Privacy policy
Last updated: 24 May 2026.
MDDR is an independently operated Australian medical news digest. This Privacy Policy explains what personal information we collect, how we use it, who we use to operate the service, and how you can contact us about privacy.
MDDR is intended for medical and health professionals. MDDR is not medical advice, clinical advice, legal advice, or a substitute for reading original sources, regulator notices, clinical guidelines, or primary literature.
Contact
For privacy questions, access requests, correction requests, deletion requests, or complaints, contact us at privacy@mddrnewsletter.com.
What we collect
We collect only the information reasonably necessary to operate MDDR.
- Email address— collected when you subscribe to receive the MDDR newsletter.
- Email engagement and delivery events— such as deliveries, bounces, complaints, unsubscribes, opens, and clicks, where reported by our email provider.
- Subscription and unsubscribe records— such as timestamps, confirmation status, unsubscribe status, suppression-list status, and random confirmation or unsubscribe tokens.
- Website analytics and technical information— such as page views, referrers, device or browser information, general location information, and other analytics reported by Vercel Analytics or our hosting infrastructure.
- Communications you send us— if you reply to an email or contact us, we may collect your email address and the contents of your message so we can respond.
We do not ask subscribers to provide their name, AHPRA number, profession, specialty, workplace, patient information, health information, Medicare number, or payment information.
How we use personal information
We use personal information to:
- send you the MDDR newsletter;
- confirm and manage newsletter subscriptions;
- process unsubscribe requests;
- maintain suppression lists so we do not email people who have unsubscribed, bounced, or complained;
- monitor email delivery, open, click, bounce, and complaint rates;
- maintain email deliverability and protect sender reputation;
- understand website and newsletter performance;
- improve MDDR content, format, reliability, and user experience;
- respond to questions, feedback, corrections, and privacy requests;
- protect the service from misuse, spam, abuse, or security issues;
- keep records reasonably necessary for compliance and disputes; and
- comply with applicable laws and legal obligations.
Newsletter consent and unsubscribe
We send MDDR only to people who have subscribed or where we otherwise have a lawful basis to send the email.
You can unsubscribe at any time using the unsubscribe link in any MDDR email. We will process unsubscribe requests as soon as practicable. Even after you unsubscribe, we may retain limited information necessary to maintain a suppression list, record your unsubscribe request, prevent further emails, and manage complaints or compliance issues.
Analytics
We use Vercel Analytics to understand how visitors use the MDDR website. Vercel Analytics is used to provide aggregate website analytics and does not require third-party cookies.
We also use analytics and event data from Resend to understand email delivery and engagement, including whether emails are delivered, opened, clicked, bounced, marked as spam, or unsubscribed from.
You may be able to reduce some email tracking by disabling remote image loading or using privacy features in your email client.
Service providers
We use trusted third-party service providers to operate MDDR. These providers may process information only as needed to provide services to us, subject to their own terms, privacy policies, and security practices.
- Resend— email delivery, newsletter sending, delivery events, bounce handling, complaint handling, unsubscribe handling, open tracking, and click tracking.
- Neon— production Postgres database hosting.
- Vercel— website and application hosting, deployment, infrastructure, logs, and Vercel Analytics.
We do not sell or rent subscriber information. We do not provide subscriber email addresses to advertisers, sponsors, or publishers.
Overseas processing
Some of our service providers may store, process, or access information outside Australia, including in countries where those providers or their infrastructure operate, such as the United States and other jurisdictions.
We use reputable providers and aim to disclose only the information reasonably necessary for them to provide their services to us.
Security
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. These steps include encryption in transit, access controls, production database hosting, secure unsubscribe and confirmation tokens, and limiting access to subscriber information to authorised operators.
No online service, email system, database, or hosting provider can be guaranteed to be completely secure.
Data retention
We keep personal information only for as long as reasonably necessary to operate MDDR, comply with legal obligations, resolve disputes, maintain security, and manage subscriptions and unsubscribes.
Active subscriber email addresses are retained while the subscription is active. Unsubscribe, bounce, complaint, and suppression records may be retained after unsubscribing so we can avoid emailing you again and maintain compliance records. Technical logs and analytics may be retained for operational, security, and performance purposes.
Access, correction, and deletion
You can request access to, correction of, or deletion of personal information we hold about you by emailing privacy@mddrnewsletter.com.
We may need to verify your identity before responding. We may retain limited information where reasonably necessary for unsubscribe suppression, security, compliance, legal obligations, or dispute resolution.
Complaints
If you believe we have mishandled your personal information, contact us at privacy@mddrnewsletter.com. Please include enough information for us to understand and respond to your complaint.
We will review and respond to privacy complaints within a reasonable period. If you are not satisfied with our response, you may be able to contact the Office of the Australian Information Commissioner or another relevant regulator.
Data breaches
If we become aware of a data breach involving personal information, we will take reasonable steps to contain, investigate, and remediate the incident. Where required by law, we will notify affected individuals and the relevant regulator.
Third-party links
MDDR links to third-party publishers, journals, regulators, websites, and other sources. We are not responsible for the privacy practices, content, security, or accuracy of third-party websites. When you click a third-party link, your interaction is governed by that third party's privacy policy, terms, and practices.
Changes to this policy
We may update this Privacy Policy from time to time. The latest version will be posted on this page with an updated date.