Last updated: 16 August 2026
MediCloud OÜ (registry code 16340560, registered in Estonia) develops and provides the MediCloud medical practice management software. In this Privacy Policy "MediCloud", "we" or "us" means MediCloud OÜ.
Contact: info@medicloud.ee, phone +372 669 2222.
This policy explains how we handle personal data of:
Patient data. Where a clinic uses MediCloud to process the health data of its patients, the clinic is the data controller and MediCloud acts solely as a data processor. We process such data only on the documented instructions of the clinic, under a data processing agreement concluded with it. Patients should address their requests to their clinic.
a) Website. IP address, browser and device type, pages visited, time of the visit, and data collected through cookies and analytics tools (Google Tag Manager, Google Analytics).
b) Contact and demo forms. The name, e-mail address, phone number and message content you submit to us.
c) User accounts. Name, e-mail address, phone number, job title, clinic and role, together with security logs (sign-in events and actions performed in the system).
d) Google account data, if you choose to connect your Google Calendar — see section 5.
MediCloud offers clinic staff an optional Google Calendar integration. It is never enabled automatically: a user has to switch it on and grant permission on Google's own consent screen. If you do not connect your Google account, we receive no data from Google about you.
What we access. When you connect the integration we ask Google for:
We cannot read, change or delete any other calendar in your Google account, and we do not read the events that you or anyone else has created there — the permission we request is technically limited to the calendar our application created itself.
What we write into that calendar. Only your work schedule: your working times (type of day, cabinet number, your name and the clinic), your absences, and, where relevant to you, the working times of other members of staff. Vacation and training days are named as such; every other absence, including sick leave, is written as a neutral "Eemal" (away) entry that does not state a reason, so no health information about you reaches Google. No patient data is ever sent to Google — no patient names, no appointments, no visit details and no patient health data.
How we use it. Google user data is used for a single purpose: keeping the MediCloud calendar in your Google account in step with your work schedule in MediCloud. We do not use it for any other feature, for profiling, or for any purpose that is not visible to you in the product.
How we store it. We store the refresh token issued by Google — encrypted — together with the e-mail address of the connected account and the identifier of the calendar we created, in the clinic's database on servers located in the European Union. For every synchronised entry we additionally store the identifier of the Google event and a checksum that lets us detect changes. Access to the database is limited to authorised administrators and all connections are encrypted with TLS. We do not copy the contents of your Google calendar into MediCloud.
How we share it. We do not sell Google user data and we do not share it with third parties for their own purposes. It may be handled by our hosting provider acting as our processor on our instructions, and it is transmitted to Google itself when performing the synchronisation you asked for.
Retention and deletion. You can end the integration at any time in MediCloud settings. When you do, we delete the calendar we created in your Google account, delete the synchronisation records, delete the stored token and withdraw the access you granted us at Google, all immediately. You may also withdraw our access directly at myaccount.google.com/permissions; synchronisation then stops, and we ask you to end the integration in MediCloud settings as well — or to write to info@medicloud.ee — so that we also remove the token held on our side. When your MediCloud account is closed, this data is deleted together with the account.
Limited Use. MediCloud's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data to serve advertising (including retargeting or interest-based advertising), we do not sell it, we do not transfer it to data brokers or for credit assessment purposes, and we do not use it to develop, improve or train generalised artificial-intelligence or machine-learning models. No human reads your Google user data, except with your explicit consent, where necessary for security purposes or to resolve a technical fault, or where required by law.
We disclose personal data only to the extent necessary: to our hosting and infrastructure partners in the European Union, to e-mail and SMS delivery providers, to Google (for the integration described in section 5), and to public authorities where we are legally obliged to do so. All processors act on our instructions and under a data processing agreement.
Where data is transferred outside the European Economic Area — for example to Google LLC in connection with the Google Calendar integration — the transfer is based on the European Commission's standard contractual clauses or another lawful transfer mechanism.
All connections to MediCloud are encrypted with TLS. Data is held on servers located in the European Union. Access is role-based and restricted to the minimum necessary, all access is logged, passwords are stored as irreversible hashes, and backups are taken regularly. Our staff are bound by confidentiality obligations.
The website uses cookies that are strictly necessary for it to work, as well as analytics cookies (Google Tag Manager, Google Analytics) which are set only with your consent. You can delete cookies and change their handling at any time in your browser settings.
Under the GDPR you have the right to:
To exercise these rights write to info@medicloud.ee. If you believe we have processed your data unlawfully, you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, info@aki.ee, www.aki.ee).
We keep this policy up to date with our actual practices. When we make material changes we update the date at the top of the page and, where the change concerns users of the software, we notify them in the product or by e-mail.
MediCloud OÜ · registry code 16340560
E-mail: info@medicloud.ee
Phone: +372 669 2222