Privacy Policy for TbilisiMed
Effective Date: 01 September 2026
Owner: TbilisiMed (“we”, “us”, “our”)
Website: tbilisimed.com
Jurisdiction: India (DPDP Act), International Users (GDPR/CCPA)
1. Introduction
This Privacy Policy explains how we collect, use, store, share, and protect personal information when medical students access our online medical lectures, courses, and related educational services. By using our website, you consent to the practices described here.
We comply with applicable privacy laws, including:
- India’s Digital Personal Data Protection Act (DPDP Act)
- General Data Protection Regulation (GDPR) for EU users
- CCPA‑style rights for users requiring enhanced transparency
We do not collect or store Protected Health Information (PHI) as defined under HIPAA.
2. Information We Collect
We collect the following categories of data:
2.1 Personal Data
Name, email address, phone number, academic details, country, and login credentials.
2.2 Payment Information
Billing details processed securely through third‑party payment gateways (e.g., PayPal, Stripe, Razorpay). We do not store full credit/debit card numbers.
2.3 Usage Data
IP address, device type, browser details, pages visited, session duration, and interaction logs.
2.4 Course Activity & Performance Data
Lecture progress, quiz scores, notes, bookmarks, and engagement metrics.
2.5 Cookies & Tracking Technologies
Essential, analytics, and preference cookies.
3. Legal Basis for Processing
We process data under the following legal bases:
- Consent (GDPR Art. 6(1)(a))
- Contractual necessity for providing course access
- Legitimate interests (platform improvement, fraud prevention)
- Compliance with legal obligations
4. How We Use Your Information
We use your data for:
- Service Delivery — course access, video streaming, quizzes
- Account Management — authentication, security
- Communication — updates, reminders, support
- Analytics & Improvement — performance optimization
- Legal Compliance — fraud prevention, regulatory duties
We do not sell personal data.
5. Sharing of Information
We share data only with:
- Service Providers — hosting (AWS/Azure), analytics (Google Analytics), email delivery providers, payment processors
- Legal Authorities — when required by law
- Academic Partners — only with explicit consent
All third‑party providers follow strict confidentiality and security standards.
6. Data Retention
We retain data only as long as necessary:
- Account Data: retained until account deletion
- Payment Records: 5–7 years (legal compliance)
- Analytics Logs: 24 months
- Course Activity: retained until account deletion
- Backups: automatically purged within 30–90 days
7. Cookies & Tracking
We use the following cookie categories:
- Essential Cookies — login, session management
- Analytics Cookies — performance insights
- Preference Cookies — saved settings
Users may disable non‑essential cookies via browser settings or our cookie banner (wherever available).
8. Student Performance Data
We use performance data to:
- Personalize learning recommendations
- Improve course quality
- Provide progress reports
- Enable certification (if applicable)
We do not share performance data with institutions without explicit consent.
9. Data Security
We implement:
- SSL/TLS encryption
- Secure server infrastructure
- Access‑controlled systems
- Regular audits
- Encrypted backups
No system is completely secure, but we follow industry best practices.
10. Data Breach Protocol
If a breach occurs:
- We assess the impact.
- We notify affected users within 72 hours (GDPR standard).
- We provide mitigation steps.
- We report to authorities when required.
11. Your Rights
Depending on your jurisdiction, you may have rights to:
- Access your data Access Data
- Correct or update information Correct Data
- Request deletion Delete Data
- Withdraw consent Withdraw Consent
- Opt out of marketing Opt Out
Requests are processed within 30 days.
12. Children’s Privacy
Our services are intended for individuals 18 years and older. If we discover a minor has registered:
- The account will be terminated
- Data will be deleted immediately
- Parents/guardians may contact us for verification
13. International Data Transfers
Data may be processed outside your country. We use standard contractual clauses and secure transfer mechanisms.
14. Changes to This Policy
We may update this Privacy Policy periodically. The “Effective Date” will reflect the latest revision. Continued use of the website indicates acceptance of updated terms.
15. Contact Information
For questions or privacy requests:
Email: support@tbilisimed.com