Last updated: July 7th, 2026
This Privacy Policy explains how DIKTA INC S.R.L., Bucharest, Romania ("Dikta", "we", "us") processes personal data on the Parol platform — the Parol websites and the Parol mobile applications for iOS and Android (the "App") (together, the "Platform").
Contact: [email protected]
1. Data We Collect
Account data: name, email, password (hashed), authentication provider and Google account ID (if you sign in with Google), email verification status, specialty, language.
Usage and device data: IP address, device and app/browser information, logs and diagnostics, message counts, and usage frequency.
Content data: chat prompts, uploaded documents, and generated outputs; for PRO, also consultation audio, transcriptions, and notes.
Billing data: payments are processed by our payment providers (Stripe on the web; Apple and Google for App purchases). We do not store full card details; we receive subscription and transaction status information.
Onboarding data: information you choose to provide to personalize your profile.
2. How We Use Data
We process data to provide and personalize the service, manage subscriptions and billing, communicate with you (service and, subject to opt-out, marketing messages), enforce usage limits and prevent abuse, maintain security and stability, improve the Platform, and comply with legal obligations. Legal bases under GDPR/LGPD include performance of a contract, legitimate interests, consent (where required), and legal obligation.
3. Data Processing Roles — Patient Data
FREE users must not submit patient-identifiable data.
For patient-related content submitted by Medical AI and PRO users, the user acts as Data Controller and Dikta as Data Processor, processing such content only to provide the service. A Data Processing Addendum is available on request; HIPAA-covered entities must execute a BAA before submitting PHI. For platform operation, analytics, and improvement, Dikta acts as an independent controller.
4. AI Training
We do not use patient-related content, chat prompts, uploaded documents, or consultation audio to train AI models. We may use aggregated or de-identified usage data for testing, quality, and performance improvement. Where a specific activity requires consent under applicable law, it will be requested.
5. Cookies & Analytics
Our websites use essential cookies (authentication, security, session) and, subject to your consent where required, analytics and advertising-measurement technologies provided by third parties. You can manage preferences via the cookie banner or your browser.
The App does not use third-party advertising trackers; it collects the usage, diagnostic, and purchase data described in Section 1.
Emails we send may include open/click measurement; you can unsubscribe from marketing emails at any time.
6. Sharing of Data
We share personal data only with service providers acting on our behalf under contractual confidentiality and data protection obligations — hosting and cloud infrastructure, AI processing subprocessors (which do not use your data to train their own models), payment providers, email delivery, and analytics/security providers — and where required by law, to protect our rights, or in connection with a corporate transaction. We do not sell personal data. A list of subprocessors is available on request.
7. International Transfers
Data may be processed outside your country. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or equivalent mechanisms under applicable law.
8. Retention & Account Deletion
Account data is retained while the account is active; chat history until you delete conversations or your account; consultation audio and outputs for a limited period necessary to provide the service; billing records as required by law; marketing data until you opt out.
You can delete your account at any time from My Account (App or web). Deletion is subject to a grace period of up to 30 days, during which you may reactivate by logging in. Thereafter, personal data is deleted or irreversibly anonymized, except for records we are legally required to retain.
9. Your Rights
Depending on your jurisdiction, you may have rights of access, correction, deletion, restriction, objection (including to direct marketing), portability, and withdrawal of consent, exercisable at [email protected] or via My Account. You may lodge a complaint with your supervisory authority (in Romania, ANSPDCP; in Brazil, ANPD). We do not sell or share personal information as defined by the California CCPA/CPRA.
10. Children
The Platform is intended for healthcare professionals and medical students and is not directed to anyone under 18. We do not knowingly collect data from minors.
11. Security
The Platform is operated on HIPAA-compliant and GDPR-compliant infrastructure, and Dikta maintains certifications supporting this compliance (details available on request at [email protected]). We apply technical and organizational safeguards appropriate to the nature of the data, including measures such as encryption and access controls. No system is perfectly secure. In the event of a personal data breach, we will notify affected users and authorities where required by law.
12. Updates
We may update this Privacy Policy periodically. Material changes will be notified through the Platform or by email where required by law.
13. Contact
DIKTA INC S.R.L., Bucharest, Romania — [email protected]