Privacy Policy

www.postdicom.com — Last updated: April 15, 2026

www.postdicom.com collects some Personal Data from its Users. This policy describes what data is collected, why, and how it is used. PostDICOM B.V. is the Data Controller for personal data collected through this website.

Legal Basis for Processing

We process personal data on the following legal bases under the GDPR and equivalent applicable legislation:

  • Performance of a contract — processing necessary to provide the Service you have subscribed to, including account management, billing, and service delivery.
  • Consent — where you have given explicit consent, such as subscribing to marketing communications or accepting analytics and advertising cookies via our cookie consent panel.
  • Legitimate interests — processing necessary for our legitimate business interests, such as improving the Service through analytics, preventing fraud, and ensuring security, where those interests are not overridden by your rights.
  • Legal obligation — processing required to comply with applicable law, such as retaining invoicing and accounting records under Dutch and Turkish law.

If you are located outside the European Economic Area, the processing of your personal data may also be subject to the data protection laws of your country of residence.

Personal Data processed and the services used

Advertising

Google Ads conversion tracking (Google LLC)

Personal Data: Trackers; Usage Data

Place of processing: United States; Ireland

LinkedIn conversion tracking — LinkedIn Insight Tag (LinkedIn Corporation)

Personal Data: device information; Trackers; Usage Data

Place of processing: United States

Analytics

Google Analytics 4 — Google LLC

Personal Data: number of Users; session statistics; Trackers; Usage Data

Place of processing: United States

HubSpot Analytics — HubSpot, Inc.

Personal Data: Trackers; Usage Data

Place of processing: United States

Contacting the User

Mailing list or newsletter

Personal Data: company name; country; email address; first name; last name; phone number; profession; Usage Data

Contact form

Personal Data: country; email address; first name; last name; various types of Data

Phone contact

Personal Data: phone number

Data transfer outside the EU

Data transfer abroad based on standard contractual clauses

Personal Data: various types of Data

Data transfer from the EU and/or Switzerland to the U.S. based on the EU–U.S. Data Privacy Framework

Personal Data: various types of Data

Displaying content from external platforms

YouTube video widget — Google LLC

Personal Data: Trackers; Usage Data

Place of processing: United States

Handling payments

Stripe

Personal Data: various types of Data as specified in the privacy policy of the service

Hosting and backend infrastructure

Microsoft Azure — Microsoft Corporation

Personal Data: various types of Data as specified in the privacy policy of the service

Place of processing: European Union; United States; United Kingdom; Switzerland; Canada; Singapore; Australia; India; Brazil

Interaction with external social networks and platforms

LinkedIn button and social widgets — LinkedIn Corporation

Personal Data: Trackers; Usage Data

Place of processing: United States

Twitter Tweet button and social widgets — X Corp.

Personal Data: Trackers; Usage Data

Place of processing: United States

Facebook Like button and social widgets — Meta Platforms, Inc.

Personal Data: Trackers; Usage Data

Place of processing: United States

YouTube button and social widgets — Google LLC

Personal Data: Usage Data

Place of processing: United States

Interaction with live chat platforms

HubSpot Chat — HubSpot, Inc.

Personal Data: Data communicated while using the service; Trackers; Usage Data

Place of processing: United States

Managing contacts and sending messages

HubSpot Email — HubSpot, Inc.

Personal Data: email address; Usage Data

Place of processing: United States

Remarketing and behavioral targeting

Google Ads Remarketing — Google LLC

Personal Data: Trackers; Usage Data

Place of processing: United States; Ireland

Tag management

Google Tag Manager — Google LLC

Personal Data: Usage Data

User database management

HubSpot CRM — HubSpot, Inc.

Personal Data: email address; phone number; various types of Data

Place of processing: United States

HubSpot Lead Management — HubSpot, Inc.

Personal Data: various types of Data

Place of processing: United States

Information on opting out of interest-based advertising

In addition to any opt-out feature provided by any of the services listed in this document, Users may learn more on how to generally opt out of interest-based advertising within the dedicated section of the Cookie Policy.

Further information about the processing of Personal Data

Selling goods and services online

Personal Data is collected and used to provide the Service and process subscription payments. All payment transactions are handled exclusively by Stripe. PostDICOM does not directly collect or store payment card details or bank account information. The personal data collected in connection with a payment depends on the payment method used and is governed by Stripe's privacy policy.

The Service is not directed to persons under the age of 18

You must be at least 18 years of age to use www.postdicom.com. Under no circumstance may persons under the age of 18 use www.postdicom.com.

Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law:

  • Account and subscription data (name, email address, billing information): retained for the duration of your account and for up to 7 years after account closure for accounting, invoicing, and legal compliance purposes.
  • Medical and patient data (DICOM files, images, reports, database records, shared links): permanently deleted upon subscription cancellation or account termination. No retention period applies after deletion.
  • Analytics and usage data: retained in accordance with the data retention settings of the relevant third-party service (typically up to 26 months for Google Analytics 4; refer to the respective service's privacy policy for details).
  • Marketing and CRM data: retained for as long as you remain subscribed to marketing communications, or until you withdraw consent or request deletion.
  • Payment data: processed and retained by Stripe in accordance with their privacy policy and PCI DSS requirements. PostDICOM does not store card or bank account details.
  • Support and chat data: retained for the duration of the support relationship and for a reasonable period thereafter.

When personal data is no longer needed, it is securely deleted or anonymised.

Contact information

🇳🇱
PostDICOM B.V.
Vinkenburgstraat 2A 3512 AB Utrecht The Netherlands
🇹🇷
Ekstrem Bir Bilgisayar Danışmanlık
Hacettepe Teknokent Üniversiteler Mah. 1596 Cad. No: 6 E/28 Çankaya, Ankara, Türkiye

Owner contact email: support@postdicom.com

Your Rights Under Applicable Data Protection Law

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection law, you may have the following rights in relation to your personal data:

  • Right of access — you may request a copy of the personal data we hold about you.
  • Right to rectification — you may ask us to correct inaccurate or incomplete personal data.
  • Right to erasure — you may ask us to delete your personal data where there is no longer a legitimate reason to retain it.
  • Right to restriction of processing — you may ask us to suspend processing of your personal data in certain circumstances.
  • Right to data portability — you may request a copy of your personal data in a structured, commonly used, machine-readable format.
  • Right to object — you may object to processing of your personal data where we rely on legitimate interests as the legal basis, or where data is used for direct marketing purposes.
  • Right to withdraw consent — where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, please contact us at support@postdicom.com. We will respond within the timeframe required by applicable law (generally 30 days). You also have the right to lodge a complaint with your local data protection authority.

Note for organisations

These rights apply to natural persons (individuals). If you access the Service as part of an organisation, these rights apply to your own personal data held by PostDICOM (such as your name, email address, and account information). They do not apply to the organisation as a legal entity, or to patient and medical data your organisation stores through the Service.

Note on third-party data

Some personal data is processed by third-party services listed in this policy (such as Google Analytics, HubSpot, LinkedIn, and Meta). PostDICOM has limited or no ability to fulfil data rights requests in relation to data held independently by those services. To exercise your rights over data held by a third-party service, please contact that service directly.

Definitions and legal references

Personal Data (or Data)

Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.

Usage Data

Information collected automatically through www.postdicom.com (or third-party services employed in it), which can include: IP addresses or domain names, URI addresses, time of the request, method of the request, file size received in response, status codes, country of origin, browser and OS details, time details per visit, path followed, and other device/IT environment parameters.

User

The individual using www.postdicom.com who, unless otherwise specified, coincides with the Data Subject.

Data Subject

The natural person to whom the Personal Data refers.

Data Processor (or Processor)

The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including security measures concerning the operation and use of www.postdicom.com.

Cookie

Cookies are Trackers consisting of small sets of data stored in the User's browser.

Tracker

Any technology — e.g. Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting — that enables the tracking of Users, for example by accessing or storing information on the User's device.