GDPR / UK-GDPR Notice (EU/UK users)
Last updated: August 27, 2026
How MDChat Inc. ("MDChat", "we", "us") handles personal data of individuals in the European Economic Area (EEA) and United Kingdom under the GDPR and UK-GDPR. This notice supplements our Privacy Policy.
1. Is this notice for you?
This notice applies to individuals located in the European Economic Area (EEA) and the United Kingdom whose personal data MDChat processes, to the extent the EU General Data Protection Regulation (GDPR) or UK-GDPR applies. MDChat is a US-based service. Swiss residents are covered by the revised Swiss Federal Act on Data Protection (FADP), which imposes similar but distinct obligations; we are confirming our FADP requirements (including any Swiss representative) separately. Whether we currently offer the service to, or monitor the behavior of, individuals in the EEA/UK — and therefore whether the GDPR/UK-GDPR applies to a given user — is being confirmed with counsel. We publish this notice so that, if and when EU/UK users are served, our commitments are clear. It supplements, and should be read together with, our Privacy Policy.
2. Who is responsible for your data (controller)
For personal data processed through MDChat, the data controller is MDChat Inc., 8 The Green, Ste. A, Dover, DE 19901. You can reach us about data protection at privacy@mdchat.com.
3. Legal bases for processing
Under the GDPR/UK-GDPR we process personal data only where we have a lawful basis. Depending on the activity, our bases are:
- Consent — for example, for marketing messages, and for processing the health information you choose to share in the chat. You can withdraw consent at any time (see §4).
- Performance of a contract — to provide the service you request, such as conducting the intake, generating your assessment, and connecting you with care.
- Legitimate interests — to operate, secure, and improve the service and prevent fraud and abuse, where those interests are not overridden by your rights. We balance these interests against your privacy.
- Vital interests — in an emergency, to protect your life or someone else’s (for example, when responding to a situation that suggests a risk of serious harm).
- Legal obligation — where we must process data to comply with the law.
Health information is a “special category” of personal data, which we process based on your explicit consent and, where applicable, for the provision of health care.
4. Your rights
Subject to the conditions and exceptions in the GDPR/UK-GDPR, you have the right to:
- Access — obtain confirmation of whether we process your data and a copy of it.
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask us to delete your data (“right to be forgotten”), subject to records we must retain by law.
- Restriction — ask us to limit how we use your data in certain circumstances.
- Portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, email privacy@mdchat.com. We will respond within the timeframe required by law and may need to verify your identity first.
5. International transfers
MDChat is hosted in the United States, and our service providers may process data in the United States and other countries. This means that, if you are in the EEA or UK, your personal data may be transferred outside your home country. Where we make such transfers, we intend to rely on an appropriate transfer mechanism — for example, the European Commission’s Standard Contractual Clauses (SCCs) together with the UK International Data Transfer Addendum, and supplementary measures where needed. The specific safeguards for each transfer are being finalized; until they are confirmed, you should not assume a particular mechanism is in place. You can ask us about transfer safeguards at privacy@mdchat.com.
6. EU / UK representative (Article 27)
Where required, a controller outside the EU/UK that is subject to the GDPR/UK-GDPR must designate a representative within the EU and the UK. MDChat intends to appoint an Article 27 representative for the EU and the UK if and when it is required; one has not yet been named. Once appointed, the representative’s name and contact details will be published here. In the meantime, you can contact us directly at privacy@mdchat.com.
7. Right to lodge a complaint
If you believe our processing of your personal data infringes the GDPR/UK-GDPR, you have the right to lodge a complaint with a supervisory authority — in particular, the authority in the EEA member state of your residence or workplace, or, in the UK, the Information Commissioner’s Office (ICO). We would, however, appreciate the chance to address your concerns first, so please consider contacting us at privacy@mdchat.com before doing so.
8. Contact us
MDChat Inc. — 8 The Green, Ste. A, Dover, DE 19901
Data protection requests and questions: privacy@mdchat.com