AIDI / POL-01
Data protection and privacy
AIDI limits the data it collects, separates the Academy and Lab contexts, and grants access based on organisations, relationships and permissions.
POL-01.1
Data and purposes
Public, account, teaching, financial and clinical data are classified and used for a defined purpose. Patient references are pseudonymous by default.
POL-01.2
Access and security
Sensitive data stays private. Access depends on authentication, the active organisation, the relationship to the resource, permissions and, where required, the assurance level.
Clinical files stay quarantined until they are validated and scanned. No clinical detail and no signed link is ever sent by email.
POL-01.3
Audience measurement and choice
Optional audience measurement is internal to AIDI and off without your consent. It uses only a public page key, the language, a device category and, when valid, the campaign source, medium and name.
No full URL, search term, referrer, entered content, identity, IP address, user agent or clinical data is sent. The choice can be changed at any time from the management button shown on public pages.
POL-01.4
Retention, transfers and rights
Retention depends on the type of data and the relationship concerned. Transfers and processors must meet the approved frame before any production Lab data is involved.
Access, correction, restriction and deletion requests are verified and handled in a dedicated workflow, subject to the applicable legal and security obligations.
Exercise my rights