Terms & Conditions

Effective Date: 7 July 2025

Version 1.2 | Last Updated: 30 March 2026

1. Acceptance of Terms

By downloading, registering for, or using PixioDoc ("the Service") you agree to be bound by these Terms & Conditions ("Terms"). If you do not accept every provision below, do not use the Service.

The Service is provided by LM TECH LABS, LDA, a limited liability company incorporated under the laws of Portugal (NIPC: 519341023), with registered office at Estrada Nacional 221 - Poente, 54, 5225-104 Sendim, Portugal ("LM TECH LABS", "we", "us"). "PixioDoc" refers to the brand and Service operated by LM TECH LABS, LDA.

These Terms should be read in conjunction with our Privacy Policy, Data Processing Agreement (DPA), and for US-based healthcare professionals, our HIPAA Authorization. Together, these documents constitute the complete agreement between you and PixioDoc.

2. Definitions

"Application" means the PixioDoc mobile software available on iOS (14+) and Android (9+) platforms.

"Account" means the credentials you create to access the Service, including your email address and password.

"Content" means all text, images, videos, metadata, annotations, treatment notes, and other material uploaded or transmitted through the Service.

"Healthcare Professional" means a licensed clinician (dermatologist, plastic surgeon, wound care specialist, etc.), supervised medical student, or authorised healthcare facility staff member with proper credentials.

"Subscription" means any paid or free plan that allows access to the Service features, including Free, Monthly (€4.99/month), and Annual (€49.90/year) plans.

"Protected Health Information (PHI)" means individually identifiable health information as defined by HIPAA, including medical images, patient identifiers, and treatment data.

Other capitalised terms have the meanings set out in context or in applicable law.

3. Eligibility

The Service is intended exclusively for Healthcare Professionals. By creating an Account you represent and warrant that:

  • You are at least 18 years old
  • You hold the necessary professional credentials, licenses, or supervision to practice medicine or healthcare services
  • Your use will comply with all applicable laws and regulations, including but not limited to HIPAA (US) and GDPR (EU)
  • You have obtained proper patient consent before uploading any identifiable medical information
  • All information you provide during registration and use is accurate and current

4. Account Registration & Security

To use the Service, you must create an Account and provide accurate, current information.

4.1 Account Security Requirements

  • Strong Password: Minimum 8 characters with at least one uppercase letter, one number, and one special character
  • Multi-Factor Authentication (MFA): Email verification codes required for sensitive actions (password reset, email change)
  • Biometric Authentication: Optional Face ID/Touch ID for app unlock (highly recommended)
  • Session Timeout: Automatic logout after 15 minutes of inactivity for security

4.2 Account Responsibility

You are solely responsible for:

  • Maintaining the confidentiality of your Account credentials
  • All activity that occurs under your Account
  • Notifying us immediately of any unauthorised access or security breach
  • Ensuring your device is secured with a PIN, password, or biometric lock

Lost or Stolen Device: If your device is lost or stolen, change your password immediately from another device and review your Activity Log (Settings → Privacy & Security → Activity Log) to ensure no unauthorised access.

5. Description of Service

PixioDoc is a secure, HIPAA and GDPR-compliant platform that lets Healthcare Professionals capture, store, organise, track, and share medical images, videos, and related patient-progress data.

5.1 Core Features

  • Medical image and video capture using mobile device cameras
  • Secure cloud storage with end-to-end encryption
  • Patient organisation with metadata and treatment notes
  • Timeline view showing patient progress over treatment periods
  • Before/after comparison tools with interactive slider (Pro plans)
  • Annotation tools for images (text, arrows, rulers, markers)
  • Secure sharing and collaboration with other healthcare professionals (Pro plans)
  • Activity logging for compliance and audit trails

5.2 Offline Capability

You may capture images and videos offline for up to 3 days. Media is stored locally (encrypted) and automatically uploads when internet connection is restored. After 3 days offline, you must connect to the internet to continue capturing new media. Shared patients cannot be accessed while offline.

5.3 Service Availability

We strive for high availability but cannot guarantee uninterrupted service. Scheduled maintenance will be announced at least 24 hours in advance via email and in-app notification. Emergency maintenance may occur without notice.

5.4 System Requirements

  • iOS 14+ or Android 9+
  • Active internet connection for most features
  • Camera permissions for image/video capture
  • Storage space for temporary offline media

6. Professional Responsibilities

As a Healthcare Professional using PixioDoc, you agree to:

  • Obtain Valid Patient Consent: Secure written patient consent before uploading any identifiable medical images or information. Maintain consent documentation independently.
  • Legitimate Medical Use Only: Use the Service solely for legitimate medical purposes, patient care, treatment documentation, and professional collaboration.
  • Maintain Patient Confidentiality: Respect patient privacy and confidentiality at all times. Follow all applicable healthcare privacy laws and professional ethical guidelines.
  • Comply with All Regulations: Adhere to HIPAA (U.S.) and GDPR (EU) regulations, any other applicable privacy, healthcare, or professional rules in your jurisdiction.
  • Accurate Record Keeping: Maintain accurate, complete, and up-to-date patient records and treatment documentation.
  • Responsible Sharing: Only share patient information with authorised healthcare professionals who have a legitimate need to know for patient care purposes.
  • Secure Device Management: Keep your mobile devices secured with passwords or biometric locks and report lost/stolen devices immediately.

Important: PixioDoc does not obtain patient consent on your behalf. You are solely responsible for obtaining, documenting, and maintaining proper patient consent for photography, digital storage, and sharing of medical information. We recommend using written consent forms and keeping them for a minimum of 7 years.

7. Patient Data & Privacy

All Content uploaded to PixioDoc is protected with multiple layers of security:

7.1 Encryption at Rest (Data Storage)

  • Standard: AES-256 (Advanced Encryption Standard with 256-bit keys)
  • Implementation: Automatic encryption via Supabase infrastructure
  • Coverage: All patient records, medical images, videos, treatment notes, and activity logs
  • Same encryption used by: Banks, government agencies, and military

7.2 Encryption in Transit (Data Transmission)

  • Protocol: TLS 1.3 (Transport Layer Security, latest version)
  • Certificate Pinning: Additional security layer preventing man-in-the-middle attacks by verifying server authenticity
  • Perfect Forward Secrecy: Each session uses unique encryption keys
  • Coverage: Every API call between your device and our servers

7.3 Access Control

  • Row Level Security (RLS): Database-level policies ensure you can ONLY access your own patients
  • Enforcement: Database-level (not just app-level), impossible to bypass
  • Authentication: Required for all data access
  • Session Management: 15-minute automatic timeout after inactivity

7.4 Audit Logging (HIPAA Compliance)

Every action involving patient data is automatically logged:

  • Who accessed what data, when, and what they did
  • 27 activity types tracked (patient created, viewed, updated, photos uploaded, etc.)
  • Logs retained for 1 year (365 days) to comply with HIPAA requirements
  • Immutable audit trail (cannot be edited or deleted by users)
  • Accessible in Settings → Privacy & Security → Activity Log

7.5 Data Storage Location

  • Primary Region: European Union (Frankfurt, Germany)
  • Backup Location: European Union (automatically replicated within EU)
  • Data Transfer: Your data NEVER leaves the EU/EEA region
  • Subject to strict EU privacy laws and GDPR protections

7.6 Data Breach Notification

In the unlikely event of a data breach affecting your Protected Health Information (PHI), we will:

  • Notify You: Within 72 hours of discovery (GDPR requirement)
  • Method: Email to your registered address and in-app notification
  • Information Provided: Nature of breach, data affected, remediation steps, and contact information
  • Support: Credit monitoring or identity theft protection if applicable

Detailed data-processing practices are described in the PixioDoc Privacy Policy. You retain ownership of your Content but grant PixioDoc a limited licence to store, process, and transmit it solely to operate the Service.

8. Subscriptions, Payments & Trials

8.1 Subscription Plans

PixioDoc offers the following Subscription plans:

Free Plan (€0.00)

  • Up to 10 patients maximum
  • Basic patient management
  • Image and video capture
  • Standard quality storage
  • Timeline view
  • No sharing or collaboration features
  • No before/after comparison slider

Monthly Plan (€4.99/month)

  • Unlimited patients
  • Enhanced patient management
  • High-quality storage
  • Interactive before/after slider
  • Full sharing & collaboration (3 access levels: View Only, Editor, Admin)
  • Standard email support
  • Billed monthly in advance, auto-renews

Annual Plan (€49.90/year)

  • All Monthly Plan features
  • Unlimited patients
  • Premium email support
  • Priority feature requests
  • Billed annually in advance, auto-renews
  • Equivalent to €4.15/month

8.2 Payment Terms

  • Billing: Fees are billed in advance (monthly or annually depending on plan)
  • Auto-Renewal: Subscriptions automatically renew unless cancelled before renewal date
  • Non-Refundable: Fees are non-refundable except where required by law
  • Payment Processor: RevenueCat handles all payment processing
  • No Credit Card Storage: We do not store credit card information
  • Currency: All prices in Euros (€)

8.3 Cancellation

You may cancel your subscription at any time through your Account settings or the app store (iOS/Android). Upon cancellation:

  • Your subscription remains active until the end of your current billing period
  • No refunds for partial months/years
  • Your account will be downgraded to Free Plan at the end of the billing period
  • You will not be charged again unless you resubscribe

8.4 Free Tier Limitations & Enforcement

Free Plan users are limited to 10 patients maximum. When this limit is reached:

  • You cannot create new patients until you delete existing patients or upgrade to Pro
  • Existing patients remain accessible (read-only)
  • You cannot accept new shared patient invitations
  • Banner notification displayed: "You've reached the patient limit. Upgrade to Pro or delete patients to access profiles."

Subscription Expiration (Paid → Free):

  • If you had more than 10 patients on a paid plan and it expires:
    • All patient profiles remain visible but locked
    • You must upgrade or delete patients (down to 10) to regain access
    • No data is deleted automatically
  • If you had 10 or fewer patients:
    • Full access to your patients continues
    • Pro features disabled (sharing, collaboration, before/after slider)

8.5 Payment Failures & Grace Period

If a subscription renewal payment fails:

  • You will receive an email and in-app notification
  • Grace Period: 7 days to update payment method
  • Subscription remains active during grace period
  • After 7 days without payment update, subscription expires (follow expiration flow above)

9. Consent Management

9.1 User Consent (Account Creation)

Before using PixioDoc, you must accept four legal agreements:

  • Terms of Service
  • Privacy Policy
  • HIPAA Authorization (if US-based)
  • Data Processing Agreement (DPA)

We track which version you accepted and when. If policies change materially, you must re-accept the updated versions before continuing to use the Service.

9.2 Patient Consent (Your Responsibility)

You are responsible for obtaining valid patient consent before uploading any identifiable medical information to PixioDoc. Required consents include:

  • Consent to photograph/record (medical photography)
  • Consent to digital storage (cloud-based storage)
  • Consent to share (if sharing with other healthcare professionals)

Important: PixioDoc does NOT obtain patient consent on your behalf, verify you have obtained proper consent, or store patient consent forms. You must maintain consent documentation independently. We recommend using written consent forms and keeping them for a minimum of 7 years (healthcare standard).

9.3 Patient Sharing Consent Confirmation

When sharing a patient with another healthcare professional, you must check a box confirming: "I confirm I have patient consent to share this information." This confirmation is logged in your activity log for audit purposes.

10. Content Ownership & License

You retain ownership of all Content you upload to PixioDoc, including patient records, medical images, videos, and treatment notes. However, to operate the Service, you grant PixioDoc a limited, non-exclusive, royalty-free, worldwide licence to:

  • Store your Content on our secure servers
  • Process your Content to provide Service features (compression, encryption, synchronization)
  • Transmit your Content between your devices
  • Display your Content to authorised users (you and healthcare professionals you've explicitly shared with)
  • Back up your Content for disaster recovery

This licence is solely to provide and improve the Service. We will NOT:

  • Use your Content for advertising or marketing
  • Sell or share your Content with third parties
  • Access your Content except for technical support (with your permission)
  • Use your Content to train AI models

This licence ends when your Content is deleted from our systems, subject to any legal retention obligations (e.g., HIPAA audit log retention for 1 year).

11. Prohibited Conduct

You must not:

  • Upload misleading, fraudulent, or unlawful medical data
  • Share patient information without proper authorisation or consent
  • Attempt to access or disrupt another user's data or the Service infrastructure
  • Use PixioDoc for non-medical or unrelated commercial purposes
  • Violate any professional, privacy, or export-control laws
  • Reverse engineer, decompile, or attempt to extract the source code
  • Use automated tools (bots, scrapers) to access the Service without written permission from PixioDoc
  • Upload content containing viruses, malware, or malicious code
  • Interfere with security features or attempt to bypass access controls
  • Impersonate another healthcare professional or misrepresent your credentials

Violation of these terms may result in immediate suspension or termination of your Account, and we may report violations to relevant authorities.

12. Service Availability & Modifications

We strive for high availability but do not guarantee uninterrupted service. We may modify, suspend, or discontinue the Service, or update these Terms, with reasonable notice where feasible.

12.1 Scheduled Maintenance

  • Announced at least 24 hours in advance via email and in-app notification
  • Typically performed during low-usage periods (nights/weekends)
  • Duration: Usually less than 2 hours

12.2 Emergency Maintenance

May occur without notice for critical security patches or infrastructure issues. We will notify you as soon as possible.

12.3 Service Modifications

We may add, modify, or remove features at our discretion. Material changes that affect your use will be announced with at least 30 days' notice. Continued use after changes constitutes acceptance.

13. Third-Party Services

The Service integrates with the following third-party providers to operate effectively:

Supabase (Infrastructure & Database)

  • Purpose: Primary database, file storage, authentication
  • Location: European Union (Frankfurt, Germany)
  • Privacy Policy: https://supabase.com/privacy
  • Safeguards: BAA signed for HIPAA compliance, EU-only storage

RevenueCat (Payment Processing)

  • Purpose: Manage subscriptions and billing
  • Privacy Policy: https://www.revenuecat.com/privacy
  • Note: We do NOT store credit card information

Firebase Cloud Messaging (Push Notifications)

  • Purpose: Send in-app notifications for sharing and activity alerts
  • Privacy Policy: https://firebase.google.com/support/privacy
  • Safeguards: Notifications contain no PHI, only event types

ZeptoMail by Zoho (Transactional Emails)

  • Purpose: Account verification, password resets, share invitations
  • Privacy Policy: https://www.zoho.com/privacy.html
  • Safeguards: GDPR-compliant, EU servers

Each third-party service is governed by its own terms and privacy policy. PixioDoc is not responsible for their acts or omissions. All third-party providers are required to sign Business Associate Agreements (BAA) for HIPAA compliance and maintain SOC 2 or ISO 27001 certification.

14. Disclaimers

PixioDoc is provided "as is" and "as available." We disclaim all warranties—express, implied, statutory, or otherwise—including merchantability, fitness for a particular purpose, and non-infringement.

Critical Medical Disclaimer: PixioDoc does NOT provide medical advice, diagnosis, or treatment recommendations. The Service is a documentation and tracking tool only. Clinical decisions remain the sole responsibility of Healthcare Professionals. PixioDoc is not a substitute for professional medical judgment, consultation with qualified specialists, or comprehensive patient evaluation.

We do not warrant that the Service will be error-free, secure, or uninterrupted. You use the Service at your own risk.

15. Limitation of Liability

To the maximum extent permitted by law, PixioDoc and its directors, employees, suppliers, and affiliates will not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to:

  • Loss of profits, revenue, or business opportunities
  • Loss of data or information
  • Loss of goodwill or reputation
  • Business interruption
  • Medical malpractice claims arising from clinical decisions

Our aggregate liability for any claim related to the Service will not exceed the fees you paid to PixioDoc in the twelve (12) months preceding the event giving rise to liability. If you are on the Free Plan, our liability is limited to €50.

Some jurisdictions do not allow the exclusion of certain warranties or limitation of liability, so these limitations may not apply to you.

16. Indemnification

You agree to indemnify, defend, and hold harmless PixioDoc, its directors, employees, agents, and affiliates from any claim, demand, damage, loss, liability, or expense (including reasonable legal fees) arising out of or related to:

  • Your use of the Service
  • Your Content (including patient data you upload)
  • Your violation of these Terms
  • Your violation of any applicable law or regulation
  • Your violation of professional ethical guidelines
  • Your failure to obtain proper patient consent
  • Medical malpractice or professional negligence claims
  • Infringement of any third-party rights

17. Termination

Either party may terminate these Terms at any time.

17.1 Termination by You

You may delete your Account at any time: Settings → Account & Security → Delete Account

17.2 Termination by Us

We may suspend or terminate your Account immediately if you:

  • Violate these Terms
  • Engage in prohibited conduct
  • Fail to pay subscription fees
  • Pose a security or legal risk to PixioDoc or other users

17.3 Effect of Termination

Upon termination:

  • Your right to use the Service ceases immediately
  • Data Retention Schedule:
    • Immediate (Day 0): Account marked for deletion, logged out, inaccessible
    • Grace Period (Days 1-30): Data hidden but recoverable - contact support@pixiodoc.com to restore
    • Permanent Deletion (After Day 30): All Content permanently deleted (patient records, images, videos, treatment logs, annotations)
    • Activity Logs: Retained for 1 year from creation date (HIPAA requirement), then automatically deleted
  • Important: Export your data BEFORE deleting account (Settings → Export Data)

17.4 Impact on Shared Patients

  • Patients you shared with others: Access revoked immediately, they receive notification, their access to your patients is permanently removed
  • Patients shared with you: You lose access immediately, but the owner retains their data

18. Governing Law & Dispute Resolution

These Terms are governed by the laws of Portugal, excluding its conflict-of-law rules. Any dispute shall be submitted to the exclusive jurisdiction of the competent courts of Porto, Portugal, unless a mandatory forum is prescribed by applicable EU or Portuguese law.

Informal Dispute Resolution: Before initiating formal legal proceedings, we encourage you to contact us at legal@pixiodoc.com to attempt to resolve the dispute informally. We commit to good-faith efforts to resolve disputes within 60 days of receiving notice.

19. Changes to Terms

We may revise these Terms from time to time to reflect changes in our practices, technology, legal requirements, or Service features.

19.1 Notification

Material changes will be announced at least 30 days before taking effect via:

  • Email notification to your registered email address
  • Prominent in-app notice upon next login
  • Updated "Last Updated" date on this page

19.2 Acceptance

Your continued use after the effective date constitutes acceptance of the revised Terms. If you do not agree to the changes, you must stop using the Service and may delete your Account.

19.3 Version Tracking

We track which version of the Terms you accepted and when. You can view your consent history in Settings → Privacy & Security → Legal Agreements.

20. Miscellaneous

20.1 Entire Agreement

These Terms, together with the Privacy Policy, Data Processing Agreement, and HIPAA Authorization (if applicable), constitute the entire agreement between you and LM TECH LABS, LDA (trading as PixioDoc).

20.2 Severability

If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions will remain in full force and effect.

20.3 Waiver

Our failure to enforce any right or provision of these Terms will not be considered a waiver of those rights.

20.4 Assignment

You may not assign or transfer these Terms without our prior written consent. We may assign these Terms to any affiliate or in connection with a merger, acquisition, or sale of assets.

20.5 Language

These Terms are provided in English. Any translated versions are for convenience only. In the event of a conflict, the English version prevails.

21. Contact

If you have any questions about these Terms, please contact us:

LM TECH LABS, LDA
NIPC: 519341023
Estrada Nacional 221 - Poente, 54
5225-104 Sendim, Portugal
General Support: support@pixiodoc.com

Response Times: <24 hours

Related Legal Documents: