Masdiag ("we", "us", or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with the EU General Data Protection Regulation (GDPR) 2016/679, which we apply as our baseline standard across all markets we serve.
The data controller responsible for your personal data is:
Masdiag
Email: privacy@masdiag.com
We may collect and process the following categories of personal data:
Name, email address, phone number, company name, job title, and country/region — collected through our contact form, email correspondence, or partnership agreements.
Biological samples (dried blood spots, blood, urine, saliva, hair, nails) and associated analytical results. Under GDPR, health data is classified as a special category of personal data and is subject to enhanced protections.
IP address, browser type, device information, and website usage data collected automatically when you visit our website, used to improve site performance and security.
Login credentials, account preferences, and result access history associated with our online results portal.
We process personal data under the following legal bases as defined by GDPR Article 6:
For health data (special category data), we rely on GDPR Article 9(2)(h) — processing necessary for medical diagnosis, the provision of health care, or the management of health care systems.
We use personal data for the following purposes:
We do not sell personal data. We may share data with:
Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) or adequacy decisions.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
Under GDPR, you have the following rights regarding your personal data:
To exercise any of these rights, contact us at privacy@masdiag.com. We will respond within 30 days.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include encrypted data transmission, access controls, secure server infrastructure, regular security assessments, and staff training on data protection obligations.
Our website uses essential cookies to ensure proper functionality. We do not use third-party advertising or tracking cookies. For analytics, we use privacy-respecting tools that do not create individual user profiles. You can control cookie preferences through your browser settings.
Our services are directed at B2B partners and healthcare professionals. We do not knowingly collect personal data from children under 16 without parental or guardian consent. Where diagnostic samples involve minors, data is processed under the authority of the commissioning healthcare professional or partner organisation.
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or regulatory guidance. Material changes will be communicated through our website. We encourage you to review this page regularly.
If you have questions about this Privacy Policy or wish to exercise your data rights, contact our Data Protection team:
Data Protection Contact
Masdiag
Email: privacy@masdiag.com
You also have the right to lodge a complaint with the relevant supervisory authority. In Poland, this is the President of the Personal Data Protection Office (UODO). In the UK, this is the Information Commissioner's Office (ICO). In Australia, this is the Office of the Australian Information Commissioner (OAIC).