Legal & Compliance / Version 2.4 (Effective August 2026)
Privacy Policy
SUPENTIS Technologies (“SUPENTIS”, “we”, “our”) is committed to protecting the privacy, security, and integrity of data processed through our enterprise platforms (Medleep, Edleep, Erpleep) and public web properties.
1. Institutional Data Sovereignty & Customer Data
SUPENTIS acts primarily as a Data Processor or Service Provider for institutional customers (hospitals, universities, enterprises, government bodies). Customer data stored or processed within Medleep, Edleep, or Erpleep remains the sole property of the customer.
We do not sell, monetize, rent, or trade customer data or personal information processed under institutional contracts. All data isolation boundaries are cryptographically maintained at the architectural level.
2. Information Collected on Public Web Properties
When you interact with our public website, request consultations, or subscribe to research publications, we collect:
- Contact Information: Name, professional email address, institution name, role, and inquiry details submitted via contact forms.
- Technical Telemetry: Anonymized IP addresses, browser type, device metadata, and referral headers used strictly for security auditing and performance optimization.
3. Regulatory Compliance Frameworks
Our data processing practices adhere to global privacy standards:
- GDPR & EU Data Protection: We support standard contractual clauses (SCCs), data protection impact assessments (DPIAs), and user rights (access, rectification, erasure).
- HIPAA (Healthcare): Medleep data processing complies with HIPAA Security and Privacy Rules, supported by Business Associate Agreements (BAAs) for covered entities.
- FERPA (Education): Edleep operates under strict student record privacy constraints with role-based access enforcement.
4. Data Retention & Cryptographic Erasure
Personal information submitted via website inquiries is retained for 24 months or until explicitly requested for deletion. Institutional customer data retention is governed strictly by the executed Master Services Agreement (MSA) and Service Level Agreement (SLA).
5. Security Officer Contact
For data protection inquiries, DPIA requests, or privacy officer correspondence:
Data Protection Office & Security Governance
Email: privacy@supentis.com
Security Portal: supentis.com/security
