GDPR & Security

Last updated: 5 January 2026

This page explains how Medtora ApS (hereinafter “Medtora”) complies with the GDPR
and ensures information security in connection with the operation and use of the platform.

Do I as a company need a data processing agreement

Yes, if you as a company use the platform to collect and store information from participants, this is considered processing of personal data according to the GDPR.

In this context, Medtora acts as a data processor, while the company is the data controller. Therefore, a data processing agreement must be concluded in accordance with GDPR Article 28(3)

When creating a company profile, the data processing agreement is automatically made available and must be signed digitally. It is then saved on the company’s profile and serves as documentation of compliance with the GDPR.

The company’s responsibility regarding personal data

The company is obliged as a data controller to ensure that all personal data, including consents and associated responses, participant data, uploaded files and documents, are processed in accordance with applicable data protection regulations, the GDPR, and other relevant legislation for the processing of personal data.

This responsibility applies both before, during and after processing, including storage for up to 5 years after the purpose has ceased, unless other legislation, including e.g. MDR (Medical Device Regulation), GCP (Good Clinical Practice) or EHDS (European Health Data Space), prescribe a longer retention obligation or additional requirements for documentation and data security.

As a private individual, do I need a data processing agreement?

No. Private individuals are not data controllers or data processors in the sense of data protection law, and therefore entering into a data processing agreement is not necessary.

Documents

Below is documentation for compliance with GDPR Article 28(1), in relation to hosting and operating the platform.
Reference is also made to internal organizational guidelines and security procedures.
Please note that participant data and other related data regarding a participant are only hosted on the company’s own SharePoint, Nextcloud or any other cloud solutions:

Cloud Certificate

Presentation of Security Environment

GDPR self-assessment report

ISO 27001 Certificate