Privacy Policy
HemoLoop · v1.0
Effective date: May 17, 2026
Last updated: May 17, 2026
Summary — HemoLoop does not collect, process, or transmit any personal data from its users. All information entered in the application is stored exclusively on the user's device (browser local storage) and never leaves the device. No cookies, analytics, advertising, or third-party tracking services are used within the application.
1. Controller identity
Data controller (to the extent any processing exists):
Dr. Martín Alberto Carballo
Cardiologist · Buenos Aires, Argentina
Email: mcarballo22@gmail.com
HemoLoop is an educational tool intended exclusively for healthcare professionals, developed independently and on a non-commercial basis.
2. Information we do NOT collect
HemoLoop does NOT collect, NOT transmit, and NOT store on external servers any of the following data:
-
Personal identifying information (name, ID number, medical record number, date of birth, address)
-
Health information or clinical data of real patients
-
Geolocation data
-
Unique device identifiers (IMEI, MAC, advertising ID)
-
IP addresses
-
Usage data or metrics (session duration, modules visited, frequency of use)
-
User contact information
3. Local on-device storage
HemoLoop uses the browser's local storage (localStorage) to save exclusively:
-
Language preference (ES / EN)
-
Visual theme preference (light / dark)
-
Record of acceptance of the legal notice (date and version)
-
Clinical cases and hemodynamic data manually entered by the user for didactic purposes
This information:
-
Remains exclusively on the user's device.
-
Is not transmitted to servers or third parties.
-
Is not accessible to the author of the application.
-
Can be deleted at any time through the browser settings (clear site data) or from the Patient tab → Clear all patient data.
IMPORTANT WARNING: Do not enter real patient identifying information. Use exclusively synthetic, anonymized, or fictional data for training purposes. Liability for the entry of third-party personal data lies entirely with the user, in accordance with applicable data and health information protection regulations (Ley 25.326 in Argentina, EU Regulation 2016/679 in the European Union, HIPAA in the United States).
4. Cookies and analytics
HemoLoop does not use cookies, does not integrate analytics services (Google Analytics, Firebase, or others), does not contain tracking pixels, does not include advertising, and does not share data with third parties for commercial purposes.
Note about the site hosting this policy: this document is published on a page built with Wix (wix.com). Wix may set its own functional and analytics cookies when you visit this page, in accordance with its own privacy policy. These practices are outside the control of HemoLoop. Consult Wix's privacy policy at https://www.wix.com/about/privacy.
5. Third-party links
HemoLoop contains external links to:
-
DOIs and academic articles hosted by scientific publishers (NEJM, JACC, JASE, AJP, among others)
-
Voluntary donation platforms: Ko-fi and Cafecito
When clicking on these links, the user leaves HemoLoop and enters third-party sites with their own privacy policies and data collection practices. We are not responsible for the privacy practices of those services. If the user makes a donation through Ko-fi or Cafecito, those platforms will process payment information under their own terms.
6. Children's privacy
HemoLoop is intended exclusively for healthcare professionals of legal age. We do not knowingly collect information from minors under any circumstances. If you become aware that a minor is using the application, please contact us at the email indicated above.
7. User rights by jurisdiction
Since HemoLoop does not collect personal data, the rights enumerated below are included for informational and formal compliance purposes. To the extent that the user has generated data in local storage, the user retains absolute control over that data from their own device.
7.1 Users in Argentina
Under Law No. 25.326 on Personal Data Protection and ANMAT Disposition 727/2013, the user has ARCO rights: Access, Rectification, Cancellation, and Opposition over their personal data. The supervisory authority is the Agencia de Acceso a la Información Pública (AAIP): www.argentina.gob.ar/aaip.
7.2 Users in the European Union, EEA, and United Kingdom
Under Regulation (EU) 2016/679 (GDPR), the user has the following rights regarding their personal data:
-
Right of access (Art. 15 GDPR)
-
Right to rectification (Art. 16 GDPR)
-
Right to erasure or right to be forgotten (Art. 17 GDPR)
-
Right to restriction of processing (Art. 18 GDPR)
-
Right to data portability (Art. 20 GDPR)
-
Right to object (Art. 21 GDPR)
-
Right not to be subject to automated decision-making (Art. 22 GDPR)
The user also has the right to lodge a complaint with the competent supervisory authority in their country of residence (e.g., AEPD in Spain, CNIL in France, BfDI in Germany, Garante in Italy, ICO in the United Kingdom).
7.3 Users in the United States
HIPAA: HemoLoop does not constitute a covered entity under the Health Insurance Portability and Accountability Act (45 CFR §160.103). It is not a healthcare provider, health plan, or healthcare clearinghouse. Therefore, HIPAA does not apply directly to this application.
If the user, in their capacity as a healthcare professional, were to enter Protected Health Information (PHI) into HemoLoop, that user would act as the covered entity or business associate under HIPAA and would be solely responsible for compliance with that regulation.
Users in California (CCPA / CPRA, Cal. Civ. Code §1798.100 et seq.): since we do not collect personal information from consumers, we do not sell or share personal information. The "Do Not Sell or Share My Personal Information" rights and access or deletion rights under CCPA/CPRA do not apply in substance with respect to HemoLoop.
8. International data transfers
Since no personal data is collected from the user, no international data transfers take place. All information generated by the user remains on the user's own device.
9. Security
Although we do not process data on our own servers, we recommend that the user implement reasonable security measures on their device (screen lock, disk encryption, updated browser) to protect data stored locally that they themselves have generated within the application.
10. Changes to this policy
This policy may be updated periodically. The current version will always be available at this URL. The date of last update is indicated at the top of the document. Substantive changes will be notified within the application by requesting renewed acceptance of the legal and usage notice.
11. Contact
For inquiries related to this privacy policy or to the application:
Dr. Martín Alberto Carballo
Email: mcarballo22@gmail.com
© 2026 Dr. Martín Alberto Carballo · HemoLoop v1.0