AdvaHealth Solutions Pte. Ltd. (hereafter, ‘we’, ‘us’, ‘our’ or ‘AHS’) has developed AdvaPACS, a software-as-a-service application (the ‘Application’) which hospitals, clinics and other healthcare providers may use to provide PACS (Picture Archiving and Communications System) for storing, indexing and retrieving medical imaging.
In connection with access and use of the Application by our customers, certain personal information, such as those of a customer’s patients, will be collected and processed by us.
If you have or will be registering for an account to use the Application (hereafter ‘Account’), this Data Protection Notice (‘Notice’) explains how we handle personal information when you use the Application, your rights and choices, and how you can contact us about our data protection practices.
- Who are we?
- We are a company based in Singapore.
- We are the provider of the Application which is intended for use by you as our customer. This means that in most cases:
- we are collecting and processing personal information on your behalf as a data processor / data intermediary.
- you are the controller of the personal information we process and how we use it.
- What information do we collect?
- Information of our users. In most cases, we collect and process information that you provide to us. These include:
- business contact information that you provide when you register for and/or add users under the Account. Such information includes but is not limited to the following: –
- Name;
- Email Address;
- Phone Number;
- Address;
- Business Name; and
- Tax Number.
- payment information, such as your billing address.
- your marketing preferences.
- business contact information that you provide when you register for and/or add users under the Account. Such information includes but is not limited to the following: –
- Information of patients. We collect and process certain personal information about patients (‘Patient Information’) on your behalf and only when provided and instructed by you. Patient Information includes the following:
- patient demographic information.
- diagnostic reports.
- DICOM files (the worldwide standard for medical imaging and communication) that you upload to the Application.
- other types of files (text, PDF, etc.) that you upload where the Application allows it.
- Information that we collect automatically. When you use or interact with the Application, we automatically collect or receive certain non-personally identifiable information through our system and other technologies (e.g., cookies) about your use of the Application. Such information includes:
- Device data about your computer or other device used to access the Application. Device data may include information such as your IP address, device type, and browser type.
- Log files from requests for diagnostic and auditing purposes. These may contain information about what was accessed and from which IP addresses.
- Location data relating to your device.
- Cookies. We currently only use functional cookies which are necessary for the Application to work properly. If you delete the functional cookies, the Application may not work properly.
- Information of our users. In most cases, we collect and process information that you provide to us. These include:
- Where do we store your information?
- Patient Information. When you register for an Account, you will be asked to select the region where you want your Account to be located in, for example, Hong Kong, Singapore, Australia, the United Kingdom, or Europe. Your Patient Information will be stored on cloud servers in the selected region. You are responsible for ensuring that your Patient Information may be stored in the selected region and complying with any laws and regulations regarding your Patient Information.
- All other information. All other information that you provide, such as user information and payment information, may be stored on servers outside of the selected region, but these will never contain any Patient Information.
- How do we use your information?
- We use and process the personal information that we collect for the purposes identified below:
- providing the Application and its tools and services.
- administering your Account.
- communicating with you about the Application, such as the sending of service and other notifications.
- performing our obligations and enforcing our Terms of Service and other policies.
- developing and improving the Application.
- sending marketing communications if you have opted to receive the same from us.
- for our business purposes, such as data analysis, audits, fraud monitoring and prevention, developing new products and features, improving or modifying our products and services, identifying usage trends and other business activities in reliance on our legitimate interests.
- complying with our legal obligations under applicable laws.
- You are under no obligation to provide personal information to us. However, if you choose to withhold the requested personal information, you may not be able to use certain aspects of the Application.
- We use and process the personal information that we collect for the purposes identified below:
- Who do we share information with?
- We may share personal information with:
- our affiliates and third party service providers who assist us in providing the Application and who perform certain functions on our behalf.
- parties involved in a transaction involving the purchase, sale, lease, merger or amalgamation or any other acquisition, disposal or financing of our business.
- other parties if required to do so by law or if we believe that such disclosure is necessary to prevent fraud or crime or to protect the application or the rights, property or personal safety of any person.
- any other person provided you have given consent to the disclosure.
- We may share personal information with:
- International data transfers
- Patient Information is stored and processed in your selected region (please see Section 3 of this Notice). Patient Information will never be transferred out of your selected region.
- Depending on your location, all other information which you provide to us may be stored and processed in a country other than where you are located. These countries may have data protection laws which are different from the laws of your country. However, regardless of where such information is located, we will take measures to ensure that:
- all transfers of personal information comply with application data protection laws
- your personal information will be protected to the standard required under applicable data protection laws.
- How long do we keep your information?
We will process and store your information (including any Patient Information) for no longer than necessary. Please refer to our Terms of Use for more information on this point. - Security
- We take the security of your personal information seriously. To safeguard personal information against unauthorised access, collection, use, disclosure, modification and other similar risks, we have implemented appropriate and robust administrative, physical and technical measures to protect person information in our possession. In addition, all Patient Information is encrypted at rest and in transit.
- While we will make every effort to ensure our system is a secure as possible, no electronic transmission over the internet or information storage technology is 100 percent secure against hackers and other cyber threats. The security of the Application and your Account also depends on you. In this respect, you must and should ensure that users under your Account comply with the following:
- take steps to secure your computer and other devices.
- that you make full use all of the tools we provide to secure your Account, such as 2 factor authentication, and IP restrictions.
- use secure passwords and maintain the confidentiality of such passwords.
- Third party sites
The Application may contain links to platforms and sites which are operated by third parties with different data protection policies from us. We encourage you to read the data protection policies of these platforms and sites. We have no control over any personal information which you choose to submit or receive through these platforms and sites. - Your rights and choices
- You may access, review, change and/or delete personal information associated with your Account by signing into your Account and editing such information as desired.
- You may opt out of receiving marketing communications from us by using the unsubscribe link in the communication or following the instructions in the communication to unsubscribe. However, we may still send service-related communications and notifications to you and you may not unsubscribe from them, although you may change some settings by signing into your Account and adjusting them as required.
- If you have any questions about your rights and choices, please contact us at compliance@advapacs.com. We take each request seriously and will comply with your request to the extent required by applicable law. If you have not received a satisfactory response from us, you may consult with the data protection authority in your country.
- Changes to this Notice
- We reserve the right to modify this Notice at any time to reflect changes in the Application, any applicable laws or other reasonable grounds. The current version of this Notice will apply each time you access and/or use the Application and you should check for any changes to this Notice when you use the Application.
- If we make material changes to this Notice or in how we use personal information, we will post a prominent notice of such change and notify you via email.
- We encourage you to review this Notice periodically to remain informed of how we protect your personal information.
- Contacting Us
If you have any questions or comments on this Notice, please email our data protection officer at compliance@advapacs.com.