Legal and Compliance
Privacy Notice
This notice explains how BioMedli handles personal and health-related data for individual consumers.
Last updated: August 3, 2026
Overview
BioMedli is operated by Terramedici LifeSciences LLP ("BioMedli," "we," "our," or "us"). We are committed to privacy by design, data minimization, and accountable processing. This Privacy Notice applies to our websites, applications, and support channels. The current Service is a direct-to-consumer product for individual adults.
Data We Collect
Depending on usage, we may collect:
- Account data: name, email, authentication identifiers, and adult-profile information.
- Health-related data: uploaded reports, extracted biomarkers, trend data, and user-entered health notes.
- Technical data: IP address, device/browser metadata, security events, and minimized diagnostics.
- Support data: inquiries, attachments, and communication history.
- Billing data: subscription metadata via payment processors (we do not store full card numbers).
How We Use Data
- Provide, maintain, and improve the Service.
- Parse and normalize reports, generate trend views, and return analysis results.
- Authenticate users and secure accounts.
- Respond to support, legal, and compliance requests.
- Monitor abuse, fraud, threats, and policy violations.
- Comply with legal obligations and enforce our agreements.
Legal Bases and Regional Scope
The legal basis for processing depends on applicable law and the processing purpose:
- Performance of our consumer contract to provide the account and requested report-processing features.
- Consent where applicable law requires it for health-related data or another specific purpose.
- Legitimate interests for proportionate security, fraud prevention, product quality, and service reliability.
- Compliance with legal obligations.
Optional analytics and advertising technologies are not enabled in this release. India's Digital Personal Data Protection Act and Rules apply as their relevant provisions are brought into force. EEA, UK, US state, and other local privacy or consumer-health laws may also apply based on your location.
US State Privacy Rights
Residents of certain US states (including California, Colorado, Connecticut, Utah, Virginia, and other states with similar laws) may have rights to access, correct, delete, and port personal data, and to opt out of certain processing such as targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
- Right to know/access categories and specific pieces of personal data we process.
- Right to correct inaccurate personal data.
- Right to request deletion, subject to legal exceptions.
- Right to data portability for data you provided to us.
- Right to non-discrimination for exercising privacy rights.
- Right to appeal certain denied requests where required by state law.
We do not sell personal data and do not share personal data for cross-context behavioral advertising as defined under California law. To submit or appeal a request, contact support@biomedli.com.
UK Privacy Wording
For UK users, personal data is processed in accordance with UK GDPR and the Data Protection Act 2018. You may exercise rights of access, rectification, erasure, restriction, data portability, and objection, subject to legal limitations.
If you have unresolved concerns, you may lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.
Retention and Deletion
We retain data only for as long as necessary to provide the Service, comply with legal requirements, resolve disputes, and enforce agreements. Account deletion and data-erasure requests are currently support-assisted: email support@biomedli.com from your registered account address.
Automated inactive-account retention and purge controls are not enabled in this release. We are implementing documented deletion, retention, and backup-reconciliation workflows; until then, verified requests are handled through the support process and applicable provider capabilities.
Security Controls
BioMedli uses layered administrative, technical, and physical safeguards, including:
- Encryption in transit (TLS) and at rest.
- Access controls and least-privilege permissions.
- Segregated environments, logging, and incident response processes.
- Data minimization and pseudonymization where feasible.
BioMedli is a consumer service and is not offered under a Business Associate Agreement. It must not be used as a HIPAA-regulated covered-entity or business-associate workflow.
International Transfers
Our providers may process data in countries other than your own, depending on the configured hosting region and provider infrastructure. Region, transfer, and contractual safeguards are being documented and reviewed; contact support@biomedli.com for the current information before relying on a specific residency requirement.
Your Rights
Subject to local law, you may request:
- Access to personal data we hold about you.
- Correction of inaccurate or incomplete data.
- Deletion of personal data.
- Restriction or objection to certain processing.
- Data portability for data provided by you.
- Withdrawal of consent where processing relies on consent.
These requests are currently support-assisted. To submit one, email support@biomedli.com. You may also have a right to lodge a complaint with your local supervisory authority.
Adult-Only Service
BioMedli is currently only available to adults aged 18 years and over. Profiles for children and guardian-managed accounts are not supported. If you believe we received a child's personal data, contact us promptly so we can investigate, restrict processing, and remove the data where appropriate.
Policy Changes
We may update this Privacy Notice periodically. Material updates will be posted on this page and, where required by law, notified through in-product communication or email.
Contact
For privacy, security, or compliance questions, contact support@biomedli.com.
Related pages: Terms of Service, Conditions of Use, and Cookie Policy.