Compliance
Biomedup is designed to support GDPR-aligned practices. This page explains our posture and the providers we rely on, in plain language.
Data minimization
We collect only what the product needs: your account details, your facility's equipment records, and the operational records you create. The public website collects nothing beyond a demo request you choose to submit. No analytics or advertising trackers are used anywhere.
Access control
Every request is verified server-side; authorization is enforced by role-based permissions and database row-level security. Your facility's data is isolated from every other facility; cross-facility access is structurally impossible, not just hidden in the interface.
Auditability
Every member action (who did what, and when) is recorded in an append-only audit trail that facility administrators can review. Records follow a no-delete lifecycle: history is preserved, and corrections are recorded as new events.
Your data, your control
Your data belongs to your facility. Administrators can export reports at any time, and account removal requests are honored through our support contact. We never sell data or share it with advertising tools.
What Biomedup is and is not
Biomedup is a software tool that helps customers manage equipment data responsibly. Biomedup is not a regulator, a certification body, or a legal advisor, and we do not guarantee any specific regulatory outcome. Compliance obligations remain with each customer organization; we provide the tooling that supports them.
Key providers
- Cloud infrastructure · Secure application hosting, deployment, and global delivery
- Backend services · Database, authentication, and secure file storage
- Email infrastructure · Transactional email delivery for notifications and business communications
Questions about compliance? Email hello@biomedup.com.