Saltar al contenido
Medical You

Health Data Processing Consent

Last updated: 18 May 2026

This Health Data Processing Consent is currently available only in English. Localised versions will be published after legal review in each language.

MedicalYou Health Data Processing Consent

FieldDetail
Document TitleMedicalYou Health Data Processing Consent
Effective DateMonday, 18 May 2026
Version1.0
Intended AudienceUsers at signup, onboarding, and via account Settings
PurposeSeparate, explicit consent for processing health and special-category personal data, distinct from and supplementary to the Terms of Service and Privacy Policy
ControllerMedical You Pte. Ltd, 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914
DPOSamuel Banks — privacy@medicalyouglobal.com

Important Notice — Read Before Consenting

This is a separate consent document. It is not bundled into, or implied by, your acceptance of the MedicalYou Terms of Service. You must read and actively consent to this document before MedicalYou can process your health information. Ticking the boxes at the bottom of this document constitutes your explicit, freely given, specific, informed, and unambiguous consent to the processing activities described herein.

If you do not grant consent for the core processing described in Section 3(a)–(d) and Section 3(g), you will not be able to use the core MedicalYou service, because those activities are inherent to the product’s function. Optional processing activities — wearable data (Section 3(e)) and family/carer sharing (Section 3(f)) — are not required to use the app; you may decline or revoke those at any time without losing access to the core service.

This consent does not cover the use of anonymised, de-identified, or aggregated data for commercial purposes. That is an entirely separate, opt-in module (Document 4 — Anonymised Data Commercialisation Consent) which will be presented to you independently, with its own dedicated consent mechanism, and which defaults to off.

1. What MedicalYou Does and Why Your Health Data Is Involved

MedicalYou is a personal health record application operated by Medical You Pte. Ltd. The app allows you to store, organise, and understand your own medical information in one place. To do that, we necessarily receive, store, and process documents and data that contain detailed information about your health.

In plain terms, this means:

  • You upload documents — lab results, imaging reports, prescriptions, clinical letters, personal health notes, and similar records.
  • We store those documents securely on our servers in Singapore.
  • Our systems read and extract the structured health information contained in those documents so the app can display it usefully.
  • Artificial intelligence tools generate written summaries and insights based on the extracted information, to help you understand trends and patterns in your own health records.
  • If you choose, the app can also receive data from fitness wearables, or allow a family member or carer to view selected records with your permission.
  • We maintain security and audit logs to protect the integrity of your account and comply with our legal obligations.

Each of those activities involves processing your health data. Because health data carries a heightened legal sensitivity, we are required to obtain your explicit consent before any of this processing takes place.

2. Legal Classification of Your Health Data

2.1 Special-Category Personal Data — GDPR and UK GDPR

Under Article 9 of the EU General Data Protection Regulation (GDPR), data concerning health is a special category of personal data. Processing such data is prohibited unless a specific condition in Article 9(2) is met. We rely on Article 9(2)(a): the data subject (you) has given explicit consent to the processing for one or more specified purposes.

The same obligation applies under the UK GDPR, which mirrors the EU GDPR text following the UK’s departure from the European Union. The ICO’s guidance on special category data confirms that explicit consent requires a clear, positive action; it cannot be inferred from silence, pre-ticked boxes, or acceptance of general terms.

2.2 Sensitive Personal Data — Singapore PDPA

Under the Singapore Personal Data Protection Act 2012 (PDPA), health information is personal data requiring consent under the Act’s Data Protection Obligations. Although the PDPA does not enumerate a formal “special category” equivalent, Singapore law and the Personal Data Protection Commission (PDPC) consistently treat health information as data requiring heightened care, and consent must be voluntary, informed, and specific to the purposes notified.

2.3 Sensitive Personal Data — UAE PDPL and DIFC

The UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL), in force since 2 January 2022, classifies health data as sensitive personal data requiring explicit consent before processing. The DIFC Data Protection Law No. 5 of 2020, applicable in the Dubai International Financial Centre, similarly requires explicit consent for processing special-category and sensitive personal data.

2.4 Sensitive Information — United States

For users located in the United States, your health information is treated as sensitive personal information under applicable state law. California’s CPRA (California AG, CCPA/CPRA) designates health information as sensitive personal information and provides you with additional rights to limit its use. Under the Washington My Health My Data Act (RCW 19.373), processing consumer health data requires opt-in consent; sharing it requires separate consent; and selling it requires a separate signed valid authorisation — a standard we exceed by default. The FTC has made clear that health-related apps not subject to HIPAA are still subject to the FTC Act and the Health Breach Notification Rule where applicable.

MedicalYou is a direct-to-consumer app and is not a HIPAA-covered entity or business associate. Most user data is therefore not Protected Health Information (PHI) under HIPAA. However, we apply standards consistent with best practice and the requirements of the above laws in all markets we serve.

2.5 Summary

Your health data is legally classified as sensitive or special-category personal data under every legal framework applicable to our operations. This document obtains the explicit consent required by GDPR Art 9(2)(a), Singapore PDPA consent obligations (PDPC), UAE PDPL explicit-consent requirements (PDPL 2021), DIFC Law No. 5 of 2020 (Linklaters DIFC overview), and applicable US state health data laws (CPRA; WA MHMDA).

3. Granular Consent Items

The following table and accompanying descriptions set out each processing activity, whether it is required to use the core service or optional, and the legal basis for processing.

#Processing ActivityRequired / OptionalDefault State
3(a)Upload of health documentsRequiredOn
3(b)Storage in Singapore (AWS ap-southeast-1)RequiredOn
3(c)Parsing and extraction of health informationRequiredOn
3(d)AI summaries and health insights (Vercel AI Gateway and Anthropic)RequiredOn
3(e)Wearable data ingestion (Terra)OptionalOff
3(f)Family/carer sharing of recordsOptionalOff
3(g)Security and audit loggingRequiredOn

3(a) — Upload of Lab Reports, Imaging, Prescriptions, and Health Notes

What we process: When you use MedicalYou, you upload documents containing your personal health information. These may include, without limitation: laboratory test reports; radiology and imaging reports; specialist letters and clinical correspondence; prescriptions and medication records; vaccination records; hospital discharge summaries; and free-text personal health notes that you enter manually.

How it is used: Your uploaded documents are transmitted to our servers over encrypted connections (TLS 1.2 minimum) and stored in your personal health record. They are not used for any purpose other than providing the MedicalYou service to you, operating and improving service infrastructure, and complying with legal obligations, unless you have separately consented to a specific additional purpose in another consent module.

Why this is required: Document upload is the core input mechanism of the MedicalYou service. Without it, there is no content for the app to store, parse, or present to you.

Legal basis: Explicit consent under GDPR Art 9(2)(a); consent under Singapore PDPA (PDPC Obligations); explicit consent under UAE PDPL 2021 (UAE PDPL) and DIFC Law No. 5 of 2020 (DIFC).

3(b) — Storage in Singapore (AWS ap-southeast-1, Aurora PostgreSQL and Amazon S3)

What we process: All health documents and structured health records are stored in data centres operated by Amazon Web Services (AWS) in the ap-southeast-1 region (Singapore). Structured records (diagnoses, medication lists, lab values, profile data) are held in Aurora PostgreSQL databases. Documents (PDFs, images, scans, avatars) are held in Amazon S3 buckets. Singapore is our primary and default data residency jurisdiction.

Subprocessor disclosure: AWS acts as a data processor on our behalf under a Data Processing Agreement. AWS holds ISO 27001, SOC 2 Type II, and other internationally recognised security certifications. AWS does not have an independent right to access or use your health data.

Cross-border transfers: Where users are located in the EU/EEA or UK, transfer of health data to Singapore (a jurisdiction without a current EU adequacy decision) is covered by Standard Contractual Clauses (EU SCCs, June 2021, Controller-to-Processor module) with appropriate supplementary measures, and the UK International Data Transfer Addendum where applicable. For UAE users, transfers are conducted with comparable protection obligations in place, consistent with PDPL and DIFC requirements.

Why this is required: All data must be stored somewhere. Singapore is our primary jurisdiction and provides a stable, regulated environment with strong data protection law.

Legal basis: Explicit consent under GDPR Art 9(2)(a); PDPA consent (PDPC); UAE PDPL explicit consent (UAE PDPL).

3(c) — Parsing and Extraction of Health Information from Documents

What we process: When you upload a document, MedicalYou’s back-end systems read the content of that document and extract structured health data — for example, test names, reference ranges, measured values, date of test, prescribing clinician, medication names and dosages, and similar clinical data points. This extracted information is stored in your structured health record in Aurora PostgreSQL, linked to the original uploaded document.

How it is used: Extracted data powers the app’s displays, timelines, charts, trend views, and AI summaries. It enables you to search your records, view historical trends, and receive plain-English explanations of your results. Extraction is performed by automated software systems operating on our AWS infrastructure.

Accuracy and correction: Automated extraction may produce errors, particularly with handwritten documents or non-standard formats. You have the right to review and correct extracted data via the app’s editing tools at any time (see Section 10 — Data Subject Rights).

Why this is required: Without parsing and extraction, the app is a document archive with no analytical or presentation value. Extraction is the process that converts uploaded documents into the structured records on which all other app features depend.

Legal basis: Explicit consent under GDPR Art 9(2)(a); PDPA consent; UAE PDPL explicit consent; ICO special-category conditions guidance.

3(d) — AI Summaries and Health Insights via Anthropic (Automated Processing)

What we process: Structured health data extracted from your records is submitted as prompts, through the Vercel AI Gateway, to Anthropic’s large language models, to generate plain-English summaries, trend narratives, and health insights tailored to your record set. This AI processing takes place on the Vercel and Anthropic infrastructure, which is located outside Singapore, and is governed by our contractual data processing terms with those providers.

Nature of outputs: AI-generated outputs are informational summaries. They are not medical diagnoses, clinical assessments, treatment recommendations, or professional medical advice. They do not replace consultation with a qualified healthcare professional. MedicalYou is not a regulated medical device.

Automated decision-making: The AI summaries do not constitute automated decision-making that produces legal or similarly significant effects on you within the meaning of GDPR Art 22. They are presented as informational outputs for your personal review. No medical or legal decision about you is made by MedicalYou solely on the basis of automated processing.

Subprocessor disclosure: Vercel (which operates the Vercel AI Gateway) and Anthropic (which provides the AI models) act as data processors for this AI processing. They process your data only to return the AI outputs to us, under their contractual data processing obligations to us.

Why this is required: AI summarisation is the primary value-add feature of MedicalYou. Users consent to this activity as part of the core service. If this consent is withdrawn, meaningful use of the app is no longer possible.

Legal basis: Explicit consent under GDPR Art 9(2)(a); PDPA consent (PDPC); UAE PDPL explicit consent (UAE PDPL).

3(e) — Wearable Data Ingestion via Terra — OPTIONAL, DEFAULT OFF

Status: Optional. This toggle is off by default. You are not required to enable it.

What we process: If you choose to enable wearable data integration, MedicalYou will receive health and fitness data from your wearable devices (such as heart rate, step count, sleep data, activity data, blood oxygen, and similar metrics) via Terra, a third-party wearable data aggregation platform. Terra connects to your wearable device accounts (such as Apple Health, Google Fit, Fitbit, Garmin, Oura, and others as supported) via webhooks and OAuth-based authorisations.

Scope of data: The specific data points received depend on your chosen wearable platform and the permissions you grant to Terra when connecting your device. You can review and revoke Terra’s access to your wearable platforms at any time via the Settings → Wearables screen within the app, or directly within your wearable platform’s account settings.

Subprocessor disclosure: Terra acts as a data processor. A current list of wearable platforms supported by Terra is available within the app’s wearable connection flow. Terra’s privacy policy governs Terra’s relationship with wearable platforms; our DPA with Terra governs Terra’s processing of your data on our behalf.

How to enable: Navigate to Settings → Wearables and toggle the switch to enable a specific wearable connection. Each individual wearable platform connection requires a separate authorisation step.

How to withdraw: Toggle individual wearable connections off in Settings → Wearables. Withdrawal will prevent future data ingestion. Historical wearable data already stored will be retained for the period described in Section 9, unless you request deletion via the app or by contacting privacy@medicalyouglobal.com.

Legal basis: Explicit consent under GDPR Art 9(2)(a); PDPA consent; UAE PDPL explicit consent.

3(f) — Family/Carer Sharing of Records — OPTIONAL, DEFAULT OFF

Status: Optional. This toggle is off by default. You are not required to enable it.

What we process: If you choose to enable family or carer sharing, selected health records, documents, or summaries from your account will be made accessible to one or more nominated family members or carers whom you specifically invite.

Scope controls: You control precisely which records or record categories are shared. Sharing is not all-or-nothing. You may share individual documents, specific health categories (e.g., only vaccination records), or a curated summary, while keeping other records private. Sharing permissions are configurable at any time via Settings → Sharing.

Who can be a family/carer contact: Any person you invite by email address. Invited individuals must create or hold a MedicalYou account to view shared records. Their identity is verified through our authentication provider, Clerk.

Safeguards: Shared access is read-only by default. Family/carer contacts cannot upload to, edit, or delete records in your account unless you expressly grant write permissions for a specific purpose. You can revoke any individual’s access at any time instantly from Settings → Sharing. Revocation removes their access to your records; they retain no copy of documents within MedicalYou’s systems.

Why this is optional: Many users have no need for family/carer sharing; enabling it involves sharing sensitive health data with a third person and carries meaningful privacy implications. We therefore default it to off and require a distinct, active choice to enable it.

How to withdraw: Revoke access for individual contacts in Settings → Sharing, or contact privacy@medicalyouglobal.com to have all sharing relationships removed. Previously viewed records are not deletable from a family/carer contact’s memory, but no further access to your account data will be provided following revocation.

Legal basis: Explicit consent under GDPR Art 9(2)(a); PDPA consent; UAE PDPL explicit consent.

3(g) — Security and Audit Logging — Required

Status: Required. This cannot be disabled.

What we process: MedicalYou maintains security logs and audit trails covering: user authentication events (login, logout, failed login, password change, multi-factor authentication events); record access events (which records were viewed, when, and from which device/IP); document upload and deletion events; sharing permission changes; consent events (the fact and timestamp of consent given, modified, or withdrawn); and system-level security events. Audit logs are stored in Amazon S3 in the ap-southeast-1 region and are retained for a minimum of three (3) years, unless a longer retention period is required by applicable law (see Section 9).

Why this is required: Security and audit logging is not optional because it is a fundamental technical and organisational security measure required under GDPR Art 32 (appropriate security measures), PDPA Protection Obligation (PDPC), and UAE PDPL. Audit logs also allow us to detect, contain, and report security incidents within mandatory timelines — 72 hours under GDPR; 3 calendar days from determination under the Singapore PDPA (PDPC breach notification). They allow you to exercise your right to access a record of events affecting your account. Disabling audit logging would degrade both your security protections and our ability to fulfil our legal obligations.

What audit logs do not contain: Audit logs do not include the content of your health documents or the clinical data within them. They record that an event occurred (e.g., “user viewed document ID X at 14:32 UTC”), not the substantive health information in that document.

Legal basis: Legal obligation (GDPR Art 32; PDPA Protection Obligation); explicit consent for the health-data processing this logging supports under GDPR Art 9(2)(a); legitimate interests in maintaining the security and integrity of the service.

4. Required vs Optional Processing — Summary

ActivityRequired for Core Service?Default State
Document upload — 3(a)YesOn
Singapore storage — 3(b)YesOn
Parsing and extraction — 3(c)YesOn
AI summaries (Anthropic) — 3(d)YesOn
Wearable ingestion (Terra) — 3(e)No — OptionalOff
Family/carer sharing — 3(f)No — OptionalOff
Security and audit logging — 3(g)YesOn

Declining or withdrawing consent for items 3(a)–3(d) and 3(g) means you cannot use MedicalYou’s core features, and your account may need to be deleted or suspended, subject to our retention obligations for legally required records (see Section 9).

Declining or withdrawing consent for items 3(e) or 3(f) does not affect your access to any other part of the service.

5. What This Consent Does NOT Cover — Anonymised Data Commercialisation

This consent document covers only the processing activities described in Section 3 above.

It does not cover, and does not constitute consent to, the creation, use, licensing, or sale of anonymised, de-identified, or aggregated datasets derived from your health data for commercial or research purposes.

That is an entirely separate processing activity, governed by a distinct consent document — Document 4: Anonymised Data Commercialisation Consent. Document 4 is an opt-in, default-off module presented separately from this document. You may accept or decline it independently. Your choice in Document 4 has no effect on your access to the core service.

If you have not consented to Document 4, your data will not be used in any anonymised commercial dataset.

6. What We Do Not Do — Firm Commitments

The following are firm commitments made by Medical You Pte. Ltd:

  • We do not sell your identifiable personal data. We do not sell, rent, broker, or transfer for value any personal data by which you are, or could reasonably be, identified.
  • We do not sell your identifiable health data. We do not sell, rent, or transfer for value any health data, medical records, clinical documents, or health-related personal information that is linked or linkable to you as an individual.
  • We do not sell Protected Health Information (PHI). Although MedicalYou is not a HIPAA-covered entity and most user data does not constitute PHI, we apply equivalent protections and make no transfers of any health data for commercial consideration without your explicit, separate, opt-in consent.
  • We do not sell special-category personal data. Health data as defined under GDPR Art 9 and equivalent categories under UAE PDPL / DIFC Law No. 5 of 2020 are never sold.
  • We do not sell pseudonymised data. Under GDPR Art 4(5) and GDPR Recital 26, pseudonymised data remains personal data because it can be re-identified using separately-held information. We do not sell pseudonymised health records. The ICO confirms that pseudonymisation is a security measure, not anonymisation.
  • We do not share your health data with advertisers or data brokers.
  • We do not use your health data to train general-purpose AI models made available to third parties. AI processing described in Section 3(d) uses your data to generate outputs for you, not to improve a shared foundation model. We do not authorise our AI gateway or model provider to use your data to train or improve general-purpose AI models. Our agreements with those providers govern these constraints.

These commitments are consistent across all MedicalYou legal documents and do not contradict any right we reserve elsewhere — specifically, the right to create and commercialise genuinely anonymised or de-identified datasets where those datasets cannot reasonably identify any individual, are subject to contractual re-identification protections, and where you have separately consented via Document 4.

7. Legal Bases and Jurisdictions

JurisdictionFrameworkLegal Basis for Core ProcessingLegal Basis for Optional Processing
EU / EEAGDPRArt 9(2)(a) — explicit consentArt 9(2)(a) — explicit consent
United KingdomUK GDPRArt 9(2)(a) — explicit consent; ICO guidanceArt 9(2)(a) — explicit consent
SingaporePDPA 2012Consent — PDPC Data Protection ObligationsConsent — PDPA
UAE (federal)PDPL 2021Explicit consent for sensitive dataExplicit consent
Dubai (DIFC)DIFC DP Law No. 5/2020Explicit consent for special-category dataExplicit consent
California, USACPRAConsent; right to limit use of sensitive PIConsent
Washington, USAMHMDA, RCW 19.373Opt-in consent to collect consumer health dataSeparate opt-in consent to share
Other US statesFTC Act; applicable state lawConsent; FTC Health GuidanceConsent

All processing activities described in this document are carried out by Medical You Pte. Ltd as data controller. Amazon Web Services (including Aurora PostgreSQL, Amazon S3, and ElastiCache), Clerk, and Terra act as data processors under written data processing agreements. Vercel (for the web application presentation layer and the Vercel AI Gateway) and Anthropic (for AI model processing) also act as data processors.

8. Withdrawal of Consent

8.1 Your Right to Withdraw

You may withdraw any consent given under this document at any time. Withdrawal is as easy as giving consent. You do not need to provide a reason.

8.2 How to Withdraw Each Consent

Consent ItemHow to Withdraw
Core processing — 3(a)–(d)Account deletion request via Settings → Account → Delete Account, or by emailing privacy@medicalyouglobal.com. Withdrawal of core consent is equivalent to account closure.
Wearable data ingestion — 3(e)Toggle off individual wearable connections in Settings → Wearables, effective immediately.
Family/carer sharing — 3(f)Revoke individual sharing relationships in Settings → Sharing, effective immediately, or email privacy@medicalyouglobal.com.
Audit logging — 3(g)Not withdrawable — see Section 4.

8.3 Effect of Withdrawing Core Consent

If you withdraw consent for core processing (items 3(a)–(d)), MedicalYou cannot continue to provide the service to you. We will:

  • Cease all active processing of your health data within 30 days of your withdrawal request.
  • Delete or anonymise your personal health records, uploaded documents, and AI-generated summaries in accordance with Section 9.
  • Retain only records that we are legally required to keep (such as security audit logs — see Section 9).
  • Notify you by email (to your registered address) to confirm completion of the deletion process.

8.4 Withdrawal Is Not Retroactive

Withdrawal of consent does not affect the lawfulness of any processing that was carried out before you withdrew consent. Processing performed on the basis of your consent before the withdrawal date was lawful at the time it occurred. Withdrawal prevents future processing only.

8.5 Effect of Withdrawing Optional Consent

Withdrawing consent for wearable data ingestion (3(e)) stops future wearable data from being received. Historical wearable data already in your account is retained and continues to be covered by your core processing consent until your account is deleted or a deletion request is submitted.

Withdrawing consent for family/carer sharing (3(f)) immediately terminates the sharing relationship. The nominated individual loses access to your records instantly. No further health data is transmitted to them through MedicalYou.

8.6 Timeline for Processing Withdrawal Requests

We will acknowledge all withdrawal requests within 5 business days. We will confirm completion of any data deletion or de-linking within 30 calendar days of your request, except where legal retention obligations apply, which we will explain in our acknowledgement.

9. Retention and Deletion

9.1 Standard Retention

CategoryRetention PeriodBasis
Health documents (uploaded files)Duration of account, plus 30 days after account deletion to allow recovery from accidental deletionYour consent
Structured health records (extracted data in Aurora PostgreSQL)Duration of account, plus 30 days after account deletionYour consent
AI-generated summariesDuration of account; deleted with accountYour consent
Wearable dataDuration of wearable consent; deleted 30 days after consent withdrawal or account deletionYour consent
Security and audit logsMinimum 3 years from creation; may be extended by legal obligation or ongoing investigationLegal obligation / legitimate interests
Consent records (the fact and timestamp of consent)7 years from last consent event, to demonstrate compliance with legal obligationsLegal obligation

9.2 Deletion on Account Closure or Withdrawal of Core Consent

Upon account deletion or withdrawal of core processing consent, we will:

  • Delete or render irretrievable all uploaded health documents from Amazon S3 within 30 days.
  • Delete all structured health records from Aurora PostgreSQL within 30 days.
  • Delete all AI-generated summaries within 30 days.
  • Remove all active sharing relationships and revoke all family/carer access immediately.
  • Retain security and audit logs for the minimum required period (3 years), as these are system-level records not linked to the substantive content of your health documents.
  • Retain a minimal consent record (user identifier, consent timestamp, withdrawal timestamp, version consented to) for 7 years for compliance purposes.

9.3 Backups

Deletion from live systems may not result in immediate deletion from encrypted backup archives. Backup archives are subject to automatic overwrite on a rolling cycle not exceeding 90 days. Data in backup archives is not accessible or used for any operational purpose and will be overwritten in the normal course of the backup cycle.

9.4 Legal Hold

Where we are subject to a legal obligation, court order, or regulatory direction requiring us to retain specific records beyond the above periods, we will retain only the minimum necessary data for only as long as required and will notify you to the extent permitted by law.

10. Your Data Subject Rights

You have the following rights under applicable law. To exercise any of them, contact our Data Protection Officer:

  • Email: privacy@medicalyouglobal.com
  • Post: Samuel Banks, DPO, Medical You Pte. Ltd, 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914
RightDescriptionApplicable Framework
AccessObtain a copy of your personal data that we hold and information about how we process it.GDPR Art 15; PDPA s21; UAE PDPL
Rectification / CorrectionCorrect inaccurate or incomplete personal data. You can correct most data directly in the app.GDPR Art 16; PDPA s22
Erasure (“Right to Be Forgotten”)Request deletion of your personal data, subject to legal retention obligations (Section 9).GDPR Art 17; PDPA (Retention Limitation Obligation)
Restriction of ProcessingRequest that we pause processing of your data in certain circumstances, e.g. while accuracy is contested.GDPR Art 18
Data PortabilityReceive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.GDPR Art 20
Object to ProcessingObject to processing based on legitimate interests. Note: core health data processing in this document is based on explicit consent, not legitimate interests, so the objection right is less directly applicable to core processing.GDPR Art 21
Withdraw ConsentWithdraw consent at any time without affecting prior lawful processing (see Section 8).GDPR Art 7(3); PDPA; UAE PDPL
Not Subject to Solely Automated DecisionsNot to be subject to a decision based solely on automated processing that produces legal or similarly significant effects without human review. MedicalYou’s AI outputs do not constitute such decisions.GDPR Art 22
Limit Use of Sensitive PICalifornia CPRA users may request to limit the use and disclosure of sensitive personal information to the uses necessary to provide the service.CPRA
Lodge a ComplaintLodge a complaint with your local data protection authority. In Singapore: PDPC (pdpc.gov.sg). In the EU/UK: your national DPA / ICO. In the UAE/DIFC: relevant UAE or DIFC authority.GDPR Art 77; PDPA

We will respond to all valid rights requests within 30 days. A 60-day extension is available for complex or multiple requests; we will notify you if an extension is required.

11. Suggested On-Screen Consent UI Copy

The following consent text and checkbox structure is recommended for implementation by the MedicalYou product team at signup, onboarding, and in the Settings → Consent screen. These are clearly marked as UI copy.

[UI COPY — FOR PRODUCT IMPLEMENTATION]

Section heading (displayed above all checkboxes):

Your health data — please read before continuing

MedicalYou stores and analyses your personal health records to give you an organised, AI-powered view of your health. Because this involves sensitive health information, we need your explicit consent before we can proceed. Please read our Health Data Processing Consent and tick the boxes below.

Checkbox 1 — Core Health Data Processing (Required)

☐ I consent to MedicalYou processing my health data for core service functions.

This includes: uploading my lab reports, imaging, prescriptions, and health notes; storing them securely in Singapore (AWS); extracting health information from those documents; and generating AI-powered summaries and health insights via the Vercel AI Gateway and Anthropic. I understand this consent is required to use MedicalYou and that I can withdraw it at any time by deleting my account, which will result in deletion of my health records.

Required — the core service is not available without this consent.

Checkbox 2 — Wearable Data Ingestion (Optional, Default Off)

☐ I consent to MedicalYou receiving health and fitness data from my wearable devices via Terra (optional).

This is optional and off by default. I can enable or disable individual wearable connections at any time in Settings → Wearables. Declining this does not affect my access to the core app.

Optional — you can change this in Settings at any time.

Checkbox 3 — Family / Carer Sharing (Optional, Default Off)

☐ I consent to sharing selected records with nominated family members or carers (optional).

I understand that family/carer sharing allows people I specifically invite to view the health records I choose to share with them. I can revoke access for any individual at any time in Settings → Sharing. Declining this does not affect my access to the core app.

Optional — you can change this in Settings at any time.

Notice displayed below all checkboxes:

By ticking the boxes above, you give explicit consent to Medical You Pte. Ltd to process your health and special-category personal data as described in our Health Data Processing Consent (v1.0, effective 18 May 2026). This consent is separate from our Terms of Service and Privacy Policy. A separate consent option is available for anonymised data uses (Document 4). You can withdraw optional consents at any time in Settings. Withdrawal of core consent will close your account and result in deletion of your health records.

[END UI COPY]

12. Consent Versioning and Re-Consent

12.1 This Version

This document is Version 1.0, effective 18 May 2026. The version you consented to, and the date and time of your consent, are recorded in our consent log and are accessible to you on request.

12.2 Changes to This Document

If we make a material change to the processing activities described in this consent — for example, by adding a new category of processing, a new subprocessor that handles health data in a materially different way, a new transfer destination, or a new purpose — we will:

  • Prepare a new version of this document with a revised version number and effective date.
  • Notify you by email to your registered address at least 30 days before the new version takes effect, unless a shorter notice period is required by law.
  • Present the revised consent document to you in-app and request your fresh, explicit consent before the change takes effect.
  • Not apply the changed processing to your data until you have consented to the new version.

If you do not consent to a material change, you will be able to continue using the service under the previous version’s terms until the new effective date, after which — if the change is necessary for the service to function — your account may need to be closed.

12.3 Non-Material Changes

Changes that do not affect your rights or the nature of processing (such as clarifications of wording, correction of typographical errors, or updates to contact details) may be made without re-consent. We will notify you of such changes by email and update the document version number.

Sources

The following primary legal sources are cited in this document: