Skip to content
ProCordis.AI

Privacy Policy

Effective from [1 September 2026] · The Polish version is the binding text

1. Who processes your data

The controller of your personal data is:

ProCordis spółka z ograniczoną odpowiedzialnością, ul. Andrzeja Frydeckiego 4/23, 54-115 Wrocław, Poland. KRS 0001182450 · NIP 8943264248 · REGON 542181105 · share capital PLN 10,000.00. Registered in the National Court Register kept by the District Court for Wrocław-Fabryczna in Wrocław, 6th Commercial Division. Email: contact@procordis.ai · https://procordis.ai

Data Protection Officer: Andrii Maslianyk — iod@procordis.ai

You may contact the Data Protection Officer directly on any matter concerning the processing of your personal data and the exercise of your rights.

2. Who this Policy applies to

ProCordis supports the interpretation of ECG images and is intended for medical professionals and medical students. Depending on whose data is being processed, we act in different roles:

Whose data Our role Covered by
Yours, as a User (account, billing, use of the Platform, ECG images you upload) Controller This entire Policy
Patient data, where you upload ECG images containing patient-identifying information in your own professional capacity Processor — acting solely on your documented instructions Section 12
Patient data, where your institution has contracted with us Processor — the institution is the controller Section 12

If you are a patient whose ECG was uploaded to the Platform by a healthcare provider, the controller of your data is that provider, not ProCordis. You exercise your rights against them. See section 12.

We do not verify professional status. When you create an account you attest that you are a medical professional or a medical student (section 5). We rely on that attestation but we do not check it against any professional register. This matters here because the lawfulness of the health-data processing described in section 4 rests on your explicit consent as a professional user, not on any verification performed by us.

3. What data we process

Category What it covers
Account data Name, email address, hashed password, optional avatar, interface language and theme
Session data Session token, IP address, browser information — necessary for login security
Organisation and billing data Name, address, tax number, organisation email, payment-provider customer identifier, member roles, invitation addresses
ECG images The image you upload after applying the redaction tool (section 6), a thumbnail, and a record confirming that redaction was applied
Interpretation results Model findings: average heart rate, rhythm, cardiac axis, abnormalities, intervals, infarct flags, suggested urgency of consultation — health data
Payment data Transaction history, and the record of your declaration consenting to immediate delivery and acknowledging the loss of the right of withdrawal. Purchases are one-off; we do not operate subscriptions or take recurring payments. We never receive your card details — you enter these directly with the payment provider
Consent and declaration records For each consent and each declaration: full text, version, language, date given and any date withdrawn, channel
Reviews and feedback Any review or result rating you submit, and — if we publish it — the fact of publication
Reports and appeals Where you report content or appeal a decision: your name, contact details and the content of the report
Analytics data Usage events and masked session recordings — only after you have given consent, and never covering the redaction editor (section 6)
Technical data Error logs containing user and organisation identifiers and request context

4. Purposes, legal bases and retention

Purpose Legal basis Retention
Creating and running your account, authentication Art. 6(1)(b) GDPR — performance of a contract Life of the account. On deletion: 30 days recovery window, then erased
Login and session security Art. 6(1)(f) — our legitimate interest in securing accounts 12 months from session creation
Storing and analysing ECG images and results Art. 6(1)(b) and Art. 9(2)(a) — your explicit consent to the processing of health data 12 months (basic analysis) or 24 months (extended analysis) from creation of the order. ECG images are deleted together with the associated result, or with the account, whichever comes first
Payments and billing Art. 6(1)(b) and Art. 6(1)(c) — tax and accounting obligations Accounting records: 5 years from the end of the financial year (art. 74 of the Polish Accounting Act)
Service emails (address verification, password reset, purchase confirmation, deletion notices) Art. 6(1)(b) and Art. 6(1)(c) Until the operation completes; links expire
Publishing reviews you have submitted Art. 6(1)(a) — your consent, and Art. 6(1)(f) for internal quality review Until you withdraw consent or we remove the review
Handling reports and appeals concerning content Art. 6(1)(c) — Regulation (EU) 2022/2065 3 years from case closure
Product analytics Art. 6(1)(a) — your consent, voluntary and revocable 12 months; processing stops immediately on withdrawal
Error monitoring and platform maintenance Art. 6(1)(f) — keeping the service running and secure 12 months
Handling requests and complaints, defence of claims Art. 6(1)(c) and (f) 3 years from case closure
Demonstrating compliance (consent and declaration records) Art. 6(1)(c) in conjunction with Art. 7(1) 3 years

Before we delete order data. We email you at least 30 days before an order and its ECG images reach the end of the retention period above, so that nothing is lost by surprise and you can export anything you need to keep. You can also delete any order yourself at any time in the Platform; a deleted order stays recoverable for 30 days and is then erased permanently.

What we do not do. We do not sell your data. We do not profile you for marketing. We do not take decisions about you producing legal effects based solely on automated processing (section 7). We do not use your ECG images or results to train, retrain, fine-tune, evaluate or benchmark artificial-intelligence models, we do not add them to any training or evaluation dataset, and we do not disclose them to any third party for those purposes. This is a binding commitment recorded in our Terms of Service, not a description of current practice. It cannot be changed by updating this Policy: it would require an amendment to the Terms of Service, which does not apply retrospectively to contracts already concluded, and a separate lawful basis for health data.

5. The consents we collect

When you create an account we ask for four separate statements. Each is stored together with its full text, version and the language in which you saw it:

  • Acceptance of the Terms of Service — the contractual basis.
  • Acknowledgement that you have read this Privacy Policy.
  • Explicit consent to the processing of health data — without it we cannot process ECG images or results (Art. 9(2)(a) GDPR).
  • Attestation that you are a medical professional or a medical student — the Platform is not intended for patients or for a general audience. We rely on this attestation and do not verify it (section 2).

Separately, and entirely optionally, you may consent to product analytics. Until you do, no analytics tooling runs at all.

When you buy an extended analysis we also record a declaration — your express request for immediate delivery, together with your acknowledgement that the right of withdrawal is lost once the analysis has been delivered. This is a contractual declaration rather than a consent to processing, but we store it the same way, with its text, version, language and date, and we send you a confirmation on a durable medium.

Withdrawing consent. You can withdraw the analytics consent and the health-data consent at any time in your account settings — as easily as you gave them (Art. 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out beforehand. Withdrawing the health-data consent means we can no longer provide the ECG interpretation service.

6. ECG images — redacting patient data

This is the most important section of this Policy and we ask you to read it carefully.

You perform the redaction, not the Platform. Before you upload an ECG image we give you an editor in which you mark and permanently obscure the parts of the image containing patient-identifying information — name, national identification number, date of birth, record number. A job cannot be submitted without confirmation that redaction was applied, and we store that confirmation alongside the job. The tool may optionally suggest areas to redact, but the decision and the responsibility for carrying it out are yours.

The editor runs on your device. It is a browser-based tool: the image is opened, edited and flattened locally, and redaction is applied before any image data reaches us. Redaction overwrites the underlying pixels rather than covering them with a layer, so it cannot be reversed from the uploaded file — by you, by us, or by anyone inspecting it. Embedded file metadata, including EXIF capture time and any geolocation recorded by a mobile device, is stripped on import. File names are not part of the image, so do not put patient identifiers in them.

THE UNREDACTED IMAGE NEVER LEAVES YOUR DEVICE. The optional suggestion feature also runs locally in your browser: it inspects the image on your own device and returns only the coordinates of the areas it proposes, within the editor. The image is not transmitted to us for that purpose and is not retained anywhere. The only image that ever reaches our systems is the redacted, flattened one you submit — which means that for the original, unredacted image we are neither controller nor processor, because we never hold it.

Session recordings never cover the editor. If you have consented to product analytics, session recording is disabled on the redaction editor and on any view in which an unredacted image can appear. No analytics, session-replay or error-reporting tool we deploy captures the editor canvas or the image loaded into it.

What this means in practice. We receive and store the image already redacted. That does not make it anonymous data: the ECG trace itself remains health data, linked to your account. We treat it as pseudonymous data, to which Art. 9 GDPR and every protection described in this Policy fully apply. We do not claim this data is anonymous.

Redact identifiers only. Redaction that extends into the trace itself, or that removes calibration pulses, lead labels, paper speed and gain settings or the rhythm strip, will degrade or invalidate the analysis.

Your responsibility. If you upload a patient’s ECG, make sure you have redacted all identifying information. If you intend to upload data that identifies a patient, a data processing agreement with us must be in place first — see section 12.

7. Interpretation using artificial intelligence

The ECG image is analysed by our own machine-learning model, which returns descriptive findings (rhythm, heart rate, cardiac axis, any abnormalities, and a suggested urgency of consultation).

This is a support tool, not a diagnosis. ProCordis is provided as software as a service for educational and consultation purposes. The result is descriptive and does not replace clinical judgement; the clinical decision is always yours. The Platform is not CE-marked as a medical device.

No solely automated decision-making. We do not take decisions about you or about a patient based solely on automated processing that would produce legal effects or similarly significantly affect anyone (Art. 22 GDPR). The result is delivered to you as information, and human oversight is required by our Terms of Service.

Transparency. Every result is labelled as AI-generated, in accordance with Art. 50 of Regulation (EU) 2024/1689 (AI Act), as amended by Regulation (EU) 2026/1744.

8. Who we share data with

We share data only with providers acting on our documented instructions under data processing agreements (Art. 28 GDPR):

Provider What they receive Processing region
Application and database hosting All Platform data Germany (EU) — Nuremberg
ECG image storage Redacted ECG images and results Germany (EU) — Frankfurt
GPU compute for ECG analysis — RunPod Redacted ECG images, job identifiers EEA — the production endpoint is restricted to EEA data centres
Product analytics — PostHog Usage events, masked recordings — only with consent, never the redaction editor. No ECG content EU
Payment provider — Stripe Payments Europe, Ltd. Billing data. No health data Ireland (EU)
Service email delivery Email address, name, language. No health data EEA, or outside the EEA under the safeguards described in section 9
Error monitoring User and organisation identifiers, error context. No ECG content EEA, or outside the EEA under the safeguards described in section 9

Your ECG images and results are never sent to external AI model providers, including providers of large language models. The analysis runs on our own model.

We provide the current list of named providers on request: contact@procordis.ai. We may also disclose data to authorities where required by law.

9. Transfers outside the European Economic Area

Health data — ECG images and results — is processed exclusively within the EEA.

For other categories (payments, service email, error monitoring) some providers may process data outside the EEA. Where they do, the transfer takes place on the basis of Standard Contractual Clauses approved by the European Commission, or an adequacy decision, together with a transfer impact assessment. We will provide a copy of the safeguards used on request.

10. Your rights

You have the right to:

  • access your data and obtain a copy (Art. 15),
  • rectification of inaccurate or incomplete data (Art. 16),
  • erasure (Art. 17),
  • restriction of processing (Art. 18),
  • data portability (Art. 20),
  • object to processing based on legitimate interest (Art. 21),
  • withdraw consent at any time (Art. 7(3)).

How to exercise them. You can correct your account data yourself in settings, where you can also withdraw consents and delete individual orders. For anything else, write to iod@procordis.ai or contact@procordis.ai.

Export. Before your data is deleted you may request a full copy — including analysis results and the ECG images you uploaded — in a structured, commonly used, machine-readable format. The export comprises JSON files and image files, is provided free of charge, and is delivered within 30 days.

Timing. We respond within one month. For complex requests we may extend this by a further two months — we will tell you within the first month, with reasons. Exercising your rights is free of charge.

Limits. Some data cannot be erased on request — this concerns accounting records, which the law requires us to keep for 5 years (Art. 17(3)(b) GDPR), and consent and declaration records, which we keep for 3 years to demonstrate compliance and to defend claims. We keep such data to the necessary minimum.

Complaints. You have the right to lodge a complaint with the supervisory authority: President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl, or with the supervisory authority of your habitual residence.

11. Security and cookies

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR): encryption in transit and at rest, role-based access control, separation of each organisation’s data, removal of sensitive values from logs, and security monitoring. Only those who need access to data have it.

Cookies and local storage are covered by a separate Cookie Policy, available at https://procordis.ai/cookie-policy.

12. Patient data — where we act as a processor

If you are a healthcare provider or a medical professional uploading ECG images that contain patient-identifying data:

  • you are the controller of that data, and ProCordis acts as processor, solely on your documented instructions;
  • a data processing agreement must be in place first (Art. 28 GDPR) — write to iod@procordis.ai;
  • the duty to inform the patient rests with you; we provide a template notice for this purpose;
  • identifiable patient data is retained for no longer than the order retention period in section 4 (12 or 24 months), and we will agree a shorter period with you in the data processing agreement where you require one; you may delete any order earlier at any time;
  • the Platform is not a medical-records system. Storing an image on the Platform does not discharge your own obligation to keep medical documentation, which you fulfil independently.

Where your institution has contracted with us, the institution is the controller, we are the processor, and the institution’s data processing agreement governs — including any different retention period agreed there.

If you are a patient wishing to exercise your rights, please contact the provider that uploaded your ECG. If you write to us directly, we will pass the matter to that provider and let you know.

13. Changes to this Policy

We will tell you about material changes in advance, by email or by a notice in the Platform. Where a change affects processing based on consent, we will ask for fresh consent — continued use of the Platform will not be treated as giving it. Previous versions are available on request.

14. Contact

Data protection matters: iod@procordis.ai

Everything else: contact@procordis.ai

Address: ProCordis sp. z o.o., ul. Andrzeja Frydeckiego 4/23, 54-115 Wrocław, Poland