Skip to content

Data protection notice

This document was last updated on: 18/08/2026

This Data Protection Notice applies to rapmed websites, applications and other access points designated by Rapid Medicine for the rapmed service (together, the “Service”). It explains how Rapid Medicine AG, Seerosenstrasse 3, 8008 Zürich, Switzerland (“Rapid Medicine”, “we”, “our” or “us”) processes personal data as controller.

Personal data” means information relating to an identified or identifiable natural person. Genuinely anonymous, synthetic and demonstration data are not personal data and fall outside this Notice. Personal data relating to Users, Authorised Users and Link Recipients remain covered. Rapid Medicine does not use Controller Personal Data processed under a DPA for its own product development or service improvement and does not anonymise such data for those purposes.

If personal data of other persons (such as patients, family members, work colleagues) are provided to us, the the respective persons must be made aware of this Data Protection Notice and their data shall only be provided if allowed and is correct.

Rapid Medicine AG is the controller for the processing described in Section 3. You can contact Rapid Medicine regarding data protection matters at privacy@rapmed.net.

For a Customer’s Authorised Users, this Notice applies only to processing for which Rapid Medicine determines the purposes and means, such as managing the business relationship or carrying out the separate analytics described below.

Where Rapid Medicine processes personal data on a Customer’s documented instructions, the Customer is the controller and Rapid Medicine is the processor. This processing, including personal data contained in data or content submitted by or for a Customer (“Customer Data”) and related access and security data (together, “Controller Personal Data”), is governed by the applicable data processing agreement (“DPA”), not by the controller processing described in Section 3. If your request concerns such processing, please contact the relevant Customer. If you contact us, we will direct or forward the request to that Customer as appropriate.

A Link Recipient may be shown this Notice without being asked to accept it. Viewing this Notice or using an unauthenticated Shared Link does not by itself create a contract with Rapid Medicine.

This Data Protection Notice is aligned with the Swiss Data Protection Act and the EU General Data Protection Regulation («GDPR»). The application of these laws depends on each individual case.

2. Data Protection Officer and Representative

Section titled “2. Data Protection Officer and Representative”

You can contact our data protection officer pursuant to art. 37 GDPR using the following contact details, who additionally is our representative in the EEA according to article 27 GDPR (if necessary):

privacy@rapmed.net

The table below describes the processing for which Rapid Medicine acts as controller. The legal bases in the fourth column apply where the EU General Data Protection Regulation (“GDPR”) governs the processing. In Switzerland and the United States, we process the data for the stated purposes and subject to the requirements and permissions of applicable law; a GDPR legal basis listed below is not presented as the sole basis in those jurisdictions.

Processing Categories of personal data and source collected Processing Purposes GDPR legal basis
Website and Service operation Technical, usage, account and security data, generated through use of the Service Deliver, authenticate, operate and protect the website and Service; prevent, detect and investigate errors, misuse and security incidents Contract, Art. 6(1)(b) GDPR, where applicable; legitimate interests in operating and securing the website and Service, Art. 6(1)(f) GDPR; legal obligations, Art. 6(1)(c) GDPR, where applicable
Accounts, Individual Testing and Shared Links Account, submission and usage data, provided by the person or generated through use of the Service Create and administer accounts; provide Individual Testing and requested Service and Shared Link functions; make information available to recipients selected by the User Contract and pre-contractual steps, Art. 6(1)(b) GDPR; legitimate interests in providing requested functions to Link Recipients, Art. 6(1)(f) GDPR
Analytics and licence administration Pseudonymous platform identifiers and interaction events; licence-related account, usage and collaboration data, including email-domain and sharing activity, generated through use of the Service Understand and administer the Service; identify use that may require a licence and conduct a human review Contract, Art. 6(1)(b) GDPR, where applicable; legitimate interests in Service and licence administration and preventing misuse, Art. 6(1)(f) GDPR
Customer relationships, communications and billing Contact, account, contract, billing and communication data, provided by the person or Customer or generated during the relationship Manage Customer relationships, contracts, accounts, licences, billing and support; send functional, service, security and contract communications Contract and pre-contractual steps, Art. 6(1)(b) GDPR; legal obligations, Art. 6(1)(c) GDPR; legitimate interests in business, Service and claims administration, Art. 6(1)(f) GDPR
Marketing Contact, communication and marketing-preference data, provided by the person, a Customer or a lawful business-contact source Send professional product, offer and event communications Consent, Art. 6(1)(a) GDPR; legitimate interests in permitted professional direct marketing, Art. 6(1)(f) GDPR, where applicable law allows
Compliance, claims, incidents and corporate transactions Contact, identity-verification, request, security, incident, claims and transaction data, provided by the person, advisers or service providers or generated through the relevant matter Handle privacy requests and legal duties; protect systems and investigate incidents; establish, exercise or defend claims; evaluate or complete a corporate transaction Legal obligations, Art. 6(1)(c) GDPR; legitimate interests in compliance, security, claims and corporate transactions, Art. 6(1)(f) GDPR

Marketing, service, security and contract emails are separate communication categories. Marketing emails include an unsubscribe method where required, and you may object to or withdraw consent for marketing at any time by using that method or contacting privacy@rapmed.net.

Service, security and contract emails are not marketing. You cannot opt out where a message is necessary to provide a requested Service, authenticate an account, protect an account or system, administer a contract or comply with law. We do not add marketing content to a message where doing so would change the message’s necessary service, security or contractual character.

We use authentication or session cookies where necessary to authenticate Users and maintain requested sessions. Their duration is determined by the applicable authentication and session requirements. If you block or delete them, you may be unable to sign in or remain signed in. We do not currently use separate analytics cookies in the Service.

Our analytics provider processes personal data for the Service analytics described in Section 3 and does not receive Customer Data. The current provider and processing location are listed in Section 13, and the applicable retention information is provided in Section 7.

If we introduce optional cookies or another non-essential method of storing or accessing information on a device, we will provide information and obtain consent before activation where applicable law requires it.

6. Recipients, Service Providers and International Transfers

Section titled “6. Recipients, Service Providers and International Transfers”

Personal data may be disclosed to our service providers supporting our cloud infrastructure, hosting, storage, communications, analytics and related Service operations; Users, Link Recipients or other recipients selected through the Service; professional advisers, auditors, financial institutions, insurers, courts, regulators and other competent authorities; and transaction counterparties, potential successors and their advisers.

The Service’s primary application infrastructure is hosted in Switzerland and the European Union. eHowever, certain service providers may process personal data in country without adequate statutory data protection.Where we disclose personal datato such country, we use safeguards recognised by applicable law, such as the European Commission’s Standard Contractual Clauses with any required Swiss adaptations and supplementary measures. You may request information about the applicable safeguards at privacy@rapmed.net; copies may be redacted where necessary to protect confidential information or the rights of others.

Transfers of Controller Personal Data carried out on a Customer’s documented instructions are governed by the DPA and the Customer’s responsibilities as controller.

We retain personal data only for as long as necessary for the purposes described in this Notice, taking into account the nature of the data, applicable legal obligations, security requirements and the need to establish, exercise or defend legal claims. When personal data are no longer required, we delete them or restrict their use where immediate deletion is not possible or continued retention is required by law. Backup copies are deleted or overwritten in accordance with our regular backup and deletion cycles.

Deleting an Authorised User’s account does not determine the retention or deletion of Customer Data in a Customer workspace. Return and deletion of Controller Personal Data are governed by the DPA and the Customer’s documented instructions.

Depending on the law applicable to our processing, you may have rights to obtain information about and access your personal data, correct inaccurate data, request deletion or restriction, receive or transfer certain data, object to processing and lodge a complaint with a competent data protection authority. Where processing is based on consent, you may withdraw that consent at any time without affecting processing that was lawful before withdrawal. Where applicable, you may also object to direct marketing, appeal a refusal of a request for exercising your privacy rights.

To exercise a right concerning processing for which Rapid Medicine is controller, contact privacy@rapmed.net. We may request information needed to verify your identity or an authorised agent’s authority. Your rights may be subject to statutory conditions and exceptions, and we will handle your request in accordance with applicable law.

9. Required Data, Automated Decisions and Licence Review

Section titled “9. Required Data, Automated Decisions and Licence Review”

An account requires an email address and User Name. The authentication or session cookie is necessary to maintain an authenticated session. If you do not provide the data required for a requested account, communication, support interaction or contract, we may be unable to provide the corresponding account, response, support or contractual service. Other data are required only where identified in the relevant context or by law.

Rapid Medicine does not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

The licence review described in Section 3 applies only to Individual-Testing accounts. It does not examine medical images, patient data or substantive case information, and it is not applied to Authorised Users of a Customer. Rapid Medicine conducts a human review before restricting Individual Testing on this ground.

Rapid Medicine implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Depending on the relevant processing and risk, these measures include confidentiality obligations and role-appropriate security training; role-based access controls applying least-privilege and need-to-know principles; strong multi-factor authentication for privileged production access; encryption at rest and secure transmission controls; logging of access, administrator activity and security-relevant events; logical separation of Customer workspaces; risk-appropriate backup and recovery measures; vulnerability and dependency-management controls; and documented secure-development, change-management and incident-response processes.

We may update this Notice to reflect changes in our processing, the Service or applicable law. We will identify the current template version and date and, where required, provide additional notice of a material change. The current version is available at https://docs.rapmed.net/legal/data-protection-notice.

The website and Service may link to third-party websites or services. The relevant third party is responsible for its own processing. Review its privacy information before providing personal data through an external site or service.