LEGAL
Privacy Policy
Last Updated: March 15, 2026

This privacy policy describes how Medel Inc. collects, uses, and protects your personal information when you use our website and services.

1. Identity of the Controller and Scope

For purposes of the GDPR and other applicable privacy laws, the “controller” of Personal Data processed through the Website is Medel Inc., a Nevada corporation, with its principal office at 732 S 6th St., Suite N, Las Vegas, NV 89101. You may contact us at legal [at] medelortho.com. This Privacy Policy applies only to Personal Data collected through the Website and does not apply to information collected offline, through your use of Medel products in clinical settings, or by any third party that may be linked from the Website. Medel does not operate the Website as a “covered entity” or “business associate” under the Health Insurance Portability and Accountability Act (“HIPAA“); the Website is not intended for the receipt of Protected Health Information (“PHI“), and you shall not submit PHI through the Website except through a secure channel that Medel has identified in writing.

2. Information We Collect

We collect Personal Data and other information about you (i) that you provide directly, including your name, email address, postal address, telephone number, country, employer or institutional affiliation, job title, professional credentials (such as medical license number or National Provider Identifier), distributor authorization status, account registration details, the content of inquiries or messages you submit, event registration data, survey responses, and any other information you elect to provide; (ii) that we collect automatically through cookies and similar tracking technologies, including your IP address, device and browser information, operating system, approximate geographic location, pages viewed, referring URL, date and time of access, and error logs; and (iii) that you voluntarily submit relating to a product complaint or adverse event, which we will process only as necessary to respond to your communication and to comply with FDA medical device reporting and post-market surveillance obligations. The Website is not designed to receive PHI, and any health-related information you submit through general web forms or unencrypted email is not protected as PHI. The Website is intended for adults and is not directed to children; we do not knowingly collect Personal Data from children under thirteen (13) (or under sixteen (16) where required by GDPR).

3. How We Use Your Information

We use the Personal Data and other information we collect to (i) operate, maintain, secure, and improve the Website; (ii) respond to inquiries, support requests, and product complaints; (iii) verify credentials and administer healthcare professional and distributor portals; (iv) provide requested information about Medel products consistent with applicable FDA-cleared or FDA-approved labeling; (v) send marketing or informational communications where you have requested them or as otherwise permitted by applicable law (you may opt out at any time using the unsubscribe link in any such communication or by contacting us); (vi) comply with our legal, regulatory, contractual, and recordkeeping obligations, including FDA medical device reporting under 21 C.F.R. Part 803, post-market surveillance, and responses to lawful requests from governmental authorities; (vii) conduct analytics, research, and quality improvement, including through third-party analytics tools; and (viii) detect, investigate, and prevent fraud, abuse, security incidents, and violations of these Terms or applicable laws, and to establish, exercise, or defend legal claims.

4. Legal Bases Under the GDPR

Where the GDPR or the UK GDPR applies to our processing of your Personal Data, we rely on one or more of the following legal bases under Article 6(1): (i) performance of a contract or pre-contractual steps at your request (Article 6(1)(b)); (ii) compliance with a legal obligation (Article 6(1)(c)), for example, adverse-event reporting and recordkeeping; (iii) your freely given, specific, informed, and unambiguous consent (Article 6(1)(a)), for example, for marketing and optional cookies; and (iv) our legitimate interests or those of a third party, balanced against your rights (Article 6(1)(f)), for example, to operate, secure, and improve the Website. Where we process special categories of personal data under Article 9, we rely on your explicit consent under Article 9(2)(a) or another lawful basis available under Article 9.

5. Cookies and Tracking Technologies

We use cookies, pixel tags, local storage, and similar tracking technologies on the Website, which fall into four categories: (i) strictly necessary cookies, which enable basic functionality such as security and navigation and cannot be disabled; (ii) performance and analytics cookies, which collect aggregated usage data and require consent where required by applicable law; (iii) functional cookies, which remember preferences such as language; and (iv) targeting cookies, which require your prior consent where applicable law requires it. Where consent is required, we obtain it through a cookie banner or preference center, which you can use to change your preferences at any time. You may also block or delete cookies through your browser settings, though doing so may impair functionality. A cookie banner alone is not sufficient authorization for the receipt of PHI, and you shall not submit PHI through the Website. Because there is no widely adopted standard, the Website does not respond to “Do Not Track” browser signals; we respond to opt-out preference signals (such as the Global Privacy Control) to the extent required by applicable law.

HIPAA & Regulatory Compliance

Medel maintains compliance with HIPAA, GDPR, and applicable medical device data regulations. Our data handling practices are audited annually by independent third-party assessors.

6. How We Share Information

We do not sell your Personal Data for monetary consideration, and we do not “share” Personal Data for cross-context behavioral advertising in a manner that would require an opt-out under the CCPA or comparable state laws. We may disclose Personal Data to (i) our affiliates, subsidiaries, and parent entities under obligations of confidentiality; (ii) service providers and vendors that perform services on our behalf (such as cloud hosting, customer relationship management, email, analytics, and information security), in each case bound by written contracts that limit their use of Personal Data and require appropriate safeguards; (iii) healthcare or commercial partners (such as hospitals, clinical investigators, or authorized distributors) where necessary to provide requested support, complaint handling, or post-market surveillance, subject to confidentiality and applicable privacy laws; (iv) competent governmental, regulatory, or law-enforcement authorities, including the FDA and comparable foreign authorities, as required by applicable law or in response to a lawful request, subpoena, court order, or demand; (v) professional advisors under obligations of confidentiality; (vi) parties to a corporate transaction such as a merger, acquisition, financing, or sale of assets, subject to confidentiality protections; and (vii) any other party with your consent. We may also use and disclose aggregated or de-identified information for any lawful purpose without restriction.

7. Data Retention

We retain Personal Data only as long as reasonably necessary for the purposes described in this Privacy Policy, to comply with our legal, regulatory, contractual, and recordkeeping obligations, to resolve disputes, and to enforce our agreements. Indicative retention periods are: (i) contact and inquiry records, up to seven (7) years from the last interaction; (ii) product complaint and adverse-event records, retained in accordance with the FDA’s reporting and recordkeeping requirements under 21 C.F.R. Part 803 and our quality management procedures (generally the expected lifetime of the device plus any required post-market period, and not less than two (2) years); (iii) account information, the duration of the account plus up to three (3) years following closure; (iv) Website analytics data, generally not exceeding twenty-six (26) months at the individual level; and (v) records subject to a legal hold, until the legal hold is released. When Personal Data is no longer required, we securely delete, destroy, or irreversibly anonymize it.

8. Data Security

We maintain a written information security program with administrative, physical, and technical safeguards designed to protect Personal Data against unauthorized access, alteration, disclosure, loss, or destruction. These safeguards include, without limitation, encryption of Personal Data in transit and at rest where appropriate, role-based access controls, multifactor authentication for administrative access, network segmentation, vulnerability scanning and penetration testing, vendor security review, employee training, and documented incident-response procedures. No method of transmission or storage is one-hundred percent secure, and we cannot warrant absolute security. You are responsible for safeguarding your account credentials, using strong passwords, and promptly notifying us of any suspected unauthorized access. In the event of a security incident affecting Personal Data, we will notify affected individuals and competent supervisory authorities as required by, and within the timeframes prescribed by, applicable law, including state breach-notification statutes and Articles 33 and 34 of the GDPR where applicable.

9. Your Privacy Rights and Choices

Depending on where you reside, you may have the right to (i) confirm whether we process your Personal Data and access categories and specific pieces collected; (ii) correct inaccurate Personal Data; (iii) request deletion of your Personal Data, subject to legal exceptions; (iv) request a copy of your Personal Data in a portable format; (v) opt out of any sale of, or “sharing” or “targeted advertising” using, your Personal Data (as noted in Section 6, we do not engage in these activities); (vi) limit our use of sensitive personal information; (vii) object to or restrict certain processing, including direct marketing and processing based on legitimate interests; (viii) withdraw any consent you have given, without affecting the lawfulness of prior processing; (ix) not be subject to a decision based solely on automated processing that produces legal or similarly significant effects; and (x) be free from unlawful discrimination for exercising your rights. To exercise any right, please contact us at legal [at] medelortho.com or at the address in Section 11. We will respond within the timeframes required by applicable law (generally forty-five (45) days under the CCPA, with one additional forty-five-day extension where reasonably necessary, and one (1) month under the GDPR, with up to a two-month extension where reasonably necessary) after we have verified your identity. You may designate an authorized agent to act on your behalf with proper authorization. Residents of the European Economic Area, the United Kingdom, or Switzerland may also lodge a complaint with their local supervisory authority.

10. International Data Transfers

Medel is headquartered in the United States and uses service providers in the United States and elsewhere. As a result, Personal Data may be transferred to, stored in, and processed in jurisdictions that may not have the same data-protection laws as your country of residence. When we transfer Personal Data of individuals in the European Economic Area, the United Kingdom, or Switzerland to a jurisdiction not recognized as providing an adequate level of data protection, we rely on appropriate safeguards required by the GDPR, including the Standard Contractual Clauses adopted by the European Commission (and the UK International Data Transfer Addendum or Agreement where applicable), the EU-U.S. and UK and Swiss extensions of the Data Privacy Framework (to the extent Medel self-certifies or otherwise relies on them), and other lawful transfer mechanisms, supported by encryption, access controls, and vendor security review. A copy of the applicable transfer mechanism may be obtained, subject to redaction of confidential information, by contacting legal [at] medelortho.com.

11. Changes; Contact Us

Medel may update this Privacy Policy from time to time. Material changes will be communicated by updating the “Last Revised” date and, where appropriate, by posting a notice on the Website or sending email; your continued use of the Website constitutes acceptance of the revised Privacy Policy. If you have questions, concerns, or requests regarding this Privacy Policy or our processing of your Personal Data, please contact: Medel Inc., Attn: Legal Team; 732 S 6th St., Suite N; Las Vegas, NV 89101; email: legal [at] medelortho.com. Where required by the GDPR, Medel will identify any appointed Data Protection Officer or designated EU or UK representative upon written request. If you are a parent or guardian and believe a child has provided Personal Data to us, please contact us to request review or deletion.

BY ACCESSING OR USING THE WEBSITE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND CONSENT TO THE COLLECTION, USE, DISCLOSURE, AND OTHER PROCESSING OF INFORMATION AS DESCRIBED HEREIN.

Questions About Your Privacy?

Our team is committed to transparency and protecting your data. Reach out to our Privacy Officer for any questions or concerns.

Contact Privacy Officer