Medpharm Logo
Back to home

Privacy Policy

Information about the processing of personal data when using the Medpharm platform.

Version: August 2026

1. Controller

The controller is medpharm GmbH, Sendlingerstraße 41, 80331 Munich, Germany, email info@med-pharm.de. Managing directors are Damun Yavari and Bardia Yaktapour. A licensed doctor who independently decides on treatment and prescription issuance may be separately responsible for medical data processing. Medpharm does not provide medical treatment; it provides the technical platform connecting patients, doctors and, where necessary, pharmacies.

2. Subject of this Privacy Policy

This policy explains which personal data Medpharm processes, for which purposes, which recipients may receive it and which rights data subjects have. The platform allows patients to create an account, submit a digital medical history, send a medical request, have it reviewed by a licensed doctor, view its status and history, select a pharmacy and, after a positive medical decision, make a prescription available to that pharmacy. Prescriptions are never issued automatically; only a licensed doctor decides after an individual review.

3. Personal Data Processed

We may process identity data such as name, date of birth, gender, address, email and telephone number, as well as account, session and authentication data. Passwords are not stored in plain text. Health data may include symptoms, previous conditions and treatments, medication, allergies, pregnancy where medically relevant, alcohol, nicotine or cannabis use where requested and relevant, height, weight, risk factors, reasons for a request, medical decisions and previous requests. These may be health data under Article 9 GDPR and receive special protection.

4. Purpose of Processing

Data is processed to create and manage accounts, receive medical requests, provide medical history to the reviewing doctor, enable individual medical review, make previous requests available for follow-up decisions, document medical decisions, technically create and process prescriptions where applicable, send prescriptions to the selected pharmacy, process payments, send necessary system and status emails, secure and operate the platform, and comply with statutory retention and evidentiary duties.

5. Legal Bases

Depending on the operation, ordinary personal data is processed under Article 6(1)(b) GDPR when necessary to perform the user or intermediary relationship, Article 6(1)(c) when legally required, and Article 6(1)(f) for legitimate interests in secure and proper platform operation. Health data additionally requires Article 9 GDPR. Before submitting a medical request, patients should expressly consent to processing their health data for handling and medical review. Article 9(2) GDPR may also apply where processing is directly necessary for treatment by a healthcare professional.

6. Registration and User Account

An account is required for certain functions. Login uses an email address and password, with technical protection against repeated failed attempts. A forgotten password can be reset through a link valid for 15 minutes. Existing sessions end after a password change, and prolonged inactivity causes automatic logout.

7. Medical History and Medical Review

Patients may complete a digital medical history. Medical data is made available to a licensed doctor. Several doctors may initially see that a new request exists, but only limited information. Once accepted, the case is assigned to that doctor. The doctor receives the information required for the decision, including the full history, health and medication information, previous courses and selected pharmacy. The decision is made exclusively by the licensed doctor; there is no solely automated medical decision-making.

8. Previous Requests and Treatment History

For later requests, the reviewing doctor may access previous requests and their history where necessary for medical assessment. Patients can view previous requests, status, medical decision, doctor name and reasons in their account. Medical-history information may be corrected or supplemented. If correction requires a new review, it is treated as a new medical request.

9. Prescription Issuance

A prescription is created only after a licensed doctor has made an appropriate medical decision following an individual review. Medpharm does not decide whether a prescription is issued. Electronic signing uses a qualified signature service. Under the current technical setup, medical prescription contents are not sent to that service; cryptographic signature information is used.

10. Transmission to Pharmacies

After a positive medical decision, the prescription may be made available to the selected pharmacy. The pharmacy receives an individual token-based access link by email, intended for one-time use. No separate pharmacy account is currently required. The pharmacy receives only the information necessary to process and dispense the prescription, not the complete medical history. Further processing is the responsibility of the pharmacy.

11. Prescription Storage

Issued prescriptions may remain stored in the technical infrastructure after transmission. Medpharm access is restricted to administrative purposes, such as complying with retention periods and later deletion. Treatment documentation generally must be retained for ten years after treatment under Section 630f(3) German Civil Code, unless another law applies. The final allocation of retention duties between doctor and Medpharm will be set out in the deletion and responsibility concept.

12. Storage and Hosting

The central infrastructure operates in Germany or the European Union. Personal and health data is encrypted according to the current security concept. Measures include encrypted storage, role-based access, authentication, time-limited tokens, automatic session termination, protection against repeated login attempts and encrypted backups. Backups are also encrypted; a binding retention and deletion policy is currently being introduced.

13. Cloudinary

Prescription PDFs are currently partly stored through Cloudinary as a technical interim solution because they may contain health data. Medpharm intends to migrate medical prescription documents to infrastructure in Germany or the EU. Until then, documents must not be publicly accessible and are provided only through protected access mechanisms. Where processing occurs outside the EEA, the required safeguards and contractual bases are applied.

14. Payment Processing with Mollie

Mollie is used for payments. Depending on availability, credit or debit cards, PayPal, Apple Pay and other methods may be offered. Mollie processes the payment and transaction data required for payment; Medpharm generally does not receive all complete payment details. Medical content and complete medical histories are not sent to Mollie. Payment concerns the medical or telemedical service provided by Medpharm, not the purchase of medication through Medpharm.

15. Email Delivery via Resend

Resend is used for technically necessary emails, especially transactional messages. Complete medical histories and prescription PDFs are not sent by email. Emails may contain information about a specific medication request and may therefore have a health connection; they are protected accordingly. Advertising and newsletters are not currently sent.

16. SIGN8

SIGN8 may be used for qualified electronic signatures. Doctors need their own SIGN8 account and complete its identification process. Under the current setup, Medpharm does not send licence documents or complete patient data to SIGN8. SIGN8 processes the identification data stored by the doctor within that independent account.

17. Verification of Medical Licence

Before access to the Medpharm doctor application, proof of a medical licence is checked. A permanent copy is not currently intended to be stored. Medpharm may document that the check took place and when.

18. Strictly Necessary Cookies and Storage Technologies

The platform uses strictly necessary cookies or comparable storage technologies for login, session management, authentication and security. Marketing, advertising and analytics cookies such as Google Analytics, Meta Pixel or Hotjar are not currently used.

19. No Use for Advertising, Profiling or Research

Patient and health data is not currently used for personalised advertising, marketing profiles, commercial analysis or research. Automated profiling for advertising does not take place.

20. Encryption and Access Protection

Medpharm uses technical and organisational measures including encryption of sensitive data and backups, secure password storage, role-based permissions, separation of patient, doctor, pharmacy and administrator roles, time-limited authentication, protection against repeated login attempts and automatic session timeouts. Administrative access is limited to technical, administrative, support, security or statutory purposes. Audit logging is intended to be introduced or further developed before final production operation.

21. Transfers Outside the European Union

Personal data is generally processed in Germany or the EU. Cloudinary storage of prescription PDFs may be an exception. Transfers to countries outside the EU or EEA occur only in compliance with the legal requirements for international transfers.

22. Storage Period and Deletion

Data is retained only as long as needed for its purpose or required by law. A binding deletion concept for ordinary account and platform data is currently being introduced. Patients may request deletion by email, although medical, commercial, tax or other retention duties may restrict it. Treatment-relevant documentation may need to be kept for ten years. Afterwards data is deleted or anonymised unless another legal basis applies.

23. Backups

Medpharm creates encrypted backups stored in Germany or the EU. A fixed backup-retention policy is being introduced so older backups are deleted regularly and automatically. Where technically and legally possible, data may be removed from backup systems in response to justified deletion requests or deleted through the defined backup lifecycle.

24. Rights of Data Subjects

Subject to legal requirements, data subjects have rights of access, rectification, erasure, restriction, data portability, objection to certain processing and withdrawal of consent for the future. Requests may be sent to info@med-pharm.de, preferably from the account email address. Medpharm may request additional identity verification where justified. Patients generally also have the right to inspect their medical file and request electronic copies.

25. Right to Complain to a Supervisory Authority

Data subjects may complain to a data protection supervisory authority if they believe processing violates the GDPR. For a company based in Munich, the competent Bavarian supervisory authority for the private sector is particularly relevant.

26. Data Breaches

Medpharm maintains an internal process for possible data-protection and security incidents, including technical containment, documentation, identification of affected data and people, risk assessment, notification to the supervisory authority where required, notification of affected people where required, and remediation of the cause.

27. Minors

The platform is intended for adults. Users must provide complete and truthful information, especially their date of birth. Before dispensing medication, the pharmacy may perform additional identity or age checks. False information may prevent a medical request from being processed properly.

28. Consents and Mandatory Information

Before submitting a medical request, patients should read this policy, accept the terms and conditions, and provide a separate declaration consenting to health-data processing. Consent should be recorded technically, including the time and version of the accepted document.

29. Changes to this Privacy Policy

Medpharm may amend this policy when legal requirements change, new functions or providers are introduced, or technical processing changes. The current version published on the platform applies.