ClinicOps
Privacy

Privacy Notice

How ClinicOps processes personal data across this website, email enquiries, client engagements and business-development outreach — and how to object at any time.

Last updated 10 September 2026. This notice replaces the notice previously published at this address on the former site; it was rewritten when the website moved to its current hosting, because the site itself changed — the current site sets no cookies, runs no analytics and has no contact form.

1. Who we are

ClinicOps · Ali Iskandar · Madrid, Spain · info@clinicops.dk. ClinicOps is the controller for the processing described in this notice. Registered business address and tax identification details are available on request via the email address above.

2. This website

This site is a static website hosted on GitHub Pages, operated by GitHub, Inc. (United States). Like any web host, GitHub processes technical connection data (such as your IP address) in server logs to deliver the pages and protect the service; ClinicOps does not receive or use those logs. ClinicOps itself sets no cookies, runs no analytics, and uses no tracking of any kind on this site.

The interactive tools on this site — the EUDAMED Identifier Check, the Transition Readiness Score, and the assessment brief builder — run entirely in your browser. Nothing you enter into them is transmitted to ClinicOps or to anyone else. The assessment brief builder only opens a draft in your own email application when you explicitly choose to; whether to send it is your decision.

3. Email enquiries

What we process. When you write to us, we process your name, email address, and the content of your message.

Why, and on what basis. To answer you and to take any steps you request before entering into a contract (Article 6(1)(b) GDPR), or otherwise on our legitimate interest in answering business enquiries (Article 6(1)(f) GDPR).

4. Client engagements

What we process. The business contact details of client representatives and the content of the material a client supplies for an engagement, processed to perform the contract (Article 6(1)(b) GDPR) and to meet legal obligations such as bookkeeping.

Do not send patient-identifiable data. ClinicOps' services do not require, and this notice does not cover, health data or any other special-category data about identifiable individuals (Article 9 GDPR). Please remove or de-identify such data before sending material. If we receive patient-identifiable data unsolicited, we delete it and notify the sender.

5. Business development and outreach

What we process. When we contact an organisation about our services, we process business contact details: a name and job title where these are published, a business email address, the employer's name, and any publicly stated regulatory role (for example, a person named as a regulatory or vigilance contact in a published document). We do not process special categories of personal data for this purpose, we do not build profiles, and we use no tracking pixels, open tracking or click tracking.

Where it comes from. We do not obtain this information from you. We take it from sources that the organisation or the individual has published or that a public register makes available: the organisation's own website, including its imprint, contact and team pages; LinkedIn; documents the manufacturer publishes itself, such as instructions for use and summaries of safety and clinical performance; and the public European database on medical devices (EUDAMED), including its actor and device registers.

Why we process it, and on what basis. Our legal basis is our legitimate interest in offering business-to-business services to organisations whose published activity indicates they may need them (Article 6(1)(f) GDPR). We have considered your interests and rights: we contact business addresses in a professional capacity, not private individuals; the message concerns the recipient's own professional field; we send at most three messages and stop immediately on request; and we keep no marketing list.

How long we keep it. Prospect records are deleted twelve months after the last contact, or immediately on request. If you ask us not to write again, we keep a minimal suppression record — your email address and the date — for as long as we operate, because deleting it would allow us to contact you again by mistake. That record is used for nothing else.

Your right to object. You may object at any time to processing based on our legitimate interest (Article 21 GDPR). Replying with the word STOP is enough, and we act on it the same day; you can also write to info@clinicops.dk. You do not need to give a reason, and objecting costs you nothing.

6. Recipients and processors

Microsoft. Email, including outreach email, is sent and received through Microsoft 365 (Microsoft Ireland Operations Limited), which processes messages and their metadata on our behalf.

GitHub. This website is hosted on GitHub Pages (GitHub, Inc., United States). Transfers to the United States rest on the EU–US Data Privacy Framework adequacy decision or standard contractual clauses.

Gumroad. Where you download or buy one of our documents, the purchase is handled by Gumroad, Inc. (United States), which collects your email address and payment details directly and acts as its own controller for that transaction. We receive the email address of buyers. Their privacy notice governs what they do with the data they collect.

7. Retention

Enquiry correspondence and client files are kept as long as needed for the purpose they were provided for and any legal retention obligations, then deleted. Outreach retention is described in section 5.

8. Your rights

You have the rights of access, rectification, erasure, restriction, data portability and objection (Articles 15–21 GDPR), and the right to withdraw any consent at any time (Article 7(3) GDPR). Write to info@clinicops.dk. You also have the right to lodge a complaint with a supervisory authority (Article 77 GDPR): the Agencia Española de Protección de Datos (AEPD) as the authority for ClinicOps' place of establishment, or your own national authority — for Denmark, Datatilsynet; for marketing email in Denmark, Forbrugerombudsmanden also handles complaints.

9. Dansk — forretningsudvikling og opsøgende kontakt

Dette afsnit gengiver afsnit 5 på dansk. Den fulde meddelelse findes på engelsk ovenfor.

Hvad vi behandler. Når vi kontakter en organisation om vores ydelser, behandler vi erhvervsmæssige kontaktoplysninger: navn og stillingsbetegnelse, hvor disse er offentliggjort, en arbejdsmailadresse, arbejdsgiverens navn og en eventuel offentligt angivet regulatorisk rolle (for eksempel en person, der er nævnt som regulatorisk kontakt eller vigilance-kontakt i et offentliggjort dokument). Vi behandler ikke særlige kategorier af personoplysninger til dette formål, vi opbygger ikke profiler, og vi anvender hverken sporingspixels, åbningssporing eller kliksporing.

Hvor oplysningerne kommer fra. Vi har ikke oplysningerne fra dig. Vi henter dem fra kilder, som organisationen eller personen selv har offentliggjort, eller som et offentligt register stiller til rådighed: organisationens eget website, herunder kolofon-, kontakt- og medarbejdersider; LinkedIn; dokumenter, som fabrikanten selv offentliggør, såsom brugsanvisninger og sammenfatninger af sikkerhed og klinisk ydeevne; samt den europæiske database over medicinsk udstyr (EUDAMED), herunder aktør- og udstyrsregistrene.

Hvorfor vi behandler dem, og på hvilket grundlag. Vores retlige grundlag er vores legitime interesse i at tilbyde erhvervsmæssige ydelser til organisationer, hvis offentliggjorte aktivitet indikerer, at de kan have brug for dem (artikel 6, stk. 1, litra f, i databeskyttelsesforordningen). Vi har afvejet dine interesser og rettigheder: vi kontakter erhvervsadresser i en professionel sammenhæng, ikke privatpersoner; henvendelsen angår modtagerens eget fagområde; vi sender højst tre henvendelser og stopper straks efter anmodning; og vi fører ingen markedsføringsliste.

Hvor længe vi opbevarer dem. Emneoplysninger slettes tolv måneder efter den seneste kontakt eller straks efter anmodning. Beder du os om ikke at skrive igen, opbevarer vi en minimal spærreliste — din mailadresse og datoen — så længe vi driver virksomhed, fordi en sletning ville gøre det muligt at kontakte dig igen ved en fejl. Den oplysning bruges ikke til andet.

Din ret til at gøre indsigelse. Du kan til enhver tid gøre indsigelse mod behandling, der er baseret på vores legitime interesse (artikel 21). Det er nok at svare med ordet STOP, og vi effektuerer det samme dag; du kan også skrive til info@clinicops.dk. Du behøver ikke at begrunde din indsigelse, og den koster dig ingenting.

Modtagere. Opsøgende e-mail sendes via Microsoft 365 (Microsoft Ireland Operations Limited), som behandler meddelelsen og dens metadata på vores vegne.

10. Changes

When this notice changes materially, the date at the top is updated. Earlier versions are available on request.