Privacy Policy

Version 1.0 provisional · Last updated: June 2026 · GDPR compliant (EU 2016/679)
Provisional version. This document is published pending the incorporation of MNEMIS SAS. The DPO's postal address and certain details will be completed upon registration.
Table of contents
  1. Who We Are
  2. Data collected
  3. Purposes and legal bases
  4. Hosting and Security
  5. Data Sharing
  6. Retention periods
  7. Your rights
  8. Cookies
  9. International Data Transfers
  10. Contact and DPO
MNEMIS processes health data, which constitute special category data within the meaning of the GDPR. We apply the highest available level of protection. Your data is pseudonymised prior to any access by researchers, and we never monetise your data without your explicit consent.

1. Who We Are

MNEMIS SAS is the data controller in respect of your personal data within the meaning of Article 4(7) of the GDPR (Regulation (EU) 2016/679). We operate as a certified Hébergeur de Données de Santé (HDS — Health Data Host) in accordance with Article L.1111-8 of the French Code de la santé publique (Public Health Code).

🔒 HDS-Certified Health Data Host · Infrastructure hosted entirely in France · Scaleway HDS

Our Data Protection Officer (DPO) may be contacted at : dpo@mnemis.health

2. Data collected

2.1 Patient data

Data fieldMandatoryPurpose
Last name, first nameYesIdentity verification and token recovery
Date of birthYesIdentity verification and epidemiological data
Sex at birthYesEpidemiological data (research)
Groupe sanguinNoEnriched medical data (research)
Country of residence and country of birthYesGeographic segmentation
EmailNoNotifications and token recovery
Phone numberNoSMS notifications and token recovery
HPK tokenYesPseudonymised authentication
Medical documentsYesDigital health record

2.2 Healthcare professional data

Data fieldPurpose
Last name, first name, medical specialtyProfessional identification
Professional email addressAuthentication and communications
Institution and countryQualification and audit trail
Upload historyAudit trail and HPK token compensation
Connection logs (IP, date)Security and audit

2.3 Technical data

MNEMIS collects technical operational data (access logs, performance metrics) solely for the purposes of securing and improving the platform. Such data is not used for commercial purposes.

3. Purposes and legal bases

PurposeLegal basis (GDPR)
Storage and access to medical documents Article 9(2)(h) — healthcare + explicit consent
Generation of AI-powered summaries Article 9(2)(h) — legitimate interests relating to healthcare + explicit consent
Sharing with the medical research community Article 9(2)(j) — public interest / scientific research + explicit consent
Email and SMS notifications Article 6(1)(b) — performance of contract
Authentication and security Article 6(1)(f) — legitimate interests (security)
Management of HPK tokens Article 6(1)(b) — performance of contract
Logs and monitoring Article 6(1)(c) — legal obligation (HDS) + legitimate interests

4. Hosting and Security

4.1 Infrastructure

All health data is hosted exclusively in France on the Scaleway infrastructure, certified as a Hébergeur de Données de Santé (HDS — Health Data Host) in accordance with French regulations. No health data is hosted outside French territory.

4.2 Technical measures

4.3 Data access

Access to health data is strictly limited to: the patient via their HPK token; the healthcare professional in respect of documents they have personally uploaded; and MNEMIS technical staff solely in the context of maintenance and security operations (all access being logged and auditable).

5. Data Sharing

5.1 Private data

Data designated as "private" is never shared with any third party, without exception. It is accessible only to the relevant patient and the healthcare professional concerned.

5.2 Data shared with research

Where the patient has given explicit consent to sharing, data is pseudonymised in accordance with the following process prior to any disclosure:

5.3 Data processors

MNEMIS engages the following data processors, each bound by data processing agreements (DPAs) compliant with the GDPR:

Data ProcessorRoleCountry
ScalewayDatabase hosting and storage (HDS-certified)🇫🇷 France
AnthropicGeneration of AI-powered summaries🇺🇸 USA (pseudonymised text only)
ResendTransactional email delivery🇺🇸 USA (email address and token only)
TwilioSMS delivery🇺🇸 USA (phone number and message only)

Note on Anthropic: Medical documents transmitted to the Claude API for summary generation contain no directly identifying data. Document text is transmitted without name, without token, and without any information that could link the content to a specific patient.

6. Retention periods

Data categoryRetention period
Private medical documentsAccount duration + 10 years following closure (medical legal obligation)
Documents shared with the research communityIndefinite — irrevocably integrated into the research repository and cannot be withdrawn
Patient profile dataAccount duration + 3 years
Healthcare professional dataAccount duration + 5 years
Logs de sécurité90 jours
Consent logs30 years (evidentiary value)
Aggregated metrics5 years

7. Your rights

In accordance with the GDPR, you have the following rights in respect of your personal data:

📋 Right of access
To obtain a copy of all personal data processed by MNEMIS.
✏️ Right to rectification
To correct inaccurate data held about you (profile, contact details).
🗑️ Right to erasure
To request deletion of your account and private data, subject to applicable legal medical retention obligations.
⏸️ Right to restriction of processing
To request that processing of your data be suspended in certain circumstances provided for under the GDPR.
📦 Right to data portability
To receive your data in a structured, commonly used, and machine-readable format (e.g. JSON, PDF).
🚫 Right to object
To object to certain processing activities based on legitimate interests.

Important limitation regarding shared data : le droit à l'effacement et le droit d'objection ne s'appliquent pas aux données que vous avez explicitement et irrévocablement partagées avec la medical research, conformément à l'article 17(3)(d) du RGPD (traitement à des fins de recherche scientifique dans l'intérêt public).

To exercise your rights : dpo@mnemis.health — Response within 30 days. If your complaint remains unresolved, you may lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés), the French supervisory authority for data protection : www.cnil.fr

8. Cookies

MNEMIS uses a minimal number of cookies, strictly necessary for the operation of the platform:

As these cookies are strictly necessary for the delivery of the service, they do not require your prior consent in accordance with the ePrivacy Directive (Directive 2002/58/EC).

9. International transfers

Health data (medical documents, patient profiles) is hosted exclusively in France and is not subject to any international transfer.

Certain non-sensitive data is processed by US-based data processors (email delivery, SMS, pseudonymised AI summaries). These transfers are governed by the Standard Contractual Clauses (SCCs) adopted by the European Commission, in accordance with Article 46 of the GDPR.

MNEMIS regularly assesses the adequacy of the safeguards provided by its US-based data processors and intends to favour European alternatives where these offer equivalent guarantees.

10. Contact and DPO

For any questions relating to the protection of your personal data:

Data Protection Officer (DPO) Email : dpo@mnemis.health
Courrier : MNEMIS SAS — DPO — Postal address to be confirmed upon incorporation of the legal entity

General support Email : support@mnemis.health

Competent supervisory authority Commission Nationale de l'Informatique et des Libertés (CNIL) — the French supervisory authority for data protection
3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07
www.cnil.fr