Legal
Privacy Policy
Last updated: 15 July 2026
This Privacy Policy explains how BeyondMed (“we”, “us”) handles personal data when you use www.beyondmed.in and related mentoring portals. It is written to meet the transparency expectations in guidance such as the ICO “right to be informed” checklist and GDPR.eu privacy notice guidance, adapted to how BeyondMed actually works today.
1. Who we are
BeyondMed is an online mentoring platform for international medical graduates preparing for the USMLE pathway and the US residency Match. Contact for privacy requests: privacy@beyondmed.in.
2. What data we collect
We collect only what is needed to run mentoring, roadmaps, and accounts:
- Account data: name, email address, password (stored only as a bcrypt hash), role (mentee / mentor / admin), timezone, account status.
- Mentee profile: current stage, specialty interest, Match year, budget band, roadmap content you generate.
- Mentor profile: title, bio, specialty, session rate, tags, approval status.
- Session & matching data: booked times, duration, notes, meeting URL placeholders, match suggestions, stub payment records (amount and status — no card numbers in v1).
- Waitlist / interest forms: email, optional stage and specialty.
- Technical data: IP address used briefly for rate-limiting abuse; security logs without passwords or full auth headers.
We do not currently collect phone numbers, date of birth, government IDs, payment card details, or health records beyond what you voluntarily type into mentoring notes.
3. Why we use your data (purposes)
- Create and secure your account (authentication).
- Generate and display your Match roadmap and mentor matches.
- Enable booking, mentor calendars, and session records.
- Operate admin approvals and quality control.
- Respond to waitlist / roadmap interest requests.
- Protect the service (rate limits, fraud/abuse prevention, security incident response).
- Improve product reliability (aggregated, non-identifying where possible).
4. Legal bases we rely on
Depending on your location and the activity, we rely on one or more of: contract (providing the mentoring platform you signed up for), legitimate interests (securing the service, preventing abuse, improving reliability — balanced against your rights), and consent where you optionally join a waitlist or marketing-style interest form. You may withdraw consent for optional communications by emailing us.
5. Who we share data with
- MongoDB Atlas — database hosting for application data (encrypted in transit).
- Hostinger VPS — application hosting and TLS termination for beyondmed.in.
- Matched mentors / mentees — only the profile and session information needed for that relationship (for example, a mentor may see matched mentee stage/specialty context; admins see broader operational data).
- Email providers (optional, if invite email is enabled) — recipient email and temporary invite content only.
We do not sell personal data. We do not use advertising trackers or third-party analytics SDKs in the current release.
6. International transfers
Infrastructure providers (for example MongoDB Atlas or hosting regions) may process data outside India. Where that happens, we rely on the provider’s contractual and security safeguards (TLS, access controls). Ask privacy@beyondmed.in if you need current region details.
7. How long we keep data
- Active accounts: while your account remains open and for a reasonable period afterward needed for security, dispute, or legal obligations.
- Deleted accounts: when you use in-app account deletion (or email us), we remove or anonymize account credentials, profiles, roadmaps, matches, waitlist rows for your email, and related sessions/payments as described in our product security baseline.
- Security / rate-limit data: short-lived and not stored as a user profile field.
8. Your rights
Subject to applicable law, you may request to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and related personal data (self-serve in the mentee profile, or by email)
- Object to or restrict certain processing
- Withdraw consent for optional processing
- Lodge a complaint with a relevant data-protection authority in your country
Email privacy@beyondmed.in with the subject “Privacy request”. We may need to verify your identity before fulfilling a request.
9. Security measures (summary)
We use HTTPS, hashed passwords (bcrypt), httpOnly session cookies, server-side authorization checks, rate limits on authentication, security headers, and production secret management via environment variables. See our Security page for a plain-language overview. No method is 100% secure; please use a unique password.
10. Children
BeyondMed is intended for adult medical graduates and trainees. We do not knowingly collect data from children under 16. Contact us if you believe a minor created an account.
11. Automated decisions
Roadmap generation and mentor matching use rule-based product logic to suggest plans and mentors. These are decision-support tools, not automated decisions that produce legal or similarly significant effects without human involvement. Mentors and admins remain involved in approvals and mentoring.
12. Cookies
We use a necessary authentication cookie and limited local preferences. Details: Cookie Notice.
13. Changes
We may update this policy as the product grows (for example when a payment gateway is added). Material changes will be reflected by the “Last updated” date on this page. Continued use after an update means you should review the revised policy.
14. Contact
Privacy: privacy@beyondmed.in
General: hello@beyondmed.in
Related: Privacy Policy · Terms of Use · Cookie Notice · Security