Privacy Policy

Protection and processing of your personal and medical data

1. Introduction

BioScan Commitment

Protection of your personal and medical data is our absolute priority. This policy details how we collect, use, store and protect your information in accordance with GDPR and specific healthcare industry requirements.

Data Controller

BioScan
Represented by Young-wouk KIM, Founder
Headquarters: Paris, France
Email: [email protected]

Data Protection Officer (DPO)

For any questions regarding data protection, you can contact our data protection officer at: [email protected]

2. Types of Data Collected

2.1 Identification Data

  • First and last name
  • Professional email address

2.2 Technical Data

  • IP address
  • Browser type and version
  • Operating system
  • Connection timestamps

2.3 Medical Data

HEALTH DATA - MAXIMUM PROTECTION

Important: Medical data you upload for processing by BioScan is handled with the highest level of security:

  • Medical documents uploaded for analysis
  • Data extracted and structured by our algorithms
  • Metadata associated with documents
  • Processing history

Zero Data Training Guarantee: Your medical documents are never used to train or improve our AI algorithms.

3. Processing Purposes

3.1 Primary Purposes

  • Service provision: Processing and analysis of your medical documents
  • Account management: Creation and management of your user account
  • Technical support: Assistance and technical issue resolution
  • Service improvement: Anonymized usage analysis to optimize the platform

3.2 Secondary Purposes

  • Communication: Sending information about service updates
  • Security: Fraud detection and prevention
  • Legal compliance: Compliance with legal and regulatory obligations

4. Legal Basis for Processing

Data Type Legal Basis Purpose
Identification data Contract execution BioScan service provision
Medical data Explicit consent Document processing and analysis
Technical data Legitimate interest Security and service improvement
Contact data Contract execution Communication and support

5. Security and Data Protection

5.1 Technical Measures

  • Encryption: All data is encrypted in transit (TLS) and at rest (AES-256)
  • Isolation: Secure architecture with environment isolation
  • Monitoring: 24/7 monitoring of access and activities
  • Backup: Encrypted and redundant backups

5.2 Organizational Measures

  • Restricted access: Principle of least privilege for data access
  • Training: Continuous staff awareness on data security
  • Incident management: Defined procedures for security incident management
HDS CERTIFICATION - HEALTH DATA HOST

Our production servers are HDS (Health Data Host) certified and located exclusively in France.

6. Data Retention

Retention Periods

Data Type Retention Period Deletion Criteria
Identification data Contract duration + 3 years End of contractual relationship
Medical data According to user choice On request or automatic deletion
Technical logs 12 months maximum Automatic deletion
Billing data 10 years Legal accounting obligation

Secure deletion: Upon expiration of retention periods, all data is securely and irreversibly deleted according to industry standards.

7. Your GDPR Rights

In accordance with the General Data Protection Regulation (GDPR), you have the following rights:

Right of access

Obtain a copy of all personal data we hold about you.

Right to rectification

Request correction of inaccurate or incomplete data.

Right to erasure

Request deletion of your personal data under certain conditions.

Right to portability

Retrieve your data in a structured, machine-readable format.

Right to object

Object to the processing of your data for legitimate reasons.

Right to restriction

Request temporary suspension of data processing.

Exercising your rights

To exercise your rights, contact us at: [email protected]

We commit to responding within 30 days maximum. Proof of identity may be requested to verify your identity.

Right to complaint

You have the right to file a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL) if you believe that the processing of your data violates your rights.

CNIL Contact

CNIL
3 Place de Fontenoy - TSA 80715
75334 PARIS CEDEX 07
Tel: 01 53 73 22 22
Website: www.cnil.fr

8. Data Sharing

8.1 Non-sharing principle

Firm commitment: BioScan does not sell, rent, or share your personal or medical data with third parties for commercial purposes.

8.2 Authorized and supervised sharing

Your data may be shared only in the following cases:

  • Technical service providers: HDS-certified hosts for secure storage
  • Legal obligation: Court orders or competent health authorities
  • Explicit consent: With your prior written authorization
  • Vital emergency: Protection of vital interests in medical context

8.3 International transfers

France location: All your data is stored and processed exclusively in France. No transfers outside the European Union are made.

9. Cookies and Similar Technologies

9.1 Cookie Categories

9.2 Cookie Lifespan and Management

Lifespan: Essential cookies expire when you close your browser session. Optional cookies have a maximum lifespan of 13 months and are automatically deleted afterward.

Managing Your Cookie Preferences

You can manage your cookie preferences through several methods:

  • Cookie banner: Clear your browser data to see the cookie banner again and update your preferences
  • Browser settings: Configure your browser to refuse all cookies or specific types
  • Contact us: Email us to reset your cookie preferences manually

Important Note: Disabling essential cookies may affect the proper functioning of certain BioScan platform features, including language preferences and secure login sessions.

10. Contact and Support

Data Protection Officer

Email : [email protected]
Subject: "Data protection - [your request]"
Address: BioScan, Paris, France

Types of requests

  • GDPR rights exercise: Access, rectification, deletion, portability
  • Policy questions: Clarifications on your data processing
  • Cookie preferences: Reset or modify your cookie consent settings
  • Security incidents: Reporting security issues
  • Complaints: Concerns about respect for your rights

Response times

Service commitment:

  • Acknowledgment of receipt: 48 hours maximum
  • Complete response: 30 days maximum (possible 60-day extension for complex requests)
  • Security emergencies: Immediate processing

11. Regulatory Compliance

11.1 Legal references

This policy is established in compliance with:

  • RGPD : Regulation (EU) 2016/679 of 27 April 2016
  • Data Protection Act: Law No. 78-17 of 6 January 1978 as amended
  • Public Health Code: Articles L.1110-4 and following
  • HDS Framework: Order of 4 January 2017

11.2 Certifications

✓ GDPR Compliant | ✓ HDS Certified | ✓ ePrivacy Compliant

11.3 Audits and controls

BioScan undergoes regular audits:

  • Monthly internal security audit
  • Quarterly cookie compliance review
  • Annual GDPR compliance assessment

12. Policy Updates and Changes

12.1 Update Process

BioScan reserves the right to update this Privacy Policy to reflect:

  • Changes in our data processing practices
  • New legal or regulatory requirements
  • Technological improvements or new features
  • User feedback and compliance best practices

12.2 Notification of Changes

When we make material changes to this Privacy Policy, we will:

  • Update the "Last updated" date at the bottom of this page
  • Notify users through email or website banner
  • Provide a 30-day notice period for significant changes
  • Re-request consent where legally required

Your continued use of BioScan services after the effective date of any changes constitutes your acceptance of the revised Privacy Policy.

Last updated: September 2025

Version: 2.0