Privacy Policy

Last updated: June 24, 2026  |  Version 1.2

1. Identification of the Controller and the Processor

Data controller (the clinic):
Max Antonio Méndez Gómez (Pequeño Contribuyente), domiciled in Guatemala City, Guatemala. Contact email for privacy matters: privacidad@medicia.app.

Data processor (platform provider):
MedicIA (clinical management SaaS platform). MedicIA processes data solely according to the Controller's instructions and has no independent access to patient data for its own purposes.

2. Data collected

The platform collects and processes the following categories of personal data:

Category Examples Sensitive data
Identification data Full name, RUT/DNI/CURP, date of birth No
Contact data Phone (WhatsApp), email address, address No
Health data Clinical record, diagnoses, allergies, medications, medical history, vital signs, medical records Yes — sensitive data
Communication data Messages sent/received via WhatsApp No
Internal user data Name and email of clinic staff (doctors, receptionists) No
Usage and audit data Access logs, actions performed, IP, user-agent No

Health data constitutes sensitive data and is protected in Guatemala by the duty of medical confidentiality under Article 195 of the Health Code (Decree 90-97) and by the right to privacy recognized in Articles 24 and 31 of the Constitution of the Republic of Guatemala and in Articles 26 to 35 of the Civil Code (Decree-Law 106). Its processing requires the data subject's informed consent or a legal basis arising from the provision of direct medical care.

For comparative reference only — and applicable solely where the clinic (Controller) operates in those countries — this type of data is also treated as a special category under Law 25.326 (Argentina), the LFPDPPP (Mexico), Law 1581/2012 (Colombia) and Law 19.628 (Chile). These laws do not constitute the regime applicable to patients in Guatemala.

3. Purpose and legal basis of processing

PurposeLegal basis
Management of the clinical relationship (appointments, records, history) Performance of the doctor-patient relationship / health care
WhatsApp communication (reminders, confirmations) Patient consent and the need to coordinate the agreed medical care
Billing and collections Contractual performance and legal obligations
Intent detection (AI) to route the patient's message Patient consent and the need to perform the requested service
Security and auditing Legal obligation and systems security

4. Relationship with the patient and informed consent

The patient does not contract directly with MedicIA. The contractual relationship exists between the clinic (data controller) and MedicIA (data processor). Accordingly, the lawful basis on which MedicIA processes the patient's data rests on the contract entered into with the clinic and on the clinic's duty to obtain the patient's informed consent for their data to be processed by MedicIA as a clinical management tool.

The clinic, as Controller, undertakes to inform its patients about the processing of their data through MedicIA and to obtain their informed consent before entering their data into the platform, in accordance with the duty of medical confidentiality (Article 195 of the Health Code) and the right to privacy recognized in the Constitution and the Civil Code of Guatemala.

By way of guidance, the clinic may use the following model notice and consent text to inform its patients:

“Your clinic uses MedicIA, a clinical management platform, to manage your appointment schedule, your clinical record and communications via WhatsApp and email. For this purpose, your personal and health data will be processed by MedicIA on behalf of and under the instructions of the clinic, for the sole purpose of providing your care and coordinating your follow-up. Your data is not used for advertising purposes nor disclosed to third parties except as necessary to provide the service or as required by law. You may exercise your rights of access, rectification, cancellation and objection before the clinic at any time. By accepting, you give your informed consent to this processing.

5. Data retention

Data is retained for as long as necessary to fulfill the purpose for which it was collected:

Once these periods elapse, the data is securely deleted or anonymized.

Deletion upon account closure: when the clinic's administrator deletes the account (the DELETE /account/clinic action) or the contractual relationship ends, access is suspended and the clinic has 30 days to export all of its data using the application's JSON export function. After those 30 days, MedicIA permanently deletes ALL data associated with that clinic — including the clinic's data, its doctors and users, and all of its patients (clinical records, appointments, conversations and documents). The retention periods stated above (such as the 10 years for the clinical record) apply while the relationship exists and while the clinic, as the data controller, is required to keep them; voluntary closure of the account triggers this total deletion.

6. International transfers

To operate the platform, MedicIA uses the following sub-processors located in the United States or other jurisdictions outside the Controller's country:

Sub-processorServiceCountryData transmitted
Anthropic, PBC AI intent detection (Claude API) USA WhatsApp message text (without name or clinical record)
Recurrente Payment and subscription processing Guatemala Clinic billing data (not patient data)
Resend, Inc. Sending transactional emails USA Recipient's email address and name
Railway Corp. Cloud infrastructure (database server) USA All data stored on the platform
Meta Platforms, Inc. (WhatsApp Business Cloud API) Sending and receiving WhatsApp messages USA / variable Incoming and outgoing WhatsApp messages
Google LLC Google Calendar + Gmail (calendar synchronization and email sending when the clinic connects its Google Workspace account) USA Calendar events (appointments) and, where applicable, emails sent from the connected Gmail account

Guatemala has no data-protection adequacy framework and is not a signatory to the EU/UK–US Data Privacy Framework (DPF), and the GDPR's standard contractual clauses (SCCs) do not constitute a legal basis under Guatemalan law. Accordingly, these international transfers are carried out on the basis of the data subject's informed consent and the necessity of those transfers to provide the service contracted by the clinic (hosting, messaging, calendar synchronization and payment processing).

Notice regarding United States law (CLOUD Act): because the hosting infrastructure (Railway) and several sub-processors are located in the United States, the stored data is subject to U.S. jurisdiction. Under the Clarifying Lawful Overseas Use of Data Act (CLOUD Act) and other applicable rules, U.S. authorities could, by lawful order, compel access to data held by those providers, even when the data subjects are located outside that country. MedicIA requires its sub-processors to limit any such access to what is strictly required by law.

The Controller may request information on the applicable safeguards at privacidad@medicia.app.

7. ARCO rights and additional rights

The data subject has the following rights, which may be exercised in writing with the Controller:

To exercise your rights, please contact the privacy contact:
Max Antonio Méndez Gómez (Pequeño Contribuyente) — privacidad@medicia.app
Address: Guatemala City, Guatemala

A response will be provided within a reasonable period (as guidance, within 30 days). Guatemala has no administrative data-protection authority. Therefore, if you believe your rights have not been addressed, the avenue for recourse in Guatemala is judicial, before the competent Civil Courts (Juzgados de lo Civil); and, for health data and the duty of medical confidentiality, you may also turn to the Ministry of Public Health and Social Assistance (MSPAS).

8. Data security

MedicIA implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss or destruction, including: encryption in transit (TLS 1.2+), encryption of backups, role-based access control, immutable audit logs and breach notification within a maximum period of 72 hours from detection.

9. Use of cookies and tracking technologies

The MedicIA web interface may use strictly necessary cookies to manage the authenticated session. No third-party tracking or advertising cookies are used.

10. Changes to this Policy

This Policy may be updated periodically. The current version will always be available at this URL. Substantial changes will be notified at least 15 days in advance.

11. Jurisdiction and applicable law

This Policy is governed primarily by the laws of the Republic of Guatemala, in particular: the Constitution of the Republic of Guatemala (Arts. 24 and 31); the Civil Code (Decree-Law 106, Arts. 26 to 35); the Health Code (Decree 90-97, Art. 195, medical confidentiality); the Law on the Recognition of Electronic Communications and Signatures (Decree 47-2008); the Consumer and User Protection Law (Decree 006-2003); and the Commercial Code (Decree 2-70).

The data protection laws of Argentina (25.326), Mexico (LFPDPPP), Colombia (1581/2012) and Chile (19.628) are cited solely as comparative reference and apply only where the clinic (Controller) operates in those countries; they do not constitute the regime applicable to patients in Guatemala. In the event of a conflict, the competent courts shall be those of Guatemala.

12. Access to Google services (Google Calendar)

When a clinic connects its Google account to MedicIA, the platform requests the Google Calendar permission (https://www.googleapis.com/auth/calendar.events) for the sole purpose of creating, updating and deleting in the clinic's Google Calendar the events that represent the appointments the user schedules within MedicIA, keeping their calendar synchronized. The basic openid and userinfo.email permissions are also requested solely to identify the Google account that grants the consent.