Privacy Policy
Version 1.6
Last updated: October 6, 2026
1. Introduction
Doktu is a private, professional community used by medical societies to connect and engage their members and invited guests. Doktu is not a patient care product, is not a medical device, and is not designed to store or process protected health information.
This Privacy Policy explains how Doktu collects, uses, and shares information when you visit Doktu's website or use a Society community on Doktu. It also explains your choices and certain U.S. state disclosures.
Doktu must not be used to share patient-identifiable information or PHI. If you believe patient-identifiable information has been posted, report it immediately in the product or by emailing support@joindoktu.com.
2. Scope
This policy applies to Doktu's website and related pages, and the Doktu platform used for Society communities.
This policy does not apply to third-party websites or services that may be linked from Doktu, including Sponsor websites. Those third parties have their own privacy policies and practices.
3. Key definitions
Doktu, we, us, our means Doktu LLC.
Society means the medical society that provides and administers your community on Doktu.
Member means a Society member using a Society community on Doktu.
Sponsor means a third party whose content may appear as clearly labeled sponsored placements if enabled by a Society.
Services means Doktu's website and Doktu's platform.
Society community data means data processed to operate a Society's Doktu community, including the member roster and profile fields used in the Society community, community content (posts and comments).
Aggregated Data means data derived from Society community data or service usage information that has been aggregated and de-identified so it does not identify any individual Member.
4. Doktu is not for PHI or patient-identifiable information
You must not post, upload, transmit, or otherwise share protected health information (PHI) or patient-identifiable information through the Services. This includes information that could reasonably lead to identification of a patient, even if a name is not included.
Doktu is designed to support professional community engagement. It is not intended for clinical decision support, patient safety monitoring, or patient communications.
5. Roles: Society and Doktu
For a Society's Doktu community, the Society determines the purposes and means of processing Society community data. In most cases, the Society is the data controller and Doktu processes Society community data as a service provider or processor on the Society's behalf. Depending on Society configuration and applicable law, the Society's and Doktu's roles may vary.
Doktu also processes certain information as needed to operate, secure, and improve the Services, such as security logs, abuse prevention, platform reliability, and website operations. For those limited purposes, Doktu may act as an independent controller.
6. Information we collect
Information required to use a Society community
To create and maintain access to a Society community on Doktu, we require your name, email address, institution, and professional credentials. We use the email address provided by the Society to verify eligibility and administer access.
Optional profile information
You may optionally add or edit additional profile fields in the app. A headshot is not required.
Community content
We collect and store content you create or provide in a Society community, including posts and comments.
Audio rooms
Doktu does not record, transcribe, or retain the audio of live audio sessions. Doktu may retain ordinary operational information about a session, such as its title, scheduled time, host, attendance counts, and technical logs. Members may not record sessions, and Doktu is not responsible for recordings made by Members in violation of the Terms of Service.
Information collected automatically
We collect limited technical and security information needed to operate the Services, such as IP address, device and browser type, timestamps and log events related to login, reliability, and security, and basic usage events needed to protect the Services and maintain performance.
7. Cookies and similar technologies
Doktu uses first-party cookies and similar technologies that are necessary for authentication, session management, and basic security.
Doktu does not use third-party advertising cookies and does not use cookies for cross-context behavioral advertising.
8. How we use information
We use information to provide and operate the Services, verify eligibility and manage access, enable Society community features, administer the Society community (including moderation workflows), maintain security, prevent abuse, troubleshoot issues, comply with legal obligations, and create reporting described in this policy.
Doktu may create aggregated engagement reporting for Society administrators and, if enabled, for Sponsors as described below. Doktu does not use Member data for targeted advertising.
Doktu is for professional networking and education. Doktu does not provide medical advice and does not use data for clinical decision support.
9. How we share information
Within a Society community
Your profile information and the content you post are visible to other Members in the Society community based on that community's settings.
With Society administrators
Designated Society administrators can access member profile information, moderation tools, and community content, subject to the controls and limits described in this policy.
Anonymous posting (identity access and enforcement)
If a Society community offers an anonymous posting feature, Society administrators will not be able to see the identity of the poster by default. Doktu may access the identity of an anonymous poster only as necessary to investigate or enforce violations of the Terms of Service, Community Guidelines, or applicable law. Access is limited to authorized Doktu personnel, is logged, and is permitted only for these purposes. A Society may request disclosure of an anonymous poster's identity only through a written request from an authorized Society contact for a good-faith safety, legal, patient privacy, harassment, or policy reason. Doktu reviews each request and discloses only the minimum information necessary, where permitted by the Terms of Service and applicable law.
With Sponsors (if enabled)
If a Society enables sponsorship, Doktu may provide Sponsors aggregated engagement metrics about sponsor placements. In v1, Sponsor reporting is limited to impressions and clicks for banner placements only. Sponsors do not receive Member identities, Member lists, user-level analytics, message-level analytics, or targeting data.
To reduce re-identification risk, Doktu may suppress, delay, or combine reporting where needed, for example when engagement counts are small.
Sponsor interactions and third-party collection
If you click a Sponsor banner or other external link, the third party may independently collect information about your interaction (for example IP address, browser information, and referring page details) under their own privacy policy. Doktu is not responsible for third-party privacy practices.
With vendors and service providers
We use vendors to support hosting, monitoring, and core platform operations. Vendors are permitted to process data only to provide services to Doktu under contractual obligations to protect data.
Legal disclosures
Doktu may access, preserve, and disclose information (including account information, content, and technical logs) if Doktu reasonably believes doing so is necessary to comply with law or legal process, protect rights, safety, and integrity, or enforce our policies and contracts.
When practicable, Doktu will notify both the relevant Society and the affected Member before disclosure and will limit disclosures to the minimum information reasonably necessary for the purpose, unless prohibited by law or court order, or if notice would compromise an investigation or security.
Business transfers
If Doktu is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information covered by this policy may be transferred as part of that transaction. Any successor will remain subject to commitments consistent with this Privacy Policy.
10. Email communications and opt-out
Doktu and the Society may send emails related to account access and security, Society community operations and announcements, incident notifications, and required policy updates.
Doktu may also send rare product or operational updates. Members may opt out of non-essential Doktu product emails. Members may not opt out of essential service communications.
11. Data retention
Member accounts, logs, and deletion
If you delete your account in the app, Doktu will retain limited security and platform logs for up to 30 days for security, abuse prevention, and support, then delete or de-identify where feasible. How your prior posts and comments are handled after account deletion is described in the Terms of Service.
Posts and comments
Members can delete their own posts and comments in the app. If a Member deletes content, it will be removed from Member-facing views. Doktu may retain limited evidence necessary to investigate or enforce violations of the Terms of Service, Community Guidelines, or applicable law.
Backups
Deleted data may persist in encrypted backups for a limited period and will not be restored except for disaster recovery or system integrity purposes.
Aggregated Data rights
Doktu may aggregate and de-identify Society community data and service usage information so it no longer identifies any individual (Aggregated Data). Doktu owns Aggregated Data as a separate dataset and may use it for lawful business purposes, including benchmarking, product improvement, security, and reporting, during and after a Society's use of the Services.
Doktu will not attempt to re-identify Aggregated Data. Doktu will not publish Society-identified benchmarking externally without the Society's permission.
12. Society termination: export and deletion
If a Society terminates its Doktu agreement, Doktu will provide the Society an export of Society community data within approximately 30 days of termination, subject to the Society's written request and verification. After the export window, Doktu will delete Society community data from active systems, except where retention is required for security, legal obligations, or backup processes.
13. Security
Doktu uses security controls designed for professional community use, including encryption in transit (TLS 1.2+), encryption at rest (AES-256), role-based access controls and least-privilege access, access controls for Doktu staff access, audit logging for sensitive administrative actions, and continuous monitoring and alerting for suspicious activity.
Security incident definition
A security incident means unauthorized access to or disclosure of Society community data, or a confirmed compromise of systems that store or process Society community data.
Security incident notification
If Doktu becomes aware of a confirmed security incident affecting a Society community, Doktu will notify the Society without undue delay, taking into account the needs of law enforcement and the scope of the investigation. Doktu will also notify affected Members without undue delay when required by applicable law or when Doktu determines it is appropriate based on the nature of the incident.
14. U.S.-only service and international access
Doktu is operated from the United States and is intended for U.S. societies in v1. All data is stored and processed in the United States. Doktu's primary support and engineering operations are based in the United States, and Doktu applies role-based access controls and logging to administrative access regardless of location.
If you access Doktu from outside the U.S., you do so at your own risk and are responsible for compliance with local laws. Your data will still be processed in the United States.
15. U.S. state privacy notice (lightweight)
Do Not Sell/Share
Doktu does not sell personal information. Doktu does not share personal information for cross-context behavioral advertising.
Categories of personal information collected
Doktu collects the categories described in this policy, including identifiers (name, email), professional/institutional information, user-generated content, and technical/security logs.
Sources
Doktu collects information directly from you and from your Society (for example to verify eligibility and administer access).
Purposes
Doktu uses information for the purposes described in this policy.
Categories disclosed
Doktu discloses information to service providers who support hosting and operations, to Societies and authorized Society administrators for community administration, to Sponsors only in aggregated form, to legal/safety disclosures, and to business transfers as described above.
Requests
Members may submit requests regarding their personal information by emailing support@joindoktu.com. Doktu may need to verify identity before processing a request. Requests related to Society community data may need to be handled by, or coordinated with, your Society.
Authorized agents
Where permitted by law, you may designate an authorized agent to submit a request on your behalf. Doktu will require verification of your identity and proof that the agent is authorized to act for you.
Appeals
Where required by law, you may appeal a decision regarding your request by replying to Doktu's response email and requesting an appeal.
Global Privacy Control
Doktu does not sell or share personal information for cross-context behavioral advertising. Where applicable, Doktu treats a Global Privacy Control signal as a request to opt out of sale/share.
Non-discrimination
Doktu will not discriminate against you for exercising privacy rights.
16. Changes to this Privacy Policy
If Doktu makes changes, Doktu will update the Last updated date and provide notice via email and an in-product message for material changes.
17. Contact
For privacy inquiries and requests: legal@joindoktu.com
