Privacy Policy
Data Controller : VTMConnect · tmendev@proton.me · Last updated : June 25, 2026
1. Overview
TransMed is a mobile application connecting patients with volunteers to facilitate prescription medication purchase and delivery in Algeria. VTMConnect commits to protecting personal data per GDPR and applicable law.
2. Data collected
Identification and contact:
- Email address — account creation and authentication (contract performance).
- First name — in-app identification and notifications (contract performance).
- Role (patient/volunteer) — display relevant features (contract performance).
- Preferred language (FR/EN) — interface localization (legitimate interest).
- Prescriptions (photo/PDF) — sensitive health data: enable volunteer purchase at pharmacy (explicit consent).
- Desired delivery city — geographic patient–transporter matching (contract performance).
- FCM token, notification preference, last activity date, audit log, charter acceptance dates — operation and traceability (consent / legitimate interest / legal obligation).
Prescription protection
Prescriptions receive health-data protections: stored in a secure private space via Supabase Storage with time-limited signed URLs and Row Level Security access controls. Only the assigned buyer and transporter access them.
3. Sub-processors and transfers
Transfers outside the EU occur via Standard Contractual Clauses or European Commission adequacy decisions.
- Supabase — PostgreSQL database, file storage, authentication (USA/EU).
- Firebase (Google) — push notifications FCM (USA).
- Resend — transactional emails (USA).
4. Retention periods
- Account data: retained while the account is active.
- Prescriptions: deleted upon request closure or explicit request.
- Chat messages: retained during the request lifetime.
- Audit log: 12 months.
- FCM tokens: automatically deleted upon Firebase invalidation.
5. Your rights (GDPR)
Exercise your rights: tmendev@proton.me (30-day response period).
- Access copies of your personal data.
- Rectify inaccurate data.
- Erase your account and data.
- Port data in a structured format.
- Object to legitimate-interest processing.
- Withdraw consent (notifications, prescriptions).
6. Security
- All communications use HTTPS/TLS.
- Prescriptions stored in a private bucket with time-limited signed URLs.
- Row Level Security (RLS) access controls.
- Supabase Auth manages passwords via bcrypt (never plain text).
- Android backup disabled.
7. Sensitive data — camera usage
The application requests camera and gallery access solely for the capture and upload of medical prescriptions. No automatic image analysis or external sharing occurs outside the request context.
8. Push notifications
Firebase Cloud Messaging sends notifications regarding request progress (new requests, delivery status, chat messages). Users may disable notifications via the application or OS settings.
9. Contact and complaints
Questions or rights exercise: VTMConnect — tmendev@proton.me.
For unresolved concerns, lodge a complaint with the competent supervisory authority (France: CNIL — www.cnil.fr).
10. Changes
This policy is updated as needed. Material changes trigger an in-app notification. The current update date appears at the top of the document.