Skip to main content
Legal

Privacy policy

What we collect, why, how long we keep it, and the rights you have over it. We minimize data on purpose — most analytics never leave your tenant.

Effective: 2026-01-15Version: 2026.1Format: Plain-language summary + full text

Plain-language summary

Oncominder is a B2B platform sold to healthcare organizations. The data inside the platform — patient records, study data, audit logs — belongs to the organization that operates the tenant, not to us. We process it as their service provider under a Business Associate Agreement (BAA) and a Data Processing Agreement (DPA), and we never sell or share it.

For our public marketing site, we collect only the minimum we need to run it: page views (no third-party ad networks), the form submissions you intentionally send us, and basic server logs for security and uptime. That's it.

1. Who we are

Oncominder, Inc. is a Delaware corporation headquartered in San Francisco, California, with EU operations in Berlin, Germany. For privacy questions, write to privacy@oncominder.com. EU residents may also contact our Data Protection Officer at the same address.

2. What we collect — and why

2.1 Inside the platform (you are a customer's user)

We process the data your organization stores in Oncominder strictly under their instructions and the BAA/DPA between us and them. We do not use this data for any other purpose. If you want a copy of your record, a correction, or deletion, contact your organization first — they control it.

2.2 Marketing site (you are a visitor)

  • Page views for aggregate traffic stats, retained 90 days. No third-party ad pixels.
  • Form submissions (demo requests, contact) so we can reply. Stored in our CRM.
  • Server logs (IP, user-agent, referrer) for security and uptime, retained 30 days.
  • Cookies: a single first-party session cookie; no advertising cookies.

3. Legal bases (GDPR)

  • Customer data inside the platform: Processed under contract with the customer (Art. 28).
  • Form submissions: Legitimate interest in responding to your inquiry and contractual necessity if you become a customer.
  • Server logs: Legitimate interest in operating the service securely.

4. Sharing

We share data only with subprocessors that need it to run the service (hosting, email delivery, CRM). The current list and their roles are in our trust center; we publish 30 days' notice for any change.

5. Your rights

You have the right to access, correct, port, and delete your personal data. For EU residents, you also have the right to object to processing and to lodge a complaint with your supervisory authority. Email privacy@oncominder.com and we'll respond within 30 days.

6. International transfers

Customers can choose US, EU, or private-cloud data residency. Where we transfer data across borders, we rely on the Standard Contractual Clauses and (for the US) the EU-US Data Privacy Framework.

7. Security

Encryption at rest (AES-256) and in transit (TLS 1.3), per-tenant key isolation on Enterprise, full audit trails, and continuous third-party security reviews. See the security page for details.

8. Changes to this policy

Material changes will be announced at least 30 days before they take effect, both on this page and via email to designated tenant admins.