This is a courtesy translation. In case of discrepancy, the Spanish version prevails.
Privacy Policy
Last updated: August 22, 2026
1. Data we collect
MedicAI collects the following types of data:
- Registration data: name, email address, professional license number.
- Patient data: demographic information, medical records, studies, prescriptions and appointments entered by healthcare professionals.
- Billing data: tax information (CUIT, tax ID), payment data processed through Mercado Pago.
- Usage data: access logs, interactions with the platform and performance metrics.
2. How we use the data
We use the data collected to:
- Provide and maintain the Service.
- Process electronic invoicing through AFIP/ARCA (the Argentine tax authority).
- Generate clinical suggestions using artificial intelligence (exclusively as a support tool for the professional).
- Improve the quality and security of the platform.
- Comply with legal and regulatory obligations.
When a doctor uses the optional "Record with AI" ("Grabar con IA") feature to auto-complete medical records, their voice is transcribed by xAI Inc. (United States), our sub-processor. The audio is automatically deleted after 30 days and is not used to train models. The extraction of clinical fields from the transcript is performed with Google Vertex AI (an existing sub-processor). The doctor is responsible for reviewing and validating the generated fields before saving the consultation. Dictation transcripts are kept encrypted for up to 72 hours solely to recover an interrupted consultation; they are deleted when the consultation is saved or discarded or, at the latest, the next time dictation is used in the organization after that period has expired.
3. Data security
We implement enterprise-grade security measures to protect your data:
- Encryption at rest: all health data is encrypted with AES-256-GCM.
- Isolation by organization: Row-Level Security (RLS) in PostgreSQL ensures that each practice can only access its own data.
- Secure transmission: all communications use TLS 1.3.
- Audit: an immutable (WORM) log of all sensitive operations.
4. Rights of the data subject
Under Law 25.326 (Argentine Personal Data Protection Act), you have the right to:
- Access: request information about your stored data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request the deletion of your personal data, subject to legal retention obligations.
- Objection: object to the processing of your data in certain circumstances.
To exercise these rights, contact narias@medicai.com.ar.
5. Health data
Health data receives special protection under Law 26.529 on the Rights of Patients in their Relationship with Health Professionals and Institutions (Patients' Rights Act):
- The medical record is the property of the patient, and the professional acts as its custodian.
- Access to clinical data is restricted to the treating professional and authorized staff.
- We do not share health data with third parties without express consent, unless required by law.
6. Data retention
We retain data while the account is active and for the time necessary to provide the Service and to comply with our own legal obligations. The obligation to retain the medical record for a minimum of ten (10) years from the last entry (Law 26.529, Art. 18) rests with the professional or the institution in their capacity as depositary (depositario), not with MedicAI (see clause 6 of the Terms of Service).
7. Data transfers
Data is stored on secure servers. We do not make international transfers of personal data without adequate safeguards in accordance with Law 25.326.
8. Changes to this policy
We reserve the right to modify this policy. Significant changes shall be notified through the platform at least 30 days in advance.
9. Sub-processors
MedicAI uses the following sub-processors to provide the Service:
- Google Cloud / Vertex AI — United States. Clinical artificial intelligence (suggestions, field extraction). Legal basis: Art. 6, subsection 5, Law 25.326.
- Cloudflare R2 — File storage with nodes in multiple regions. Legal basis: Art. 6, subsection 5, Law 25.326.
- Sentry — United States. Error monitoring (technical data, no PHI). Legal basis: Art. 6, subsection 5, Law 25.326.
- xAI Inc. — United States. Automated transcription of medical dictation (Speech-to-Text). Data processed: audio of the doctor's voice, which may contain patient PHI mentioned during dictation. Retention: 30 days at xAI, followed by automatic deletion. NOT used to train models. BAA in progress. Legal basis: Art. 6, subsection 5, Law 25.326.
10. Contact
Data controller:
MedicAI
Email: narias@medicai.com.ar