Legal
Privacy policy
GDPR compliant (EU 2016/679) · Version 1.1 · Last updated: 14/08/2026
Article 1 · Data controller
The controller of the personal data collected through the MedNews service is:
MedNews, trading name of Maxence Albertin, sole trader, company number 108 529 991, 848 avenue Gustave Charpentier, 83370 Fréjus, France
Legal representative: Maxence ALBERTIN, sole trader
Personal data contact: contact@med-news.fr
In the absence of a Data Protection Officer (DPO) being mandatory at this stage (fewer than 250 employees, no large-scale processing of sensitive data), any request concerning personal data is handled directly by the controller within 30 calendar days.
Article 2 · Data collected and purposes
MedNews applies the data minimisation principle: only the data strictly necessary to deliver the service is processed. The following are collected:
- Identity: last name, first name
- Contact professionnel : adresse email
- Professional profile: medical specialty, chosen from those the service covers
- Engagement data: articles read (opening, reading time, click through to the source document, sorting by swipe), bookmarked content, newsletter open frequency. These reading events are kept for a maximum of 13 months, then deleted automatically
- Personalised watches: topics and keywords you define freely for your watch (the « My watches » feature), kept for as long as the watch is active and deleted with it
- Sign-in with Google or Apple: if you choose this sign-up route, the provider passes us your verified email address, your name where it is available, and a technical account identifier. MedNews has access to nothing else: not your messages, not your contacts, not your documents. You can revoke this link at any time from the security settings of your Google or Apple account
- Payment data: handled exclusively by Stripe (PCI-DSS certified), MedNews stores no bank data
Purposes of processing: personalised filtering of alerts by specialty, alerts on your watch topics, personalisation of the content offered, sending of newsletters, improvement of the scoring algorithms, management of subscriptions. Engagement data serves solely to personalise the service within MedNews: it is neither transferred, nor resold, nor used for advertising purposes. In accordance with article 21 of the GDPR, personalisation can be switched off at any time (Settings → Privacy): the collection of reading events then stops immediately.
No patient data is collected. The service is intended solely for practitioners, for their own professional watch.
Article 3 · Legal basis for processing
- Performance of the contract (art. 6.1.b GDPR): for all data needed to deliver the service, including sending the newsletter and the watch emails, which are the service itself. Their frequency is freely set from the account settings, and every email carries an unsubscribe link
- Consent (art. 6.1.a GDPR): for notifications on the device, collected by the operating system at the first request and revocable at any time in the phone settings
- Legitimate interest (art. 6.1.f GDPR): for platform security, fraud prevention, service improvement, and informing subscribers about changes to it. It may be objected to at any time
Article 4 · Processors and data transfers
MedNews uses the following processors, with which a Data Processing Agreement (DPA) is signed before any processing:
- Anthropic (Claude) : automated analysis of public content only. Your personal data (name, email) is never passed to the AI
- Brevo (Sendinblue SAS, France) : technical delivery of newsletters and transactional emails
- Stripe : secure payment processing (PCI-DSS level 1 certified)
- Google and Apple: only if you choose to create your account or sign in through them. The exchange is limited to verifying your identity at sign-in, and each acts here as controller for its own service
- Render / Neon : hosting of the application and the database, exclusively on servers located in the European Union
No personal data is transferred outside the European Union without appropriate safeguards in accordance with Chapter V of the GDPR.
Article 5 · Data security
- AES-256 encryption of sensitive data stored in the database
- Salted bcrypt hashing of passwords, never stored in plain text
- Short-lived JWT tokens with rotating refresh tokens
- Communications encrypted with HTTPS/HSTS on every route
- Security headers: X-Content-Type-Options, X-Frame-Options, Referrer-Policy
- Explicit CORS configuration (allow-list of permitted origins)
- Anonymised logs: email addresses never appear in activity logs
- Record of processing activities kept in accordance with Article 30 GDPR
Article 6 · User rights
In accordance with the GDPR, every member has the following rights over their personal data:
- Right of access: obtain a copy of all the data processed about them
- Right to rectification: correct inaccurate or incomplete information
- Right to erasure (right to be forgotten): request the deletion of their data
- Right to data portability: receive their data in a structured, machine-readable format
- Droit d'opposition : object to processing based on legitimate interest
- Right to withdraw consent: at any time for processing based on consent
To exercise these rights: contact@med-news.fr, maximum response time 30 calendar days.
Immediate unsubscribe: a working unsubscribe link is present in every newsletter.
Data retention: deletion or anonymisation within 12 months of the subscription ending.
Right of appeal: if the answer is unsatisfactory, the user may refer the matter to the CNIL at www.cnil.fr.