Privacy Policy
Last updated: 24 May 2026 · This policy describes how Artifakt Vigilance processes personal data of users in the European Economic Area and the United Kingdom.
1. Data Controller
The controller responsible for the processing described in this policy is:
Artifakt Vigilance
Operator: Oskar Slavicek, Czech OSVČ (sole trader), IČO 17672058, Czech Republic. See the Imprint for the full §5 TMG provider identification
Email: hello@artifaktmedical.com
We have assessed that the appointment of a Data Protection Officer under GDPR Art. 37 is not currently mandatory for our scale of processing. We will reassess as the service grows and will publish the appointment here if required.
2. Personal Data We Process
The service processes the following categories of personal data:
| Category | Fields | Source |
|---|---|---|
| Account | Email address and Cognito account identifier | Provided by Cognito after authentication |
| Search activity | Query terms, date ranges, data sources selected, result counts, timestamps | Generated whenever the search is used - by both signed-in users and anonymous (free Quick search) visitors |
| Exports | Query, result counts, optional organisation name, timestamp | Generated when you download a report |
| Alert subscriptions | Subscribed query terms, active flag, last-sent timestamp | Created when you opt in to alerts |
| Product usage analytics | Coarse interaction events (page views, which features you used, search configuration such as selected data sources and filter counts, literature-workflow milestones such as creating a review, freezing a protocol, running a search, starting AI screening, and generating or exporting a document and which document type, literature screening include/exclude decisions, viewing the vigilance-data stage and marking a recall relevant or not, timestamps) and a first-party analytics identifier. No raw search terms, protocol text, device, manufacturer or recall names, or free text. | Generated as you use the site, only if you accept the analytics cookie tier |
| Anonymous usage totals | Daily counts of how often a feature is used (for example reports generated by document type, documents exported, protocols frozen). These are aggregate totals only - no identifier, no IP address, and nothing stored on your device - so they are not personal data and are not linked to you. | Counted automatically server-side when an action happens; not personal data, so no consent is required |
| Survey responses | Workflow questions you answered, optional contact info if you opted in | Provided by you in the optional feedback survey |
| PSUR drafts | Title, query parameters, the assembled markdown body, timestamps. Auto-saved at the end of every PMS report generation for signed-in users. | Generated when you run the PMS Report Generator |
| Literature-review workspace | The review and its search protocol: device and manufacturer identity, intended purpose, any equivalent device(s) and their manufacturer, the objective/PICO question, search strategy and selection criteria, and any names and details you enter for the researcher(s) and the author/reviewer/approver of the document. Plus your screening and appraisal decisions on the records found and the generated documents. Where you enter another person's name (e.g. a researcher or approver), you provide it as the data controller for that information. | Provided by you when you build a review, define its protocol, and screen records |
| Technical | Salted SHA-256 hash of your IP (for per-IP search quota - 10 free searches per UTC day - and regulator rate-limit - 300 calls per hour). The raw IP never lands in our database; only the salted hash is stored, which resets at the window boundary. | HTTP request headers |
We do not collect special categories of data (GDPR Art. 9) and we do not perform device fingerprinting or cross-site tracking.
3. Purposes and Legal Bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide the search, comparison, AI analyst, and export features you have requested | Art. 6(1)(b) - performance of contract |
| Send alert emails for searches you subscribed to | Art. 6(1)(a) - consent (you can withdraw at any time) |
| Send occasional product and safety-signal newsletters | Art. 6(1)(a) - consent (you can withdraw at any time) |
| Aggregate, anonymised analytics on which device categories are most searched | Art. 6(1)(f) - legitimate interest in improving the service; the data is not used to profile individuals |
| Rate limit and prevent abuse of the AI endpoints | Art. 6(1)(f) - legitimate interest in protecting the service from cost-drain attacks |
| Comply with legal obligations (accounting, tax, security incident reporting) | Art. 6(1)(c) - legal obligation |
4. Sub-processors and International Transfers
We use the following sub-processors to operate the service. See the sub-processor page for up-to-date details, locations, and processing scopes.
- Amazon Web Services - the entire stack runs on a single Lightsail VM in Frankfurt: frontend hosting (Caddy), backend (FastAPI), and self-hosted PostgreSQL. Generative-AI inference goes to Amazon Bedrock with Anthropic Claude models using the eu. cross-region inference profile so all AI inputs and outputs stay inside the EU.
- Stripe Payments Europe Ltd. (Ireland) - subscription billing. Card details are collected and stored by Stripe; we only retain the Stripe customer ID and subscription state.
- Resend (Resend.com Inc.) - transactional email for PMS alert digests and product notifications. Delivered from the EU region.
- Web3Forms (US) - form-to-email backend for the public “Request access / contact” form only. It forwards the name, email and message you type to our inbox; it is not used for any signed-in account data. We are migrating this form to our EU backend.
All primary processing - database, authentication, AI inference, and frontend hosting - happens inside the EU. We self-host PostgreSQL on the Lightsail VM, so personal data never leaves the EU-region disk. Bedrock inference uses the eu. cross-region inference profile (data does not leave the EU). Corporate access by AWS / Stripe / Resend US parent entities is governed by the European Commission's Standard Contractual Clauses. The one exception to EU-only processing is the public contact form, handled by Web3Forms in the US, which carries only the name, email and message you enter - we are migrating it to our EU backend. You may request a copy of the relevant safeguards by emailing hello@artifaktmedical.com.
5. AI Processing (EU AI Act, GDPR Art. 22)
The service uses generative AI models to (a) normalise search queries, (b) answer questions about search results (the “AI Vigilance Analyst”), and (c) draft Post-Market Surveillance report sections.
The AI outputs are decision support, not automated decisions. They are intended to assist regulatory professionals and do not produce decisions that have legal or similarly significant effects on individuals (GDPR Art. 22).
When you use an AI feature, the inputs (your query, the loaded search-result aggregates) are sent to Amazon Bedrock, which serves Anthropic Claude models entirely inside EU regions under the eu. cross-region inference profile. We do not include account-level identifiers in those payloads. Anthropic's Bedrock DPA confirms the inputs are not used to train models. AI outputs may be incomplete, inaccurate, or inconsistent - you are responsible for verifying them before any downstream use.
6. Cookies and Local Storage
We use only strictly necessary local storage to remember your authenticated session (so you do not have to log in on every visit). Optional convenience storage - such as remembering the organisation name pre-filled in the export dialog - is only used when you have consented via the banner. If you accept the analytics tier, we also store a first-party analytics identifier (a random id in local storage and a per-session id) so we can understand how the tool is used; both are erased if you withdraw consent. We do not use third-party tracking cookies, advertising pixels, or cross-site identifiers.
You can withdraw or change your consent at any time via the “Manage preferences” link in the page footer.
7. Data Retention
- Account data - retained while your account is active and for up to 30 days after deletion (then permanently erased).
- Search activity - retained 24 months, then aggregated into anonymised statistics and the underlying rows deleted.
- Exports - retained 24 months for audit purposes, then deleted.
- Alert subscriptions - retained while active; deleted within 30 days of cancellation.
- Survey responses - retained 24 months in identifiable form, then anonymised.
- Product usage analytics - retained up to 24 months, then deleted or aggregated into anonymous statistics. Events recorded before sign-in are not linked to an account.
- PSUR drafts - retained while your account is active. Hard-deleted at the end of the 30-day grace period if you request account erasure (FK cascade on user delete).
- Rate-limit counters - IP-quota search bucket resets at 00:00 UTC daily; regulator rate-limit bucket resets every hour.
8. Your Rights (GDPR Art. 15-22)
You have the right to:
- Access a copy of the personal data we hold about you.
- Rectification of inaccurate data.
- Erasure (“right to be forgotten”).
- Restriction of processing while a request is being resolved.
- Portability in a structured, commonly used, machine-readable format (JSON).
- Object to processing based on legitimate interest.
- Withdraw consent at any time, where processing is based on consent.
- Not be subject to automated decision-making that has legal or significant effects (we do not perform such processing - see section 5).
How to exercise these rights: sign in and visit your account page - “Download my data” produces a JSON export, and “Delete my account” initiates a 30-day-grace erasure. For any request we cannot satisfy automatically, email hello@artifaktmedical.com. We respond within one month (GDPR Art. 12(3)).
9. Right to Lodge a Complaint
If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement. A list of EU data protection authorities is available at edpb.europa.eu/about-edpb/about-edpb/members_en.
10. Security
Personal data is encrypted at rest by the database provider and in transit via TLS. Access is gated by row-level security policies scoped to each user's authenticated identity. We minimise the data we collect, audit access internally, and have a documented procedure for notifying the supervisory authority within 72 hours of becoming aware of a personal data breach.
11. Changes to This Policy
We will notify active account holders by email of material changes at least 14 days before they take effect. Continued use of the service after that date constitutes acceptance of the updated policy.
12. Contact
Privacy questions: hello@artifaktmedical.com. General contact: hello@artifaktmedical.com.