Privacy Policy

Privacy Policy Last Updated: 21/10/2024
Technoosft Solutions (“we,” “us,” or “our”) operates the ClinicaConnect mobile application and Website. This Privacy Policy outlines how we collect, use, disclose, and protect your personal information in compliance with the Health Insurance Portability and Accountability Act (HIPAA), the General Data Protection Regulation (GDPR), and relevant U.S. laws. By using the App, you agree to this Privacy Policy. If you do not agree, please discontinue the use of the App.
1. Information We Collect
We collect the following types of information to provide and improve our services:
1.1 Personal Information
- Protected Health Information (PHI): As defined by HIPAA, we may collect PHI such as medical records, conditions, treatments, and prescriptions if you choose to provide it.
- Personal Data (GDPR): Under GDPR, personal data such as name, email address, phone number, and location data may be collected.
- Account Information: Username, password, and any preferences provided when setting up an account.
1.2 Usage Data
We collect data about how you interact with the App, including:
- Device Information: IP address, device type, operating system, and mobile network information.
- Log Data: Access times, pages visited, and actions taken.
- Location Data: With your permission, we may collect your device’s location.
1.3 Cookies and Tracking Technologies
We use cookies and similar technologies to track user activity and improve services. Under GDPR, you will be given the opportunity to accept or reject the use of cookies. You can manage your cookie preferences in your browser settings.
2. How We Use Your Information
We use the information we collect for the following purposes, ensuring compliance with HIPAA and GDPR:
2.1 Providing Healthcare Services
We may use your PHI and personal data to deliver health-related services, including symptom tracking, treatment reminders, and communication with healthcare providers. This is done in compliance with HIPAA regulations regarding the handling of sensitive health data.
2.2 Legal Basis for Processing (GDPR)
For users within the European Union, we rely on the following legal bases for processing your personal data under GDPR:
- Consent: When you voluntarily provide your data, we process it with your consent.
- Contractual Necessity: To fulfill the services you request through the App.
- Legitimate Interest: To improve the App’s functionality and ensure security.
2.3 Communication
We may use your contact information to send service-related notifications or respond to your inquiries. We will not send marketing communications without your explicit consent, in accordance with GDPR and U.S. laws like the CAN-SPAM Act.
2.4 Research and Analytics
We may anonymize and aggregate your data for research purposes, statistical analysis, or to enhance our services. Data used for research will be anonymized in accordance with HIPAA de-identification standards and GDPR requirements.
2.5 Compliance with Legal Obligations
We may use your data to comply with legal obligations, including those required by HIPAA and GDPR, such as regulatory reporting or responding to lawful requests from authorities.
3. How We Share Your Information
We do not sell your personal information. However, we may share it in the following situations, ensuring HIPAA, GDPR, and U.S. legal compliance:
3.1 With Healthcare Providers
With your consent or at your request, we may share your PHI with your healthcare provider(s) to deliver the services you request. Any such sharing will comply with HIPAA’s “minimum necessary” standard.
3.2 With Service Providers
We may share your data with third-party service providers (e.g., cloud storage providers) who assist in delivering the App’s services. These providers are required by law to protect your data and are bound by HIPAA Business Associate Agreements (BAAs) where applicable. Under GDPR, these providers must also comply with applicable data protection laws.
3.3 Legal and Regulatory Requirements
We may disclose your information to comply with legal obligations, such as responding to a subpoena, court order, or governmental request in compliance with HIPAA’s Privacy Rule and GDPR’s legal obligation basis.
3.4 International Data Transfers (GDPR)
If you are in the European Economic Area (EEA), your data may be transferred outside the EEA to countries that may not have the same data protection laws as your jurisdiction. In such cases, we will ensure that appropriate safeguards (e.g., Standard Contractual Clauses) are in place as required by GDPR.
4. Data Security
We implement administrative, physical, and technical safeguards in compliance with HIPAA’s Security Rule and GDPR’s Article 32 to protect your data. Despite these measures, no system is completely secure, and we cannot guarantee absolute security.
5. Your Data Rights
5.1 HIPAA Rights
As a U.S. user, you have the following rights under HIPAA:
- Right to Access and Copy PHI: You may request a copy of your PHI that we maintain.
- Right to Amend: You may request an amendment to your PHI if you believe it is incorrect or incomplete.
- Right to Accounting of Disclosures: You may request a list of disclosures of your PHI that we have made.
5.2 GDPR Rights
If you are located in the EEA, you have the following rights under GDPR:
- Right of Access: You have the right to request access to your personal data.
- Right to Rectification: You can request that we correct inaccurate or incomplete personal data.
- Right to Erasure (“Right to be Forgotten”): You can request the deletion of your personal data.
- Right to Restrict Processing: You may request that we restrict the processing of your data.
- Right to Data Portability: You can request a copy of your data in a structured, commonly used format to transfer to another provider.
- Right to Object: You have the right to object to our processing of your data.
- Right to Withdraw Consent: You can withdraw your consent at any time where consent is the legal basis for processing.
To exercise any of these rights, please contact us at [Insert Contact Information].
6. Data Retention
We will retain your personal information and PHI only as long as necessary to fulfill the purposes for which it was collected, as required by law (HIPAA), or as needed for legitimate business purposes (GDPR). After that, we will securely dispose of or de-identify your data.
7. Children’s Privacy
The App is not intended for use by individuals under the age of 13, in compliance with the Children’s Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13. If you believe we have collected such data, please contact us to have it removed.
8. Your California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the right to:
- Request to Know: You may request information on how we have collected, used, and shared your personal data.
- Request to Delete: You may request the deletion of your personal data, subject to certain exceptions.
- Non-Discrimination: You have the right not to be discriminated against for exercising any of your CCPA rights.
To exercise your rights under CCPA, please contact us at [Insert Contact Information].
9. International Data Transfers
If we transfer personal data from the EEA or other regions with data protection laws to countries outside the region, such as the U.S., we will ensure the data is adequately protected by mechanisms approved under GDPR, such as Standard Contractual Clauses.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated Privacy Policy on the App and updating the “Last Updated” date. Continued use of the App after any changes indicates your acceptance of the updated terms.
11. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
- Email: info@clinicaconnect.com
- Phone: 203-208-8866
- Mailing Address: 87-1A Florence Road, Branford, CT. USA
