Privacy Policy

Effective date: July 2026 · B3 Trinitas Media & Ventures, d/b/a BiomedDesk

1. Overview

BiomedDesk ("Service") is operated by B3 Trinitas Media & Ventures. This Privacy Policy describes how we collect, use, store, and share information when you use our Service. We are committed to handling your data responsibly.

2. Information We Collect

Account Information

When you register, we collect your name, email address, and organization name. This information is used to authenticate your account and communicate with you about the Service.

Equipment and Operational Data

We store the operational records your organization creates: equipment records, work orders, PM schedules, AEM programs, repair history, parts inventory, contracts, recall alerts, user accounts, and organization preferences. This data belongs to your organization and is used solely to provide the Service to you.

Usage Data

We collect anonymized usage metrics such as feature usage frequency and AI query counts to improve the Service. This data is not linked to individual users in analytics reporting.

Payment Information

Billing and payment processing is handled entirely by Stripe, Inc. We do not store credit card numbers, bank account numbers, or full payment details on our servers. We receive only a Stripe customer ID and subscription status from Stripe. Stripe's privacy practices are governed by Stripe's Privacy Policy.

3. Protected Health Information (PHI)

BiomedDesk does not store Protected Health Information. The Service is designed for equipment management and maintenance documentation only. Do not enter patient names, medical record numbers, diagnoses, or any other PHI into any field. Equipment serial numbers, department names, and technical fault descriptions are not PHI.

BiomedDesk is not a covered entity or business associate under HIPAA for the purposes of this platform. A Business Associate Agreement is available on request for customers who require one — contact hello@biomeddesk.com, or see our BAA page.

4. Data Storage and Security

All data is stored in Supabase, a PostgreSQL-based cloud database platform hosted on AWS infrastructure. Data is encrypted at rest and in transit using TLS 1.2+. Row-Level Security (RLS) policies ensure that each organization can only access its own data. We employ authentication tokens, role-based access control, and audit logging.

AI troubleshooting queries are processed by the Anthropic API. The symptom description and equipment context you submit are sent to Anthropic's servers for processing. You should not include PHI in AI queries. Anthropic's data handling practices are governed by Anthropic's Privacy Policy.

5. Data Sharing

We do not sell your data. We do not share your data with third parties except: (a) service providers necessary to operate the platform (Supabase for database and authentication, Netlify for hosting, Stripe for payments, Anthropic for AI troubleshooting, and Brevo for transactional email); (b) when required by law or to respond to legal process; (c) to protect the safety, rights, or property of the Company or others.

6. Data Retention

We retain your account data for as long as your account is active. If you cancel your subscription, we retain your data for 90 days to allow for account reinstatement, after which it is deleted. You may request immediate deletion at any time.

7. Your Rights

You have the right to: (a) access the personal data we hold about you; (b) correct inaccurate data; (c) request deletion of your data; (d) export your data in a machine-readable format; (e) object to certain processing activities. You can export all of your organization's data yourself at any time from Settings → Export My Data, which produces a ZIP archive of CSV files covering every module. To request deletion or exercise any other right, contact privacy@biomeddesk.com.

8. Cookies

We use only essential cookies required for authentication (session tokens). We do not use tracking cookies or third-party advertising cookies.

9. Children's Privacy

The Service is intended for use by healthcare professionals and is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or in-app notice at least 30 days before the changes take effect.

11. Contact

For privacy inquiries or data requests:
B3 Trinitas Media & Ventures
Email: privacy@biomeddesk.com