Privacy Policy
Effective Date: 11 July 2025
Version 1.2 | Last Updated: 30 March 2026
1. Introduction and Scope
PixioDoc is a mobile application designed to empower healthcare professionals with efficient tools for secure medical image tracking and patient progress monitoring. We are committed to protecting your privacy and ensuring the security of your personal and medical information in accordance with the highest standards of data protection.
PixioDoc is operated by LM TECH LABS, LDA, a company incorporated in Portugal (NIPC: 519341023), with registered office at Estrada Nacional 221 - Poente, 54, 5225-104 Sendim, Portugal.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use PixioDoc and related services. By using our application, you agree to the collection and use of information in accordance with this policy.
Geographic Scope: This policy applies to all users of PixioDoc, including healthcare professionals and patients in the United States, European Union, Switzerland, and other jurisdictions where our services are available.
Relationship to Terms: This Privacy Policy should be read in conjunction with our Terms & Conditions, which govern your use of PixioDoc. In the event of a conflict between this Privacy Policy and the Terms & Conditions, the Terms & Conditions shall prevail.
2. Definitions and Terms
For the purposes of this Privacy Policy:
- "Application" or "PixioDoc" means the mobile application and related services provided by PixioDoc
- "Personal Data" means any information relating to an identified or identifiable natural person (e.g., name, email, credentials)
- "Medical Data" means any personal data concerning health, including medical images, progress notes, treatment information, and patient identifiers
- "Healthcare Professional" means licensed medical practitioners, nurses, and other authorized healthcare providers using PixioDoc
- "Protected Health Information (PHI)" means individually identifiable health information as defined by HIPAA (patient photos, IDs, treatment data)
- "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, or deletion
- "Data Controller" means the healthcare professional who determines the purposes and means of processing personal data (you, the user)
- "Data Processor" means PixioDoc, which processes personal data on behalf of the data controller
LM TECH LABS, LDA acts as Data Controller in respect of account registration data, billing and subscription data, support communications, and app usage analytics. LM TECH LABS, LDA acts as Data Processor in respect of patient and Protected Health Information (PHI) content uploaded by Healthcare Professionals, who remain the Data Controller of such content.
3. Information We Collect
3.1 Personal Information
We collect personal information that you provide directly to us:
- Account Information: Name, email address, password (encrypted)
- Professional Credentials: Credential type (dermatologist, plastic surgeon, etc.), credential number (optional), healthcare facility affiliations
- Profile Information: Profile photo (optional), professional bio
- Billing Information: Handled by RevenueCat - we do NOT store credit card numbers or payment details
3.2 Medical Images and Data
As a healthcare application, we process medical information you upload:
- Patient Records: Patient ID (user-defined), full name, date of birth, gender, clinical notes
- Medical Images: Photos captured via app or uploaded from device gallery
- Medical Videos: Videos captured via app (max 60 seconds)
- Treatment Logs: Date, title, notes, observations, treatment plans
- Annotations: Text labels, arrows, rulers, measurements, markers added to images
- Progress Data: Before/after comparisons, treatment timelines
3.3 Technical Information
We automatically collect certain technical information when you use our application:
- Device Information: Device type, operating system version, unique device identifiers, mobile network information
- Connection Information: IP address (anonymized), general location (country/city level), timezone
- Usage Data: Features accessed, session duration, screen views
- Performance Data: Crash reports, error logs, performance metrics
- Authentication Data: Login timestamps, session tokens (encrypted), MFA verification codes
3.4 Third-Party Service Data
We receive limited information from third-party services that integrate with PixioDoc:
- Supabase (Infrastructure): Database connection logs, storage usage metrics
- RevenueCat (Payments): Subscription status, transaction IDs, purchase receipts (no credit card data)
- Firebase (Notifications): Device tokens for push notifications, delivery status
- ZeptoMail (Email): Email delivery status, open/click tracking (if enabled)
3.5 Data Storage Location
- Primary Region: European Union (Frankfurt, Germany)
- Backup Location: European Union (automatic replication within EU)
- Data Transfer: Your data NEVER leaves the EU/EEA region
- Infrastructure Provider: Supabase (EU region with BAA for HIPAA compliance)
Why This Matters: Full GDPR compliance, strong EU privacy protections, Swiss FADP compliance, no risk of access by non-EU governments, low latency for European users.
4. How We Use Your Information
We use the collected information for the following purposes:
4.1 Primary Healthcare Functions
- Medical Image Tracking: Capture, organize, and track patient medical images over time
- Progress Monitoring: Enable healthcare professionals to monitor patient progress and treatment outcomes
- Secure Sharing: Facilitate secure sharing and collaboration between healthcare professionals (Pro plans only)
- Treatment Documentation: Support comprehensive medical record keeping and documentation
- Comparison Tools: Provide before/after comparison features for visual progress tracking
- Timeline View: Display chronological patient progress over treatment periods
4.2 Application Operations
- Service Delivery: Provide, maintain, and improve our application services
- Authentication: Verify user identity and ensure secure access to medical data
- Billing: Process subscription payments via RevenueCat (we don't handle payment details directly)
- Support: Provide technical support and customer service
- Communications: Send important updates, security notifications, and service announcements
- Performance: Monitor and improve application performance and user experience
4.3 Security & Compliance
- Regulatory Compliance: Comply with HIPAA, GDPR, Swiss FADP, and other applicable healthcare regulations
- Legal Obligations: Respond to legal requests, court orders, and regulatory inquiries
- Security Monitoring: Detect and prevent fraud, abuse, and security threats
- Audit Logging: Maintain comprehensive audit trails for 1 year (HIPAA requirement)
- Compliance Audits: Conduct security audits and compliance monitoring
5. Legal Basis for Processing
Under applicable data protection laws (GDPR, Swiss FADP), we process your information based on the following legal grounds:
5.1 GDPR Legal Bases
- Consent (Article 6(1)(a) & Article 9(2)(a)): Where you have provided explicit consent for specific processing activities, particularly for processing sensitive health data
- Contract (Article 6(1)(b)): To provide the healthcare services you have requested and to fulfill our contractual obligations
- Legal Obligation (Article 6(1)(c)): To comply with healthcare regulations, court orders, and legal requirements
- Vital Interests (Article 6(1)(d) & Article 9(2)(c)): To protect the health and safety of individuals in emergency situations
- Legitimate Interests (Article 6(1)(f)): For improving healthcare outcomes, application functionality, and security (balanced against your privacy rights)
- Healthcare Services (Article 9(2)(h)): For the provision of healthcare services by healthcare professionals
5.2 Swiss FADP Compliance
- Processing is necessary for the performance of healthcare services
- Processing serves legitimate interests that outweigh privacy concerns
- Processing is required by law or regulation
- Explicit consent has been obtained where required for sensitive health data
5.3 HIPAA Compliance
For US-based healthcare professionals, we process PHI as a Business Associate under HIPAA. Our processing is covered by a Business Associate Agreement (BAA) and is limited to Treatment, Payment, and Healthcare Operations (TPO) as defined by HIPAA.
6. Data Security and Protection
We implement comprehensive, industry-leading security measures to protect your medical data:
6.1 Technical Safeguards
Encryption at Rest (Data Storage)
- Standard: AES-256 (Advanced Encryption Standard with 256-bit keys)
- Implementation: Supabase automatic encryption
- Coverage: All patient records, medical images, videos, treatment notes, activity logs
- Same encryption used by: Banks, government agencies, military for classified information
- What this means: Even if someone gained physical access to our servers, they would only see scrambled, unreadable data
Encryption in Transit (Data Transmission)
- Protocol: TLS 1.3 (Transport Layer Security, latest version)
- Certificate Pinning: Prevents man-in-the-middle attacks by verifying server authenticity
- Perfect Forward Secrecy: Each session uses unique encryption keys
- Coverage: Every API call between your device and our servers
- What this means: Like sending a sealed, tamper-proof envelope that only the intended recipient can open
How Certificate Pinning Works
- Your app knows our exact certificate fingerprint
- On connection, app verifies server certificate matches our fingerprint
- If match → Connection proceeds (secure communication)
- If no match → Connection blocked immediately (prevents imposter servers)
- Row Level Security (RLS): PostgreSQL database-level policies ensure you can ONLY access your own patients - enforced by the database itself, impossible to bypass even with direct database access
- Multi-Factor Authentication (MFA): Email verification codes required for sensitive actions (password reset, email change)
- Biometric Authentication: Optional Face ID/Touch ID for app unlock (device-level security)
- Session Management: Automatic 15-minute timeout, secure session tokens (httpOnly cookies), immediate invalidation on logout
- API Security: Advanced authentication and authorization for all data access, rate limiting to prevent abuse
- Regular Updates: Continuous monitoring and patching of security vulnerabilities, dependency updates applied immediately
6.2 Administrative Safeguards
Comprehensive Audit Logging (HIPAA Compliance)
Every action involving patient data is automatically logged:
- 27 Activity Types Tracked: Authentication (sign up, sign in, sign out, profile updated, password changed, email changed), Patient Management (created, viewed, updated, deleted, profile photo uploaded/deleted), Treatment Logs (created, updated, deleted), Media (photos/videos uploaded, viewed, deleted), Sharing (patient shared, share accepted, share rejected, share revoked, access level updated), Progress Tracking (before/after comparison viewed, mode changed), Data Access (data exported, account deleted)
- Log Contents: User ID and email, timestamp (UTC with millisecond precision), activity type, patient ID, IP address (optional), device type
- Retention: 1 year (365 days) to comply with HIPAA, then automatically deleted daily at 2 AM UTC
- Immutable: Cannot be edited or deleted by users (HIPAA requirement)
- Access: View in Settings → Privacy & Security → Activity Log
- Exportable: Settings → Export Data includes all activity logs
- Access Controls: Role-based access limitations to medical data (Owner, Editor, View Only for shared patients)
- Staff Training: Regular security awareness training for all PixioDoc personnel
- Incident Response: Established procedures for security breach response, including notification within 72 hours
- Business Associate Agreements: Contractual protections with all third-party vendors (Supabase, RevenueCat, Firebase, ZeptoMail)
- Compliance Monitoring: Regular audits and compliance reviews
6.3 Physical Safeguards
- Secure Data Centers: Medical-grade physical security for data storage facilities (managed by Supabase in EU region)
- Device Security: Secure authentication and data protection on mobile devices (biometric locks recommended)
- Backup and Recovery: Secure backup systems with encrypted storage, automatic replication within EU
- Disaster Recovery: Comprehensive disaster recovery and business continuity planning
6.4 Security Monitoring & Incident Response
24/7 Automated Monitoring
- Unauthorized access attempts (alerts if >50 attempts/hour)
- File upload/download failures (alerts if >5% failure rate)
- Query performance (alerts if >2 seconds)
- Certificate expiration (alerts 90 days before)
- Database errors and anomalies
- API failures and timeouts
Response Times: Critical alerts <1 hour | High priority <4 hours | Medium priority <24 hours
6.5 Data Breach Notification
In the unlikely event of a data breach affecting your personal or medical information, we will:
- Rapid Detection: 24/7 automated security monitoring with real-time alerts for suspicious activity
- Timely Notification: Within 72 hours of discovery (GDPR requirement) via email and in-app notification
- Information Provided: Nature of breach, data affected, number of records, potential consequences, remediation steps, mitigation measures, contact point
- Regulatory Reporting: Notify Swiss FDPIC, EU DPAs, and comply with HIPAA breach notification requirements
- Support Services: Credit monitoring, identity theft protection (if applicable), dedicated support email
Prevention Measures: Regular security audits (quarterly), penetration testing (annual), security training, incident response drills, third-party assessments
Historical Record: Last Security Audit: November 8, 2025 | Next Scheduled Audit: February 8, 2026 | Data Breaches to Date: Zero (0)
7. Information Sharing and Disclosure
We do not sell, trade, or otherwise transfer your personal or medical information to third parties except in the following circumstances:
7.1 Healthcare Collaboration (Your Authorization)
- Authorized Sharing: With healthcare professionals you explicitly authorize for collaboration (Pro plans only)
- Access Levels: View Only (view patient data only), Editor (view and add photos, cannot delete), Admin (full access except ownership transfer)
- Treatment Purposes: To facilitate patient care and treatment coordination
- Continuity of Care: To ensure seamless healthcare delivery across providers
- Audit Trail: All sharing activity logged in activity logs
- Consent Confirmation: You must confirm patient consent before sharing
7.2 Third-Party Service Providers
We share limited data with the following trusted service providers who help us operate PixioDoc:
Supabase (Infrastructure & Database)
- Data Shared: All patient data, user accounts, medical images, treatment logs
- Purpose: Primary database, file storage, authentication
- Location: European Union (Frankfurt, Germany)
- Safeguards: BAA signed for HIPAA compliance, end-to-end encryption, EU-only storage, SOC 2 Type II certified, ISO 27001 certified
- Privacy Policy: https://supabase.com/privacy
RevenueCat (Payment Processing)
- Data Shared: Email, subscription status, transaction IDs (no credit card information)
- Purpose: Manage subscriptions and billing
- Safeguards: PCI-DSS compliant, GDPR-compliant, we do NOT receive or store credit card information
- Privacy Policy: https://www.revenuecat.com/privacy
Firebase Cloud Messaging (Push Notifications)
- Data Shared: Device token, user ID (no PHI in notifications)
- Purpose: Send push notifications for sharing and activity alerts
- Safeguards: Notifications contain NO patient data, only event types ("Patient shared with you", "New photos uploaded")
- Privacy Policy: https://firebase.google.com/support/privacy
ZeptoMail by Zoho (Transactional Emails)
- Data Shared: Email address, name
- Purpose: Account verification, password resets, share invitations
- Safeguards: GDPR-compliant, EU servers, emails contain NO PHI
- Privacy Policy: https://www.zoho.com/privacy.html
Third-Party Requirements: All service providers are required to sign Business Associate Agreements (BAA) for HIPAA compliance, maintain SOC 2 or ISO 27001 certification, use EU servers for data processing (where applicable), and comply with GDPR and Swiss FADP.
7.3 Legal and Regulatory Requirements
- Legal Compliance: To comply with court orders, subpoenas, or legal obligations
- Regulatory Reporting: To meet healthcare regulatory reporting requirements
- Public Health: To protect public health and safety as required by law
- Law Enforcement: To assist law enforcement in legitimate investigations (with valid legal process)
- Vital Interests: To protect the vital interests of individuals in emergency situations
7.4 What We Do NOT Do
- ❌ Sell your data to third parties
- ❌ Use your data for advertising or marketing
- ❌ Share your data with anyone without your explicit permission (except shared patients you authorize)
- ❌ Access your data for any reason other than technical support (with your permission)
- ❌ Track your location
- ❌ Access your contacts, calendar, or other personal data
- ❌ Use third-party analytics that identify individuals
- ❌ Train AI models on your patient data
8. International Data Transfers
Primary Data Location: All data is stored in the European Union (Frankfurt, Germany) and NEVER leaves the EU/EEA region. This eliminates most international data transfer concerns.
When limited data transfers occur (e.g., for payment processing via RevenueCat), we ensure adequate protection through:
8.1 GDPR Compliance
- Adequacy Decisions: Transfers only to countries with adequate data protection as determined by EU Commission
- Standard Contractual Clauses (SCCs): EU-approved contracts for international transfers
- Binding Corporate Rules: Internal data protection standards for international operations
- Explicit Consent: Where required for specific international transfers
8.2 Swiss FADP Compliance
- Adequate Protection: Ensuring recipient countries provide adequate data protection equivalent to Swiss standards
- Contractual Safeguards: Agreements ensuring Swiss-equivalent data protection
- Consent Mechanisms: Explicit consent for transfers where required
8.3 Data Processing Agreement
For healthcare organizations requiring a formal Data Processing Agreement (DPA), we provide a comprehensive DPA that includes:
- Scope and purpose of data processing
- Types of personal data processed and categories of data subjects
- Security measures and safeguards
- Sub-processor arrangements (Supabase, RevenueCat, etc.)
- Data subject rights procedures
- Assistance with data protection impact assessments
- Notification of personal data breaches
- Deletion and return of data procedures
How to Obtain DPA: Email support@pixiodoc.com with subject "DPA Request" and provide your organization name and contact details. We will send an executed DPA within 5 business days.
9. Data Retention and Deletion
We retain your information according to the following policies:
9.1 Active Data (While Account is Active)
- Patient Records: Retained indefinitely while your account is active
- Medical Images & Videos: Retained indefinitely while your account is active
- Treatment Logs: Retained indefinitely while your account is active
- Activity Logs: Retained for 1 year from creation date (HIPAA requirement), then automatically deleted
9.2 Deleted Data
- Soft Delete Period: When you delete a patient, it's hidden (not permanently deleted) for 30 days
- Recovery Window: You can restore deleted patients within 30 days by contacting support@pixiodoc.com
- Permanent Deletion: After 30 days, deleted patients are cryptographically erased and cannot be recovered
- Activity Log Deletion: Automatically deleted after 1 year via scheduled job (runs daily at 2 AM UTC)
9.3 Account Deletion
When you delete your account (Settings → Account & Security → Delete Account):
- Immediate (Day 0): Account marked for deletion, logged out, account inaccessible
- Grace Period (Days 1-30): Data hidden but recoverable - contact support@pixiodoc.com to restore
- Permanent Deletion (After Day 30):
- All patient records permanently deleted
- All medical images and videos permanently deleted
- All treatment logs permanently deleted
- All activity logs permanently deleted
- Account removed from database
- Cannot be undone
Important: Export your data BEFORE deleting account (Settings → Export Data)
9.4 Impact on Shared Patients
- Patients you shared: Others lose access immediately, receive notification
- Patients shared with you: You lose access, but owner keeps their data
9.5 Subscription Expiration (Unpaid Account)
- Data NOT deleted automatically when subscription expires
- Account becomes read-only after 30 days of non-payment
- Data retained for 120 days to allow reactivation
- After 120 days: Email notification sent, then deletion process begins
10. Your Rights and Choices
You have the following rights regarding your information under GDPR, Swiss FADP, and HIPAA:
10.1 Access and Portability
Data Export Functionality
You can export ALL your data anytime: Settings → Privacy & Security → Export Data
What's Included:
- Patient Records (JSON format with all metadata)
- Medical Images (JPEG, original quality)
- Medical Videos (MP4/MOV, original quality)
- Treatment Logs (JSON format with notes, dates)
- Annotations (JSON format with coordinates, colors)
- Activity Logs (CSV format, all 27 activity types)
- User Profile (JSON format)
- Share Relationships (JSON showing who has access)
Format: ZIP archive with organized folder structure (patient → logs → media), JSON for structured data, README.txt explaining file structure
Process: Request export → Processing (few minutes) → Download link emailed → Link expires after 7 days → No limit on export frequency
- Data Access: Right to access and review your personal and medical information anytime in the app
- Data Portability: Right to receive your data in a portable format (JSON, CSV, original files)
- Data Transparency: Clear information about how your data is processed
- Account Dashboard: Self-service access to your data and privacy settings
10.2 Control and Correction
- Data Correction: Right to request corrections to inaccurate information (Settings → Edit Profile, Edit Patient)
- Sharing Controls: Granular control over medical data sharing permissions (3 access levels: View Only, Editor, Admin)
- Consent Management: Ability to modify or withdraw consent for data processing
- Preference Management: Control over communications and notifications (Settings → Notifications)
- Biometric Settings: Enable/disable Face ID/Touch ID for app unlock
10.3 Deletion and Restriction
- Data Deletion: Right to request deletion of your account and associated data (Settings → Delete Account)
- Processing Restriction: Right to limit how your data is processed
- Objection Rights: Right to object to certain types of data processing
- Complaint Procedures: Right to lodge a complaint with supervisory authority (Swiss FDPIC, EU DPAs)
10.4 HIPAA Rights (US Users)
- Access to PHI: Right to access your Protected Health Information
- Accounting of Disclosures: Right to receive an accounting of PHI disclosures (activity logs)
- Request Restrictions: Right to request restrictions on uses and disclosures of PHI
- Confidential Communications: Right to request confidential communications
11. Children's Privacy
PixioDoc is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@pixiodoc.com. If we become aware that we have collected personal information from a child under 18 without verification of parental consent, we will take steps to remove that information from our systems immediately.
Note: Healthcare professionals may document treatment of minor patients with proper parental/guardian consent. This is distinct from children using the application themselves.
12. Cookies and Tracking Technologies
PixioDoc uses minimal tracking technologies:
12.1 Essential Cookies
- Authentication: Secure session management and user authentication (httpOnly cookies, encrypted session tokens)
- Security: Protection against security threats and unauthorized access (CSRF tokens, rate limiting)
- Functionality: Core application features and user preferences
- Performance: Application performance monitoring and optimization (error tracking, crash reports)
12.2 Optional Tracking
- Analytics: Application usage analytics (with consent) - anonymized and aggregated only
- Preferences: User interface and preference settings
- Communications: Email and notification preferences
- Opt-out: Easy opt-out mechanisms for non-essential tracking (Settings → Privacy)
12.3 What We Do NOT Track
- ❌ Location data (GPS, precise location)
- ❌ Contacts or calendar
- ❌ Browsing history outside the app
- ❌ Third-party advertising trackers
- ❌ Social media tracking pixels
- ❌ Cross-site tracking
13. Compliance Frameworks
13.1 HIPAA Compliance
PixioDoc is fully compliant with the Health Insurance Portability and Accountability Act (HIPAA). We implement appropriate administrative, physical, and technical safeguards to protect your Protected Health Information (PHI) in accordance with HIPAA requirements.
HIPAA Safeguards Met:
- ✅ Encryption at rest (AES-256) and in transit (TLS 1.3)
- ✅ Access controls (Row Level Security, authentication)
- ✅ Audit logging (complete activity trail for 1 year)
- ✅ Automatic session timeout (15 minutes)
- ✅ Data backup and recovery procedures
- ✅ Business Associate Agreement (BAA) with Supabase
- ✅ Breach notification procedures (72 hours)
- ✅ Employee training and security policies
Business Associate Agreement: Available upon request for covered entities. Email support@pixiodoc.com with subject "BAA Request"
13.2 GDPR Compliance
For users in the European Union, we comply with the General Data Protection Regulation (GDPR). We implement privacy by design principles, provide comprehensive user rights, and ensure lawful bases for all data processing activities.
GDPR Principles:
- ✅ Lawfulness, fairness, and transparency
- ✅ Purpose limitation (healthcare services only)
- ✅ Data minimization (only essential data collected)
- ✅ Accuracy (users can correct data)
- ✅ Storage limitation (1 year activity logs, 30 days soft delete)
- ✅ Integrity and confidentiality (AES-256, TLS 1.3)
- ✅ Accountability (audit logs, DPA available)
Data Processing Agreement: Email support@pixiodoc.com with subject "DPA Request" - executed DPA sent within 5 business days
13.3 Swiss FADP Compliance
For users in Switzerland, we comply with the Swiss Federal Act on Data Protection (FADP). We ensure adequate protection for Swiss residents' personal data and provide equivalent rights to those under GDPR.
Swiss FADP Requirements Met:
- ✅ Data minimization (only necessary data collected)
- ✅ Purpose limitation (healthcare documentation only)
- ✅ EU data hosting (no cross-border transfer)
- ✅ Security measures (encryption, access controls)
- ✅ Transparency (clear privacy policy)
- ✅ Data subject rights (access, correction, deletion)
13.4 SOC 2 Controls Implemented
We implement SOC 2 Type II controls for:
- Security (access controls, encryption, monitoring)
- Availability (uptime, disaster recovery)
- Processing Integrity (data accuracy, error handling)
- Confidentiality (data protection, non-disclosure)
- Privacy (GDPR/HIPAA compliance, user rights)
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or Service features.
14.1 Notification Methods
Material changes will be announced at least 30 days before taking effect via:
- Email notification: Direct notification to your registered email address
- Application notice: Prominent notice within the PixioDoc application upon next login
- Website posting: Updated policy posted on our website with revision date
- Version tracking: "Last Updated" date displayed prominently
14.2 Your Choices
Your continued use of the Service after the effective date constitutes acceptance of the revised Privacy Policy. If you do not agree to the changes, you must stop using the Service and may delete your Account.
14.3 Review Recommendation
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. You can view your consent history in Settings → Privacy & Security → Legal Agreements.
15. Contact Information
If you have any questions about this Privacy Policy, our privacy practices, or wish to exercise your privacy rights, please contact us:
PixioDoc Privacy Team
LM TECH LABS, LDA
NIPC: 519341023
Estrada Nacional 221 - Poente, 54
5225-104 Sendim, Portugal
General Support: support@pixiodoc.com
Response Times: <24 hours
Supervisory Authorities (for complaints):
• Swiss users: Swiss Federal Data Protection and Information Commissioner (FDPIC)
• EU users: You may contact your national data protection authority, and in particular the Comissão Nacional de Proteção de Dados (CNPD) in Portugal (www.cnpd.pt), where LM TECH LABS, LDA is established.
Related Legal Documents:
- Terms & Conditions - Legal terms for using PixioDoc
- Data Processing Agreement (DPA) - GDPR-compliant data processing terms
- HIPAA Authorization - For US-based healthcare professionals