Who is responsible for your data
Your clinic is the data controller for your medical records. It decides why and how your health data is processed, and it is your first point of contact for any question about that data.
ClinTouch is the data processor. We provide the software the clinic uses, and we process data only on the clinic's documented instructions under a data processing agreement.
This distinction matters in practice: if you want your records corrected or deleted, the request goes to your clinic, and we act on the clinic's decision.
What we collect
Identity and contact details: name, date of birth, gender, phone, email, and where the clinic records it, a national ID or passport number.
Health data: diagnoses, symptoms, treatment plans, prescriptions, vital signs, allergies, chronic conditions, and any documents your clinician uploads.
Appointment and administrative data: bookings, attendance, and insurance details where provided.
Technical and security data: IP address, browser user-agent, and a record of every access to your file. We keep this because we are required to, and because it is what allows you to see who has opened your record.
Our lawful basis
Health data is a special category of personal data under GDPR Art. 9. We process it on the basis of Art. 9(2)(h) — the provision of health care and management of health care systems — and, where the clinic relies on it, your explicit consent under Art. 9(2)(a).
Withdrawing consent stops future processing on that basis. It does not erase care already given, because the clinic has a separate legal obligation to keep that record.
Who can see your record
Access is restricted by role, and the restriction is enforced by the software rather than by policy alone:
• Your treating doctor sees your full clinical record.
• Nurses see clinical notes and record vital signs; they cannot prescribe.
• Reception and secretarial staff see only registration and scheduling details. They cannot open clinical notes at all.
• Clinic administrators manage staff, scheduling and compliance, and cannot read clinical notes.
• ClinTouch staff, including the platform operator, cannot access any clinical record. This is enforced at the database access layer, not as a configurable setting.
In a medical emergency a doctor may use "break-glass" access to open a record outside their normal caseload. Doing so requires a written justification, is recorded permanently, and is shown to you in your own access log.
How we protect it
Directly identifying fields such as national ID numbers are encrypted with AES-256-GCM at the application layer, so they are unreadable in a database dump or backup file.
Uploaded documents — scans, lab reports, letters — are encrypted the same way and stored outside the public web space. They have no shareable link: each download goes through an authenticated check and is written to your access log, so a copied URL is useless to anyone else.
Every read and write of a medical record is written to an append-only audit log that cannot be edited or deleted from inside the application.
Accounts lock temporarily after repeated failed sign-in attempts, and sessions expire after a period of inactivity set by your clinic.
No security measure is absolute. If a breach occurs that is likely to affect your rights, your clinic is required to notify the supervisory authority within 72 hours and, where the risk is high, to notify you directly.
How long we keep it
Your clinic sets a retention period for medical records — commonly between 6 and 10 years from the last episode of care, and longer for minors, depending on local law.
Records under a legal hold (litigation, a regulatory investigation, or an open insurance claim) are retained until the hold is released, regardless of any deletion request.
Your rights
You can ask for a copy of your data, correct it, ask for deletion, restrict or object to processing, and receive your data in a portable format. All of these can be requested from the Privacy & Consent page when you sign in.
You will get a response within one month. If a request is refused in whole or in part — most often because medical records must legally be retained — you will be told the specific reason.
You also have the right to see an accounting of who has accessed your record, which ClinTouch shows you directly rather than on request.
If you are unhappy with how a request was handled, you can complain to your national data protection authority.
Contact
For questions about this policy: privacy@clintouch.com.
For anything about your own medical record, contact your clinic directly — they hold it, and they decide on it.