1. Scope & roles
This policy applies to CLINQOV's corporate website, sales and support interactions, and the CLINQOV Meditrack platform (HMIS, EMR, ERP, HRMS, and all connected modules). CLINQOV plays two distinct roles depending on the data in question:
- Data Controller — for information we collect directly, such as website visitor data, sales inquiries, and the account details of individuals who work for our customers.
- Data Processor — for patient, clinical and operational data that our hospital, government and enterprise customers enter into the platform. In this role, we process data strictly on the customer's instructions and under a signed Data Processing Agreement; the customer remains the controller and is responsible for lawful collection and use of that data, including patient consent.
2. Information we collect
Information you provide to us
- Contact details submitted through demo requests, sales enquiries or support tickets (name, organization, email, phone)
- Account credentials and profile information for named platform users at customer organizations
- Content of correspondence when you contact sales, support or compliance teams
Information processed on behalf of customers
- Patient demographic, clinical, diagnostic, billing and administrative records entered into HMIS/EMR modules
- Staff, payroll and workforce data entered into HRMS
- Inventory, procurement, financial and operational records entered into ERP and connected modules
Information collected automatically
- Device, browser and log data (IP address, timestamps, pages visited) when you use our website or platform
- Cookies and similar technologies, described in Section 10
3. How we use information
- To operate, maintain and support the CLINQOV Meditrack platform for our customers
- To respond to demo requests, sales enquiries and support tickets
- To authenticate users and enforce role-based access controls
- To monitor platform performance, detect security incidents, and improve reliability
- To comply with applicable law, contractual obligations and regulatory reporting requirements
- To communicate product updates, security notices and — where permitted — relevant product information
We do not sell personal data or patient data, and we do not use patient data processed on behalf of customers for advertising purposes.
4. Our role with health data
Where CLINQOV processes health data as a processor, we act strictly under the written instructions of the relevant hospital, clinic, government body or enterprise customer, as set out in the applicable Data Processing Agreement or Master Services Agreement. Access to this data by CLINQOV personnel is limited to what is necessary to provide support, maintain the platform, and fulfil contractual obligations, and is logged and access-controlled.
Customers are responsible for ensuring they have a lawful basis — including, where required, patient consent — for the health data they input into the platform, and for responding to data subject requests from their own patients and staff.
6. International transfers
CLINQOV serves customers across multiple jurisdictions, including India and Kenya. Where data is transferred across borders — for example between a regional data center and our support teams — we apply appropriate safeguards consistent with India's Digital Personal Data Protection Act, 2023, Kenya's Data Protection Act, 2019, and other applicable data protection frameworks, including contractual data protection commitments with sub-processors and, where required, data residency arrangements agreed with the customer.
7. Security
We apply administrative, technical and physical safeguards appropriate to the sensitivity of the data we handle, including:
- Encryption of data in transit and at rest
- Role-based access control and least-privilege administration
- Audit logging across clinical and administrative modules
- Regular vulnerability assessment and patch management
- Incident response procedures, including customer notification obligations under our agreements
No system is perfectly secure. We continuously invest in strengthening our controls and will notify affected customers without undue delay in the event of a confirmed data breach affecting their data, consistent with our contractual and legal obligations.
8. Retention
Patient and operational data processed on behalf of a customer is retained for as long as instructed by that customer, or as required by applicable healthcare record-keeping law, and is deleted or returned in accordance with the governing agreement upon contract termination. Website and sales enquiry data is retained only as long as necessary for the purpose it was collected, or as required by law.
9. Your rights
Depending on your jurisdiction and role, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. If you are a patient, please direct these requests to your healthcare provider in the first instance, as they control your medical records. If you are a website visitor, sales contact, or a named platform user acting outside of a customer instruction, you can reach us using the details in Section 13.
11. Children's privacy
Our website and sales processes are not directed at children. Where the platform is used by a healthcare provider to store pediatric patient records, that processing is carried out strictly on the provider's instructions as described in Section 4, under their responsibility as data controller.
12. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or the jurisdictions we operate in. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated to customers in accordance with their agreement with us.
13. Contact us
If you have questions about this policy or how your information is handled, contact us at:
- Privacy enquiries: info@clinqovmeditrack.com
- Sales & general enquiries: sales@clinqovmeditrack.com