Privacy Policy
Last Updated: March 8, 2026
Your trust matters. This document describes how we handle information across the Eman Clinic platform with an emphasis on confidentiality, patient safety, and responsible technology.
1. Overview
This Privacy Policy explains how Eman Clinic ("Eman Clinic", "we", "our", or "us") collects, uses, discloses, and safeguards personal, health, and usage information when you access our digital clinic platform, related mobile or web interfaces, and connected services (collectively, the "Services"). We are committed to protecting confidentiality, integrity, and lawful processing of healthcare data.
2. Scope & Regulatory Alignment
This Policy applies to all users including patients, clinicians, administrative staff, and third-party integrators. We apply principles consistent with internationally recognized health data standards (e.g. confidentiality, minimum necessary use, purpose limitation, security-by-design). Where local law imposes stricter requirements, those obligations prevail.
3. Information We Collect
- Identity Data: name, date of birth, gender, identifiers issued by us or your organization.
- Contact Data: email, phone, address, emergency contact (if provided).
- Clinical / Patient Data: visit notes, lab orders/results, medications, allergies, services rendered, billing codes.
- Account & Authentication: role, permissions, audit trail entries, session tokens.
- Financial Data: limited payment metadata (we do not store full card numbers if processed by a PCI compliant processor).
- Usage & Technical: device type, browser, IP address, timestamps, feature interaction, error logs (pseudonymized when feasible).
- Optional Feedback: survey responses, support tickets, feature requests.
4. How We Use Information
- Deliver core clinic workflows (scheduling, charting, medication / inventory management, reporting).
- Authenticate users; enforce role-based access control (RBAC) and auditability.
- Generate internal analytics to improve reliability, quality of care tooling, and user experience (aggregated / de‑identified whenever possible).
- Provide patient safety alerts (drug interactions, abnormal results) where supported.
- Detect, investigate, and prevent security incidents or misuse.
- Comply with legal, accreditation, or regulatory obligations and respond to lawful requests.
- Communicate service notices, updates, and support responses.
5. Legal / Lawful Bases
We process data under one or more of: (a) performance of a healthcare or service provision contract; (b) legitimate interests in operating and securing the platform (balanced against user rights); (c) explicit consent where required (e.g. optional marketing); (d) compliance with legal obligations; (e) protection of vital interests in emergent scenarios.
7. International / Cross-Border Handling
Data may be processed in jurisdictions where our infrastructure or vetted subcontractors operate. We implement logical isolation, encryption in transit & at rest, strict access logging, and contractual clauses where required to maintain comparable protection levels.
8. Retention
We retain personal and clinical data only for the duration necessary to deliver Services, meet clinical recordkeeping obligations, resolve disputes, and enforce agreements. When no longer required, we securely delete or irreversibly de‑identify data using industry-standard procedures.
9. Security Controls
- Encryption (TLS in transit, encrypted storage for sensitive records).
- Role-based access, multi-factor authentication support, and session timeouts.
- Audit logging of privileged actions and data access pathways.
- Segregated environments (production vs. test) and principle of least privilege.
- Routine vulnerability scanning and secure development lifecycle practices.
10. User & Patient Rights
- Access / obtain a copy of your data within reasonable system capabilities.
- Request correction of inaccurate information.
- Request deletion where retention is not legally or clinically mandated.
- Object or restrict certain processing (e.g. analytics) where legally permitted.
- Portability of certain structured data (on request and feasibility).
- Withdraw consent for optional communications.
11. Children & Vulnerable Persons
Accounts for minors or vulnerable patients are created and managed only by authorized clinical or guardian stakeholders consistent with applicable law. We do not intentionally market Services directly to minors.
12. Policy Updates
We may revise this Policy to reflect regulatory, technical, or operational changes. The “Last Updated” date will change accordingly. Material updates may be communicated via dashboard notice, email, or in‑app banner. Continued use after the effective date constitutes acceptance.
13. Contact
Questions, data requests, or escalation of privacy concerns can be directed to: privacy@emanclinic.example (replace with operational address). We aim to acknowledge inquiries within 5 business days.