Data Privacy Framework

Last updated: August 07, 2025

1. Purpose
To outline Medello’s commitments under data protection laws and frameworks (e.g., GDPR,
CCPA).
2. Guiding Principles
– Lawfulness, fairness, transparency
– Purpose limitation
– Data minimization
– Accuracy
– Storage limitation
– Integrity and confidentiality
3. Accountability
– Regular audits, staff training, and documentation.
– Privacy-by-design approach to systems and processes.
4. International Transfers
– If transferring data abroad, use mechanisms like Standard Contractual Clauses or other
approved safeguards.
5. Third‑Party Vendors
– Conduct due diligence and require contractual privacy obligations.
6. Incident Response
– Maintain a response plan for data breaches, following applicable laws for notifications.
7. Governance
– Compliance overseen by [Privacy Officer, if applicable].
8. Updates
– Framework updates will be posted; material changes will be communicated to users.