Last Updated: December 7, 2025
This Data Protection Addendum (DPA) supplements our Privacy Policy and provides detailed information about our data protection practices, specifically addressing requirements under the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR).
This DPA applies to all personal data processed by MedZone Ltd in connection with providing our UCAT preparation platform services to users in the UK, European Economic Area (EEA), and other jurisdictions with equivalent data protection requirements.
For purposes of this DPA:
Entity Name: MedZone Ltd
Registered Address: London, United Kingdom
Data Protection Officer: dpo@medzone.co
Privacy Contact: privacy@medzone.co
UK ICO Registration: [Registration Number]
We process personal data necessary to provide our services under the Terms of Service:
We process data based on legitimate interests, balanced against user rights:
We obtain explicit consent for:
We process data to comply with legal requirements such as tax obligations, financial record-keeping, and responding to law enforcement requests.
Name, email address, account password (encrypted)
School year, UCAT test date, previous test experience, study preferences
Question attempts, answers, scores, time taken, skill mastery metrics
Login times, features accessed, session duration, device/browser information
Transaction history, subscription status (card details held by Stripe, not MedZone)
Support tickets, feedback, AI Tutor conversations
We engage the following processors who have access to personal data:
Location: United States
Purpose: Database hosting, user authentication
Safeguards: Standard Contractual Clauses, ISO 27001 certified
Location: United States
Purpose: Payment processing, subscription management
Safeguards: Standard Contractual Clauses, PCI DSS Level 1
Location: Varies
Purpose: AI Tutor functionality
Safeguards: Data minimization, anonymization where possible
Location: European Union
Purpose: Transactional and notification emails
Safeguards: GDPR compliant, EU-based infrastructure
All processors are bound by data processing agreements ensuring GDPR compliance. We conduct due diligence before engaging any processor and monitor their security practices regularly.
Some personal data may be transferred outside the UK/EEA to our processors. We ensure appropriate safeguards through:
You have the following rights under GDPR, which you can exercise at any time:
Request a copy of your personal data and information about how it's processed.
Timeline: 30 days
Correct inaccurate or incomplete personal data.
Timeline: 30 days
Request deletion of your personal data ("right to be forgotten").
Timeline: 30 days
Limit how we process your data in certain circumstances.
Timeline: 30 days
Receive your data in a structured, machine-readable format.
Timeline: 30 days
Object to processing based on legitimate interests or for direct marketing.
Timeline: Immediate for marketing; 30 days for other objections
Withdraw consent for processing at any time without affecting prior processing.
Timeline: Immediate
File a complaint with your local data protection authority (UK ICO or relevant EU DPA).
To exercise any of these rights, contact us at privacy@medzone.co with:
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Account data | Active account + 90 days | Contract |
| Practice/performance data | Active account lifetime | Contract |
| Payment records | 7 years | Legal obligation |
| Support communications | 3 years after resolution | Legitimate interest |
| Marketing consents | Until withdrawn | Consent |
| Security logs | 12 months | Legitimate interest |
After retention periods expire, data is securely deleted or anonymized beyond recovery.
We implement technical and organizational measures pursuant to Article 32 GDPR:
In the event of a personal data breach:
Special protections apply for users under 18 (UK) or 16 (most EU countries):
See our Parental Consent Statement for full details.
We use automated processing for:
These processes do not constitute "solely automated decision-making" under Article 22 GDPR as they do not produce legal effects or similarly significantly affect you. However, you may request human review of any automated assessment by contacting support.
We may update this DPA to reflect changes in data protection law, our processing activities, or best practices. Significant changes will be communicated via email with 30 days notice. Continued use after changes take effect constitutes acceptance.
Data Protection Officer
Email: dpo@medzone.co
Privacy Inquiries
Email: privacy@medzone.co
Postal Address
MedZone Ltd
London, United Kingdom
Supervisory Authority
UK Information Commissioner's Office
Website: ico.org.uk
Telephone: 0303 123 1113
This Data Protection Addendum supplements and forms part of our Privacy Policy and Terms & Conditions.