Legal
Privacy Policy
1. Data controller
The data controller for personal data processed through dicomly.io is:
Ing. Martin HögerIČO: 76263428
Svestkova 2337
412 01 Litoměřice
Czech Republic
Contact: info@dicomly.io
2. What data we collect
We collect only what is necessary to provide the service:
- Account data — name and email address provided at registration.
- Billing data — payment method details processed and stored by Stripe, Inc. We receive only non-sensitive billing metadata (last four digits, country, transaction amounts).
- API credentials — API keys you create to authenticate against the Dicomly API. Keys are stored as irreversible hashes; the plaintext is shown once and then discarded.
- Usage data — endpoint identifiers, byte counts, and timestamps, used for billing and service operation. No DICOM payload content, SOP UIDs, or patient identifiers are recorded.
- Log data — connection and request metadata (timestamps, endpoint identifiers, certificate identifiers, transfer byte counts, and outcome status codes) from website, console, and API requests. IP addresses collected for connection troubleshooting are redacted within 30 days. This metadata also passes through our security and DNS provider (see section 4).
Dicomly never stores DICOM payload data. DICOM bytes flow in real time from the sender to your destination URL and are never written to disk, a queue, or any cache on Dicomly infrastructure. No protected health information (PHI) or patient data is processed or retained by Dicomly.
3. Legal basis for processing
- Contract performance (Art. 6(1)(b) GDPR) — processing your account, billing, and API credential data is necessary to provide the service you have agreed to use.
- Legitimate interests (Art. 6(1)(f) GDPR) — security logging and fraud prevention, where our interest in protecting the service and its customers does not override your rights.
- Legal obligation (Art. 6(1)(c) GDPR) — retaining transaction records as required by Czech accounting law.
4. Sub-processors and data transfers
We use a limited number of sub-processors to operate the service. The summary below covers every third party that processes personal data on our behalf, including those that never appear in the product. For the authoritative, versioned registry with contractual transfer mechanisms and change notification commitments, visit ourSub-processor Directory:
- Amazon Web Services EMEA SARL (38 Avenue John F. Kennedy, L-1855 Luxembourg) — server infrastructure. All servers are located in the AWS
eu-central-1region (Frankfurt, Germany), within the European Union. - Cloudflare, Inc. (United States) — authoritative DNS, web application firewall, and hosting of the dicomly.io website. Requests to our website, console, and API pass through Cloudflare's network, which processes connection metadata (IP address, request headers, timestamps) in transit to protect the service from attack and abuse.DICOM traffic does not pass through Cloudflare — imaging connections reach our EU servers directly, so no imaging data is exposed to Cloudflare at any point.
- Backblaze, Inc. (United States) — off-site storage of system backups, held in Backblaze's EU region (Amsterdam, Netherlands). Backups are encrypted with keys we control before they leave our servers, so Backblaze stores ciphertext only and never holds a decryption key. Backups contain account, billing, and usage records — never DICOM data.
- Stripe, Inc. — payment processing. Stripe acts as an independent data controller for payment card data under applicable law.
Personal data is stored in the European Union. Cloudflare, Inc., Backblaze, Inc., and Stripe, Inc. are established in the United States and may process personal data outside the European Economic Area; each of those transfers is governed by a data processing agreement incorporating the European Commission's Standard Contractual Clauses, alongside the safeguards described above (Cloudflare never receives imaging data; Backblaze receives only data we have already encrypted).
We do not sell personal data, and we do not use it for advertising or profiling. If we add or replace a sub-processor, we update this page; customers with a signed data processing agreement are notified in advance as that agreement requires.
5. Retention
- Account data is retained for the duration of the account and deleted within 30 days of account closure.
- Billing records are retained for 10 years as required by Czech accounting law (Act No. 563/1991 Coll.).
- Security and audit logs are retained for 6 years for security analysis and compliance auditing. These logs contain connection metadata only (timestamps, endpoint identifiers, certificate identifiers, transfer byte counts, and outcome status codes); sender IP addresses collected during connection troubleshooting are redacted within 30 days, and logs never contain DICOM tags or health data.
- Usage data used for billing is retained for the duration of the account and exported to the monthly invoice record thereafter.
6. Your rights under GDPR
As a data subject, you have the right to:
- Access (Art. 15) — request a copy of the personal data we hold about you.
- Rectification (Art. 16) — request correction of inaccurate data.
- Erasure (Art. 17) — request deletion of your data, subject to legal retention obligations.
- Restriction (Art. 18) — request that we restrict processing in certain circumstances.
- Data portability (Art. 20) — receive your data in a machine-readable format.
- Objection (Art. 21) — object to processing based on legitimate interests.
To exercise any of these rights, contact info@dicomly.io. We will respond within 30 days.
You also have the right to lodge a complaint with the Czech supervisory authority:Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, www.uoou.cz.
7. Cookies
The dicomly.io website does not use tracking or advertising cookies. We may set a strictly necessary session cookie when you are signed in to the Dicomly console.We use only first-party, self-hosted, cookieless analytics (Matomo, on our own infrastructure) to understand which pages are useful; no advertising or third-party tracking scripts are loaded on marketing pages.
8. Changes to this policy
We may update this policy to reflect changes in the service or applicable law. Material changes will be communicated by email to registered users at least 14 days before they take effect. The date at the top of this page always reflects the most recent revision.
9. Governing law
This policy is governed by the laws of the Czech Republic and, where applicable, EU Regulation 2016/679 (GDPR).