Privacy Policy

    Last updated: 24 May 2026 · This policy describes how Artifakt Vigilance processes personal data of users in the European Economic Area and the United Kingdom.

    1. Data Controller

    The controller responsible for the processing described in this policy is:

    Artifakt Vigilance
    Operator: Oskar Slavicek, Czech OSVČ (sole trader), IČO 17672058, Czech Republic. See the Imprint for the full §5 TMG provider identification
    Email: hello@artifaktmedical.com

    We have assessed that the appointment of a Data Protection Officer under GDPR Art. 37 is not currently mandatory for our scale of processing. We will reassess as the service grows and will publish the appointment here if required.

    2. Personal Data We Process

    The service processes the following categories of personal data:

    CategoryFieldsSource
    AccountEmail address and Cognito account identifierProvided by Cognito after authentication
    Search activityQuery terms, date ranges, data sources selected, result counts, timestampsGenerated whenever the search is used - by both signed-in users and anonymous (free Quick search) visitors
    ExportsQuery, result counts, optional organisation name, timestampGenerated when you download a report
    Alert subscriptionsSubscribed query terms, active flag, last-sent timestampCreated when you opt in to alerts
    Product usage analyticsCoarse interaction events (page views, which features you used, search configuration such as selected data sources and filter counts, literature-workflow milestones such as creating a review, freezing a protocol, running a search, starting AI screening, and generating or exporting a document and which document type, literature screening include/exclude decisions, viewing the vigilance-data stage and marking a recall relevant or not, timestamps) and a first-party analytics identifier. No raw search terms, protocol text, device, manufacturer or recall names, or free text.Generated as you use the site, only if you accept the analytics cookie tier
    Anonymous usage totalsDaily counts of how often a feature is used (for example reports generated by document type, documents exported, protocols frozen). These are aggregate totals only - no identifier, no IP address, and nothing stored on your device - so they are not personal data and are not linked to you.Counted automatically server-side when an action happens; not personal data, so no consent is required
    Survey responsesWorkflow questions you answered, optional contact info if you opted inProvided by you in the optional feedback survey
    PSUR draftsTitle, query parameters, the assembled markdown body, timestamps. Auto-saved at the end of every PMS report generation for signed-in users.Generated when you run the PMS Report Generator
    Literature-review workspaceThe review and its search protocol: device and manufacturer identity, intended purpose, any equivalent device(s) and their manufacturer, the objective/PICO question, search strategy and selection criteria, and any names and details you enter for the researcher(s) and the author/reviewer/approver of the document. Plus your screening and appraisal decisions on the records found and the generated documents. Where you enter another person's name (e.g. a researcher or approver), you provide it as the data controller for that information.Provided by you when you build a review, define its protocol, and screen records
    TechnicalSalted SHA-256 hash of your IP (for per-IP search quota - 10 free searches per UTC day - and regulator rate-limit - 300 calls per hour). The raw IP never lands in our database; only the salted hash is stored, which resets at the window boundary.HTTP request headers

    We do not collect special categories of data (GDPR Art. 9) and we do not perform device fingerprinting or cross-site tracking.

    3. Purposes and Legal Bases (GDPR Art. 6)

    PurposeLegal basis
    Provide the search, comparison, AI analyst, and export features you have requestedArt. 6(1)(b) - performance of contract
    Send alert emails for searches you subscribed toArt. 6(1)(a) - consent (you can withdraw at any time)
    Send occasional product and safety-signal newslettersArt. 6(1)(a) - consent (you can withdraw at any time)
    Aggregate, anonymised analytics on which device categories are most searchedArt. 6(1)(f) - legitimate interest in improving the service; the data is not used to profile individuals
    Rate limit and prevent abuse of the AI endpointsArt. 6(1)(f) - legitimate interest in protecting the service from cost-drain attacks
    Comply with legal obligations (accounting, tax, security incident reporting)Art. 6(1)(c) - legal obligation

    4. Sub-processors and International Transfers

    We use the following sub-processors to operate the service. See the sub-processor page for up-to-date details, locations, and processing scopes.

    • Amazon Web Services - the entire stack runs on a single Lightsail VM in Frankfurt: frontend hosting (Caddy), backend (FastAPI), and self-hosted PostgreSQL. Generative-AI inference goes to Amazon Bedrock with Anthropic Claude models using the eu. cross-region inference profile so all AI inputs and outputs stay inside the EU.
    • Stripe Payments Europe Ltd. (Ireland) - subscription billing. Card details are collected and stored by Stripe; we only retain the Stripe customer ID and subscription state.
    • Resend (Resend.com Inc.) - transactional email for PMS alert digests and product notifications. Delivered from the EU region.
    • Web3Forms (US) - form-to-email backend for the public “Request access / contact” form only. It forwards the name, email and message you type to our inbox; it is not used for any signed-in account data. We are migrating this form to our EU backend.

    All primary processing - database, authentication, AI inference, and frontend hosting - happens inside the EU. We self-host PostgreSQL on the Lightsail VM, so personal data never leaves the EU-region disk. Bedrock inference uses the eu. cross-region inference profile (data does not leave the EU). Corporate access by AWS / Stripe / Resend US parent entities is governed by the European Commission's Standard Contractual Clauses. The one exception to EU-only processing is the public contact form, handled by Web3Forms in the US, which carries only the name, email and message you enter - we are migrating it to our EU backend. You may request a copy of the relevant safeguards by emailing hello@artifaktmedical.com.

    5. AI Processing (EU AI Act, GDPR Art. 22)

    The service uses generative AI models to (a) normalise search queries, (b) answer questions about search results (the “AI Vigilance Analyst”), and (c) draft Post-Market Surveillance report sections.

    The AI outputs are decision support, not automated decisions. They are intended to assist regulatory professionals and do not produce decisions that have legal or similarly significant effects on individuals (GDPR Art. 22).

    When you use an AI feature, the inputs (your query, the loaded search-result aggregates) are sent to Amazon Bedrock, which serves Anthropic Claude models entirely inside EU regions under the eu. cross-region inference profile. We do not include account-level identifiers in those payloads. Anthropic's Bedrock DPA confirms the inputs are not used to train models. AI outputs may be incomplete, inaccurate, or inconsistent - you are responsible for verifying them before any downstream use.

    6. Cookies and Local Storage

    We use only strictly necessary local storage to remember your authenticated session (so you do not have to log in on every visit). Optional convenience storage - such as remembering the organisation name pre-filled in the export dialog - is only used when you have consented via the banner. If you accept the analytics tier, we also store a first-party analytics identifier (a random id in local storage and a per-session id) so we can understand how the tool is used; both are erased if you withdraw consent. We do not use third-party tracking cookies, advertising pixels, or cross-site identifiers.

    You can withdraw or change your consent at any time via the “Manage preferences” link in the page footer.

    7. Data Retention

    • Account data - retained while your account is active and for up to 30 days after deletion (then permanently erased).
    • Search activity - retained 24 months, then aggregated into anonymised statistics and the underlying rows deleted.
    • Exports - retained 24 months for audit purposes, then deleted.
    • Alert subscriptions - retained while active; deleted within 30 days of cancellation.
    • Survey responses - retained 24 months in identifiable form, then anonymised.
    • Product usage analytics - retained up to 24 months, then deleted or aggregated into anonymous statistics. Events recorded before sign-in are not linked to an account.
    • PSUR drafts - retained while your account is active. Hard-deleted at the end of the 30-day grace period if you request account erasure (FK cascade on user delete).
    • Rate-limit counters - IP-quota search bucket resets at 00:00 UTC daily; regulator rate-limit bucket resets every hour.

    8. Your Rights (GDPR Art. 15-22)

    You have the right to:

    • Access a copy of the personal data we hold about you.
    • Rectification of inaccurate data.
    • Erasure (“right to be forgotten”).
    • Restriction of processing while a request is being resolved.
    • Portability in a structured, commonly used, machine-readable format (JSON).
    • Object to processing based on legitimate interest.
    • Withdraw consent at any time, where processing is based on consent.
    • Not be subject to automated decision-making that has legal or significant effects (we do not perform such processing - see section 5).

    How to exercise these rights: sign in and visit your account page - “Download my data” produces a JSON export, and “Delete my account” initiates a 30-day-grace erasure. For any request we cannot satisfy automatically, email hello@artifaktmedical.com. We respond within one month (GDPR Art. 12(3)).

    9. Right to Lodge a Complaint

    If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement. A list of EU data protection authorities is available at edpb.europa.eu/about-edpb/about-edpb/members_en.

    10. Security

    Personal data is encrypted at rest by the database provider and in transit via TLS. Access is gated by row-level security policies scoped to each user's authenticated identity. We minimise the data we collect, audit access internally, and have a documented procedure for notifying the supervisory authority within 72 hours of becoming aware of a personal data breach.

    11. Changes to This Policy

    We will notify active account holders by email of material changes at least 14 days before they take effect. Continued use of the service after that date constitutes acceptance of the updated policy.

    12. Contact

    Privacy questions: hello@artifaktmedical.com. General contact: hello@artifaktmedical.com.