Skip to content
MedAlert
ES
MedAlert
  • MedAlert
  • Home
  • Pricing
  • About Us
    • About Us
    • Careers
  • Help Center
  • Contact Us
  • ES
  • See pricing

Privacy Policy

Effective as of July 15, 2026. Explains how MedAlert handles personal and health-related data on the website and platform.

This Privacy Policy (“Policy”) describes how MedAlert (“MedAlert,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you visit medalert.ai, contact us, or use our clinical platform (the “Services”). Read it together with the Terms of Use and, where applicable, the Cookies Policy.

If a clinic, practice, or hospital (“Customer”) contracts for MedAlert, much of the patient data is processed on the Customer’s behalf. In those cases the Customer is generally the controller / covered entity for that processing and MedAlert acts as a processor / service provider under the Customer’s documented instructions, except where law assigns MedAlert a different role for a specific activity (for example, Customer account data or website analytics).

1. Scope and roles

  • Website and marketing: when you browse the public site, request a demo, or receive MedAlert commercial communications, we typically act as controller of that contact and usage data.
  • Customer platform: when the Customer uploads or generates patient data, appointments, labs, imaging, notes, alerts, or campaigns, MedAlert primarily processes them as the Customer’s processor.
  • End patients: if you are a patient receiving a message or using a link sent by your clinic through MedAlert, your care provider decides the processing; this Policy also explains how MedAlert safeguards that data in Service infrastructure.

2. Data we process

Depending on context, we may process categories such as:

  • Account and Customer data: name, role, email, phone, organization, credentials, roles, billing information, and communication preferences.
  • Clinical and health data: patient identifiers, history, encounters, notes, lab results, imaging studies, orders, derived risks or segments, and attachments the Customer uploads.
  • Communications data: messaging identifiers, alert/campaign content or templates, delivery statuses, replies, and opt-in / opt-out flags when the Customer uses WhatsApp, SMS, email, or other channels.
  • Usage and technical data: IP address, device and browser type, access logs, product events, error diagnostics, and cookies or similar technologies.
  • Support data: contents of tickets, emails, or calls you send us.
  • Integration data: identifiers and payloads exchanged with HIS/LIS or other systems via HL7, FHIR, or APIs when the Customer enables connectors.

We do not knowingly solicit children’s data through the marketing site. The Customer is responsible for lawful bases when processing minors’ or other special-category data in clinical practice.

3. Sources of data

  • information you provide directly (forms, demo requests, contracting, support);
  • information uploaded or generated by the Customer and Authorized Users on the platform;
  • information received from patients or other recipients when they reply to Customer-initiated messages;
  • Customer-integrated systems (for example, HIS/LIS);
  • vendors that help us operate the Service (hosting, email, analytics, messaging), to the extent they transmit data to us; and
  • data generated automatically by use of the site or application.

4. Purposes of processing

We process information to:

  • provide, maintain, secure, and improve the Services (including clinical records, preventive AI alerts, campaigns, and assisted scheduling);
  • create and administer accounts, Organizations, roles, and access;
  • process orders, billing, and commercial support;
  • send operational communications (security notices, Service changes, billing);
  • send marketing communications where we have a lawful basis or consent, with an opt-out option;
  • generate AI Content (predictions, prioritizations, segments) from data the Customer makes available, under Customer oversight;
  • detect abuse, fraud, spam, or security risks;
  • meet legal obligations, audits, and valid authority requests; and
  • produce aggregated or de-identified statistics that do not identify individuals or specific Customers.

5. Artificial intelligence

AI modules may process clinical history and operational context to produce alerts or segments. That processing occurs to deliver the Service to the Customer. AI outputs are not a diagnosis or medical advice; the Customer’s clinician must validate them. We may use model providers (for example, LLM services) under contracts and controls aimed at limiting unauthorized training use, as configuration and agreements allow. We avoid placing unnecessary PHI in debug logs.

6. Legal bases

Depending on jurisdiction and context, we rely on one or more of:

  • performance of a contract (providing the Services to the Customer or handling your request);
  • legitimate interests (security, product improvement, abuse prevention, relevant B2B communications), balanced against your rights;
  • consent, where required (certain non-essential cookies or marketing);
  • legal obligations; and
  • for patient data processed on the Customer’s behalf, the legal bases the Customer determines and documents (including consent or other applicable health / data-enablement grounds).

7. How we share information

We do not sell personal data. We may share information with:

  • Service providers: hosting, databases, email, messaging (WhatsApp/SMS/email), monitoring, support, and, where applicable, AI providers, under confidentiality and processing obligations;
  • the Customer and Authorized Users within their Organization according to configured roles;
  • integrations authorized by the Customer;
  • professional advisers (legal, accounting) under secrecy duties;
  • authorities when a valid legal request applies; and
  • successors in a merger, acquisition, or asset sale, with reasonable notice where appropriate.

Messaging-channel providers may process recipient data under their own policies; the Customer should review those terms when enabling each channel.

8. International transfers

MedAlert and its providers may process data in countries other than your country of residence. Where required, we apply appropriate safeguards (for example, contractual clauses or other recognized measures). The Customer is responsible for assessing whether transferring patient data to MedAlert is lawful in its jurisdiction.

9. Retention

We retain account and billing data for the life of the relationship and as required by law or dispute prevention. Customer Data on the platform is retained during the contract and, after termination, for a reasonable export window, rotating backups, legal compliance, or incident resolution, unless the Customer instructs otherwise or mandatory law requires a different period. Marketing data is retained until you withdraw consent or object, or until it is no longer needed.

10. Security

We apply reasonable technical and organizational measures appropriate to a clinical cloud service, including access controls, encryption in transit, Organization-scoped segregation, and logging practices aimed at minimizing unnecessary exposure of clinical data. No method of transmission or storage is perfectly secure. The Customer must protect credentials, devices, and its own network, and notify us of relevant incidents it detects in its environment.

11. Your rights

Depending on your location and the processing role, you may have rights to access, rectify, update, delete, object, restrict processing, request portability, or withdraw consent. To exercise rights:

  • if your data was processed by your clinic in MedAlert, contact that clinic first (controller); we may redirect or assist the Customer where appropriate;
  • for MedAlert account, marketing, or website data, email info@medalert.ai.

We may request information to verify your identity and will respond within timelines required by applicable law.

12. Cookies and similar technologies

We use cookies and similar technologies for site operation, preferences, security, and, where applicable, measurement. Details and management options are described in the Cookies Policy.

13. Third-party links and services

The site or platform may link to third-party sites or services we do not control. Their privacy practices govern use of those services. This Policy does not cover non-MedAlert sites.

14. Children

The marketing site is not directed to individuals under 18. If you learn that a child provided us personal data without appropriate authorization, contact us so we can delete it where applicable. Clinical processing of minors’ data by a Customer is governed by that Customer’s obligations.

15. Changes to this Policy

We may update this Policy by posting the revised version and indicating the effective date. For material changes, we will seek reasonable notice (by email or in-product) to affected Customers. Continued use after the effective date means you are aware of the updated Policy, without prejudice to rights reserved by law.

16. Governing law

Without prejudice to mandatory data-protection rules that apply to you, this Policy is interpreted consistently with the Terms of Use and the laws of the Republic of Guatemala when MedAlert acts as contracting party, unless otherwise agreed with the Customer.

17. Contact

Privacy questions or rights requests directed to MedAlert:

MedAlert
Email: info@medalert.ai
Website: medalert.ai

This Policy describes privacy practices for the Service. It is not personalized legal advice. Customers should consult their own counsel on clinical and data-protection duties in their jurisdiction and, where appropriate, execute a data-processing agreement.

MedAlert

MedAlert is dedicated to helping clinics enhance patient care and operational efficiency. By increasing consultations and lab tests by up to 3x, we empower healthcare providers to deliver better outcomes while maximizing their practice’s potential.

Company
  • About Us
  • Careers
  • Our Blog
  • Contact Us
Product
  • Customers
  • Pricing
  • Help Center
Legal
  • Terms of Use
  • Privacy Policy
  • Cookies Policy
Connect With Us

Contact us

info@medalert.ai

  • Facebook
  • Twitter

Copyright 2026 MedAlert. All rights reserved.

  • About Us
  • Blog
  • Careers
  • Contact Us
Launch login modal

User login

Create an Account Close
Launch register modal

Create an Account

Back to login Close