What data of yours Medline processes, why, who else receives it, how long it is kept and how to have it corrected or deleted. Colombian data protection law.
Document version: 2026-01-v1
Who is responsible for your data
The controller of your personal data is Thinking AI S.A.S., tax ID (NIT) 901.302.982, domiciled in Medellín, Colombia, which operates the Medline platform and the medlinecare.co website.
Address for legal notices
Thinking AI S.A.S., tax ID (NIT) 901.302.982 — Medellín, Colombia. Notices are served in writing at Contactenos@medlinecare.co. A communication sent there is deemed received, and it is what starts the ten- and fifteen-business-day periods set out below.
Data subject support e-mail
Contactenos@medlinecare.co — this is the habeas data mailbox, the same one shown in the site footer. Write from your account e-mail address, or prove your identity some other way.
Phone
WhatsApp 301 820 1118. Use it to ask questions and have the procedure explained to you. Formal requests are answered in writing, at the e-mail address above, because that is what leaves a dated record — and that date is what proves it was handled on time.
What Medline is and what it is not
Medline is a technology platform that connects people with healthcare providers: doctors, laboratories, pharmacies and couriers. It does not deliver the medical care itself and it is not licensed as a healthcare institution by the Colombian health authority.
That distinction changes who keeps what. The clinical record of a medical encounter is produced and kept by the provider who treated you, not by Medline. What Medline stores is what you load into your account and what is generated by using the platform: your orders, your appointments, your reminders and the health information you choose to record.
What data we process
Identification
First and last name, identity document type and number, and date of birth. Collected when the account is created. The date of birth also serves one specific purpose: Colombian Law 1799 of 2016 forbids selling cosmetic procedures to people under 18, and it is only consulted when someone tries to buy one of the flagged products.
Contact
E-mail address and mobile phone number. The phone number is verified with a one-time code, and the channel that delivered the code is stored: it is the evidence that the number belongs to whoever claims it.
Health data (sensitive)
Conditions and diagnoses, allergies, medicines and doses, laboratory results, vital signs, blood glucose readings, weight, vaccinations, skin lesion follow-up, the orders and prescriptions a provider sends you, and your conversations with the Soul assistant.
Prescriptions you upload
The photograph of an external medical prescription, when you attach one in order to buy a medicine that requires it. That image may carry your name, the doctor’s name and sometimes the diagnosis.
Location and addresses
The city you choose for delivery, the delivery addresses you save and, if you grant the browser or phone permission, your approximate location so we can look for nearby pharmacies. The permission can be denied and withdrawn; without it the platform still works and asks you for the city.
Payments
The amount, the order reference and the payer’s e-mail address. Medline does not store your card number: card data is captured and kept by the payment gateway, and what comes back to the platform is a token from which the number cannot be reconstructed.
Technical data
IP address and browser or device identifier. They are used for two things and only two: to record when and from where you granted your authorization and who accessed clinical information, and to limit automated use of the public catalogue. There is no behavioural analytics and no advertising.
Health data is sensitive: you are not required to provide it
Colombian Law 1581 of 2012 classifies anything health-related as sensitive data, and its article 6 requires that you be warned of this when it is requested. No one is obliged to hand over sensitive data, and refusing to do so cannot cost you access to whatever does not depend on it.
In practice: you can create an account, search for medicines, compare prices and browse the doctor directory without recording a single item of health data. What does not work without it is what is built from it — your record, your reminders, Soul’s guidance — and in each case you are told beforehand.
What we process your data for
The purposes are deliberately kept apart, because you may accept some and not others. Each one is stored as a separate authorization, together with the version of the text you accepted and the date:
Data processing — running the service
Creating and maintaining your account, handling your orders, charging for them, coordinating delivery, booking appointments and tests, and communicating with you about all of the above. This is the only mandatory purpose: without it there is no account.
Use of clinical data by the Soul assistant
Allowing Soul to read a summary of your health information — age, allergies, conditions, active medicines and latest readings — in order to guide you. Soul does not diagnose, does not prescribe and does not interpret results. You may decline it, or revoke it later: the assistant stops working and the rest of the platform is unaffected.
Telemedicine
The informed consent required by Colombian Resolution 2654 of 2019 in order to treat you remotely. It is requested by the provider who treats you, through the platform.
Commercial communications
News, promotions and notices about new sections. This is the only purpose that is not needed for anything you buy, and it can be revoked with no consequences whatsoever.
Sharing with one specific provider
Authorizing ONE specific professional or institution to send you, through the platform, the orders and prescriptions they sign for you. It is not a master switch: each provider is authorized separately, and revoking one does not affect the others.
Your data is not used outside these purposes. In particular, it is not sold, it is not handed to third parties for their own benefit, and it is not used to build advertising profiles.
How your authorization is requested, stored and revoked
Your authorization is requested before the data is processed, by ticking a box that is never pre-ticked. It is not stored as a plain "yes": what is stored is the purpose, the exact version of the document you accepted, the date and time, and the IP address and browser you used. That is what makes it possible to prove later which text you read and when.
When the substance of this policy changes, its version goes up and you are asked to authorize again. Previous authorizations are kept as evidence of what you accepted at the time; they are not overwritten.
Revoking is equally explicit: the revocation is recorded with its date and the service that depended on that purpose stops operating. Revoking the mandatory purpose amounts to requesting that your account be closed.
Who else processes your data
In order to run the service, some providers process data on Medline’s behalf. These are the ones that receive data today:
Anthropic (United States)
The language model behind the conversation with Soul. It receives what you type in the chat and a summary of your health information: age, allergies, conditions, active medicines and latest readings. Only if you authorized the Soul purpose.
OpenAI (United States)
Two distinct uses. Closed knowledge questions — the reference range of an analyte, a medicine’s data sheet — for which it receives the lab value plus sex and age, without your name. And transcription of audio when you describe your symptoms by voice: the audio is turned into text and discarded, not stored.
Mapbox (United States)
Draws the pharmacy maps and powers the street search. The search receives the address text you type and the city. The map receives the pharmacy’s coordinates, never yours.
Pharmacies, laboratories and couriers in the network
They receive the minimum needed to fulfil your specific request: what was ordered, where it goes and how to reach you. The pharmacy that is awarded the order is moreover the only one that can open the prescription photo for that line, and every opening is logged.
And these are wired into the platform but do not receive anything yet, because the feature that uses them is not active. They are named so the list does not change behind your back the day they are switched on: Wompi and Stripe (card payments), Twilio and Meta’s WhatsApp Cloud API (delivering the verification code to your phone), Resend (delivering the verification code to your e-mail), and Google and Apple (identity verification if you sign in with those accounts). No video consultation provider has been contracted, and notifications do not go out to any third party.
When a doctor treats you through the platform, their scheduling data and yours are exchanged with Laniakea Care, the system where that professional runs their practice. There the doctor is not acting on Medline’s behalf: they are themselves responsible for the clinical record they produce.
Data leaving Colombia: Anthropic, OpenAI and Mapbox process in the United States. All three are processors — they handle data on Medline’s behalf and not for their own benefit — so what takes place is not a transfer to another controller but a transmission, and it rests on two things at once: the transmission contract required by article 25 of Decree 1377 of 2013 — the data processing agreement each of the three publishes, setting out what they may and may not do with what they receive — and your authorization, which is prior and express. [PENDING: accept those three agreements in each provider’s console and record the date; as of today nobody has verified that they are signed].
How your data is protected
Every access to clinical information is logged: who entered, what they looked at, whose data it was, from which IP address and when. It is audited even when the one looking is you, because with a stolen session that line is the only evidence left.
The photo of a prescription you attach is stored encrypted, on our own infrastructure and not on a third-party service, and can only be opened by the pharmacy awarded that order line. There is no way for another pharmacy, the courier or any third party to open it.
Communications between your browser or phone and the platform travel encrypted.
External provider credentials live only on the server. None of them travel inside the app you install or inside the page your browser downloads.
How long data is kept
The photo of an attached prescription
30 days. Once the period expires the image is destroyed and only the record that it existed and when it was deleted remains. The supporting document that health regulations require to be kept is kept by whoever dispensed, which is not Medline.
The audio of your symptoms
Not kept. It is transcribed during the request itself and discarded; what remains is the text.
Your health information while the account is active
Kept for as long as you keep the account, because that is what the account is.
The access log and the audit trail
24 months. This is the line that records who accessed your clinical information, when and from where: while it lives, an improper access can be proven.
Your conversations with Soul
24 months from the last time you wrote in them. You may revoke the Soul purpose sooner: the assistant stops reading your health information from that moment on.
The supporting records of your orders and payments
10 years. This is not a Medline decision: article 60 of the Colombian Commercial Code and article 28 of Law 962 of 2005 require every merchant to keep its books and the papers supporting them for that period. These are the purchase documents — what, how much and when — not your health information.
The clinical data in your record
15 years from the last recorded episode of care, which is the period set by Colombian Resolution 839 of 2017 (Ministry of Health) for clinical records. The record of each episode is kept by the provider who treated you; what you load here is kept on the same basis, because deleting it sooner would strip the backing from data that may be needed years later.
Two of those periods are far longer than the others, and it is worth saying why: it is not that Medline wants to keep them, it is that it cannot delete them any sooner. The ten years for accounting records and the fifteen for clinical data are set by law, not by a policy of ours, and no deletion request can shorten them while that law applies. What does happen when you close your account is what the "What 'delete' means here" section says: the rest is anonymized, and what remains is that plus the audit trail.
Your rights
Colombian Law 1581 of 2012 grants you, as the data subject, these rights over your data:
To know: to find out what data of yours we hold, free of charge and as often as you wish whenever there has been a change; once a month otherwise.
To update and rectify data that is incomplete or inaccurate.
To revoke your authorization, at any time and without giving reasons, for any purpose other than running the service.
To request deletion of your data where no legal or contractual obligation requires us to keep it.
To lodge complaints with the Colombian Superintendence of Industry and Commerce if you believe the law has been breached. The law itself asks that you first exhaust the enquiry or complaint procedure with us.
To be informed of the use made of your data, upon request.
What "delete" means here
This deserves to be said precisely, because the word promises more than any clinical system can deliver. Closing your account does not trigger a cascading deletion: it anonymizes your data and keeps only what other regulations require us to keep — the accounting records of what you bought and the dispensing records — plus the audit trail, which by definition cannot be erased without destroying the evidence of what was done with your data.
The same applies to a revoked authorization: it is marked as revoked with its date and kept, because it must be possible to prove that it was in force while it was.
How to exercise your rights: enquiries and complaints
The area responsible for handling enquiries and complaints about personal data is the Medline support team, and the channel is Contactenos@medlinecare.co. Simply write from your account e-mail address, or otherwise prove your identity, and state what you want: to know, update, rectify, revoke or delete. If you are acting on behalf of another person, representation must be proven.
Enquiry
Answered within a maximum of ten (10) business days from receipt. If that is not possible, we tell you the reasons and the date on which it will be answered, which cannot be more than five (5) further business days.
Complaint
Handled within a maximum of fifteen (15) business days from the day after receipt. If that is not possible, you are told the reasons and the new date, which cannot be more than eight (8) further business days. If the complaint arrives incomplete, we ask you to complete it within the following five (5) days.
Every request is recorded with its date, which is what makes it possible to prove that it was handled on time.
Minors
Processing a minor’s data is only permissible where it serves their best interests and respects their fundamental rights, and it requires authorization from whoever holds parental authority. Where an account records data about a dependent minor, the person creating the account declares that they are entitled to authorize it.
Separately, and under a different rule: Colombian Law 1799 of 2016 forbids cosmetic medical and surgical procedures on people under 18, and parental authorization is not an exception to it. That is why the platform checks age before selling one of those products.
Effective date, changes and databases
This policy applies from the date it is published and remains in force for as long as Medline operates. Databases are kept for as long as they are necessary for the declared purposes and for whatever periods the law requires.
Any substantial change is communicated through the platform or by e-mail before it takes effect, and raises the document version, which means you are asked to authorize again.