Privacy Policy

Mediwhale Inc.
LAST UPDATED: September 11, 2026

This Privacy Policy (the “Policy”) explains how Mediwhale Inc. (“Mediwhale,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal data when you visit our websites, submit an inquiry, subscribe to updates, participate in an event or consultation, or use or receive services for which this Policy is presented (collectively, the “Services”).

This Policy is intended to apply globally. Certain jurisdictions impose additional requirements. The Addendum for the United States in Section 11 supplements this Policy for U.S. residents where applicable. If the U.S. Addendum conflicts with this Policy, the U.S. Addendum controls for U.S. residents.

Our role depends on the context

When you interact directly with Mediwhale through our public websites, Contact Us forms, subscriptions, or events, Mediwhale generally determines the purposes and means of that processing. For Dr. Noon services provided through hospitals or other healthcare institutions, the healthcare institution generally determines why patient data is processed and Mediwhale may act as a processor or service provider under the applicable agreement. When we act solely on behalf of a healthcare provider, that provider’s privacy notice and instructions also govern the processing.

CONTENTS

Part I – Global Privacy Policy

Part II – Addendum for the United States

PART I – GLOBAL PRIVACY POLICY

1. INFORMATION WE COLLECT

We collect personal data that is reasonably necessary for the Services and the purposes described in this Policy. The information we collect depends on how you interact with Mediwhale and which Service is involved.

1.1 Information You Provide to Us

InteractionPersonal DataPurposeRetention
Contact Us / Product InquiryRequired: full name, email address, and message. Optional: location information such as ZIP code, city, and state. When you submit an inquiry, referral information, campaign parameters, pages visited, and timestamps may also be associated with the submission.Receive, review, and respond to inquiries about Dr. Noon CVD; provide requested information; investigate and address questions; and conduct appropriate follow-up.One year after the inquiry is resolved, unless a longer period is required or permitted by applicable law.
Email Updates / NewsletterEmail address.Send news, updates, educational information, and other communications you request.For as long as you remain subscribed or until the information is no longer needed for this purpose, subject to applicable law and any necessary opt-out records.
Event / Solution ConsultationName, email address, and company; optional job title and phone number where requested.Arrange solution consultations, meetings, and related follow-up communications.Through completion of the meeting and follow-up communications, and for one year thereafter.

1.2 Information We Receive from Healthcare Providers


For certain Dr. Noon services, Mediwhale receives personal data through hospitals or other healthcare providers rather than collecting it directly from the patient. Depending on the Service and customer arrangement, this may include:

  • retinal fundus images (fundus photographs);
  • gender, age, date of birth, date of hospital visit, and similar clinical or demographic information where provided and permitted;
  • diagnostic, risk, analytical, or service output information generated through Dr. Noon, to the extent associated with an identifiable individual; and
  • other information that the healthcare provider is authorized to submit for the applicable Service.

Dr. Noon may be used to assess cardiovascular disease risk and, where applicable to the relevant service, certain eye-related conditions. The healthcare provider determines how Dr. Noon results are used in the clinical context.

1.3 Information We Collect Automatically

When you visit our websites or use online Services, we may automatically collect technical and usage information through logs, cookies, and similar technologies. This may include:

  • online identifiers, including cookie or client identifiers;
  • IP address and related network information;
  • browser type, device type, operating system, language settings, screen resolution, and other technical information;
  • pages visited, page titles, referring URLs, access times, session information, page-view events, and other website usage information; and
  • approximate location information inferred from technical information or location information you choose to provide.

1.4 Cookies, Analytics, and Similar Technologies

We use Cookiebot, a consent management platform provided by Usercentrics A/S, to manage cookie preferences and consent on applicable Mediwhale websites. Strictly necessary technologies, including technologies needed to remember and administer your privacy choices, may operate without consent where permitted by applicable law. In connection with providing consent management services on our behalf, Usercentrics A/S may process consent-related information such as a consent identifier and consent state, the date and time of the choice, the URL where the choice was made, language settings, user-agent or device/browser information, IP address, and geolocation information, as applicable. Where prior consent is required by applicable law, non-essential analytics or marketing technologies are disabled until you grant the relevant consent through the Cookiebot banner or preference center. You may accept, reject, or manage available cookie categories and may later change or withdraw your choices through the cookie settings. Withdrawal applies to future processing and does not affect the lawfulness of processing based on consent before withdrawal. Certain Mediwhale and Dr. Noon websites also use or may enable analytics technologies, including Google Analytics 4 (GA4), depending on the website and deployment. Where GA4 is enabled, Google may receive online identifiers, device and browser information, IP address, page and session information, and other internet or electronic network activity information. Our Cookie Declaration, available through the cookie settings where implemented, provides more current information about the cookies and trackers detected on the relevant website, including their categories, purposes, providers, and retention periods.

2. HOW WE USE YOUR PERSONAL DATA

We use personal data only for purposes that are reasonably necessary and proportionate to the context in which the information was collected, including to:

  • provide, operate, maintain, support, secure, and improve the Services;
  • perform Dr. Noon processing made available through healthcare providers and provide results back to the applicable provider or customer;
  • receive, verify, investigate, and respond to product, customer, privacy, or other inquiries;
  • manage email subscriptions, events, solution consultations, meetings, and related communications;
  • analyze website traffic, usage, and performance through analytics technologies;
  • protect the security, integrity, and availability of our websites, infrastructure, data, and business operations;
  • prevent, detect, investigate, and respond to fraud, misuse, security incidents, or other harmful activity;
  • comply with applicable legal, regulatory, contractual, and professional obligations and respond to lawful requests from courts, regulators, government authorities, or law enforcement; and
  • develop or improve the Services where permitted by applicable law and the relevant agreement. When Mediwhale acts as a processor for healthcare data, development or improvement activities involving that data are performed only to the extent permitted by the controller’s documented instructions, the applicable agreement, or another lawful basis.

2.1 LEGAL BASES, INCLUDING GDPR ARTICLE 6

Where Mediwhale acts as a controller and the EU General Data Protection Regulation (GDPR) applies, we rely on one or more legal bases under Article 6(1) GDPR. Other jurisdictions may recognize equivalent or additional legal grounds. The legal basis depends on the processing activity and our role. Typical bases for direct interactions with Mediwhale include the following:

Processing ActivityGDPR Legal Basis (where applicable)
Contact Us / product inquirySteps at your request before entering into a contract (Article 6(1)(b) GDPR), where applicable, and/or our legitimate interests in responding to inquiries and managing business communications (Article 6(1)(f) GDPR).
Email updates / newsletterYour consent (Article 6(1)(a) GDPR), together with applicable electronic-marketing requirements. You may withdraw consent or unsubscribe at any time.
Non-essential analytics cookiesYour consent (Article 6(1)(a) GDPR) where consent is required by applicable cookie, ePrivacy, or data protection law.
Cookie consent and preference managementCompliance with applicable legal obligations where relevant (Article 6(1)(c) GDPR) and our legitimate interests in administering, documenting, and demonstrating cookie and consent choices (Article 6(1)(f) GDPR).
Website security, fraud prevention, and service integrityOur legitimate interests in protecting the security, integrity, and availability of our Services (Article 6(1)(f) GDPR) and, where applicable, compliance with a legal obligation (Article 6(1)(c) GDPR).
Legal and regulatory complianceCompliance with a legal obligation to which Mediwhale is subject (Article 6(1)(c) GDPR) or another ground provided by applicable law.

When we rely on legitimate interests under Article 6(1)(f) GDPR, those interests include responding to inquiries, managing business communications, protecting the security and integrity of our Services and systems, and preventing fraud, misuse, and security incidents. We consider the nature of the data, your reasonable expectations, and the potential impact on your rights and freedoms, and we do not rely on this basis where those interests are overridden by your interests or fundamental rights and freedoms.

For Dr. Noon patient data processed on behalf of a hospital or other healthcare provider, Mediwhale generally acts as a processor or service provider. The healthcare provider, as controller where applicable, determines the lawful basis and any additional condition required under applicable law for processing health or other special-category data. Mediwhale processes such data on documented instructions and under the applicable agreement. Where Mediwhale independently determines the purposes and means of processing personal data, we identify and document a valid legal basis and, for health or other special-category data, any additional condition required by applicable law before processing.

3. HOW WE DISCLOSE YOUR PERSONAL DATA

We may disclose personal data when reasonably necessary to provide and support the Services, at the direction of a healthcare provider or user, with authorization where required, or as otherwise permitted by applicable law. Recipient categories may include:

Recipient CategoryWhy We May Disclose
Healthcare Providers / CustomersHospitals or other healthcare providers that provide data to Mediwhale, receive Dr. Noon results, or otherwise use the Services.
Cloud and Infrastructure ProvidersProviders that host, store, secure, or support our systems, including Amazon Web Services (AWS).
Analytics ProvidersAnalytics providers, including Google Analytics where enabled, used to measure website traffic, usage, and performance in accordance with applicable consent and opt-out requirements.
Consent Management ProvidersUsercentrics A/S, which provides Cookiebot, processes consent and preference information on our behalf to operate the cookie banner, preference center, consent records, and related compliance functionality.
Website, IT, and Support ProvidersVendors that support website development and maintenance, cloud operations, monitoring, technical support, communications, or similar business functions.
Professional AdvisorsAttorneys, accountants, auditors, insurers, consultants, and other professional advisors where reasonably necessary.
Government Authorities and Law EnforcementRegulators, courts, government agencies, and law-enforcement authorities where disclosure is required or permitted by applicable law.
Business Transaction PartiesPotential or actual parties to a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar corporate transaction.
At Your Direction or With AuthorizationOther parties where you, or an authorized healthcare provider acting within its authority, direct or authorize the disclosure.

4. DATA RETENTION AND DELETION

We retain personal data for no longer than reasonably necessary for the purposes for which it was collected, taking into account applicable legal, contractual, regulatory, security, audit, and dispute-resolution requirements.

Data / ActivityRetention Approach
Dr. Noon dataThe period specified in the applicable healthcare-provider agreement or data processing terms and as required or permitted by applicable law. A retention period required by one jurisdiction is not automatically applied to a different jurisdiction.
Contact inquiriesOne year after the inquiry is resolved, unless longer retention is required or permitted by law.
Event / solution consultationUntil completion of the meeting and follow-up communications, plus one year.
Email subscriptionsUntil you unsubscribe, withdraw any consent on which the communication relies, or the information is no longer needed for the subscription, subject to legally required suppression or compliance records.
Website analytics and technical dataFor the period reasonably necessary for analytics, performance measurement, security, and related business purposes, based on the relevant configuration, cookie settings, and applicable law.
Cookie consent and preference recordsFor the period reasonably necessary to administer and demonstrate consent choices, based on the Cookiebot configuration and applicable legal, audit, and dispute-resolution requirements.
Legal, regulatory, security, or dispute recordsFor the period reasonably necessary to meet legal obligations, establish or defend claims, resolve disputes, investigate incidents, or enforce agreements.

When personal data is no longer required, we delete, anonymize, or otherwise dispose of it using methods appropriate to the medium and designed to prevent unauthorized recovery or reconstruction. Where personal data is subject to a healthcare-provider agreement, data processing agreement, or Business Associate Agreement, return or deletion will be handled in accordance with that agreement and applicable law.

5. YOUR PRIVACY RIGHTS

Depending on where you live and subject to applicable exceptions, you may have rights to request information about our processing; access to or a copy of personal data; correction; deletion; restriction or objection; data portability; withdrawal of consent where processing is based on consent; rights concerning certain profiling or automated decision-making; and the right to lodge a complaint with a competent data protection or supervisory authority. Additional rights for U.S. residents are described in the Addendum for the United States.

Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. Where processing is based on legitimate interests, you may have the right to object on grounds relating to your particular situation. You may object to direct marketing at any time.

When Mediwhale processes personal data solely on behalf of a healthcare provider, the healthcare provider may be responsible for responding to your request. In that case, we may direct you to the provider or assist the provider as required by the applicable agreement and law.

6. CHILDREN’S PRIVACY

Our public websites are not directed to children, and we do not knowingly collect personal data directly from children through the public websites in circumstances that require parental or guardian authorization without obtaining the required authorization. Minimum age requirements vary by jurisdiction.

Where a healthcare provider submits information relating to a minor through a Service, the provider’s privacy notice, authorizations, contractual terms, and applicable healthcare and data protection laws may govern the processing. Mediwhale processes such information in accordance with the applicable provider arrangement and law.

7. INTERNATIONAL DATA TRANSFERS AND HOSTING

Mediwhale is based in the Republic of Korea and operates in an international environment. Personal data may be processed in countries other than the country where it was collected, depending on the Service, customer arrangement, and service providers involved.

Personal data for EEA Dr. Noon deployments is primarily hosted using AWS infrastructure in Frankfurt, Germany, where the applicable deployment is configured for EEA hosting.

Personal data for U.S. Dr. Noon deployments is primarily hosted using AWS infrastructure in the U.S. East (N. Virginia) region in the United States.

Authorized Mediwhale personnel in the Republic of Korea may remotely access data where necessary to operate, maintain, support, secure, or develop the applicable Service. Where Mediwhale acts as a processor, such access is limited to the controller’s documented instructions and the applicable agreement.

Where required by law, we use recognized transfer mechanisms and appropriate contractual, technical, and organizational safeguards for international processing and transfers. For transfers of personal data from the EEA to the Republic of Korea, we may rely on the European Commission adequacy decision for the Republic of Korea where applicable, or another lawful transfer mechanism where required.

8. HOW WE PROTECT PERSONAL DATA

We implement administrative, technical, and physical safeguards designed to protect personal data from unauthorized access, use, disclosure, alteration, destruction, or accidental loss. Depending on the context, these measures include:

  • administrative measures, including internal policies, access minimization, personnel training, and periodic reviews or audits;
  • technical measures, including access-right management, access controls, encryption where appropriate, security software, monitoring, and controls designed to protect systems and data; and
  • physical measures, including access controls for computer rooms, document-storage areas, and other restricted facilities.

No method of transmission or storage can be guaranteed to be completely secure, but we maintain safeguards designed to reduce privacy and security risks.

9. CHANGES TO THIS PRIVACY POLICY

We may update this Policy from time to time. We will update the “Last Updated” date when changes are made. If a change is material, we will provide notice in a manner appropriate to the Services and applicable legal requirements, such as a prominent notice on our website or other notice where required.

10. CONTACT US

If you have questions, concerns, complaints, or privacy-related requests, you may contact us using the following methods:

Contact MethodDetails
CompanyMediwhale Inc.
Chief Privacy OfficerGeunyoung Lee
Emailg.young@mediwhale.com
Phone+82-2-6959-8010
Mail4F, 746 Nonhyeon-ro, Gangnam-gu, Seoul, Republic of Korea
Website FormContact Us form available on the applicable Mediwhale or Dr. Noon website

11. REGIONAL ADDENDUM

The following regional addendum forms part of this Policy where applicable. Additional jurisdiction-specific privacy notices, local representative details, or addenda may be provided separately where required by applicable law:

  • Addendum for the United States

PART II – ADDENDUM FOR THE UNITED STATES

LAST UPDATED: September 11, 2026

This Addendum applies to residents of the United States to the extent applicable U.S. privacy laws apply to Mediwhale’s processing of their personal data. It supplements and forms part of the Privacy Policy (the “Policy”). If this Addendum conflicts with the Policy, this Addendum controls for U.S. residents.

For purposes of this Addendum, “personal data” includes information referred to as “personal information” or a similar term under applicable U.S. state privacy laws.

1. CATEGORIES OF PERSONAL DATA COLLECTED

U.S. CategoryExamples Relevant to Mediwhale
IdentifiersName, email address, phone number, IP address, online or cookie identifiers, client identifiers, and similar identifiers.
Demographic InformationGender, age, and date of birth where provided for Dr. Noon and permitted by applicable law.
Internet or Other Electronic Network ActivityBrowser and device information, operating system, language settings, screen resolution, pages visited, page-view events, session information, referring URLs, campaign parameters, access times, and related website usage information.
Approximate Location InformationZIP code, city, state, or approximate location derived from information you provide or from technical information, where used.
Audio, Electronic, Visual, or Similar InformationRetinal fundus images and other electronic content provided through the Services.
Professional or Employment-Related InformationHospital/company affiliation, company name, job title, and similar business information provided through inquiries or event consultations.
Inferences / Analytical OutputsDiagnostic, risk, analytical, or service outputs generated from information processed by Dr. Noon, to the extent associated with an identifiable individual.
Sensitive Personal Data / Sensitive Personal InformationHealth information, including retinal fundus images and diagnostic or risk information associated with an identifiable individual. Other sensitive categories are collected only if relevant to a specific Service and permitted by applicable law.

2. SOURCES OF PERSONAL DATA

  • Directly from you, for example when you contact us, subscribe to updates, request information, or participate in a solution consultation.
  • From hospitals, healthcare providers, or other customers that use Dr. Noon and provide information necessary to perform the Service.
  • Automatically through your use of our websites or online Services, including through cookies and analytics technologies.
  • From service providers or partners where they are authorized to provide the information to us.

3. HOW WE DISCLOSE PERSONAL DATA

We may disclose personal data to the recipient categories described in Section 3 of the main Policy. These include healthcare providers or customers, cloud and infrastructure providers, analytics providers, website and IT service providers, professional advisors, government authorities and law enforcement, business-transaction parties, and parties acting at your direction or with appropriate authorization.

Where Google Analytics is enabled on a Mediwhale or Dr. Noon website, Google may receive identifiers, device or browser information, IP address, page and session information, and other internet or electronic network activity information for analytics purposes.

4. SALE, SHARING, AND TARGETED ADVERTISING

Mediwhale does not receive monetary payment in exchange for personal data through the activities described in this Policy. Certain U.S. state privacy laws, however, define “sale,” “sharing,” or targeted advertising more broadly and may treat some disclosures involving analytics or advertising technologies as regulated disclosures even when no direct monetary payment is exchanged.

Certain Mediwhale and Dr. Noon websites use or may enable Google Analytics 4 depending on the website and deployment. Where GA4 is enabled, Google may receive online identifiers, device and browser information, IP address, page and session information, and other internet or electronic network activity information. Depending on applicable law and the configuration and use of these technologies, certain disclosures may be treated as a “sale,” “sharing,” or processing for targeted advertising. Where applicable law gives you a right to opt out, we will provide and honor the applicable opt-out mechanism. Where prior consent is required, non-essential analytics technologies are not activated until the relevant consent is obtained.

5. YOUR U.S. PRIVACY RIGHTS

RightDescription
Right to Know / AccessRequest information about the personal data we collect, sources, purposes, and recipient categories, and request access to specific personal data where required.
Right to DeleteRequest deletion of personal data, subject to legal, contractual, security, and other permitted exceptions.
Right to CorrectRequest correction of inaccurate personal data we maintain about you.
Right to Data PortabilityReceive personal data in a portable and, where technically feasible, readily usable format.
Right to Opt OutWhere applicable, opt out of sale, sharing for cross-context behavioral advertising, or processing for targeted advertising.
Right to Limit Certain Uses of Sensitive DataWhere applicable law grants this right and our processing triggers it, request limits on certain uses or disclosures of sensitive personal data.
Rights Concerning Profiling / Automated Decision-MakingWhere applicable law grants such a right and the processing falls within its scope, request information about or opt out of certain profiling or automated decision-making activities.
Right to AppealAppeal a decision regarding a privacy-rights request where applicable state law provides an appeal right.
Right to Non-DiscriminationNo unlawful discrimination for exercising applicable privacy rights.

Some U.S. state privacy-law rights do not apply to information that is exempt from those laws, which may include protected health information governed by HIPAA or information processed on behalf of a regulated healthcare provider, depending on the law and circumstances.

6. HOW TO EXERCISE YOUR RIGHTS

You may submit a privacy-rights request using one or more of the methods below. We may ask you to provide information reasonably necessary to identify the relevant records and verify your identity or authority. A dedicated privacy-rights portal is not required to use these methods.

MethodDetails
Website FormContact Us form available on the applicable Mediwhale or Dr. Noon website
Emailg.young@mediwhale.com
Phone+82-2-6959-8010
MailMediwhale Inc., 4F, 746 Nonhyeon-ro, Gangnam-gu, Seoul, Republic of Korea

6.1 Verification and Authorized Agents

To protect privacy and security, we may verify your identity before processing a request. Where permitted by law, you may designate an authorized agent to submit a request on your behalf. We may require proof of the agent’s authority and verification of your identity, subject to applicable exceptions.

6.2 Response Timing, Appeals, and Preference Signals

We will respond within the period required by applicable law. If applicable law provides a right to appeal a denial, you may submit an appeal using the same contact methods listed above and identify the request and decision you are appealing. Where legally required, we process recognized opt-out preference signals, such as Global Privacy Control, as a valid opt-out request for the browser or device from which the signal is sent.

7. CHILDREN’S PRIVACY

Our public websites and Services covered by this Policy are not directed to children under 13 years of age. We do not knowingly collect personal data directly from children under 13 through the public website without verifiable parental consent where required by the Children’s Online Privacy Protection Act (COPPA). If we learn that we collected personal data directly from a child in violation of applicable law, we will take steps to delete or otherwise address the information.

If a healthcare provider submits data relating to a minor through a Service, Mediwhale processes that information in accordance with the applicable provider arrangement and applicable law.

8. HEALTHCARE DATA AND HIPAA

8.1 Healthcare Provider Arrangements

Dr. Noon personal data is generally provided through hospitals or healthcare providers rather than collected directly from the patient by Mediwhale. In a U.S. deployment where Mediwhale creates, receives, maintains, or transmits protected health information (PHI) on behalf of a HIPAA covered entity as its business associate, Mediwhale will process that PHI in accordance with applicable HIPAA requirements and the applicable Business Associate Agreement (BAA).

This Privacy Policy does not replace a covered healthcare provider’s HIPAA Notice of Privacy Practices. A healthcare provider may be responsible for responding to individual HIPAA rights requests concerning PHI maintained through the Service, and Mediwhale may assist that provider in accordance with the applicable BAA.

8.2 Retention of U.S. Healthcare Data

Mediwhale does not treat a medical-record retention period required under Korean law as an automatic retention period for U.S. Dr. Noon data. For U.S. deployments, retention is determined by the applicable healthcare-provider agreement, any BAA, the purpose of processing, and applicable federal and state law. Upon termination of the applicable services or agreement, PHI will be returned or deleted as required by the applicable BAA and law, unless continued retention is required or permitted.

8.3 State Consumer Health Data Laws

Certain U.S. states have consumer health data laws that may apply to health-related information not governed by HIPAA or another applicable exemption. Where such a law applies, Mediwhale will provide any additional notice and rights required by that law.

9. THIRD-PARTY SERVICES AND LINKS

Our websites or Services may contain links to websites, applications, or services operated by third parties. Their privacy practices are governed by their own notices, not this Policy. We encourage you to review the privacy notice of any third-party service you access.

10. CONTACT US

If you have questions, concerns, complaints, or a privacy-rights request relating to this Addendum or our privacy practices, contact us at:

Contact MethodDetails
CompanyMediwhale Inc.
Chief Privacy OfficerGeunyoung Lee
Emailg.young@mediwhale.com
Phone+82-2-6959-8010
Mail4F, 746 Nonhyeon-ro, Gangnam-gu, Seoul, Republic of Korea