Privacy Policy

Version: July 2026

1. Scope and general information

We process personal data confidentially and in accordance with the GDPR, the German Federal Data Protection Act (BDSG), the German Telecommunications-Telemedia Data Protection Act (TDDDG) and other applicable law. This notice covers medioora.com, the Medioora requirements-engineering application, Medioora Academy, contact, support and sales enquiries, and our relationships with customers, prospects, sales partners, suppliers and other business partners. The data processed depends on the services and functions used.

2. Controller

MEDtech Ingenieur GmbH
Am Weichselgarten 7
91058 Erlangen, Germany
E-mail: info@medtech-ingenieur.de

3. Data protection officer

Goran Madzar
E-mail: madzar@medtech-ingenieur.de

4. Roles when companies use Medioora

Where a customer determines the purposes and means of processing user, project and content data, the customer is normally controller and MEDtech Ingenieur GmbH processor under an Art. 28 GDPR data processing agreement (AVV/DPA). This includes accounts, requirements, documents, test cases, comments, reviews and change histories. Users should address questions about these data to the organisation that granted access. For our own licensing, billing, security, abuse prevention and support purposes, we are controller.

5. Hosting by IONOS

Our website and Medioora infrastructure are hosted in Germany by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. IP addresses, access times, requested resources, referrers, browser and operating-system data, device information and technical security/error data may be processed for secure provision, troubleshooting and attack prevention. Legal bases are Art. 6(1)(f) and, where applicable, Art. 6(1)(b) GDPR. IONOS is processor under Art. 28 GDPR. Server logs controlled by us are generally deleted after eight weeks unless needed for a specific security incident.

6. Website access

When the website is accessed, the server may process IP address, date and time, requested page or file, data volume, referrer URL, browser/version, operating system/device type and HTTP status or error messages. These data are not used to create user profiles. Legal basis is Art. 6(1)(f) GDPR.

7. Cookies and similar technologies

Technically necessary cookies support language selection, form protection, login functions and storage of cookie-consent choices. Device access is based on Section 25(2) no. 2 TDDDG; subsequent processing is based on Art. 6(1)(b) or (f) GDPR. Optional external media (including YouTube) and non-essential comfort functions are activated only after consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR. Consent may be withdrawn through the website’s cookie settings. Details are provided in our Cookie Policy.

8. Contact and support

For forms, e-mail, telephone and other contact, we may process name, business contact details, organisation, role, enquiry, support information, technical diagnostics and further correspondence. Legal bases are Art. 6(1)(b) GDPR for contractual/pre-contractual enquiries and otherwise Art. 6(1)(f) GDPR. General enquiries are normally deleted no later than twelve months after completion; legally relevant business and tax records may be retained longer. Do not send passwords, API keys, session cookies or unnecessary confidential or special-category data.

9. Comments and Medioora Academy

Comments and ratings may involve the submitted content, name, contact details, time, IP address and necessary metadata for the function, quality assurance and abuse prevention (Art. 6(1)(b) or (f) GDPR). Academy usage counts and ratings may be aggregated; non-identifiable aggregates are not personal data.

10. YouTube

Videos may be provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A YouTube connection is established only after consent to external media or deliberate activation of a blocked video. IP, device/browser, content, cookie and usage data may then be transferred; processing in third countries, particularly the United States, cannot be excluded. Legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

11. Purpose of Medioora

Medioora supports the structured creation, management, coordination, review and documentation of requirements, architecture/design descriptions, test cases and project information. Processing supports administration, authentication, permissions, projects, collaboration, reviews, traceability, support, backups, security and abuse prevention. For customer use, the customer determines the legal basis; Art. 6(1)(b)/(f) GDPR and Section 26 BDSG may apply. For our own purposes, Art. 6(1)(b)/(f) GDPR applies.

12. Accounts and administration

Self-registration is unavailable. Authorised customer administrators create and manage accounts. Required data include user name, cryptographic password hash, role, permissions, activation status and internal user ID. Optional data include display name, business e-mail, telephone, initials, avatar and notification settings; optional security data may include MFA status/secret and setup data. Passwords are never stored in plain text. Accounts remain until deletion/deactivation or contract end. Deactivation blocks access but does not itself delete the account. Necessary audit and project references may remain or be pseudonymised.

13. Project, content and collaboration data

We process project/customer names, memberships and roles; documents, requirements, architecture/design descriptions, test cases/results; comments, replies, reviews and approvals; assignments and author/reviewer details; versions, changes, timestamps and status; files, images, diagrams; and temporary locks/presence data. These data are processed under the customer’s instructions and deletion rules. Medioora is not intended for patient data or Art. 9 GDPR data unless expressly approved contractually, legally and technically.

14. Login, security and audit data

We may process user ID, login/logout times, successful and failed attempts, IP address, lockouts, security/administrative actions, and change/error details for authentication, traceability, attack detection, abuse prevention, troubleshooting and legal claims. Legal bases are Art. 6(1)(f), and where applicable (b) and (c) GDPR. Security and audit data are retained only as long as necessary.

15. Required session cookie and local browser storage

Medioora uses only technologies required to provide the application. After login, the medtech.sid session cookie assigns the server-side session; it is HttpOnly, SameSite=Lax, encrypted in HTTPS production and valid for a maximum of eight hours. Browser localStorage stores language, last view/project/document and interface, filter, table and display preferences. No advertising, profiling or cross-site tracking is performed. Section 25(2) no. 2 TDDDG therefore exempts these technologies from consent. If non-essential technologies are added, they will be activated only after any required consent.

16. Optional AI function and OpenAI API

The optional AI supports requirements, architecture/design descriptions, test cases, reviews and improvement suggestions. Administrators can disable it. A request is triggered only by deliberate user action. Depending on the use case, the prompt, task, title and limited excerpt of the open document, linked or expressly selected work items, recent dialogue/drafts, available work-item types, chapter goals and the AI response may be transmitted. Other project contents are not transmitted merely because they exist in the project. Configured customer names and user-defined terms may be replaced by placeholders where possible; this does not remove the duty to avoid unnecessary personal or confidential data.

Recipient/processor: OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. OpenAI may use subprocessors, including outside the EEA, subject to Art. 44 et seq. GDPR safeguards such as adequacy decisions or Standard Contractual Clauses. API inputs and outputs are not authorised for general model training; optional sharing for feedback, evaluation or fine-tuning is disabled for the Medioora API organisation. Current OpenAI information states that API content may be kept in abuse-monitoring logs for up to 30 days by default, and Responses API application state may be kept for at least 30 days. Zero Data Retention or Modified Abuse Monitoring requires OpenAI approval. Medioora does not maintain a separate prompt archive; adopted outputs become normal project content. The current model is from the GPT-5 family.

17. Customers, prospects and business partners

For contacts at customers, prospects, sales partners, suppliers and other partners we may process names, business contact and organisation details, roles, contracts, offers, orders, projects, licences, support, communications, invoices, bank/payment data, delivery/performance data, compliance information and professional information from public sources or the person’s organisation. Purposes include enquiries, contracts, licensing, delivery, support, invoicing, relationship management, security, compliance and legal claims. Legal bases are Art. 6(1)(b), (c) and (f) GDPR. If data are received from another source, Art. 14 GDPR information is provided unless an exception applies. Direct marketing is subject to applicable marketing law and may be objected to at any time.

18. Recipients

Access within MEDtech Ingenieur GmbH is limited to those who need it. Recipients may include IONOS, Microsoft 365/Exchange Online (Microsoft Ireland Operations Limited or the contracting entity named in Microsoft’s DPA) for transactional notifications and support e-mails, OpenAI and subprocessors for expressly requested AI, banks, payment providers, tax advisers, auditors, professional advisers, sales/project partners, authorities and courts. Processors are bound by Art. 28 GDPR agreements. Microsoft processing is governed by Microsoft’s Product Terms and Products and Services DPA; tenant region and subprocessors must be checked for the actual contract.

19. Transfers to third countries

Hosting is configured in Germany. Microsoft 365, YouTube and OpenAI may involve processing outside the EU/EEA depending on service, tenant and subprocessors. Transfers occur only under Art. 44 et seq. GDPR safeguards. A third-country level of protection may nevertheless differ from that in the EU.

20. Retention and deletion

Data are deleted or anonymised when purposes end unless retention duties, contractual rules, legitimate interests or claims require otherwise. Contact enquiries are normally deleted after twelve months; accounts and project content follow the customer contract; security logs follow the necessary period; backups may contain deleted data until overwritten. Business correspondence is generally retained six years, accounting records eight years and certain commercial books/financial statements ten years. Claims data may be retained until limitation expires.

21. Data security

We apply Art. 32 GDPR technical and organisational measures, including role-based access, password hashing, encrypted transport, session/login protection, optional MFA, security logging, backups and system updates. Website and application use TLS.

22. No use by children

Our business services and Medioora are not directed to children. Public registration by minors is not possible. Inadvertently received children’s data will be deleted as required by law.

23. Obligation to provide data

Some data are necessary for contracts, enquiries or protected functions. Without a user name, password and required authorisation, a Medioora account cannot be provided. Optional information is identified as such.

24. No solely automated decisions

We do not make solely automated decisions with legal or similarly significant effects. AI produces suggestions that users must review and consciously accept or reject.

25. Your rights

Subject to legal requirements, you have rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection to Art. 6(1)(e)/(f) processing (Art. 21). Consent may be withdrawn for the future. Customer users should first contact their organisation; processor requests are forwarded or supported.

26. Right to complain

You may complain to a supervisory authority. The authority generally responsible for MEDtech Ingenieur GmbH is Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de. You may also contact another competent authority under Art. 77 GDPR.

27. Changes to this notice

We update this notice when processing activities, services or legal requirements change. The current version published on this page applies.