By using Dalilent.com (the “Site”, “we”, or the “Service”)—whether via browser, mobile app, or any related WebView—you confirm that you have read and understood this policy and agree to the processing of your personal data as described herein, in accordance with the General Data Protection Regulation (GDPR) and applicable Swedish/EU data protection laws.
Who We Are
This Site is operated and managed by the owner/entity referenced on the “Contact Us” page. We act as the Data Controller for personal data processed in connection with medical educational services, membership management, payment administration, and medical tools/calculators.
For GDPR matters, you may contact us via:
- The contact form on the “Contact Us” page.
- The email address published on the same page.
Scope
This policy applies to:
- Visiting and browsing Dalilent.com.
- Using medical content, articles, on-call sheets, protocols, guides, and MCQ sections.
- Creating an account, logging in, purchasing or activating membership/subscriptions (including payments via PayPal or Stripe).
- Using interactive medical tools, calculators, search features, and assistants such as the “Vertigo Assistant”.
This policy does not apply to third-party websites/services/apps you may access via links from our Site. Those parties have their own privacy policies.
Legal Bases for Processing (GDPR)
We process personal data based on one or more of the following legal bases under GDPR and Swedish supplementary law:
- Contract performance: creating accounts, activating membership, granting access to paid/locked features.
- Legal obligation: retaining financial/tax records where applicable; responding to lawful authority requests.
- Legitimate interests: improving Site performance, securing the platform, preventing fraud/abuse, internal analytics with appropriate balancing of rights.
- Consent: optional cookies; opt-in educational/notification emails; storing certain calculator results in your account (where relevant).
Data We Collect
- Name or display name
- Email address
- Username
- Password (hashed — not visible to us)
- Membership status (Active/Pending/Expired)
- Preferred UI language & display preferences
- We do not store card details (PayPal/Stripe handle this)
- Receipt / Transaction / Order ID / Token
- Plan type (1 month, 12 months, etc.)
- Subscription start & expiry dates
- Messages via “Contact Us” form
- Emails sent directly to us
- Support requests, feedback, bug reports
- IP address (partial/masked where feasible)
- Approximate country/region
- Pages visited, session duration, UI interactions
- Session identifiers & login cookies
- Security logs (attack patterns, IP blocking)
- MCQ results (correct/incorrect counts, sections completed)
- Data entered into calculators/scales (clinical values, BP, HR, scores)
- Notes/comments linked to your account (if enabled)
- Essential cookies (session/login, security, load balancing)
- Preference cookies (language, UI settings)
- Analytics cookies (Google Analytics or similar — consent-based)
Important: The Site is designed for ENT clinicians/residents/students and is not intended for entering fully identifiable patient data (full name, national ID, home address). Do not enter information that directly identifies a patient. If you do, you are responsible for having a lawful basis; we process it only to the minimum necessary to provide the tool.
How We Use Your Data
- Account & membership management: Create accounts, authenticate logins, manage membership state, gate locked content to active members. Legal basis: contract performance, legitimate interests.
- Payments & subscriptions: Confirm payments via PayPal/Stripe, associate with accounts, record plan type and expiry. Legal basis: contract performance, legal obligation.
- Deliver educational content & tools: Provide access to medical chapters/sections, MCQs, assistants, calculators; store results for “My Results” (visible only to you). Legal basis: contract performance, legitimate interests.
- Improve and develop the Service: Analyze usage patterns, measure device/platform performance to enhance UX. Legal basis: legitimate interests; consent for optional analytics cookies.
- Security & fraud prevention: Detect unauthorized access, brute force, DDoS attempts; restrict suspicious accounts/sessions. Legal basis: legitimate interests; legal obligation where applicable.
- Communications: Respond to support requests; send important membership/legal/technical notices; send educational updates if you opted in (unsubscribe anytime). Legal basis: contract performance, legitimate interests, or consent.
- Legal compliance: Respond to lawful authority requests, maintain financial records as required. Legal basis: legal obligation.
Cookies
- Essential cookies: Required for login, security, and session/payment protection — cannot be disabled via consent banners as they are technically necessary.
- Preference cookies: Remember language and basic UI settings.
- Analytics cookies: Measure traffic and usage patterns, enabled based on your consent where required by law.
You can manage cookies via: the cookie consent banner (if shown), or your browser settings (block/delete cookies). Disabling certain cookies may reduce functionality or prevent successful login.
Sharing Data with Third Parties
We do not sell or rent personal data. We may share limited data with service providers strictly as necessary:
- Hosting/infrastructure providers: to run the Site securely and reliably.
- Payment providers (PayPal/Stripe): to confirm transactions; sensitive payment data is processed by them.
- Analytics/performance providers: e.g., Google Analytics — potentially receiving anonymized/masked usage data.
- Email/notification providers: to send activation notices, important updates, or subscribed newsletters.
- Professional advisors: legal/accounting support when necessary.
- Authorities: where required by law or valid legal order.
We require appropriate data protection agreements and request that providers process data only for the stated purposes and in compliance with law.
Data Retention · Security Measures
We retain personal data only as long as needed for the purposes described or to meet legal obligations, then delete or anonymize where feasible:
- Account/membership data: while account is active; deleted/anonymized on request, retaining what is legally required (e.g., payment records).
- Payment/invoice records: typically several years per accounting/tax laws.
- Support communications: for a reasonable period for documentation, then deleted/anonymized.
- Security logs: shorter periods based on technical need to mitigate attacks.
- MCQ results/educational statistics: while account is active for “My Results”, unless you request deletion.
We apply reasonable technical and organizational measures, including:
- HTTPS to secure all communication.
- Hashed/encrypted password storage (not plain text).
- Restricted database access to authorized personnel only.
- Firewalls and security plugins to monitor and block attacks.
No system can guarantee 100% security on the internet. You use the Site at your own risk, while we commit to reasonable care for data protection.
Your Rights Under GDPR
If you are in the EU/EEA, you have rights under GDPR, including:
Confirm whether we process your data and obtain a copy.
Correct inaccurate data or complete incomplete data.
“Right to be forgotten” — request deletion in certain cases, subject to legal exceptions.
Restrict processing in certain circumstances.
Receive your data in a structured, machine-readable format where applicable.
Object to processing based on legitimate interests, including direct marketing.
Where processing is consent-based, withdraw anytime without affecting prior processing.
To IMY (Sweden) or your local EU supervisory authority.
To exercise these rights, contact us via “Contact Us”. We may request verification of identity before fulfilling requests.
Children · Automated Decisions · Analytics · AI · Policy Changes
The Site is primarily intended for adult clinicians/residents/students and is not directed to children. If we learn that we collected personal data from a child without appropriate consent, we will take reasonable steps to delete it promptly.
12 — Automated Decisions and ProfilingWe generally do not rely on fully automated decisions that produce significant legal or similarly significant impacts on users. We may perform limited internal profiling — for example, distinguishing active vs. inactive users to link membership status to access permissions. If we introduce significant automated decision-making in the future, we will update this policy accordingly.
13 — Analytics, Statistics, and Research UseWe may use your data—after removing direct identifiers—to produce: statistics on active users and most-used sections, educational analytics to improve questions and protocols, and aggregated reports on tool/calculator usage. Such analytics are typically aggregated or anonymized and used only to improve the Service.
14 — Use of Data for AI PurposesWe commit not to use your identifiable personal data to train external AI models or commercial data platforms without a clear legal basis and your explicit consent where required. We may use fully anonymous or aggregated data (without personal identifiers) to improve educational tools, provided it cannot identify you as an individual.
15 — Changes to This Privacy PolicyWe may update this policy due to legislative/regulatory changes (GDPR or Swedish law updates) or service changes (new tools, payment/membership changes). If we make material changes, we will update the “Last updated” date and may notify you by email or via a Site notice. Continued use after publication means you accept the updated version.
Contact
For questions or requests regarding privacy, your rights, or this policy, contact us via:
- The “Contact Us” form on the Site.
- The email address shown there, with “Data Privacy” in the subject line to help route your request.
We will respond within a reasonable timeframe, in accordance with our legal obligations.