Effective Date: July 31, 2026
This Data Retention Policy describes how long MedSystum ("Company," "we," "us," or "our") retains the categories of data processed through MedSystum (the "Service"), and how that data is returned or destroyed. It supplements our Privacy Policy and any Business Associate Agreement ("BAA") between us. Where a BAA conflicts with this Policy, the BAA controls for Protected Health Information ("PHI").
Note: This is a placeholder policy provided for the initial release of the marketing website and does not constitute legal advice. Specific retention periods will be confirmed with counsel and reflected in your contract and BAA before general availability.
We retain data only for as long as necessary to provide the Service, to meet our legal and contractual obligations, and to support legitimate business needs such as security and audit. We apply the minimum-necessary principle to PHI throughout its lifecycle.
On termination of the Service, and in accordance with the applicable BAA, we will return or securely destroy PHI in our possession, and certify destruction on request, except where retention is required by law. Secure destruction renders data unreadable and unrecoverable.
You may request export or deletion of your data at any time by contacting us. We will honor verified requests subject to our legal obligations and the terms of any BAA. Requests involving PHI are handled through the covered entity or its authorized representative.
We may retain data beyond the periods described above where required to comply with legal obligations, resolve disputes, enforce our agreements, or preserve information subject to a legal hold. Such data is retained only for as long as the obligation or hold requires.
We may update this Policy from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, by notice to customers.
Questions about this Policy may be directed to hello@medsystum.com.