unless the conversation is still live |
| Web server logs | 14 days, after which they are deleted automatically |
| Contact API operational log | Rotated automatically by size; never archived or analysed |
| IP used for rate limiting | 10 minutes, in memory only |
| Your cookie decision | In your browser, until you change it or clear the site's data |
| Google Analytics | 14 months at user and event level |
| Microsoft Clarity | Per Microsoft's retention period for the service |
Your rights
Wherever you live, you can ask us what we hold about you, have it corrected, have it deleted, have us stop using it, or receive it in a readable format. You can also withdraw consent at any time, without that affecting anything done beforehand.
Write to the address in the first section. We answer within 30 calendar days at the latest, and sooner when the case is straightforward. We may ask for something extra to confirm it is you, but only the minimum.
What your country's law adds
European Economic Area and United Kingdom. The GDPR and the UK GDPR also give you the right to object to processing based on legitimate interest and to complain to the supervisory authority where you live.
United States. The laws of California, Colorado, Connecticut, Virginia, Utah and those that have joined them give you the right to know, correct, delete and not be discriminated against for exercising those rights. We neither sell nor share personal data in the sense those laws give those words, and we run no targeted advertising, so there is nothing to opt out of. We honour your browser's Global Privacy Control signal all the same: if it is on, we treat your visit as a refusal and do not show you the notice.
Brazil. On top of the above, the LGPD gives you the right to have unnecessary data anonymised or blocked, to know who we have shared it with, and to revoke consent. The competent authority is the ANPD.
Costa Rica. Law 8968 and its regulations give you rights of access, rectification and deletion, and let you turn to the Agencia de Protección de Datos de los Habitantes (Prodhab) if our answer does not satisfy you.
Rest of Latin America. Colombia, Chile, Mexico, Argentina, Peru, Ecuador and Uruguay have laws with equivalent rights. They are exercised through the same channel and, if our answer does not convince you, before your country's data protection authority.
Changing or withdrawing your consent
The “Cookie preferences” link in the footer opens the same panel you saw the first time, with your current choice ticked. You can change it or withdraw it entirely, and the effect is immediate: analytics cookies stop being written, and if you switch off session recording the page reloads so the script actually stops running rather than merely appearing to.
Your browser can also block or delete cookies on its own, from the site settings. If you clear this site's data, your decision goes with it and we will ask again.
Automatic browser signals
If your browser sends the Global Privacy Control signal, we take it as a refusal before the page finishes loading: nothing that requires consent is activated and the notice is not shown. We do not store it, so if you ever turn the signal off, we will ask you again.
The Do Not Track header has no agreed meaning across browsers and we base no decision on it. Global Privacy Control does, which is why that is the one we honour.
Security
- The whole site travels encrypted over HTTPS, and the bare domain redirects to the main one in a single hop.
- The form posts to the same domain. The email provider's key lives only on the server and is never included in the code that reaches your browser.
- Every submission passes a Cloudflare anti-abuse check that also verifies the token came from our own domain.
- The service rate-limits submissions per IP address and rejects any request body outside the expected size or shape.
- The site is published as static files: there is no admin panel, no database and no user session to compromise.
No system is impregnable. If we detect a breach affecting your data, we will tell you and notify the relevant authority within the deadlines the applicable law sets.
Children
This site addresses health professionals and institutions. We do not knowingly request or collect data from minors. If you believe a minor has sent us data, write to us and we will delete it.
Changes to this policy
When what we do changes, this page changes, and the date at the top with it. If the change affects the tools that need your permission, the cookie notice appears again: consent given for one set of tools is not consent for a different one.
Contact and complaints
Write to us first: it is faster and almost always enough. If you are not satisfied, you can turn to your country's data protection authority.

