Cookie policy

Last updated: August 5, 2026

At DEEPIC ("DEEPIC", "we", "us"), the trust and security of the people who entrust us with their medical documents and health data are at the heart of our mission. This Cookie Policy (the "Policy") explains how we use cookies and similar technologies on our DEEPIC platform and applications (the "Service"), what types of cookies we use, on what legal basis, and how you can exercise your choices.

Given the particularly sensitive nature of the data processed by DEEPIC — personal data relating to health within the meaning of Organic Law No. 2004-63 of 27 July 2004 and data of a "special category" within the meaning of the applicable international frameworks — this Policy is designed to be stricter than a standard cookie policy, with a guiding principle: no cookie used by DEEPIC serves to profile, track or monetise health information.

For more information on how DEEPIC collects and processes personal data and health data, please consult our Privacy Policy and our Medical Data Security Charter.

1. Applicable legal framework

DEEPIC designs its cookie policy to cumulatively comply, depending on where its users are located and where its data is hosted:

1.1 In Tunisia

  • Organic Law No. 2004-63 of 27 July 2004 on the protection of personal data, in particular its Articles 62 to 65 which specifically govern the processing of personal data relating to health (processing reserved for doctors or persons subject to professional secrecy, reinforced consent, power of the INPDP to restrict or prohibit the dissemination of such data);
  • Decree No. 2007-3004 of 27 November 2007 setting the conditions and procedures for declaration and authorisation for the processing of personal data, and the deliberations of the National Authority for the Protection of Personal Data (INPDP), in particular those relating to health data;
  • Law No. 5-2004 of 3 February 2004 on computer security, which imposes obligations to secure information systems;
  • Convention 108 of the Council of Europe and its Additional Protocol (Convention 108+), ratified by Tunisia, which set international data protection standards;
  • The applicable provisions of the Telecommunications Code and the regulations relating to cross-border transfers of personal data (prior authorisation required for any transfer outside Tunisia, except for the exceptions provided for by law).

1.2 Internationally

  • The General Data Protection Regulation (GDPR – Regulation (EU) 2016/679), for users located in the European Union or the European Economic Area, in particular its Article 9 on health data as a special category of data;
  • The equivalent data protection laws of the other jurisdictions in which DEEPIC offers its services (e.g. national health data protection laws), applied in accordance with the principle of the most favourable protection for the data subject;
  • The principles of the conventions and treaties administered by the World Intellectual Property Organization (WIPO) relevant to the protection of DEEPIC's content, databases, software, interfaces and trademarks, in particular the Paris Convention for the protection of industrial property, the Berne Convention for the protection of literary and artistic works and the WIPO Copyright Treaty ("WCT") — this component covers the intellectual property of the platform and its technologies, and not the health data themselves, whose protection falls under data protection law.

2. What is a cookie?

Cookies are small text files placed on your device when you use the DEEPIC Service. They enable us to recognise your device, maintain your secure session while you consult or share medical documents, remember your preferences and, to a strictly limited and anonymised extent, measure the technical performance of the platform.

DEEPIC does not use cookies to infer, declare or classify a state of health, nor to build marketing profiles from platform usage.

3. Types of cookies used by DEEPIC

3.1 By issuer

  • First-party cookies: placed directly by DEEPIC to ensure authentication, session security and the proper functioning of medical document transfers;
  • Third-party cookies: placed by technical providers strictly governed by a subcontracting contract compliant with Article 55 et seq. of Law No. 2004-63 and, where applicable, Article 28 of the GDPR (secure hosting, protection against automated attacks, anonymised audience measurement). DEEPIC does not allow any third-party cookie for advertising purposes on pages where medical documents or health data are consulted or transmitted.

3.2 By purpose

  • Strictly necessary cookies: essential for authentication, session security, protection against request forgery (CSRF), the integrity of medical document transfers and the storage of consent. They do not require prior consent and cannot be disabled without preventing secure access to the Service;
  • Functional cookies: facilitate the user experience (language, practitioner/patient display mode, resuming an interrupted document upload). Subject to user consent;
  • Audience measurement cookies: when configured to be exempt from consent in accordance with the applicable frameworks (strictly aggregated, anonymised data, no cross-referencing with health data, limited retention period), they are used solely to measure the technical performance of the platform; failing such an exempted configuration, prior user consent is required;
  • Marketing or advertising cookies: DEEPIC does not use advertising cookies or marketing tracking on the authenticated areas of the Service where medical documents are handled. If such cookies were to be used on non-authenticated pages (e.g. showcase website), they would be subject to free, specific and revocable consent, separate from any access to the medical document sharing Service.

4. Cookies and health data: reinforced guarantees

  • No cookie is used to record the content, nature or clinical metadata of shared medical documents (CT scans, MRIs, reports, laboratory results); this data is processed exclusively via the secure and encrypted channels of the Service, outside the cookie mechanism;
  • Strictly necessary cookies related to security (session, two-factor authentication, CSRF token) are configured with the Secure, HttpOnly and SameSite attributes to limit the risks of interception or diversion;
  • In accordance with Article 63 of Law No. 2004-63, access to features enabling the consultation of health data remains conditional on enhanced authentication, independently of functional or audience measurement cookies;
  • DEEPIC does not allow any subcontractor to reuse the data collected via cookies for purposes other than those strictly defined in the subcontracting contract.

5. Consent and withdrawal of consent

On your first visit, a consent banner allows you to accept or refuse non-essential cookies. You can at any time modify your choices via the preference centre accessible from the footer of the Service, or withdraw your consent as easily as it was given. Refusing functional or audience measurement cookies does not affect your ability to consult or share your medical documents, only strictly necessary cookies being required for this purpose.

6. Managing cookies via your browser

You can also control cookies via your browser settings. Please note that blocking strictly necessary cookies may prevent secure access to your medical documents on DEEPIC.

  • Google Chrome: manage cookies in Chrome
  • Mozilla Firefox: manage cookies in Firefox
  • Microsoft Edge: manage cookies in Edge
  • Safari (macOS): manage cookies in Safari
  • Safari (iOS): manage cookies in Safari mobile

7. International transfers of cookie-related data

Where cookies involve a transfer of data outside Tunisia (for example to a hosting or audience measurement provider located abroad), DEEPIC ensures that this transfer is based on an appropriate authorisation or legal basis in accordance with Article 52 of Law No. 2004-63, and, where the GDPR applies, on a recognised mechanism (standard contractual clauses, adequacy decision or equivalent appropriate safeguards).

8. Your rights

In accordance with Law No. 2004-63 and, where applicable, the GDPR, you have a right of access, rectification, objection, erasure and withdrawal of consent concerning the data collected via cookies. For health data, these rights are exercised under the reinforced conditions provided for in Articles 62 to 65 of Law No. 2004-63. You may also lodge a complaint with the National Authority for the Protection of Personal Data (INPDP) or, for users covered by the GDPR, with the competent supervisory authority.

9. Amendments to this Policy

DEEPIC may amend this Policy to reflect technical, legal or regulatory developments, in particular any change to the Tunisian or international legal framework applicable to the protection of health data. Any substantial update will be published on the Service and, where applicable, communicated by email or in-app notification.

10. Contact

For any question relating to this Policy, to cookies or to the processing of your data, including your health data, you may contact the DEEPIC data protection officer at: dpd@DEEPIC.net, or our support service at contact@DEEPIC.net.