๐ 1. Introduction Overview
SmartClinic is a healthcare management platform designed to help clinics, hospitals and healthcare organizations manage their operations digitally. This Privacy Policy explains how SmartClinic may collect, use, store, share and protect information when healthcare organizations and their authorized users use the SmartClinic platform.
This policy describes what information may be collected, why it is collected, how it is used, how it is protected, when it may be shared, user rights, data retention, cookies, third-party services, security practices, and contact information for privacy-related inquiries.
Important: SmartClinic is a software platform. The healthcare organization using SmartClinic is responsible for determining the lawful basis for collecting, using and sharing patient information and for complying with applicable healthcare, privacy and data-protection requirements.
๐ค 2. Information We May Collect Data Types
A. Patient Information
Depending on how the SmartClinic system is configured by the healthcare organization, patient information may include:
- Patient name and contact information
- Date of birth, gender and address
- Identification information
- Medical record information
- Appointment and consultation information
- Prescription and laboratory information
- Admission and billing information
- Payment and insurance information where applicable
B. Doctor and Healthcare Professional Information
- Doctor name, professional designation and specialty
- Schedule and availability information
- Appointment information
- Professional profile information
- User account, login, role and permissions information
C. Employee and Staff Information
- Employee records and attendance information
- Leave and recruitment information
- Performance and payroll-related information
- Employee ID and user role information
- System permissions and access information
D. Technical Information
- IP address, browser type and device information
- Operating system and login timestamps
- Session and security logs
- Error logs and usage information
Healthcare organizations are responsible for determining what information they enter into the system and ensuring compliance with applicable laws.
โ๏ธ 3. How We Use Information Processing
Information may be used to support the following SmartClinic functions:
- Patient Management: Registration, records, patient flow, queue management, and admission.
- Appointments: Scheduling, availability, notifications, and patient portal services.
- Laboratory: Orders, test management, results, and patient access to lab information.
- Pharmacy: Medicine management, prescription workflows, and inventory management.
- Administration: Billing, payroll, inventory, reporting, and analytics.
- Communication: System notifications, internal staff messages, and support tickets.
- Security: User authentication, access control, role-based permissions, and security monitoring.
๐ฅ 4. Medical Information Sensitive Data
SmartClinic may be used by healthcare organizations to process sensitive patient and medical information. This includes health records, diagnoses, treatments, prescriptions, laboratory results, and other clinical data.
Important: SmartClinic is a software platform. It is not a healthcare provider. The healthcare organization using SmartClinic is solely responsible for ensuring that patient information is collected, used and shared in accordance with applicable healthcare, privacy and data-protection laws and regulations.
๐ 5. Role-Based Access Control Security
SmartClinic provides role-based access control to ensure that users only have access to information necessary for their assigned responsibilities.
Common roles include:
- Administrator
- Doctor
- Receptionist
- Laboratory Staff
- Pharmacy Staff
- HR Staff
- Other authorized users
Healthcare organizations are responsible for configuring appropriate permissions and managing user accounts. Users should only be granted access to information necessary for their assigned responsibilities.
๐ก๏ธ 6. Data Security Protection
We use reasonable technical and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration or disclosure. These measures include:
- Authentication and password protection
- Role-based permissions and access controls
- Secure session management
- Security monitoring and logging
- Administrative controls and procedures
- Backup procedures where implemented
No system can be guaranteed 100% secure. We continuously evaluate and improve our security practices to protect information.
๐ 7. Data Sharing & Disclosure Transparency
Information may be shared in the following circumstances:
- Authorized Healthcare Organization: Information may be accessed by authorized personnel of the organization using SmartClinic.
- Service Providers: Information may be processed by selected third-party service providers required to operate the platform.
- Legal Requirements: Information may be disclosed where required by applicable law, regulation, court order, or lawful governmental request.
- Security and Fraud Prevention: Information may be processed where necessary to investigate security incidents, abuse, or unauthorized access.
SmartClinic does not sell personal or patient information for advertising purposes.
๐ 8. Third-Party Services Integrations
SmartClinic may integrate with external services depending on the configuration. Examples may include email services, messaging platforms, payment processing, hosting providers, and analytics services.
Third-party services may have their own privacy policies and terms. Users should review the applicable policies of those services.
Healthcare organizations are responsible for configuring and managing third-party integrations in compliance with applicable laws.
๐ป 9. Patient Portal Self-Service
The SmartClinic patient portal may allow authorized patients to:
- View relevant personal and medical information
- Access appointment information
- Book appointments with available doctors
- Access available laboratory services and results
- Receive notifications
Patients should protect their login credentials and should not share their account information with others. Healthcare organizations are responsible for managing patient portal access.
๐ช 10. Cookies Tracking
SmartClinic may use cookies or similar technologies for:
- Authentication and session management
- Security purposes
- Website functionality and preferences
- Analytics, if implemented
Users may manage cookie preferences through their browser settings. Disabling cookies may affect certain features of the platform.
๐ 11. Data Retention Storage
Information may be retained for as long as necessary to provide the services, maintain business and healthcare records, satisfy legal or regulatory obligations, resolve disputes, enforce agreements, and protect legitimate interests.
Retention periods may depend on:
- Healthcare organization policies
- Legal and regulatory requirements
- Type of information
- Operational requirements
Healthcare organizations are responsible for determining appropriate retention periods for the information they manage using SmartClinic.
๐ 12. Data Ownership & Responsibility Accountability
The healthcare organization using SmartClinic is generally responsible for the patient and employee information entered into its SmartClinic account.
Healthcare organizations are responsible for ensuring that information entered into SmartClinic is collected and processed in accordance with applicable laws, regulations, professional obligations and their own privacy policies.
Users should only be granted access to information necessary for their assigned responsibilities. Healthcare organizations should regularly review user access and remove access when employees leave or change roles.
โ๏ธ 13. User Rights Privacy Rights
Depending on applicable law, individuals may have rights concerning their personal information, including:
- Access to their information
- Correction of inaccurate information
- Deletion where legally applicable
- Restriction of processing
- Objection to processing
- Data portability where applicable
- Withdrawal of consent where processing is based on consent
Important: Requests relating to patient records may need to be directed to the healthcare organization that created or controls the record. SmartClinic will assist healthcare organizations in responding to valid requests where required.
โ ๏ธ 14. Security Incidents Breach Response
SmartClinic follows applicable procedures regarding security incidents. Where required by applicable law, relevant parties and authorities will be notified of qualifying security incidents within the legally required timeframe.
Healthcare organizations are responsible for notifying affected individuals and regulatory authorities as required by applicable law.
๐ 15. Policy Updates Changes
This Privacy Policy may be updated periodically to reflect changes in legal requirements, business practices, or technical implementations.
Significant changes may be communicated through appropriate channels. The "Last Updated" date at the top of this policy indicates when the most recent changes were made.
Last Updated: January 15, 2026
๐ง 16. Contact Get in Touch
For privacy-related questions, data requests, or concerns, please contact: