Personal data protection policy
Last updated 2026-07-04
Why this page exists
Your health information is among the most sensitive data there is, and you trust us with it. This policy explains — as plainly as we can — exactly what we hold, why we hold it, who can see it, how long we keep it, and the control you keep over it at every step. If anything here is unclear, our Data Protection Officer is here to answer.
Our promises to you
The essentials, in plain language — before the detail below.
Your medical record can never be lost by accident
Health records are protected at the database level: they can be archived when the law requires, but they are never silently deleted or destroyed by a cascade. Closing your account does not erase your medical history.
We never sell your data, and never use it for advertising
Your health data is used to give and coordinate your care — nothing else. We do not sell it, rent it, or profile you for ads. Ever.
Only your care team can see your record
Access is strictly need-to-know: only the professionals in an active care relationship with you, inside the organisation treating you, can see your data. Every access is recorded.
You stay in control
Export a portable copy of your data, correct it, withdraw a consent, or close your account — at any time, directly from your settings, with a clear explanation of what happens to each type of data.
Emergency access is always logged and reviewed
In a life-threatening emergency a clinician may reach your essential health facts (blood type, allergies, major conditions) even without a prior link. Every such "break-glass" access is limited, justified, logged, and reviewed afterwards.
Encrypted, and hosted on certified health infrastructure
Your data is encrypted in transit (TLS) and at rest, and stored on certified health-data hosting (HDS) within the European Economic Area, with an append-only audit trail of who accessed what and when.
Who is responsible for your data
Two responsibilities exist side by side. Ibenseena is the data controller for your platform data — your account and login, your professional directory listing, the clinical network, cookies and security telemetry. For the clinical records created during your care (consultations, prescriptions, lab and imaging results, nursing notes), the healthcare organisation treating you — a hospital, clinic, pharmacy or laboratory — is the controller, and Ibenseena acts only as its processor, handling the data on its instructions. In practice: for a specific medical record, your healthcare provider decides on correction or erasure and we assist them; for anything about your account or the app itself, you can come straight to us. Our Data Protection Officer (DPO) can be reached via the address in the Legal notice for any privacy question.
What data we hold
We keep only what your care and the service actually require. This includes: your identity and contact details; your account, login and security data (devices you use, sign-in events, multi-factor authentication); and your health data — a "special category" under GDPR Article 9 that receives the strongest protection — such as appointments, prescriptions, lab and imaging results, care plans, vital signs, clinical messages and any documents you choose to share. We also hold billing and insurance data, the consents you have given, and access logs showing who viewed your record and when. We do not collect data we do not need.
The legal grounds we rely on
Every use of your data has a lawful basis. We process health data on your explicit consent (Art. 9(2)(a)) and where it is necessary to provide your care (Art. 9(2)(h)); we process account and security data to deliver the service you asked for (our contract with you) and for our legitimate interest in keeping the platform safe; we retain certain records because the law obliges us to (medical-record and accounting duties); and, in a life-threatening emergency, we may act to protect vital interests (Art. 9(2)(c)). Where we rely on consent, you can withdraw it at any time — and we tell you what that changes.
What we use it for
We use your data to create and manage your account; to connect you with your care team and enable secure messaging that only works within an active care relationship; to deliver, coordinate and document your care; to process appointments, prescriptions, laboratory orders, billing and insurance; to keep the platform secure and detect abuse; and to meet our legal obligations. To be explicit about what we do not do: we never use your health data for advertising, and we never make automated decisions that produce legal or similarly significant effects on you without human involvement.
Who can see your data
Far fewer people than you might fear. Your data is visible only to the health professionals in your active care relationships and to the organisation treating you, on a strict need-to-know basis that is enforced automatically by per-organisation access rules — not left to good intentions. With your involvement, specific data may be shared with your pharmacy, laboratory or insurer to fulfil a request you initiated (for example, filling a prescription or processing a claim). Behind the scenes we rely on a small number of vetted sub-processors — including certified health-data hosting — each bound by a contract that forbids using your data for their own purposes. We never sell your data, and we never share it with advertisers or data brokers.
How access works by role
Ibenseena applies role-based, organisation-scoped access. A role is not a blank permission to browse patient data: access must match a care relationship, an operational workflow, an approved staff assignment, a legal obligation or a patient-authorised request. Structured patient data, sensitive documents, messages, prescriptions, laboratory results, billing records, minimal metadata and logs are separated so each role receives only the minimum data needed for its purpose. Every sensitive access or mutation is logged, and cross-actor workflow changes can trigger notifications so unusual activity is visible rather than hidden.
Patient data access
A patient can access their own profile, appointments, care documents, released prescriptions, released laboratory or imaging results, messages, consent choices, insurance requests, privacy requests and data exports. Patients can correct account and profile information directly where the app allows it, and can request correction, restriction, portability, erasure or account closure through privacy tools. A patient cannot delete medical, billing or audit records that the law requires a provider or organisation to retain; those records are archived, restricted or pseudonymised according to the applicable retention rule.
Doctor data access
A doctor can access patient data only when there is an active care relationship, appointment, referral, emergency workflow or other authorised clinical basis. Depending on permissions, doctors may create or update consultation notes, diagnoses, prescriptions, referrals, laboratory or imaging orders, care plans, summaries and clinical messages. Doctors cannot use platform access to browse patients outside their care, export records for unrelated purposes, or use health data for advertising. Clinical corrections and deletions must preserve medico-legal traceability and usually require organisation review.
Nurse data access
Clinical nurses can access the patient information needed for assigned care tasks such as intake, vitals, eMAR, wound care, follow-up, care-plan execution and clinical coordination. Office nurses can access the minimum information needed for scheduling, administrative triage, appointment approval, queue handling, intake coordination and communication routing. Nurse access is limited by organisation, nurse type and assignment; nurses must escalate clinical decisions to the responsible clinician and must not open or share records outside a legitimate care or operational need.
Healthcare staff data access
Healthcare staff access is granted through the staff-assignment workflow and approved by an authorised organisation manager. Staff may see or update operational data such as schedules, intake status, billing support fields, document routing, stock administration, patient communication tasks or workflow statuses only where their permissions allow it. They do not receive broad clinical access by default, and any export, document download, record change or cross-organisation action must be justified by the approved workflow and recorded in audit logs.
Hospital manager data access
Hospital managers can administer their organisation, approve staff assignments, configure services, supervise operational queues and review audit-sensitive activity for their organisation. They may see aggregated or operational information needed to manage care delivery, staffing and compliance, but they should not access detailed clinical content unless a specific legal, clinical, compliance or authorised operational reason exists. Manager rights are designed to protect organisation continuity, not to bypass medical confidentiality.
Pharmacy manager data access
Pharmacy managers and authorised pharmacy staff can access prescription, dispensing, stock, pickup, delivery and billing information needed to fulfil a pharmacy workflow. They may receive patient identity and contact details only to the extent needed to verify the prescription, counsel the patient, dispense safely, manage recalls or document pickup and reimbursement. They cannot access unrelated clinical notes, full medical histories or laboratory results unless a lawful pharmacy workflow specifically requires it.
Laboratory technician and manager data access
Laboratory technicians can access order details, sample identifiers, required patient identity checks, test information, operational status and files needed to process an analysis. Laboratory managers can additionally validate results, release reports, supervise staff and correct laboratory records with traceability. Laboratory users see what is needed for the diagnostic workflow, not the patient's full care record. Draft or unvalidated results are protected from ordinary patient or external access until the authorised release step is completed.
Pharmaceutical company manager data access
Pharmaceutical company managers generally work with product, batch, campaign, recall, professional communication and supply-chain data, not identifiable patient records. When a recall, safety notice or pharmacovigilance workflow requires patient-related information, access is limited to the minimum necessary data and is routed through authorised healthcare organisations or legally required reporting channels. Campaign or directory tools must not use patient health data for advertising, profiling or unauthorised targeting.
Distributor manager data access
Distributor managers access inventory, purchase orders, shipment, delivery, batch, recall and supply-chain status data. Patient-identifiable information is not part of ordinary distributor access; if a delivery or recall workflow needs contact or location information, it must be limited, logged and tied to that specific workflow. Distributors are responsible for protecting commercial, medicine and logistics data and for correcting inaccurate stock, batch or shipment information quickly.
Legacy administrative access
Legacy administrative roles may remain visible for compatibility, but the preferred model is healthcare staff access with organisation-specific approval and granular permissions. Administrative users may support scheduling, intake, billing, document handling or communication routing only where authorised. They must not make clinical decisions, browse records out of curiosity, export patient data without permission or keep local copies after the workflow ends. Organisations should migrate legacy access to the current staff-assignment model when available.
How long we keep your data
We keep data only as long as it is genuinely needed and as the law requires — governed by a written retention policy set per data category and per country, not decided case by case. Indicative periods: non-clinical account data is erased or pseudonymised 30–90 days after you close your account; medical records are kept for 20 years from your last care contact (for a minor, until their 28th birthday), because medical law requires it; billing records for around 10 years; security and access-audit logs for 6 years; and encrypted backups are automatically purged after 30–90 days. When a period expires, the data is deleted or irreversibly de-identified — it does not linger indefinitely.
The rights you have
You can ask us, at any time, to: give you access to your data; correct it if it is wrong; erase it; restrict or object to certain processing; hand it to you or another provider in a portable format; and withdraw any consent you gave. You can also lodge a complaint with your data-protection supervisory authority (such as the CNIL in France). One honest limit, for your protection as much as ours: some data cannot be erased on demand while a legal retention period or a legal hold applies — a clinical record, for instance, is archived until its retention expires rather than deleted. Whenever that happens, we tell you exactly what is kept, on what basis, and until when — no silent refusals.
How to exercise your rights in the app
You do not need to write a formal letter — you can act directly from Settings → Privacy. "Download my data" exports a portable copy (JSON) of the records where you are the data subject. "Request erasure" files your request and immediately shows you a clear, itemised breakdown of what will be erased now, what is legally retained and why, and until when. We verify your identity before acting on any request, and we respond within one month — extendable once for genuinely complex requests, exactly as the GDPR allows. Every request and its outcome is logged, so there is always a record that you asked and what we did.
Closing your account
You can close your account yourself from Settings → Account. Closing immediately revokes your access and, after a short cancellation window, erases or pseudonymises your non-medical personal data — preferences, device tokens, drafts and any marketing data. What we cannot delete, we are honest about: your medical, billing and audit records are not erased, because the law requires us to keep them; instead they move to a restricted archive, sealed from ordinary access, until their retention period expires. You can cancel a closure request during the grace window, and once an account is closed it can no longer sign in. Your record is pseudonymised in place — never destroyed in a way that would break the audit trail the law requires.
Emergency ("break-glass") access
Medicine sometimes cannot wait for paperwork. In a genuine medical emergency, a treating clinician may need your essential health information — such as blood type, allergies and major conditions — even without an active care relationship. This "break-glass" access is deliberately narrow: it exposes essential data only (never your notes or full history), it requires the clinician to state a reason, it is fully logged the moment it happens, and it is reviewed afterwards by our data-protection team. It is never a back door for routine access, and misuse is treated as a serious breach.
How we keep it safe
Protecting your data is engineered in, not bolted on. We use strict per-organisation access controls so data cannot leak between organisations, encryption in transit (TLS) and at rest on certified infrastructure, and an append-only audit log that records who accessed a record and when — a log that cannot be quietly altered. Sensitive security tokens are cryptographically signed so they cannot be forged. Accounts are never deleted in a way that would lose the legally-required audit trail: a closed account is pseudonymised in place. Emergency access is separately logged and reviewed, and our information-security management follows recognised standards (ISO/IEC 27001). If a data breach ever affected your rights, we would notify you and the authorities as the law requires.
Where your data is stored
Your health data is encrypted at rest and hosted on certified health-data infrastructure (HDS) within the European Economic Area, except in specific and safeguarded cases. Where any transfer outside your region is unavoidable, we rely on appropriate legal safeguards — such as a European Commission adequacy decision or standard contractual clauses — so your data keeps an equivalent level of protection wherever it is processed.
Changes to this policy
As the platform and the law evolve, we may update this policy. If a change is material — if it affects your rights or how we use your data — we will notify you rather than change it quietly, and the "last updated" date above will always reflect the current version.