MNEMIS SAS is the data controller in respect of your personal data within the meaning of Article 4(7) of the GDPR (Regulation (EU) 2016/679). We operate as a certified Hébergeur de Données de Santé (HDS — Health Data Host) in accordance with Article L.1111-8 of the French Code de la santé publique (Public Health Code).
Our Data Protection Officer (DPO) may be contacted at : dpo@mnemis.health
| Data field | Mandatory | Purpose |
|---|---|---|
| Last name, first name | Yes | Identity verification and token recovery |
| Date of birth | Yes | Identity verification and epidemiological data |
| Sex at birth | Yes | Epidemiological data (research) |
| Groupe sanguin | No | Enriched medical data (research) |
| Country of residence and country of birth | Yes | Geographic segmentation |
| No | Notifications and token recovery | |
| Phone number | No | SMS notifications and token recovery |
| HPK token | Yes | Pseudonymised authentication |
| Medical documents | Yes | Digital health record |
| Data field | Purpose |
|---|---|
| Last name, first name, medical specialty | Professional identification |
| Professional email address | Authentication and communications |
| Institution and country | Qualification and audit trail |
| Upload history | Audit trail and HPK token compensation |
| Connection logs (IP, date) | Security and audit |
MNEMIS collects technical operational data (access logs, performance metrics) solely for the purposes of securing and improving the platform. Such data is not used for commercial purposes.
| Purpose | Legal basis (GDPR) |
|---|---|
| Storage and access to medical documents | Article 9(2)(h) — healthcare + explicit consent |
| Generation of AI-powered summaries | Article 9(2)(h) — legitimate interests relating to healthcare + explicit consent |
| Sharing with the medical research community | Article 9(2)(j) — public interest / scientific research + explicit consent |
| Email and SMS notifications | Article 6(1)(b) — performance of contract |
| Authentication and security | Article 6(1)(f) — legitimate interests (security) |
| Management of HPK tokens | Article 6(1)(b) — performance of contract |
| Logs and monitoring | Article 6(1)(c) — legal obligation (HDS) + legitimate interests |
All health data is hosted exclusively in France on the Scaleway infrastructure, certified as a Hébergeur de Données de Santé (HDS — Health Data Host) in accordance with French regulations. No health data is hosted outside French territory.
Access to health data is strictly limited to: the patient via their HPK token; the healthcare professional in respect of documents they have personally uploaded; and MNEMIS technical staff solely in the context of maintenance and security operations (all access being logged and auditable).
Data designated as "private" is never shared with any third party, without exception. It is accessible only to the relevant patient and the healthcare professional concerned.
Where the patient has given explicit consent to sharing, data is pseudonymised in accordance with the following process prior to any disclosure:
MNEMIS engages the following data processors, each bound by data processing agreements (DPAs) compliant with the GDPR:
| Data Processor | Role | Country |
|---|---|---|
| Scaleway | Database hosting and storage (HDS-certified) | 🇫🇷 France |
| Anthropic | Generation of AI-powered summaries | 🇺🇸 USA (pseudonymised text only) |
| Resend | Transactional email delivery | 🇺🇸 USA (email address and token only) |
| Twilio | SMS delivery | 🇺🇸 USA (phone number and message only) |
Note on Anthropic: Medical documents transmitted to the Claude API for summary generation contain no directly identifying data. Document text is transmitted without name, without token, and without any information that could link the content to a specific patient.
| Data category | Retention period |
|---|---|
| Private medical documents | Account duration + 10 years following closure (medical legal obligation) |
| Documents shared with the research community | Indefinite — irrevocably integrated into the research repository and cannot be withdrawn |
| Patient profile data | Account duration + 3 years |
| Healthcare professional data | Account duration + 5 years |
| Logs de sécurité | 90 jours |
| Consent logs | 30 years (evidentiary value) |
| Aggregated metrics | 5 years |
In accordance with the GDPR, you have the following rights in respect of your personal data:
Important limitation regarding shared data : le droit à l'effacement et le droit d'objection ne s'appliquent pas aux données que vous avez explicitement et irrévocablement partagées avec la medical research, conformément à l'article 17(3)(d) du RGPD (traitement à des fins de recherche scientifique dans l'intérêt public).
To exercise your rights : dpo@mnemis.health — Response within 30 days. If your complaint remains unresolved, you may lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés), the French supervisory authority for data protection : www.cnil.fr
MNEMIS uses a minimal number of cookies, strictly necessary for the operation of the platform:
As these cookies are strictly necessary for the delivery of the service, they do not require your prior consent in accordance with the ePrivacy Directive (Directive 2002/58/EC).
Health data (medical documents, patient profiles) is hosted exclusively in France and is not subject to any international transfer.
Certain non-sensitive data is processed by US-based data processors (email delivery, SMS, pseudonymised AI summaries). These transfers are governed by the Standard Contractual Clauses (SCCs) adopted by the European Commission, in accordance with Article 46 of the GDPR.
MNEMIS regularly assesses the adequacy of the safeguards provided by its US-based data processors and intends to favour European alternatives where these offer equivalent guarantees.
For any questions relating to the protection of your personal data: