Mediclad

Statement on non-storage of patient data

This service displays DICOM radiographs in your browser. It is designed not to store patient data on the server. Here we explain what happens to your file and what we do keep.

What happens when you upload a file

  1. The file travels to the server over an encrypted connection (HTTPS).
  2. The server reads only the file header (the first 4 MB) to check that it is DICOM and to build the study card. It does not decode or store the image pixels.
  3. While the request lasts, PHP keeps the file in the system temporary folder and deletes it automatically when the request ends. Our code does not copy or move it anywhere else.
  4. The study card (name, ID, dates, equipment, etc.) goes back to your browser in the same response and is not stored.
  5. The image is drawn in your browser from the file on your own device. The JPG download is also generated in your browser.
  6. If the file arrives from an authorized third-party system (integration API, with its own key), it goes through the same process: it is not stored, and the study card is sent back to whoever requested it in the same response.

What we do keep

Your account
Email and whether you have confirmed it, password (only its encrypted hash), plan and validity, date you accepted the consents, sign-up date and last sign-in.
Integration API keys
For each key: the name of who uses it, their contact email, the key's irreversible fingerprint (not the key itself), when it was created, who created it and when it was last used. The full key is only shown once, when it is created; we do not keep it.
Email links
When you ask to recover your password or confirm your email we keep the irreversible fingerprint of the link code, when it was requested and when it expires. The link cannot be rebuilt from that fingerprint. They are deleted after 7 days or when you close your account.
Query counter
To apply the daily limit we keep the day, an irreversible code of who is querying (your account id, or for people without an account a code derived from the IP address, not the IP itself) and an irreversible code of the study identifier. That code cannot be used to recover the study or the patient. It is deleted automatically after 48 hours (no account) or 35 days (with an account).
Sign-in attempts
A code derived from the IP and the time, to stop repeated sign-in attempts. A 15-minute window is used and expired records are deleted automatically.
Recorded payments
Date, amount, method and reference of each payment (those the team records and those Wompi confirms, with the transaction identifier), and until when it covers. They are kept for accounting even if you delete your account (then without your email). They carry no patient data or card data.
Payment orders
When you press "Pay" an order is created with your account, the plan, the amount and our own reference, so the payment can be credited when Wompi confirms it.
Administration changes
Account creation, plan and settings changes, blocks, with date and who made them. No patient data.

What we do not keep on our server

Technical logs and cookies

Email and online payments

Deleting your account

Google Drive (optional)

What this statement is not

It describes how the service works. It is not a certification or a guarantee of compliance with HIPAA, GDPR or local laws. If your organization must comply with any regulation, review this document with your advisor. The service is for viewing only: it is not a diagnosis and does not replace a certified diagnostic viewer.

Questions about this statement: desarrollo@gruponetblu.com
Version 6, September 27, 2026.