Legal

Privacy Policy

Last updated: 13 August 2026

Privacy Policy details

1. Who We Are

This Privacy Policy explains how Mediosta ("Mediosta," "we," "us," or "our") collects, uses, shares, and protects information in connection with:

  • our website, mediosta.com;
  • our AI-powered growth and operations services (lead identification, outreach, sales/workflow automation, and operations automation) provided to our business clients ("Clients"); and
  • our communications with website visitors, prospective clients, and Clients.

Registered address: Mediosta, Fuse Building 40, Beechwood Road, London, E8 3DY, United Kingdom.
Contact: contact@mediosta.com

Mediosta primarily serves business clients in the United States, alongside clients elsewhere. Where we process personal data on a Client's behalf as part of delivering our services, we act as a service provider / processor for that Client, and the Client remains responsible for its own compliance obligations toward the individuals whose data it shares with us.

2. Scope of This Policy

This Policy covers two distinct categories of data handling, which we describe separately below because different rules apply to each:

  • Data about you as a website visitor, prospective client, or Client contact, where Mediosta is the party deciding how and why the data is used.
  • Data processed through our services on behalf of a Client (e.g., business contacts, leads, or prospects that a Client engages us to identify, research, and reach out to, and, where a Client is a HIPAA-covered healthcare entity, PHI that the Client shares with us), where the Client determines the purposes of processing, and we act on their instructions.

3. Information We Collect

a) Information you provide directly: Name, email address, phone number, company name, job title, and any message content, when you contact us, book a call, or enter into a service agreement with us.

b) Information collected in the course of delivering services to Clients: On behalf of our Clients, we identify, research, and contact business prospects using publicly available professional information (e.g., name, job title, company, business email, phone number, LinkedIn profile) and data our Clients provide to us directly. Where a Client is a healthcare or wellness provider subject to HIPAA and shares Protected Health Information with us for a permitted purpose, we handle that PHI under the terms of a separate Business Associate Agreement with that Client, and use it only as instructed and authorized.

c) Information collected automatically: As of this Policy's last update, the Mediosta website does not use cookies or tracking/analytics tools (e.g., Google Analytics, ad pixels). If this changes, we will update this section and, where required by law, obtain your consent first.

d) Payment information: Payments and billing are processed by Stripe. We do not store full payment card details ourselves; Stripe's own privacy policy and terms govern how it handles that data.

4. How We Use Information

We use the information above to:

  • respond to inquiries and book/manage calls;
  • deliver, operate, and improve our AI growth and operations services for Clients;
  • identify, qualify, and conduct outreach to business prospects on behalf of Clients;
  • process payments, invoicing, and subscriptions via Stripe;
  • meet legal, contractual, and security obligations; and
  • where you are a healthcare Client's contact and PHI is involved, carry out the specific, limited purposes authorized under the applicable Business Associate Agreement.

We do not sell personal information, and we do not use PHI for any purpose beyond what a Client has authorized.

5. How We Share Information

We share information with:

  • Acquisity.ai, the platform we use for CRM, data storage, prospect research/data sourcing, and outreach (email and LinkedIn).
  • Stripe, for payment processing, invoicing, and subscription billing.
  • Calendly, for scheduling and managing calls booked through our website.
  • LinkedIn, as a channel through which outreach on behalf of Clients is conducted, subject to LinkedIn's own user agreement.
  • Professional advisors, auditors, and regulators, where necessary for legal or compliance purposes.
  • A successor entity, in the event of a merger, acquisition, or sale of assets, subject to this Policy or a comparable one.

We do not share PHI with any of the above except where necessary to deliver the contracted services and in a manner consistent with the applicable Business Associate Agreement.

6. International Data Transfers

Mediosta currently maintains a UK-registered address and serves Clients primarily in the United States, with a UAE entity forthcoming. Data may accordingly be transferred to, stored, or processed in the United Kingdom, the United States, the United Arab Emirates, and other countries where our service providers operate. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for such transfers.

7. Data Retention

We retain personal data for as long as needed to deliver our services, maintain our business relationship with you or a Client, and meet legal, tax, and contractual obligations, after which it is deleted or anonymized. PHI is retained and disposed of in accordance with the retention and destruction terms in the applicable Business Associate Agreement.

8. Data Security

We use administrative, technical, and organizational safeguards designed to protect personal data, including PHI, against unauthorized access, use, or disclosure. No system is completely secure, and we cannot guarantee absolute security.

9. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal information, or to opt out of certain uses. This includes rights available to California and other U.S. state residents under applicable state privacy laws, and to UK/EU residents under the UK GDPR or EU GDPR where applicable. To exercise these rights, contact us at contact@mediosta.com. If you are the contact of a healthcare Client and your request relates to PHI, we will direct you to that Client, as they control that data.

10. Children's Privacy

Mediosta's website and services are directed at businesses and professionals, not children. We do not knowingly collect personal information from individuals under 16.

11. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by an updated "Last updated" date, and where required by law, we will provide additional notice.

12. Contact Us

Questions about this Policy or how we handle your data can be sent to contact@mediosta.com or Mediosta, Fuse Building 40, Beechwood Road, London, E8 3DY, United Kingdom.