Effective date: August 11, 2026
Last updated: August 11, 2026
MedInfosys (“MedInfosys,” “we,” “us,” or “our”) is a product of TikaMobile / TIKA Solutions. We respect your privacy and are committed to protecting the personal data we handle. This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with our marketing website at medinfosys.com (the “Site”) and the MedInfosys medical information request management platform, including the application at app.medinfosys.com (the “Platform” or “Service”). If you do not agree with this policy, please do not use the Site or the Service.
1. Our two roles: controller and processor
Because MedInfosys is a multi-tenant software platform for life sciences, we handle personal data in two different capacities:
- When we act as a data controller. For visitors to our Site, prospects who request a demo or free trial, and administrators who create accounts, we determine how and why personal data is used. This Privacy Policy governs that data.
- When we act as a data processor. When our life sciences customers (for example, pharmaceutical or medical device companies) use the Platform to capture and manage Healthcare Professional (HCP) inquiries, the customer is the data controller of the information submitted into their environment, and we process it on their behalf and under their instructions, governed by our customer agreement and Data Processing Addendum (DPA). If you are an HCP or other individual whose data was submitted to a customer’s MedInfosys environment, please direct privacy requests to that organization; the customer’s own privacy notice controls.
2. Information we collect
Information you provide to us (as controller):
- Demo, contact, and free-trial requests: name, business email, phone number, company, job title/role, country, and anything you include in a message (collected via our forms, powered by Fluent Forms and HubSpot).
- Account registration and onboarding: administrator name, work email, organization details, and account credentials.
- Billing information: where you subscribe to a paid plan, billing contact and payment details are processed by our payment providers (see Section 5). We do not store full card numbers.
- Communications: records of your correspondence with our sales, support, and success teams.
Information collected automatically (as controller): IP address, browser type, operating system, referring URLs, pages viewed, interactions, and cookies and similar technologies (see Section 4). Site analytics are provided by Google Analytics 4 and marketing/CRM tools by HubSpot.
Information we process on behalf of customers (as processor): When customers operate their MedInfosys environment, the Platform processes data they and their HCP submitters provide, which may include submitter name and contact details, professional identifiers (including National Provider Identifier (NPI) lookups), the content of medical inquiries, attachments, call logs and recordings where telephony is enabled, and related correspondence. Depending on the inquiry, this may include information relating to adverse events, product safety, or health. We process this data only to provide the Service under the customer’s instructions and our DPA.
3. How we use information
As a controller, we use personal data to: respond to demo, trial, and contact requests and communicate with you; create, administer, and secure accounts; provide, maintain, and improve the Site and Service; process payments and manage subscriptions; send administrative messages and, where permitted, marketing communications (you can opt out at any time); analyze and improve site performance and user experience; detect, prevent, and address security incidents, fraud, and misuse; and comply with legal obligations and enforce our terms.
Legal bases (EEA/UK). Where GDPR/UK GDPR applies, we rely on: your consent (e.g., non-essential cookies, marketing); performance of a contract (e.g., providing accounts and the Service); our legitimate interests (e.g., securing and improving our services, B2B marketing); and legal obligations.
4. Cookies and tracking technologies
We use essential cookies needed for the Site and Service to function; analytics cookies (Google Analytics 4) to understand site usage (logged-in platform users are excluded from analytics collection); and marketing/CRM technologies (HubSpot) to manage forms, chat, and understand prospect engagement. Where required by law, we request consent for non-essential cookies via our cookie banner, and you can withdraw consent or adjust preferences at any time. You can also control cookies through your browser settings.
5. How we share information
We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws. We disclose information only to:
- Service providers / sub-processors who perform services for us under contract, such as cloud hosting and infrastructure providers, analytics (Google), CRM and marketing (HubSpot), telephony (Twilio), email delivery, and payment processing (Stripe, PayPal, Razorpay, and Cashfree). A current list of platform sub-processors is available on request.
- Our customers, where you interact with a customer’s MedInfosys environment (in which case that customer is the controller).
- Legal and safety purposes, when required to comply with law, respond to lawful requests, or protect the rights, property, or safety of MedInfosys, our users, or others.
- Business transfers, in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
6. Data retention
We retain personal data only as long as necessary for the purposes described here, to comply with our legal, regulatory, and contractual obligations (including pharmacovigilance and medical information recordkeeping requirements applicable to our customers), and to resolve disputes. Retention periods for customer (tenant) data are configured by each customer and governed by their agreement and applicable regulatory requirements.
7. Data security
We maintain technical and organizational measures designed to protect personal data, including schema-per-tenant isolation, role-based access control, two-factor authentication, encryption in transit (TLS), encrypted access tokens, and comprehensive audit logging. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. International data transfers
We and our service providers may process data in countries other than your own, including the United States and other countries where we or our service providers operate. Where we transfer personal data internationally, we use appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum) where required. Contact us for more information about these safeguards.
9. Your privacy rights
Depending on where you live, you may have rights to access the personal data we hold about you; correct inaccurate data; delete your data; restrict or object to certain processing; data portability; withdraw consent at any time (without affecting prior processing); and opt out of marketing communications.
- EEA/UK: you may exercise the GDPR/UK GDPR rights above and lodge a complaint with your local supervisory authority.
- California (CCPA/CPRA) and other U.S. states: you may request to know, delete, and correct your personal information, and you have the right to non-discrimination for exercising these rights. We do not sell or share personal information as defined by these laws.
To exercise any right, contact us at hello@tikamobile.com. We will verify your request and respond within the timeframes required by law. If your request concerns data held by us as a processor on a customer’s behalf, we will refer you to, or act on the instructions of, that customer.
10. Health-related and sensitive information
The MedInfosys Platform may process information relating to health, product safety, or adverse events that our customers submit or receive from HCPs. We handle such information as a processor under our customers’ instructions and our DPA, with safeguards designed to support our customers’ compliance obligations (including HIPAA and GDPR awareness where applicable). MedInfosys is not a covered entity; where a customer requires a Business Associate Agreement or equivalent, that is addressed in the customer agreement. We do not use health-related information for our own purposes.
11. Children’s privacy
The Site and Service are intended for businesses and professional users and are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
12. Contact us
MedInfosys — a TikaMobile / TIKA Solutions product
485 Madison Ave, 7th Floor, New York, NY 10022, USA
Email: hello@tikamobile.com
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Site or Service after changes take effect constitutes acceptance of the updated policy.