Privacy Policy
Effective Date: September 27, 2026
This Privacy Policy describes how Argomedix ("we," "our," or "us") collects, uses, and secures information within the Argomedix Virtual Data Room (VDR) platform. This document outlines our technical security mechanisms and compliance alignment with the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), and the technical safeguards of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule.
1. Data Processing Roles
In accordance with GDPR and applicable privacy frameworks, Argomedix operates under two distinct roles depending on the context of the data being processed:
- Data Controller: Argomedix acts as the Data Controller for information strictly related to SaaS user account creation, billing administration, and platform analytics required to deliver our services.
- Data Processor: Argomedix acts as the Data Processor for all customer diligence data, documents, and sensitive information uploaded to and hosted within our virtual data rooms.
2. Types of Data Collected
In our role as a Data Controller, we collect the following categories of personal data:
- Account & Contact Data: Full name, corporate email address, organizational affiliation, and phone numbers required for MFA or account recovery.
- Billing Information: Payment details securely tokenized via our authorized payment subprocessors.
- Technical & Usage Data: IP addresses, browser agents, authentication timestamps, and platform engagement metrics collected via securely signed session cookies.
3. Purposes and Legal Basis of Processing
We process collected data exclusively for the following authorized purposes, relying on the following legal bases under GDPR Article 6:
- Performance of a Contract (Art. 6(1)(b)): To provision, maintain, and secure the Argomedix VDR platform, and deliver essential customer support and transactional communications.
- Legitimate Interests (Art. 6(1)(f)): For platform security, detecting and preventing fraudulent or malicious activity, and service improvement.
- Legal Obligation (Art. 6(1)(c)): To comply with statutory data retention, technical access controls, and audit requirements.
4. Hosting & Data Residency
To ensure stringent data sovereignty, all databases and object storage volumes are strictly isolated to EU jurisdictions. We do not transfer or replicate customer diligence data outside of the European Union.
5. Security of Processing (GDPR Art. 32)
Argomedix implements advanced technical measures to ensure a level of security appropriate to the risk. Document processing functions (such as dynamic watermarking) occur entirely transiently in volatile edge memory. No unencrypted files or health-related data are ever cached or written to persistent disk outside of the established EU boundary.
6. HIPAA Security Rule (§ 164.312) Technical Alignment
While prioritizing EU data protection standards, the Argomedix VDR is architected to align with the stringent technical safeguards mandated by the HIPAA Security Rule for electronic Protected Health Information (ePHI):
- Access Control & Authentication: Access to the platform requires Multi-Factor Authentication (MFA) via hardened email OTP. Sessions are secured using cryptographically signed session cookies, enforced with a rolling 30-minute idle inactivity timeout, and a 12-hour absolute session maximum.
- Audit Controls & Retention: Comprehensive, immutable audit logs are maintained for all critical platform activities. To balance US healthcare audit expectations with GDPR data minimization mandates, logs are securely offloaded to cold storage protected by a multi-year Object Lock prior to the execution of our automated data minimization routines.
- Encryption:
- At Rest: We utilize native AES-256 Transparent Data Encryption (TDE) across all cloud storage volumes and databases.
- In Transit: All data transmissions are secured using strict TLS 1.3 enforcement alongside HTTP Strict Transport Security (HSTS).
- Emergency Access Protocol: In the event of an operational emergency, an out-of-band break-glass procedure is established. Authorized personnel must submit urgent data access requests to our compliance team. If approved, overrides are executed via strictly administrative scoped access constrained to a maximum 2-hour window. All emergency actions are immutably recorded in the platform audit logs.
7. Cookies & Tracking (TDDDG Compliance)
The Argomedix platform utilizes zero third-party marketing or analytics trackers. We rely exclusively on strictly necessary session and security cookies to authenticate users and prevent cross-site request forgery (CSRF). Because these cookies are strictly necessary for the secure provision of the service, no consent banners are required under the Telecommunications Digital Services Data Protection Act (TDDDG).
8. Disclosure & Data Sharing
We treat your data with the highest confidentiality. Disclosure of data occurs only under the following constrained circumstances:
- Authorized Subprocessors: We engage vetted infrastructure and security subprocessors essential to operating the VDR. All subprocessors are bound by strict Data Processing Agreements (DPAs) and operate within approved EU boundaries. For a full list, see our Subprocessors page.
- Legal & Regulatory Obligations: We may disclose data if compelled by a lawful subpoena, court order, or binding request by a supervisory authority, subject to strict jurisdictional reviews.
- Business Transactions: In the event of a merger, acquisition, or asset sale, data may be transferred subject to continued adherence to this Privacy Policy.
9. General Data Retention
Personal data is retained only for as long as necessary to fulfill the operational purposes outlined above, or as mandated by statutory compliance obligations. Upon the termination of a contract or the conclusion of a diligence project, customer diligence data is permanently destroyed in accordance with secure cryptographic erasure protocols.
10. US State Privacy Laws (CCPA / CPRA)
For residents of California and applicable US states, we disclose that in the preceding 12 months, we have collected the categories of personal data outlined in Section 2. We firmly assert that Argomedix does not "sell" or "share" personal information for cross-context behavioral advertising.
You possess the right to request access to the specific pieces of data we hold, the right to request deletion, and the right to request a limitation on the use of sensitive personal information. To exercise these rights or opt-out mechanisms, please submit a request to compliance@argomedix.com.
11. User Rights & Data Subject Access Requests (DSAR)
Under the GDPR, BDSG, and applicable US state laws, you possess specific rights regarding your personal data:
- Right to Access: You may request a copy of the personal data we hold about you as a Controller.
- Right to Rectification (Art. 16): You have the right to request the correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17): You may request the deletion of your account. Upon deletion, personal identifiers in our active databases are permanently scrubbed and anonymized to
[DELETED USER], ensuring audit continuity without retaining identifiable information. - Right to Restrict Processing (Art. 18): You have the right to request a temporary halt to the processing of your data under certain conditions.
- Right to Data Portability (Art. 20): You may request to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): You have the right to object to our processing of your personal data when based on legitimate interests.
To exercise your rights or submit a Data Subject Access Request (DSAR), please direct all inquiries to compliance@argomedix.com. We will respond in accordance with statutory timelines. If you believe your rights have been violated, you have the right to lodge a complaint with the competent supervisory authority: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit.
12. Children's Privacy
The Argomedix VDR is strictly an enterprise B2B platform and is not directed at or intended for individuals under the age of 18. We do not knowingly collect personal data from minors.
13. Changes to this Privacy Policy
We reserve the right to update this Privacy Policy periodically to reflect changes in our security posture or legal obligations. Significant material changes will be communicated via email or an explicit in-app administrative notice prior to taking effect.
14. Contact Information
For any questions, concerns, or emergency data access requests, please contact our privacy team:
Argomedix Privacy & ComplianceEmail: compliance@argomedix.com