1. WHO WE ARE
MDcells ("we", "us", "our") is operated by Harsh Sahrawat (ABN [ABN]) trading as "MDcells", of 30 Grandview Avenue, Glen Iris, Melbourne, Victoria 3146, Australia. For privacy questions contact our Privacy Officer at privacy@mdcells.com.
2. SCOPE
This Policy explains how we collect, use, disclose, store, transfer, and protect personal information (also "personal data") when you use our websites, iOS/Android apps, and services (the "Platform"). It forms part of our Terms of Service.
3. THE INFORMATION WE COLLECT
3.1 You provide: name, email, password, date of birth/age confirmation, country, exam(s) of interest, profile details, payment identifiers (processed by our payment providers — we do not store full card numbers), support communications, community posts, and any content you submit. 3.2 Automatically: device and browser type, IP address, approximate location (from IP), operating system, app version, identifiers, usage and interaction data (questions attempted, scores, time spent, feature use), performance/analytics, crash logs, and cookies/SDK data (§10). 3.3 AI-interaction data: the prompts, questions, and inputs you submit to AI features, and the outputs generated, together with associated metadata. 3.4 From third parties: payment/app-store confirmations (Apple, Google, Stripe), authentication providers (if you use social/SSO login), and fraud-prevention signals. 3.5 Health-related note. The Platform is an education product; we do not ask for your health information and you should not submit real patient data or your own health data.
4. HOW WE USE IT — AND OUR LAWFUL BASES (GDPR)
| Purpose | GDPR lawful basis (EU/UK) |
|---|---|
| Create/administer your account; provide the Platform and Content | Contract |
| Process payments, renewals, and refunds | Contract; Legal obligation |
| Personalise study (adaptive learning, analytics, "readiness") | Contract; Legitimate interests |
| Improve, develop, secure, and troubleshoot the Platform and our models (using de-identified/aggregated data where possible) | Legitimate interests |
| Detect/prevent fraud, account sharing, scraping, and abuse | Legitimate interests; Legal obligation |
| Communicate service/transactional messages | Contract |
| Send marketing (where permitted) | Consent; Legitimate interests (soft opt-in) |
| Comply with law, enforce terms, resolve disputes | Legal obligation; Legitimate interests |
(For Australia (APPs) we rely on collection for the primary purpose + reasonably-expected secondary purposes + consent for sensitive data; for CCPA/CPRA we identify business/commercial purposes. Counsel to align the framing per regime.)
5. WHEN WE DISCLOSE IT — SERVICE PROVIDERS & SUB-PROCESSORS
We share personal information only as needed, with: - Cloud/hosting & database: Supabase, and cloud infrastructure providers (e.g., AWS, Google Cloud) - AI/LLM providers: AI processing providers (e.g., OpenAI, Anthropic, Google) to power AI features - Payments: Apple, Google, and Stripe - Analytics & product telemetry: PostHog - Email/communications: our email delivery provider - Fraud/security & anti-abuse: our fraud-prevention and security providers - Professional advisers, and acquirers in a business sale/merger (subject to this Policy) - Authorities, where required by law or to protect rights/safety.
We do not sell your personal information for money. Maintain a current sub-processor list (with DPAs) — attach or link it.
6. INTERNATIONAL TRANSFERS
We operate from Australia and use providers that may process data in other countries (including the US and EU). Where we transfer personal data across borders, we use appropriate safeguards — Standard Contractual Clauses (EU/UK), the UK IDTA/Addendum, and equivalent mechanisms — and take reasonable steps to ensure comparable protection (APP 8).
7. HOW LONG WE KEEP IT (RETENTION)
We keep personal information only as long as necessary for the purposes above or as required by law, then delete or de-identify it. Indicative periods: account data — for the the life of your account plus 12 months; transaction records — 7 years (tax/legal); usage/analytics — 24 months; support tickets — 24 months; marketing consent records — until withdrawn plus 24 months.
8. YOUR RIGHTS
Depending on where you live, you may have rights to: access your data; correct it; delete/erase it; restrict or object to processing; data portability; withdraw consent; and to lodge a complaint with a regulator. To exercise any right, contact privacy@mdcells.com; we will respond within the time your law requires (e.g., 30 days GDPR/CCPA; reasonable time under the APPs) and will verify your identity first. - EU/UK (GDPR): all the above, plus rights regarding automated decisions (§9). - California (CCPA/CPRA): rights to know, delete, correct, and to opt out of sale/sharing and limit use of sensitive personal information; we honour authorised agents and the Global Privacy Control; we will not discriminate for exercising rights. - Australia (Privacy Act/APPs): access and correction rights; complaints to us then to the OAIC. - Canada (PIPEDA): access/correction; complaints to the OPC. - Singapore (PDPA): access/correction/withdrawal; complaints to the PDPC.
9. AUTOMATED DECISION-MAKING & PERSONALISATION
Adaptive learning, analytics, and "readiness" estimates use automated processing to personalise your experience. These do not produce legal or similarly significant effects on you.
10. COOKIES & SIMILAR TECHNOLOGIES
We use strictly-necessary, functional, analytics, and (where applicable) advertising cookies/SDKs. You can manage non-essential cookies via our cookie banner/settings and your device/browser controls.
11. SECURITY
We use reasonable technical and organisational measures (encryption in transit, access controls, RLS, monitoring) but no system is perfectly secure. In a qualifying breach we notify affected individuals and regulators as required (Australia's Notifiable Data Breaches scheme; GDPR 72-hour authority notice; and other applicable laws).
12. CHILDREN
The Platform is for users 18+. We do not knowingly collect data from children. If you believe a child has provided data, contact privacy@mdcells.com and we will delete it.
13. MARKETING & COMMUNICATIONS
We send service/transactional messages as part of the Platform. Marketing is sent only where permitted, and you can opt out anytime via the unsubscribe link or settings.
14. THIRD-PARTY LINKS & SERVICES
The Platform may link to third-party sites/services governed by their own privacy policies; we're not responsible for them.
15. CHANGES
We may update this Policy; we'll post the new version with an updated date and, for material changes, give reasonable notice. Continued use after the effective date constitutes acceptance where permitted by law.
16. HOW TO CONTACT US / COMPLAIN
Privacy Officer: privacy@mdcells.com, 30 Grandview Avenue, Glen Iris, Melbourne, Victoria 3146, Australia. If you're unsatisfied with our response you may complain to your regulator: OAIC (Australia), ICO (UK), your EU supervisory authority, the California Privacy Protection Agency/AG, the OPC (Canada), or the PDPC (Singapore).