A note on one specific point, because it surprises people. We retain a minimal permanent record of every certificate we issue: name, programme, date, outcome and credit value. This is what makes a MediEdify certificate independently verifiable years later, and it is the one retention period we will push back on if you ask us to erase it.
01Who we are and who this covers
MediEdify Global is the data controller for personal data collected through www.mediedifyglobal.com. We are an international healthcare education company founded in 2026, delivered by a distributed team rather than from physical offices.
This policy covers conference delegates, workshop participants, speakers and workshop leads, partner and institutional contacts, people who apply to join us or volunteer, and anyone who contacts us. It does not cover data your own employer or university holds about you, even where they registered you for one of our events.
Our data protection contact can be reached at info@mediedifyglobal.com. Where our processing falls under UK or EU GDPR, we handle requests under those frameworks directly.
02What we collect and why
We collect the minimum needed to deliver our events, allocate workshop places, issue certificates and take payment where a fee applies. We have deliberately avoided collecting data that would be commercially useful but educationally unnecessary.
Information you give us
- Identity and contact details: name, email address, telephone number, country, and postal address where an invoice requires it.
- Professional details: profession, specialty, employer or institution, and professional registration number where you choose to provide it.
- Registration data: the event you registered for, your programme stream, your workshop preferences and allocation, attendance, and any feedback you give us.
- Payment data, where a fee applies: billing name and address, and the last four digits and expiry of your card. Full card numbers are handled by our payment processor and never reach our servers.
- Accessibility requirements, dietary requirements and any adjustments you request for an in-person event.
- Correspondence: the content of enquiries, support tickets and forum posts.
Information we generate or observe
- Attendance and certificate issuance records for the events and workshops you complete.
- Technical data: IP address, browser and device type, and pages visited, used for security and to fix faults.
- For recorded live sessions, your name if you speak or appear on camera, and any questions you submit.
We do not collect health data about you, we do not build advertising profiles, and we do not sell or rent your details to anyone.
03Our legal basis for using it
Where GDPR or an equivalent framework applies, we rely on the following bases.
- Contract: to deliver the event you have registered for, allocate your workshop places, issue your certificate and take payment where a fee applies.
- Legitimate interests: to secure the website, prevent certificate fraud, improve our programmes using aggregated data, and contact partner and institutional contacts about arrangements already in place.
- Consent: for marketing emails, for optional cookies, and for using your name or image in material about our events. Consent can be withdrawn at any time without affecting your access to anything you have paid for.
- Legal obligation: to keep financial records and to respond to lawful requests.
05How long we keep it
- Registration and attendance records: for as long as needed to administer your participation, and up to six years for CPD records routinely requested during revalidation.
- Certificate records: retained permanently in a minimal verifiable form (name, programme, date, outcome and credit value) so credentials remain verifiable.
- Payment records: seven years, as required by tax and accounting rules in the jurisdictions we operate in.
- Enquiry correspondence: three years from the last contact.
- Marketing consent records: for as long as consent stands, plus two years to demonstrate compliance.
- Session recordings: twelve months for training recordings, or as archived for conference resources.
06Your rights and how to use them
Subject to the framework that applies where you live, you can ask us to do the following. We do not charge for any of it and we aim to respond within thirty days.
- Access a copy of the personal data we hold about you.
- Correct anything inaccurate by writing to info@mediedifyglobal.com.
- Erase your data, subject to legal and certificate verification retention obligations.
- Restrict or object to processing based on legitimate interests.
- Receive your data in a portable, machine-readable format.
- Withdraw marketing consent directly via the unsubscribe link in any email or by emailing us.
To exercise any of these, email info@mediedifyglobal.com from the address you registered with, or contact us through the website and we will verify your identity another way. If you are unhappy with our response you can complain to your local data protection authority; we would rather you told us first so we can put it right.
08Changes to this policy
We update this policy when our processing changes. Where a change materially affects you, we notify registered delegates in advance.
Previous versions are archived and available on request, so you can see what changed and when.
Questions about this document
Data protection questions, access requests and erasure requests all go to info@mediedifyglobal.com. A person reads them, and we aim to respond within thirty days.

