Privacy Policy – MedzExchange App

MedzExchange Mobile App

Symbio Farma B.V.
Last updated: 10 September 2026

Applies to: MedzExchange mobile application (iOS and Android)

1. Who We Are

The MedzExchange mobile app is provided by:

Symbio Farma B.V.
Diamantlaan 89
2132 WV Hoofddorp
Netherlands
Trade register (KvK): 94737623

You can reach us per e-mail sales@symbiofarma.nl, if you have any questions or concerns about how we process your data.

Symbio Farma B.V. is the data controller for personal data processed through the app.

2. What The App Is

MedzExchange is a business-to-business platform for the pharmaceutical trade. The app allows companies to publish product enquiries and offers, and to see enquiries and offers published by others.

The app is intended for business use only. It is not intended for consumers, and it does not sell medicines, provide medical advice, or handle patient data.

3. Who Uses The App

The app has two types of user, and we handle their data differently.

Registered users are companies already approved on the MedzExchange platform. They sign in with their existing MedzExchange credentials, and their activity in the app is part of their platform account.

Guest users are companies that are not registered on the platform. They can provide basic contact details to browse enquiries and offers, and to submit an enquiry or offer for our team to follow up. Guest activity is handled separately and does not create a platform account.

4. What Data We Collect
4.1 Registered Users

When you sign in and use the app, we process:

  • Your login credentials, to authenticate you against your existing MedzExchange account
  • Your company reference number and role (customer or supplier)
  • The enquiries, offers and product listings you create, including product details, quantities, prices, countries of origin, lead times and expiry periods
  • Records of actions you take in the app, such as creating, editing or closing a line
  • Your device manufacturer, model, and operating system, recorded against your session for security purposes
  • Login timestamps, and, where applicable, failed sign-in attempts and any resulting temporary lockout

This is largely the same information already held in your MedzExchange platform account, together with the technical and security data described above and in section 4.3.

Your password is used only to authenticate you at the point of sign-in. It is not stored or logged by the app or its servers.

4.2 Guest Users

If you choose to explore the app as a guest, we ask for:

  • Your role (supplier or customer)
  • Company name
  • Contact name
  • Email address
  • Telephone number
  • Country

If you then submit an enquiry or an offer, we also process the commercial details you enter, such as product name, quantity, price, lead time and expiry.

Your session details are used to generate a temporary access token; this token is held only for the duration of your session and is not persisted on your device beyond that. Separately, to save you re-entering your details on a future visit, we store your company name, contact name, phone number and country locally on your device, linked to the email address you provide. On a return visit, if you enter the same email address, these details are filled in automatically; you can clear them at any time using the “Not you? Clear these details” option in the app. This local record stays only on your device, is not sent to our servers on its own, and remains until you clear it or uninstall the app.

4.3 Technical And Security Data

For all users, we process limited technical information necessary to operate the app securely and to protect it against misuse, including:

  • Date and time of sign-in or session activity
  • Device manufacturer, model, and operating system version
  • Where a sign-in attempt fails, the email address entered is recorded in our application logs for security monitoring
  • IP address, recorded via our hosting platform’s monitoring (Azure Application Insights), used to track API request success and errors

Some internal records created when you use the app may include your email address or contact details as part of that record. Examples include an administrative log entry confirming that a new enquiry was created, or a queued email used to deliver a guest submission to our team. These are operational records used to run the service and are not made visible to other users of the app.

4.4 What We Do Not Collect

The app does not collect:

  • Location data
  • Contacts, photos, or files from your device
  • Health or patient data
  • Payment card or bank details
  • Advertising identifiers

The app contains no advertising and no third-party analytics or tracking.

5. Why We Process Your Data, And On What Legal Basis

We process personal data to provide the app’s core functionality (performance of a contract with registered users, or steps taken at your request as a guest), to keep the app and our platform secure (legitimate interest), and to comply with legal obligations where applicable.

We do not use your data for automated decision-making or profiling.

6. What Other Users Can See

Identities are not revealed between trading parties. When a supplier views a customer enquiry, or a customer views a supplier offer, they see only reference numbers and the commercial details of the enquiry or offer. Company names, contact names, email addresses and telephone numbers are never shown to the other party through the app.

Contact details are exchanged only when both parties have been verified and a trading relationship is established outside the app.

7. Guest Submissions: How They Are Handled

This section explains specifically what happens when a guest submits an enquiry or an offer.

Guest submissions are stored separately from the MedzExchange trading platform. They do not create a platform account, an enquiry record or an offer record on the platform.

The submission and your contact details are sent by email to the relevant Symbio Farma team so that we can follow up with you directly. To deliver that email reliably, the message content is held briefly in our email delivery system before and after sending.

Follow-up is carried out manually by a member of our team, normally by email.

If you wish to trade, you will need to complete our full registration process, which includes providing regulatory documentation such as a wholesale distribution licence and GDP certification. That process takes place outside the app.

Your guest details are not shown to any other user of the app.

8. Who We Share Data With

We share personal data only where necessary:

  • Service providers who host and operate the app and platform on our behalf, including our cloud hosting provider (Microsoft Azure) and our software development partner. These parties act on our instructions under written agreements.
  • App stores, to the extent Apple and Google process data as part of distributing the app. Their own privacy policies apply to that processing.
  • Regulators or authorities, where we are legally required to disclose information.

We do not sell personal data, and we do not share it for advertising purposes.

9. Where Your Data Is Held

The app and its supporting services are hosted in an Azure region in West Europe.

Some of our service providers who support and maintain the app and platform may access data from outside the European Economic Area for support and maintenance purposes. Where this occurs, we rely on appropriate safeguards to protect your data to the same standard as within the EEA.

10. How Long We Keep Your Data

We keep data for as long as necessary for the purposes described in this policy, or as required by law. In line with our standard retention practice, this is typically up to 6 years, unless you ask us to delete your data sooner in line with section 12, or a shorter period applies to specific data (such as the on-device guest details described in section 4.2, which you can clear at any time).

11. Your Rights

Under the GDPR you have the right to:

  • Request access to the personal data we hold about you
  • Ask us to correct inaccurate data
  • Ask us to delete your data, where we have no continuing reason to keep it
  • Object to, or ask us to restrict, our processing of your data
  • Receive your data in a portable format
  • Withdraw consent, where we rely on consent

To exercise any of these rights, contact sales@symbiofarma.nl. We will respond within one month.

You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

12. Deleting Your Data

Guest users: email sales@symbiofarma.nl and ask us to delete your guest record. We will delete it unless we are required to keep it for a legal reason.

Registered users: account deletion is handled through your MedzExchange platform account. Contact your account manager, or email sales@symbiofarma.nl.

13. Security

We protect your data using measures including encrypted connections (HTTPS) between the app and our servers, authentication controls, access restrictions for our staff, and separation of guest data from platform trading data.

No system can be guaranteed completely secure, but we take reasonable steps to protect your information and to keep those measures under review.

14. Children

The app is intended for business users only and is not directed at children. We do not knowingly collect data from anyone under 18.

15. Changes To This Policy

We may update this policy from time to time. The current version is always available at https://symbiofarma.nl/medzexchange-app-privacy, and the date at the top shows when it was last changed. Where changes are significant, we will take reasonable steps to notify users.

16. Contact

Symbio Farma B.V.
Diamantlaan 89, 2132 WV Hoofddorp, Netherlands


Email: sales@symbiofarma.nl
Telephone: 0031-2380-80042


Version 1.0 | Last updated: 10 September 2026