Legal
Last updated: September 2026
The data controller responsible for your personal data is:
PreMedEU
[Company legal name and registration number — to be confirmed]
[Registered address — to be confirmed]
Email: [email protected]
If you have any questions about how we handle your data, or wish to exercise your rights, please contact us at the email address above.
We collect the following categories of personal data:
We process your personal data only where we have a valid legal basis under Article 6 GDPR:
We share your data with the following sub-processors, each bound by data processing agreements (DPAs) and appropriate safeguards:
Supabase (Supabase Inc.)
Authentication and PostgreSQL database hosting. Your account data and learning records are stored on Supabase infrastructure. Data may be hosted in EU regions; refer to Supabase's DPA for transfer safeguards.
Stripe (Stripe Payments Europe, Ltd.)
Payment processing. Stripe acts as an independent data controller for payment card data under PCI DSS. We share only the minimum billing metadata necessary. Stripe is certified under EU Standard Contractual Clauses.
Vercel (Vercel Inc.)
Application hosting, CDN, and edge infrastructure. Vercel processes request logs including IP addresses. Covered by Vercel's DPA and EU Standard Contractual Clauses.
Upstash (Upstash Inc.)
Serverless Redis used for API rate-limiting. Only request-rate counters keyed on anonymised identifiers are stored; no personal data is persisted beyond the TTL window.
OpenAI (OpenAI, L.L.C.)
AI-assisted question generation and content improvement (admin-side pipeline only). Prompts contain no student personal data. Covered by OpenAI's data processing addendum.
We do not sell your personal data to any third party, and we do not share it with advertisers.
Some of our sub-processors are based outside the European Economic Area (EEA), primarily in the United States. Where such transfers occur, we rely on European Commission Standard Contractual Clauses (SCCs, Commission Decision 2021/914) and, where available, adequacy decisions to ensure an equivalent level of data protection. You may request a copy of the relevant safeguards by contacting [email protected].
Under GDPR Articles 15–22, you have the following rights regarding your personal data:
To exercise any of these rights, email [email protected]. We will respond within 30 days. We may ask you to verify your identity before acting on the request.
We use strictly necessary cookies for authentication (managed by Supabase) and local storage for user preferences such as theme selection and cookie consent state. We may use anonymised analytics (Vercel Analytics). For full details, please read our Cookie Policy.
PreMedEU is intended for users who are 16 years of age or older. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by a prominent notice on the platform at least 14 days before the changes take effect. Continued use of PreMedEU after the effective date constitutes acceptance of the updated policy.
If you believe we have processed your personal data in breach of the GDPR, you have the right to lodge a complaint with a supervisory authority. In Hungary, the competent supervisory authority is:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
National Authority for Data Protection and Freedom of Information
Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Website: naih.hu
Email: [email protected]
Phone: +36 (1) 391-1400
You may also lodge a complaint with the supervisory authority of your EU member state of habitual residence or place of work.