Privacy Policy

Effective date: 1 January 2026

1. Data Controller and Contact

Tribe Cartilage Sp. z o.o., Ul. Czwartaków 158, 04-430 Warsaw, Poland.
E-mail: contact@tribe-cartilage.com

This is the single point of contact for all data protection matters, including exercise of your rights, deletion requests, and enquiries from users in all jurisdictions.

2. Scope of This Privacy Policy

This Policy applies to personal data processed in connection with:

  • - visits to our websites: www.tribe-cartilage.com, www.cartilage.help, www.cartilage.in, and www.knee.help, including all subpages
  • - subscription sign-ups and subscription management (research reports: Weekly Report and Monthly Report)
  • - use of the AI chat feature available on cartilage.help
  • - delivery of purchased research reports via email
  • - contact forms and e-mail communication with us
  • - basic web analytics (Google Analytics 4)

Our websites are not intended for children under 16. We do not knowingly process personal data of users under this age. If you believe we have collected data of a child under 16, please contact us at the address provided in Section 1.

Our content is educational and informational in nature. We do not provide medical diagnoses, treatment plans, or clinical recommendations. The AI assistant on our platforms provides general information only and does not constitute medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional regarding your condition and treatment decisions.

3. Categories of Personal Data We Process

Depending on how you use our sites and services, we may process:

  • Identification data: first name
  • Contact data: e-mail address
  • Subscription and billing data: language preference, subscription product type, subscription status, Stripe customer ID, billing date. Payment card data is processed exclusively by Stripe - we do not store card numbers.
  • AI chat interaction data: content of queries submitted to the AI chat tool on cartilage.help. Data is retained for up to 24 months.
  • Communication content: messages sent via contact forms or e-mail
  • Technical data: IP address, browser type, device type, operating system, time and pages visited - collected via cookies and analytics tools

4. Purposes and Legal Bases of Processing (EU/EEA)

(a) Subscription management and report delivery
We process your name, email, language, and subscription details to create and manage your subscription and deliver purchased research reports via email.
Legal basis: Art. 6(1)(b) GDPR - contract performance.

(b) AI chat functionality
We process the content of your queries to provide responses through the AI chat tool and to improve service quality.
Legal basis: Art. 6(1)(b) GDPR - contract performance; Art. 6(1)(f) GDPR - legitimate interest in service improvement.

(c) Handling enquiries and contact forms
Legal basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.

(d) Analytics and site optimisation
Tools: Google Analytics 4 (with IP anonymisation and Consent Mode).
Legal basis: your consent - Art. 6(1)(a) GDPR, or legitimate interest - Art. 6(1)(f) GDPR, depending on jurisdiction.

(e) Legal obligations and defence of claims
Legal basis: Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR.

5. Automated Decision-Making / Profiling (Art. 22 GDPR)

We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on you within the meaning of Article 22 GDPR. AI chat responses are informational and educational only and do not constitute medical decisions.

6. Cookies and Analytics

We use cookies to ensure technical operation of the sites and to measure traffic via Google Analytics 4.

Analytics cookies (e.g. _ga) are activated only after your explicit consent through our cookie consent banner. Before consent, Google Analytics runs in Consent Mode ("denied"), which limits data sent to Google. You can withdraw or change your consent at any time using the cookie settings icon on the site or via your browser.

We do not use advertising cookies, remarketing tags, Facebook Pixel, or any marketing tracking technologies.

7. Data Recipients and International Transfers

We may share data with:

  • Stripe, Inc. - payment processing and subscription billing (Stripe processes payment card data under its own Privacy Policy; we receive only billing metadata)
  • Anthropic, PBC - AI infrastructure provider operating the chat feature on cartilage.help, located in the United States
  • Google Ireland Ltd. / Google LLC - Google Analytics 4
  • EEA-based hosting provider - website hosting and server infrastructure located within the European Economic Area

Transfers to Stripe, Inc. and Anthropic, PBC (USA) are covered by Standard Contractual Clauses (SCCs) adopted by the European Commission. Transfers to Google LLC (USA) are covered by the EU-US Data Privacy Framework or SCCs.

8. Data Retention

  • Subscription data - retained for the duration of your subscription and up to 5 years thereafter for accounting and legal purposes
  • AI chat queries - up to 24 months from the date of submission
  • Enquiries - up to 24 months after last contact
  • Analytics - per Google Analytics 4 retention settings (typically 14-26 months)

9. Your Rights (GDPR - EU/EEA)

You have the following rights: access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent.

To exercise any of these rights, contact us at the address provided in Section 1.

You may also lodge a complaint with your local data protection authority. In Poland: the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.

10. Users in India (cartilage.in)

For users accessing our services through www.cartilage.in or from India, we process personal data in accordance with the Digital Personal Data Protection Act 2023 (DPDP Act). You have the right to access, correct, and erase your personal data, and to nominate a representative in the event of your incapacity. To exercise these rights, contact us at the address provided in Section 1.

11. Users from the USA and Canada

Our sites are accessible in the United States and Canada. Local consumer or privacy laws may grant you additional rights. To submit any request, contact us at the address provided in Section 1.

California users (CCPA/CPRA): we do not sell or share personal data for cross-context behavioural advertising. You may request access, correction, or deletion of your data by contacting us at the address provided in Section 1.

12. Data Security

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. No method of transmission or storage is fully secure. Payment card data is processed exclusively by Stripe and is not stored on our systems.

13. Changes to This Privacy Policy

We may update this Policy to reflect changes in applicable law or our services. The latest version is always available on each of our websites. Material changes will be communicated to active subscribers by email.