Skip to main contentSkip to main content
MediEdify Global — Healthcare Education

Legal

Privacy Policy

What we collect, why we collect it, how long we keep it and what you can ask us to do about it. Written to be read rather than to satisfy a checklist.

Last updated 1 August 2026Effective 15 August 2026

A note on one specific point, because it surprises people. We retain a minimal permanent record of every certificate we issue: name, programme, date, outcome and credit value. This is what makes a MediEdify certificate independently verifiable years later, and it is the one retention period we will push back on if you ask us to erase it.

01Who we are and who this covers

MediEdify Global is the data controller for personal data collected through www.mediedifyglobal.com. We are an international healthcare education company founded in 2026, delivered by a distributed team rather than from physical offices.

This policy covers conference delegates, workshop participants, speakers and workshop leads, partner and institutional contacts, people who apply to join us or volunteer, and anyone who contacts us. It does not cover data your own employer or university holds about you, even where they registered you for one of our events.

Our data protection contact can be reached at info@mediedifyglobal.com. Where our processing falls under UK or EU GDPR, we handle requests under those frameworks directly.

02What we collect and why

We collect the minimum needed to deliver our events, allocate workshop places, issue certificates and take payment where a fee applies. We have deliberately avoided collecting data that would be commercially useful but educationally unnecessary.

Information you give us

  • Identity and contact details: name, email address, telephone number, country, and postal address where an invoice requires it.
  • Professional details: profession, specialty, employer or institution, and professional registration number where you choose to provide it.
  • Registration data: the event you registered for, your programme stream, your workshop preferences and allocation, attendance, and any feedback you give us.
  • Payment data, where a fee applies: billing name and address, and the last four digits and expiry of your card. Full card numbers are handled by our payment processor and never reach our servers.
  • Accessibility requirements, dietary requirements and any adjustments you request for an in-person event.
  • Correspondence: the content of enquiries, support tickets and forum posts.

Information we generate or observe

  • Attendance and certificate issuance records for the events and workshops you complete.
  • Technical data: IP address, browser and device type, and pages visited, used for security and to fix faults.
  • For recorded live sessions, your name if you speak or appear on camera, and any questions you submit.

We do not collect health data about you, we do not build advertising profiles, and we do not sell or rent your details to anyone.

04Who we share data with

We do not sell personal data and we do not share it with advertising networks. We share it with the following categories of recipient, each under a written agreement limiting them to our instructions.

  • Payment processing: Stripe, for secure payment processing.
  • Platform and hosting: our secure cloud infrastructure providers, located in the EU and the United States.
  • Email delivery: Resend, our transactional and communications email provider.
  • Faculty: your name and professional role are visible to faculty running your sessions.
  • Institutional sponsors: where your employer paid for your place, we share attendance and completion status as required.
  • Certificate verification: name, programme, date and credit value are confirmed to verifying employers upon presentation of your certificate details.

Where data leaves your country we use standard contractual clauses or an equivalent transfer mechanism. A list of our sub-processors and their locations is available on request.

05How long we keep it

  • Registration and attendance records: for as long as needed to administer your participation, and up to six years for CPD records routinely requested during revalidation.
  • Certificate records: retained permanently in a minimal verifiable form (name, programme, date, outcome and credit value) so credentials remain verifiable.
  • Payment records: seven years, as required by tax and accounting rules in the jurisdictions we operate in.
  • Enquiry correspondence: three years from the last contact.
  • Marketing consent records: for as long as consent stands, plus two years to demonstrate compliance.
  • Session recordings: twelve months for training recordings, or as archived for conference resources.

06Your rights and how to use them

Subject to the framework that applies where you live, you can ask us to do the following. We do not charge for any of it and we aim to respond within thirty days.

  • Access a copy of the personal data we hold about you.
  • Correct anything inaccurate by writing to info@mediedifyglobal.com.
  • Erase your data, subject to legal and certificate verification retention obligations.
  • Restrict or object to processing based on legitimate interests.
  • Receive your data in a portable, machine-readable format.
  • Withdraw marketing consent directly via the unsubscribe link in any email or by emailing us.

To exercise any of these, email info@mediedifyglobal.com from the address you registered with, or contact us through the website and we will verify your identity another way. If you are unhappy with our response you can complain to your local data protection authority; we would rather you told us first so we can put it right.

07Cookies, security and children

Our cookie use is described in full in our cookie policy. In short, we use essential cookies for form protection and security, and analytics cookies only where you have consented. There are no advertising cookies on this site.

We protect data with encryption in transit and at rest, role-based access controls, and access logging on systems holding delegate or payment records. We test our platform regularly and will notify you and relevant regulators without undue delay if a breach is likely to affect you.

Our services are intended for qualified healthcare professionals and students in health professions education. We do not knowingly collect data from anyone under sixteen.

08Changes to this policy

We update this policy when our processing changes. Where a change materially affects you, we notify registered delegates in advance.

Previous versions are archived and available on request, so you can see what changed and when.

Questions about this document

Data protection questions, access requests and erasure requests all go to info@mediedifyglobal.com. A person reads them, and we aim to respond within thirty days.

info@mediedifyglobal.comoruse the contact form

Need Something Clarified

We would rather explain it than have you guess

If any part of this document is unclear or seems unfair, tell us. Several clauses have been rewritten because a learner pointed out that they read badly.