GDPR Compliance Notice for MediCareBot
Effective Date: October 1st, 2024
Company Name: MediCareBot
Company Address: Andrassy ut 1, Budapest, Hungary
Contact Information: support@medicarebot.live, +36 21 201 2020
Introduction
MediCareBot is committed to ensuring that the personal data of users is handled in compliance with the General Data Protection Regulation (GDPR). This GDPR Compliance Notice outlines how we collect, process, and protect personal data and informs you of your rights under the regulation.
1. What Data We Collect
MediCareBot collects and processes the following types of personal data, which may include but are not limited to:
- Personal Identification Information: Name, email address, phone number, and other contact details.
- Healthcare-Related Data: Medical records, appointment details, and other sensitive data necessary for patient engagement, lead capture, and routine healthcare management.
- Usage Data: Information related to how you interact with our platform, including cookies, usage statistics, and device information.
2. Purpose of Data Processing
We collect and process personal data for the following purposes:
- Service Provision: To deliver automated patient engagement, appointment scheduling, and related healthcare services through the MediCareBot platform.
- Compliance with Legal Obligations: MediCareBot processes data in accordance with GDPR and HIPAA regulations to meet healthcare compliance requirements.
- Improvement of Services: To improve and optimize our AI-driven communication tools and healthcare platform.
- Security and Monitoring: To ensure the security and integrity of patient data and the platform.
3. Lawful Basis for Processing
MediCareBot processes personal data lawfully under the following legal bases as permitted by GDPR:
- Consent: For specific processing activities where explicit consent is required, such as patient data processing for healthcare services.
- Performance of a Contract: Data processing necessary to provide services under our contractual obligations with healthcare providers and patients.
- Legal Obligations: To meet regulatory requirements, such as maintaining compliance with healthcare regulations like GDPR and HIPAA.
- Legitimate Interests: Where necessary, we may process data for our legitimate business interests, such as improving the functionality of the platform.
4. Your Rights as a Data Subject
Under GDPR, users have several rights regarding their personal data. MediCareBot is committed to upholding these rights:
- Right to Access: You may request access to the personal data that MediCareBot holds about you.
- Right to Rectification: If you believe that your data is inaccurate or incomplete, you have the right to request corrections.
- Right to Erasure (“Right to be Forgotten”): You can request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected.
- Right to Restrict Processing: You may request that we restrict the processing of your data under certain circumstances.
- Right to Data Portability: You have the right to receive your data in a structured, commonly used, and machine-readable format and to transfer it to another controller.
- Right to Object: You may object to the processing of your personal data in cases where we rely on legitimate interests as a legal basis.
- Right to Withdraw Consent: If the data processing is based on your consent, you may withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us at support@medicarebot.live or +36 21 201 2020. We will respond to your request in accordance with GDPR timelines and requirements.
5. Data Retention
MediCareBot retains personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. Data retention periods vary depending on the type of data and the purposes of processing.
- Healthcare Data: Retained for the duration of your relationship with the platform and any legal retention requirements under applicable healthcare regulations.
- User Data: Retained as long as necessary to provide services, improve the platform, and meet regulatory requirements.
6. Data Sharing and Transfers
MediCareBot may share your personal data with trusted third parties, including:
- Healthcare Providers and Partners: As part of the service we provide, to ensure healthcare services are properly delivered.
- Sub-processors: Third-party vendors who help us operate the platform, such as data storage and cloud service providers.
- Legal Authorities: If required by law, we will disclose personal data to legal authorities.
If data is transferred outside the European Economic Area (EEA), MediCareBot ensures appropriate safeguards are in place, such as the use of standard contractual clauses approved by the European Commission or other lawful mechanisms.
7. Data Security
MediCareBot implements industry-standard security measures to protect your personal data, including:
- Encryption: Ensuring that sensitive data, particularly medical information, is encrypted in storage and during transmission.
- Access Control: Limiting access to personal data to authorized personnel only.
- Monitoring and Auditing: Regularly auditing our systems and practices to ensure compliance with GDPR and HIPAA security standards.
Despite our efforts to safeguard data, no system can be 100% secure. MediCareBot cannot guarantee the absolute security of your information.
8. Cookies and Tracking Technologies
MediCareBot uses cookies and similar tracking technologies to enhance user experience, analyze site performance, and for marketing purposes. You can manage your cookie preferences through your browser settings. For more details, please refer to our [Cookie Policy] (Link).
9. How to Contact Us
For questions, concerns, or to exercise your GDPR rights, please contact our Data Protection Officer:
Email: support@medicarebot.live
Phone: +36 21 201 2020
Address: Andrassy ut 1, Budapest, Hungary
If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority, such as the Hungarian Data Protection Authority (NAIH) or the data protection authority in your country.