Legal
Terms of Service & Data Processing Agreement
Terms of Service
1Acceptance of Terms
By accessing or using the MedRAG service (the "Service"), including the API, web portal, MCP server, and any related tools or documentation, you ("Customer") agree to be bound by these Terms of Service ("Terms"). If you do not agree, you must not use the Service.
2Definitions
- "Provider"
- Rivux EOOD, a company registered in the Republic of Bulgaria.
- "Customer"
- Any individual or entity that accesses or uses the Service.
- "Service"
- The MedRAG platform, including the REST API, web portal, MCP server, and all associated infrastructure and documentation.
- "Customer Data"
- Any data, documents, or content uploaded or submitted to the Service by the Customer.
- "Personal Data"
- As defined in Regulation (EU) 2016/679 (GDPR).
3Service Description
MedRAG is a software-as-a-service platform providing retrieval-augmented generation over healthcare datasets. The Service enables semantic search, document ingestion, and knowledge base management via API and web interface.
4Medical Device Disclaimer
Not a medical deviceThe Service is NOT a registered medical device under Regulation (EU) 2017/745 (Medical Device Regulation) or any other applicable medical device legislation. The Service is not intended for use in clinical decision support, medical diagnosis, treatment planning, or any other clinical purpose.
The Customer acknowledges that the Service shall not be used as a substitute for professional medical judgment. The Provider assumes no responsibility for any clinical decisions made based on outputs of the Service.
5No Warranty
The Service is provided on an "AS IS" and "AS AVAILABLE" basis without warranties of any kind, whether express, implied, or statutory. The Provider makes no representations regarding the accuracy, completeness, reliability, or correctness of any information or results provided by the Service.
The Provider expressly disclaims all warranties, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
6Limitation of Liability
To the maximum extent permitted by applicable law, Rivux EOOD, its directors, employees, agents, or affiliates shall not be liable for any direct, indirect, incidental, special, consequential, punitive, or exemplary damages, including damages for loss of profits, goodwill, data, or business opportunities, arising out of or in connection with the use or inability to use the Service, regardless of the theory of liability, even if the Provider has been advised of the possibility of such damages.
7Pricing & Billing
The Provider reserves the right to modify pricing at any time. Price changes shall take effect at the end of the current billing cycle. The Provider shall notify affected Customers of any price changes via email at least thirty (30) days prior to the change taking effect. Continued use of the Service after a price change constitutes acceptance of the new pricing.
8Service Termination
The Provider may suspend, discontinue, or terminate the Service at any time and for any reason. The Provider shall not be liable for any losses incurred by the Customer as a result of such suspension or termination. Upon termination, the Customer's right to access the Service ceases immediately.
The Customer may export their data at any time via the API prior to termination. After account closure, Customer Data will be deleted within thirty (30) days.
9Customer Obligations
The Customer agrees to:
- Use the Service in compliance with all applicable laws and regulations;
- Maintain the confidentiality of their account credentials and API keys;
- Not reverse-engineer, decompile, or disassemble any part of the Service;
- Not use the Service to store or transmit unlawful, infringing, or harmful content;
- Not exceed usage limits or circumvent access controls;
- Not resell or sublicense access to the Service without prior written consent;
- Ensure that any Personal Data uploaded complies with GDPR.
10Intellectual Property
All intellectual property rights in the Service remain the exclusive property of Rivux EOOD. The Customer retains ownership of their Customer Data. These Terms grant no rights to the Provider's intellectual property beyond the limited right to use the Service as intended.
11Governing Law & Jurisdiction
These Terms shall be governed by and construed in accordance with the laws of the Republic of Bulgaria. Any disputes arising out of or relating to these Terms shall be subject to the exclusive jurisdiction of the competent courts in Sofia, Bulgaria.
12Amendments
The Provider reserves the right to modify these Terms at any time. Changes will be posted with an updated revision date. For material changes, the Provider will notify Customers via email at least fifteen (15) days prior to the change taking effect.
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Rivux EOOD ("Processor") and the Customer ("Controller") and governs the processing of Personal Data in connection with the Service.
1Scope & Roles
The Customer acts as the Data Controller determining the purposes and means of processing. The Provider acts as the Data Processor processing Personal Data solely on behalf of and under the instructions of the Controller.
2Subject Matter & Duration
| Element | Description |
|---|---|
| Purpose of processing | Providing the MedRAG Service: storing, indexing, embedding, and retrieving Customer Data |
| Duration | For the term of the Service agreement, plus 30 days for deletion |
| Categories of data subjects | Determined by Customer (may include patients, healthcare professionals, research subjects) |
| Types of Personal Data | Determined by Customer (may include clinical text, anonymised health records, medical literature extracts) |
3Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, including transfers to third countries (none apply — see Section 6);
- Ensure that persons authorised to process Personal Data are bound by confidentiality obligations;
- Implement appropriate technical and organisational measures pursuant to Article 32 GDPR, including:
- Encryption at rest (LUKS full-disk encryption on all servers)
- Encryption in transit (TLS 1.3 for all external connections)
- Network isolation (private vSwitch between servers, no public exposure of databases)
- Access control (API key authentication, row-level security per tenant)
- Automated backups with encrypted storage
- Monitoring and anomaly detection (Prometheus + Grafana)
- Not engage another processor without prior written authorisation from the Controller (see Section 5);
- Assist the Controller in responding to data subject requests (access, rectification, erasure, portability);
- Delete or return all Personal Data upon termination of the Service, at the Controller's choice, and delete existing copies within 30 days unless EU/member state law requires storage;
- Make available all information necessary to demonstrate compliance and allow for audits;
- Immediately inform the Controller if an instruction infringes GDPR or other EU/member state data protection law.
4Data Breach Notification
The Processor shall notify the Controller without undue delay, and no later than 48 hours, after becoming aware of a Personal Data breach. The notification shall include:
- The nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned;
- The likely consequences of the breach;
- The measures taken or proposed to address the breach.
5Sub-Processors
The Controller provides general authorisation for the following sub-processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure hosting (cloud servers, dedicated servers, storage, network) | Germany (Falkenstein, Nuremberg) |
The Processor shall:
- Inform the Controller of any intended addition or replacement of sub-processors, providing an opportunity to object;
- Ensure sub-processors are bound by equivalent data protection obligations via contract;
- Remain fully liable for the acts and omissions of sub-processors.
See our Sub-Processor List for the current register.
5aThird-Party Controllers
The following parties receive limited Personal Data as independent data controllers for their own purposes:
| Third Party | Purpose | Data Shared | Location |
|---|---|---|---|
| Mollie B.V. | Payment processing (mandates, recurring billing, refunds) | Customer name, email, payment details | Netherlands (Amsterdam) |
Mollie acts as an independent data controller for payment transactions, not as a sub-processor. Mollie determines its own purposes and means of processing payment data in accordance with PSD2 and applicable financial regulations. Mollie's privacy policy: mollie.com/privacy
6International Transfers
No Personal Data is transferred outside the European Economic Area (EEA). All infrastructure is hosted exclusively within Germany by Hetzner Online GmbH, a German company. No US-based cloud providers or sub-processors are used.
The Processor is a Bulgarian entity (EU member state). Hetzner is a German entity. All data remains within EU jurisdiction at all times.
7Technical & Organisational Measures (Annex)
| Measure | Implementation |
|---|---|
| Encryption at rest | LUKS full-disk encryption on all server volumes |
| Encryption in transit | TLS 1.3 via Caddy reverse proxy; internal traffic over private network |
| Access control | API key per tenant, bcrypt-hashed; row-level security in PostgreSQL |
| Tenant isolation | Logical multi-tenancy with RLS; all queries scoped to tenant_id |
| Network security | UFW firewall; private vSwitch for inter-server communication; no public DB exposure |
| Backup | Daily encrypted PostgreSQL backups; off-host sync to separate storage |
| Monitoring | Prometheus metrics, Grafana alerting, structured logging via Loki |
| Data minimisation | Embeddings are vector representations only; original text stored separately with access controls |
| Deletion | Customer can delete documents/knowledge bases via API; full account purge within 30 days of termination |
8Audits
The Controller may, upon reasonable notice (minimum 30 days), audit the Processor's compliance with this DPA. Audits shall:
- Be conducted during normal business hours;
- Not unreasonably interfere with the Processor's operations;
- Be at the Controller's expense unless a breach is found.
Alternatively, the Controller may accept third-party audit reports or certifications as evidence of compliance.
9Governing Law
This DPA shall be governed by the laws of the Republic of Bulgaria. To the extent not addressed herein, the provisions of Regulation (EU) 2016/679 shall prevail.
10Contact
For data protection inquiries:
Rivux EOOD
Email: admin@medrag.eu
Subject line: "DPA Inquiry — [Customer Name]"
Acceptance
This DPA is accepted electronically upon Customer's acceptance of the Terms of Service during account registration. The acceptance timestamp and version are recorded in the Customer's account record.