Privacy Policy

Privacy Policy

Your privacy is important to us.

Effective Date: November 25, 2025

At MediStack, we understand that healthcare data is deeply personal and sensitive. Your trust in us to protect your health information is fundamental to our mission. This Privacy Policy outlines our commitment to safeguarding your information while providing you with quality healthcare services.

Important: MediStack is a healthcare platform governed by healthcare privacy regulations including HIPAA (where applicable). We treat all health information with the highest level of security and confidentiality.

1

Introduction

Welcome to MediStack ("we," "us," or "our"). MediStack is part of the Duck family of companies. We are committed to protecting your privacy and ensuring the confidentiality of your healthcare information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services (the "Services"). Your privacy and the security of your health information are paramount to us.

2

Information We Collect

We may collect information about you in a variety of ways. The information we may collect on the Services includes: • Personal Data: Personally identifiable information, such as your name, email address, phone number, professional credentials, and demographic information, that you voluntarily provide when you register with the Services. • Healthcare Data: Medical information, patient records, clinical notes, treatment history, and other health-related data necessary for healthcare delivery. • Financial Data: Financial information, such as data related to your payment method (e.g., valid credit card number, card brand, expiration date) that we may collect when you make a purchase or pay for services. • Professional Data: For healthcare providers, credentials, licenses, specializations, qualifications, and practice information. • Device Information: Information about the devices you use to access MediStack, including device type, operating system, and unique device identifiers.

3

How We Use Your Information

Having accurate information permits us to provide you with a smooth, efficient, and customized healthcare experience. Specifically, we may use information collected about you via the Services to: • Create and manage your account and patient/provider profile. • Process your transactions, appointments, and healthcare services. • Email you regarding your account, orders, appointments, or healthcare communications. • Enable user-to-user communications between patients and providers. • Facilitate telemedicine consultations and healthcare delivery. • Improve our healthcare services and platform functionality. • Conduct medical research (with appropriate consent and anonymization). • Comply with healthcare regulations and legal obligations.

4

Sharing Your Information

We may share information we have collected about you in certain situations. Your information may be disclosed as follows: • By Law or to Protect Rights: If we believe the release of information about you is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others. • Healthcare Providers: We share your healthcare information with healthcare providers, specialists, and other medical professionals involved in your care, as necessary for treatment purposes. • Third-Party Service Providers: We may share your information with third parties that perform services for us or on our behalf, including payment processing, data analysis, email delivery, hosting services, and customer service. • Emergency Situations: In medical emergencies where sharing your health information is necessary to protect your life or health.

5

The Duck Family of Companies

As part of the Duck ecosystem, we may share your information with our parent company, subsidiaries, and affiliates (collectively, the "Duck Family"). This sharing is done to provide integrated services, such as connecting your MediStack healthcare activities with your travel and hospitality needs on other Duck platforms, and to offer a more personalized and seamless experience across all our services. All members of the Duck Family are bound by this Privacy Policy or a similar policy with equally protective terms. We will always seek your consent before sharing sensitive health information with non-healthcare members of the Duck ecosystem.

6

Legal Basis for Processing

We process your personal data on several legal bases: (1) with your explicit consent; (2) as necessary to perform our contract with you; (3) as necessary for our legitimate interests (e.g., for administrative purposes, to improve our services); (4) as necessary to comply with our legal obligations; and (5) as necessary to protect vital interests in emergency healthcare situations. For healthcare data specifically, we rely on your consent and on legal requirements to provide treatment services. You have the right to withdraw consent at any time by contacting us, except where processing is required by law.

7

Data Retention

We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy policy, unless a longer retention period is required or permitted by law. Healthcare data is typically retained for: • During your active use of the Service plus a minimum of 3 years after account closure (for continuity of care and legal compliance). • Longer periods as required by healthcare regulations (e.g., medical records retention laws typically require 7-10 years depending on jurisdiction). • Tax, accounting, or other legal requirements may necessitate longer retention periods. When data is no longer needed, we securely delete or anonymize it.

8

Security of Your Information

We use administrative, technical, and physical security measures to help protect your personal information. Our security measures include: • AES-256 encryption for data at rest. • TLS 1.3 encryption for data in transit. • Multi-factor authentication for account access. • Regular security audits and penetration testing. • HIPAA-compliant infrastructure and procedures. • Role-based access control to limit who can access health data. While we have taken reasonable steps to secure the personal information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable.

9

Your Data Protection Rights

Depending on your location, you may have the following rights regarding your personal data: • Right to Access: You can request access to your personal data and health records. • Right to Rectification: You can request correction of inaccurate or incomplete information. • Right to Erasure: You can request deletion of your data (subject to legal retention requirements). • Right to Restrict Processing: You can request limitation of how your data is used. • Right to Object: You can object to certain types of data processing. • Right to Data Portability: You can request your data in a portable format. • Right to Withdraw Consent: You can withdraw consent at any time. To exercise these rights, please contact us at privacy@medistack.com.

10

International Data Transfers

Your information, including personal data and health information, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ. When we transfer health data internationally, we implement appropriate safeguards such as Standard Contractual Clauses and appropriate level of data protection. By using MediStack, you consent to such transfer of your information to jurisdictions outside your country of residence.

11

Children's Privacy

Our Services are not intended for use by children under the age of 13, and we do not knowingly collect personal information from children under 13. For users between 13-18 years old, parental consent is required. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete such information promptly. If you believe we have collected information from a child, please contact us immediately.

12

HIPAA Compliance

For users subject to HIPAA (Health Insurance Portability and Accountability Act), MediStack implements HIPAA-compliant safeguards for protected health information (PHI). Our Business Associate Agreements (BAAs) are available to covered entities and business associates. We maintain: • Administrative, physical, and technical safeguards. • Breach notification procedures. • Audit controls and access logging. • Encrypted communications and storage. • Regular risk assessments and security evaluations.

13

"Do Not Track" Signals

Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature or setting you can activate. We do not currently respond to DNT browser signals or mechanisms, but you can control tracking through your browser privacy settings and our preference center.

14

Third-Party Websites

The Services may contain links to third-party websites and applications of interest, including advertisements and external services, that are not affiliated with us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services before providing your information.

15

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. For changes involving health data handling, we will provide at least 30 days' notice. You are advised to review this Privacy Policy periodically for any changes. Your continued use of the Service following the posting of revised Terms means that you accept and agree to the changes.

16

Contact Us

If you have questions or comments about this Privacy Policy, or wish to exercise your data protection rights, please contact us at: Email: privacy@medistack.com Mailing Address: Global Headquarters (Contact page for current location) Phone: +1 (800) 123-4567 For privacy complaints, you also have the right to lodge a complaint with your local data protection authority.

Your Privacy Rights

Healthcare Regulations

  • ✓ HIPAA Compliant
  • ✓ GDPR Compliant
  • ✓ CCPA Compliant
  • ✓ SOC 2 Type II Certified

Your Rights

  • ✓ Access your data
  • ✓ Correct inaccuracies
  • ✓ Request deletion
  • ✓ Withdraw consent

Questions About Your Privacy?

Our privacy and data protection team is ready to assist you with any questions or concerns about how we handle your data.

Contact Privacy Team