Privacy Policy
Huniverse Global Co., Ltd. ("we", "us", or "our") is committed to protecting your privacy
and the confidentiality of your data.
This Privacy Policy explains how personal data is collected, used, stored, shared, and
protected in compliance with the EU General Data Protection Regulation (GDPR, Regulation
(EU) 2016/679) and other applicable data protection laws.
This Privacy Policy explains how we collect, use, store, share, and protect personal data
when users access or use our services, websites, and platforms (collectively, the
"Services").
1. Introduction
Huniverse Global Co., Ltd. ("Huniverse Global", "we", "us", "our") is committed to protecting your privacy and personal data.
This Privacy Policy explains how we collect, use, share, and protect your information when you visit our website at www.medipencil.com (the “Website”), contact us or request
information about our products and services, express interest in or evaluate our SaaS platform (the “Platform”), or when you are in contact with us for any other business purpose.
We will treat your personal data confidentially and in compliance with statutory data protection regulations, in particular, the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), and other applicable data protection laws.
- We act as a data controller for personal data we process about you for the operation of this website and the provision of the services offered on this website to our customers
- When you use our Platform as an end user, we instead act as a data processor
- The service provider acts as the Data Controller for professional user account data and service administration
- Where patient data is processed on behalf of healthcare providers, the service provider acts as a Data Processor
- Only the minimum personal data necessary is processed for clearly defined purposes
- Patient data, audio data, and text data are not used to train general-purpose or large language models
- No solely automated decision-making producing legal or similarly significant effects is carried out
2. Contact information
Huniverse Global Co., Ltd. is registered in South Korea with address 9th floor, 25 Wangsan-ro, Dongdaemun-gu, Seoul, Republic of South Korea
You can contact us via email: contact@medipencil.com
Representative
We value your privacy and your rights
as a data subject and have therefore appointed Prighter Group with its local
partners as our privacy representative and your point of contact
for the
following regions:
Prighter gives you an easy way to
exercise your privacy-related rights (e.g. requests to access or erase personal
data). If you want to contact us via our representative, Prighter or make use
of your data subject rights, please visit the following website: https://app.prighter.com/portal/13487768251
3. Personal data we collect
We collect and process personal data
only to the extent necessary to provide, secure and improve MediPencil and to
comply with applicable legal obligations.
The personal data we process depends
on how you use MediPencil and may include the following:
Account and professional information
When you create and use a MediPencil
account, we may collect name, email address, telephone number, hospital or
organisation, department and professional position, user ID and account
credentials, and information you provide when contacting us for support.
Technical and usage information
When you use MediPencil, we may
automatically collect information necessary to operate, secure and maintain the
service, including IP address, device and browser information,
access dates and
times, log records, service usage information, and records relating to security
incidents, misuse or unauthorized access.
We use this information for service
operation, security, troubleshooting, fraud and abuse prevention, and service
improvement.
Communications and marketing
information
If you contact us, register for an
event, request information, or communicate with us, we may process your name,
contact details, organisation, professional information and the
content of your
communication.
Where you have provided the required
consent, we may also process your contact information to send marketing
communications, product updates, event invitations and other information about
MediPencil.
You may withdraw your consent or opt
out of marketing communications at any time.
Special category data
Healthcare-related information may
constitute special categories of personal data, including health data, under
Article 9 of the GDPR. MediPencil processes such information
only to provide the requested clinical documentation service and in accordance
with the applicable legal basis and instructions of the
relevant healthcare
professional or organisation.
Where MediPencil processes patient or
other health data on behalf of a healthcare professional or healthcare
organisation, the relevant healthcare professional or organisation is generally
the data controller and MediPencil acts as a data processor. The respective
roles and responsibilities may be further defined in the applicable agreement
between the
parties.
Children’s personal data
Huniverse Global does not knowingly
provide services to children under the age of 16.
4. Legal basis for processing
We process personal data only where
we have a valid legal basis under the GDPR and other applicable data protection
laws. The legal basis depends on the type of data and the
purpose for which it
is processed.
You are generally not required to
provide personal data to us. However, certain information is necessary to
create an account, provide MediPencil, or respond to your requests. If
you do
not provide such information, we may not be able to provide the relevant
service.
Performance of a contract
We process personal data where it is
necessary to create and manage your MediPencil account and provide the services
you request.
This may include processing your
name, email address, telephone number, professional information, account
credentials, and other information necessary to provide and support
the
service.
The legal basis for this processing
is Article 6(1)(b) GDPR, where processing is necessary for the performance of a
contract with you or to take steps at your request before
entering into a
contract.
Processing of health and patient data
MediPencil may process health data
and other special categories of personal data when you use the service to
create clinical documentation.
Where such data is processed on
behalf of a healthcare professional or healthcare organisation, the relevant
healthcare professional or organisation is responsible for determining the
appropriate legal basis and applicable condition under Article 9 GDPR for
processing the patient's health data. MediPencil processes such data only as
necessary to provide
the service and in accordance with the applicable
instructions and agreements.
Where MediPencil processes special
categories of personal data for its own purposes, we will do so only where an
applicable condition under Article 9 GDPR permits such
processing, in addition
to a valid legal basis under Article 6 GDPR.
Legitimate interests
We may process personal data where
this is necessary for our legitimate interests, provided that these interests
are not overridden by your interests or fundamental rights and
freedoms.
Our legitimate interests may include:
- maintaining the security,
availability and integrity of MediPencil;
- preventing fraud, abuse and
unauthorised access;
- monitoring and investigating
security incidents;
- troubleshooting and improving
the reliability and functionality of our services;
- maintaining appropriate
technical and organisational safeguards; and
- establishing, exercising or defending legal
claims.
The legal basis for such processing
is Article 6(1)(f) GDPR.
Legal obligations
We may process personal data where
processing is necessary to comply with legal obligations applicable to
MediPencil, including applicable tax, accounting, regulatory, legal or
other
statutory requirements.
The legal basis for such processing
is Article 6(1)(c) GDPR.
Marketing and communications
Where we send marketing
communications, product updates, newsletters or event invitations, we will
process your personal data in accordance with applicable data protection and
electronic communications laws.
Where consent is required, we will
rely on your consent under Article 6(1)(a) GDPR. You may withdraw your consent
or unsubscribe from marketing communications at any time.
Withdrawal of consent
does not affect the lawfulness of processing carried out before withdrawal.
We may continue to send
service-related or transactional communications where necessary to provide
MediPencil or manage your account.
Anonymised information and service
improvement
We may use information that has been
irreversibly anonymised for statistical analysis, research, product development
and service improvement. Because properly anonymised
information can no longer be linked to an identifiable individual, such
information is not considered personal data under the GDPR.
We do not use identifiable or
pseudonymised patient health data for AI model training or improvement unless
an appropriate legal basis, Article 9 condition, and other applicable
safeguards have been established.
Consent
Where we rely on consent as the legal
basis for processing, consent will be requested separately and must be freely
given, specific, informed and unambiguous.
You may withdraw your consent at any
time. Withdrawal of consent does not affect the lawfulness of processing based
on consent before it was withdrawn.
5. Data retention periods
Personal data is retained only for as
long as necessary to fulfill the stated purposes or to comply with legal
obligations in accordance with GDPR. When personal information becomes
unnecessary, such as when the retention period expires or the processing
purpose is achieved, the personal information will be destroyed without delay.
The processing and retention periods
for each type of personal information are as follows.
| Data Category | Retention Period | Purpose |
|---|
| Account and membership data | Until account deletion + 30 days for processing | Service provision and account management |
| Customer support and communications records | 1 year from resolution | Customer support, service management and dispute resolution |
| Marketing information and preferences | Until consent is withdrawn or the user unsubscribes, subject to limited retention where necessary to record the withdrawal or comply with legal obligations | Marketing communications and preference management |
| Technical, security and access logs | For as long as reasonably necessary for security, troubleshooting, fraud prevention and legal purposes | Service security and operation |
| Billing and payment records | 10 years | Billing, accounting and legal compliance |
| Clinical research data | May be retained indefinitely where the information has been irreversibly anonymized | Statistical analysis, research, product and service improvement |
| Encrypted authentication values (CI) | 1 year | Customer service verification |
| Records of rights infringement reports | 5 years | Legal compliance |
Where a healthcare professional or organisation uses MediPencil to process patient or other health data, the applicable retention period for that data may be determined by
the relevant healthcare professional or organization as the data controller and may be subject to applicable healthcare, legal or regulatory requirements.
Where personal data is subject to an ongoing legal claim, investigation, regulatory inquiry, or other legal requirement, we may retain the relevant information for as long as
necessary to address the matter or comply with the applicable obligation.
Retention periods may be reviewed and updated periodically to ensure that personal data is not retained longer than necessary.
6. Sharing of personal data and processors
Personal data is not shared with
third parties unless there is a valid legal basis or other lawful basis for
doing so.
Where personal data is processed on
behalf of healthcare professionals or healthcare providers, MediPencil acts as
a data processor and the relevant healthcare professional, or healthcare
provider remains the data controller for patient data. We may share personal
data with the following third parties and service providers where necessary to
provide and
operate MediPencil:
- Service providers acting as
processors or sub-processors, such as cloud infrastructure and hosting
providers, speech-to-text and AI/LLM service providers;
- Other suppliers providing
services such as IT and system administration;
- Email and notification service
providers; and
- Payment service providers, where applicable.
Our processors are required to
process personal data only on our documented instructions, maintain
confidentiality, and implement appropriate technical and organisational
measures to protect personal data. Where required by GDPR, we enter into Data
Processing Agreements (DPAs) with our processors and ensure that applicable
sub-processors
are subject to appropriate data protection obligations.
We may also disclose personal data to
courts, regulators, law enforcement authorities, or other public authorities
where required or permitted by applicable law.
7. Data storage location and international transfers
Personal data is stored in secure
data centres located in the Republic of Korea.
The European Commission has
recognised the Republic of Korea as providing an adequate level of protection
for personal data under Article 45 GDPR. The Commission's
adequacy decision was
reviewed in July 2026 and confirmed that the Republic of Korea continues to
provide an adequate level of protection. Accordingly, transfers of personal
data
from the EEA to the Republic of Korea may take place on the basis of the
adequacy decision without additional transfer safeguards being required under
Chapter V GDPR.
For service provision, maintenance,
troubleshooting and technical support, authorised personnel at our headquarters
in the Republic of Korea may access your account
information. Such access is
subject to role-based access controls, audit logging and strict necessity
limitations.
Where personal data is transferred to or accessed
from countries that are not covered by an EU adequacy decision, we will use an
appropriate transfer mechanism under Chapter V GDPR, such as the European
Commission's Standard Contractual Clauses, where required.
6. Data subject rights
Individuals in the European Economic
Area have the following rights regarding their personal data, subject to the
conditions and limitations provided by the GDPR.
Right of access
You have the right to request
confirmation as to whether we process your personal data and, where applicable,
to access your personal data and information about how it is
processed.
Right to rectification
You have the right to request
correction of inaccurate or incomplete personal data that we hold about you.
Right to erasure
You have the right to request
deletion of your personal data in certain circumstances, including where the
data is no longer necessary for the purposes for which it was collected or
where you have withdrawn your consent and there is no other legal basis for
processing.
Right to restriction of processing
You have the right to request
restriction of the processing of your personal data in certain circumstances,
including where you contest the accuracy of the data, the processing is
unlawful, or you have objected to processing while we consider your objection.
Right to data portability
Where the requirements of Article 20
GDPR are met, you have the right to receive personal data you have provided to
us in a structured, commonly used and machine-readable format and to transmit
it to another controller.
Right to object
You have the right to object to
processing based on our legitimate interests where you have reasons relating to
your particular situation. You also have an absolute right to object to
the
processing of your personal data for direct marketing purposes.
Right not to be subject to certain
automated decisions
You have the right not to be subject
to a decision based solely on automated processing, including profiling, that
produces legal or similarly significant effects, except where an
applicable
exception under Article 22 GDPR applies.
MediPencil does not currently make
decisions based solely on automated processing that produce legal or similarly
significant effects concerning individuals.
Right to withdraw consent
Where we process your personal data
based on consent, you have the right to withdraw your consent at any time.
Withdrawal of consent does not affect the lawfulness of
processing carried out
before withdrawal.
Exercising your rights
To exercise your rights, please
contact us using the contact details provided in this Privacy Policy. We may
request information necessary to verify your identity before processing
your
request.
We will respond to your request
without undue delay and, in any event, within one month of receiving the
request. This period may be extended by up to two additional months where
necessary due to the complexity or number of requests, in which case we will
inform you of the extension.
Where MediPencil processes personal
data on behalf of a healthcare professional or healthcare organization as a
data processor, requests relating to that processing should generally be
directed to the relevant data controller. MediPencil will assist the controller
as required under applicable data protection law.
Right to lodge a complaint
You have the right to lodge a
complaint with a data protection supervisory authority if you believe that your
personal data has been processed in violation of the GDPR. You may generally
contact the supervisory authority in the EEA country where you live, work, or
where the alleged infringement occurred.
Exercise your data subject rights
under GDPR
We provide you with an easy way to
submit us privacy related request like a request to access or erase your
personal data. If you want to make use of your data subject rights, please
visit our Trust Center: https://app.prighter.com/portal/13487768251
7. Our role as data controller and data processor
MediPencil may act as either a data
controller or a data processor, depending on how our services are used and who
determines the purposes and means of processing personal data.
MediPencil as a data controller
MediPencil acts as a data controller
when we determine the purposes and means of processing personal data for our
own purposes. This may include processing personal data for account management,
customer support, service security, billing, marketing, legal compliance, and
other purposes described in this Privacy Policy.
MediPencil as a data processor
Where a healthcare professional,
clinic, hospital, or other healthcare organisation uses MediPencil to process
patient or other personal data on its behalf, that healthcare
professional or
organisation is generally the data controller, and MediPencil acts as a data
processor.
In these circumstances, MediPencil
processes personal data only as necessary to provide the service and in
accordance with the controller's documented instructions and the
applicable
Data Processing Agreement (DPA).
Responsibilities of the data
controller
Where MediPencil acts as a data
processor, the relevant healthcare professional or organisation remains
responsible for determining the purposes and legal basis for processing patient
data and for complying with applicable data protection requirements.
If you are a patient or other
individual whose personal data is processed through MediPencil on behalf of a
healthcare organisation, you should generally direct requests
concerning that
processing to the relevant healthcare organisation.
MediPencil will provide reasonable
assistance to the data controller in fulfilling its data protection
obligations, including responding to data subject rights requests and personal
data breaches, as required by applicable law and the applicable DPA.
8. Cookies and consent management
We may use cookies and similar
tracking technologies to improve your experience, analyze usage, and provide
personalized services. Your consent is required before we place
non-essential
cookies on your device.
Essential
cookies are necessary for service functionality.
Non-essential
cookies (analytics, marketing) are used only with user consent.
EEA users may manage cookie
preferences at any time via the cookie banner or settings panel. Consent logs
are maintained for compliance purposes.
9. Security measures and data breach notification
We implement appropriate technical
and organisational measures to protect personal data against unauthorised or
unlawful access, processing, disclosure, alteration, loss or
destruction.
Our security measures include:
- Strong authentication and
role-based access controls;
- Encryption of data in transit
and at rest;
- Audit logging and monitoring of
system access;
- Regular security assessments and
penetration testing;
- Automated data deletion and
retention controls; and
- Ongoing employee training on data protection and
information security.
In the event of a personal data
breach, we will take appropriate measures to contain, investigate and remediate
the breach.
Where MediPencil acts as a data
controller, we will notify the competent supervisory authority without undue
delay and, where required, within 72 hours of becoming aware of a
personal data
breach.
Where MediPencil acts as a data
processor, we will notify the relevant data controller without undue delay
after becoming aware of a personal data breach and provide the
assistance
required under applicable data protection law.
Where required by the GDPR, affected
individuals will be informed without undue delay where the breach is likely to
result in a high risk to their rights and freedoms.
10. Updates to this Privacy Policy
We may update this Privacy Policy
from time to time to reflect changes to our services, data processing
practices, or applicable laws and regulatory requirements.
Where we make material changes that
affect how we process personal data or your rights, we will provide appropriate
notice before the changes take effect, such as by posting the updated Privacy
Policy on our website, sending an email, or providing a notice through the
MediPencil service where appropriate.
The effective date of the current
version is shown below. We encourage you to review this Privacy Policy
periodically.
Last updated: August 14, 2026