Medify Logo
← Back to Home

Privacy Policy

Last updated: April 2026

1. Introduction

Medify ("we," "our," or "us") is a company registered in Sofia, Bulgaria. We are committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Bulgarian data protection legislation.

This Privacy Policy explains how we collect, use, and protect personal data when you visit our website at medifyclinical.com. This policy applies exclusively to the website. Data processing related to the Medify clinical trial platform is governed by separate agreements, including a Data Processing Agreement, provided to clients during onboarding.

2. Data Controller

The data controller for the personal data collected through this website is:

Company: Medify

Location: Sofia, Bulgaria

Email: info@medifyclinical.com

3. Information We Collect

3.1 Contact Form Data

When you submit our contact form, we collect the following personal data:

  • Full name (required)
  • Email address (required)
  • Company name (optional)
  • Professional role (optional)
  • Message content (required)

3.2 Local Storage

We use browser local storage to save your language preference (English or Bulgarian). This data is stored locally on your device, is not transmitted to our servers, does not identify you personally, and is not used for tracking or analytics purposes.

3.3 Information We Do Not Collect

This website does not use analytics cookies, advertising trackers, or third-party tracking scripts. We do not collect IP addresses, device fingerprints, or browsing behavior data through this website. We do not process any health data, clinical trial data, or protected health information through this website.

4. Purpose and Legal Basis for Processing

We process your personal data for the following purposes and on the following legal bases under Article 6 of the GDPR:

  • Responding to enquiries (legal basis: your consent, provided by voluntarily submitting the contact form, and our legitimate interest in responding to business enquiries)
  • Following up on expressed interest (legal basis: legitimate interest in business development, limited to information you have specifically requested)
  • Storing language preference (legal basis: legitimate interest in providing a functional, accessible website experience)

5. Data Sharing

We do not sell, rent, or trade your personal data. We do not share contact form submissions with third parties for their marketing purposes. Your data may be accessible to:

  • Medify team members who need access to respond to your enquiry
  • Our hosting provider (Vercel Inc.) for the purpose of website operation and contact form delivery
  • Legal authorities if required by applicable law or valid legal process

6. International Data Transfers

Our website is hosted on Vercel, which may process data in the United States and other countries outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, in accordance with Article 46 of the GDPR.

7. Data Retention

Contact form submissions are retained for a maximum of 24 months from the date of submission, after which they are deleted unless an ongoing business relationship has been established. Language preferences stored in your browser's local storage persist until you clear your browser data or change the setting.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. The website is served over HTTPS with TLS encryption. Contact form submissions are transmitted securely.

9. Your Rights Under GDPR

Under the General Data Protection Regulation and applicable Bulgarian data protection legislation, you have the following rights:

  • Right of access (Article 15) — request a copy of the personal data we hold about you
  • Right to rectification (Article 16) — request correction of inaccurate or incomplete data
  • Right to erasure (Article 17) — request deletion of your personal data
  • Right to restrict processing (Article 18) — request that we limit how we use your data
  • Right to data portability (Article 20) — request your data in a structured, machine-readable format
  • Right to object (Article 21) — object to processing based on legitimate interests
  • Right to withdraw consent (Article 7) — withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal

To exercise any of these rights, contact us at info@medifyclinical.com. We will respond within 30 days of receiving your request. There is no fee for exercising your rights, unless requests are manifestly unfounded or excessive.

10. Right to Complain

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Commission for Personal Data Protection of the Republic of Bulgaria (CPDP):

Commission for Personal Data Protection

Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria

Website: www.cpdp.bg

You may also lodge a complaint with the supervisory authority in your country of residence if you are located in another EU/EEA member state.

11. Children's Privacy

This website is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has submitted personal data through our contact form, please contact us and we will delete it promptly.

12. Third-Party Links

This website contains links to LinkedIn and email services. These third-party services have their own privacy policies that govern how they collect and process your data. We are not responsible for the privacy practices of third-party websites.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. Changes will be effective immediately upon publication on this page, and the "Last updated" date will be revised. We encourage you to review this policy periodically.

14. Relationship to Platform Privacy

This Privacy Policy governs data collected through the medifyclinical.com website only. The Medify clinical trial platform processes health data, clinical trial data, and other sensitive personal data under separate legal agreements, including a Data Processing Agreement compliant with Article 28 of the GDPR. If you are a Medify platform user, please refer to the privacy documentation provided during your onboarding process.

15. Contact Us

For any questions about this Privacy Policy or to exercise your data protection rights:

Email: info@medifyclinical.com

Company: Medify

Location: Sofia, Bulgaria

LinkedIn: linkedin.com/company/medify-clinical