Health Report Writer Privacy Policy

Introduction

Welcome to Health Report Writer (or the "Company"). We are committed to protecting your privacy and ensuring the confidentiality of your data. This Privacy Policy outlines our practices regarding the collection, use, and disclosure of your information when you use our website, our application platform, in social media messages and marketing campaigns and the use of any of our products and services.

We comply with the Personal Data Protection Act 2012 (PDPA) of Singapore, as well as applicable data privacy laws, including the General Data Protection Regulation (GDPR) in the EU, the Health Insurance Portability and Accountability Act (HIPAA) in the US, and the Australian Privacy Principles (APPs).

Any person using the Services should familiarise themselves with this Privacy Policy and ensure they review it from time to time.

Scope

This Privacy Policy applies to all users of our Services, including healthcare providers, businesses, and individuals who interact with our platform. By using our Website and / or Services, you consent to the collection, use, and disclosure of your personal data as described in this policy.

Definitions

  • Documentation: Means any documentation relevant to Health Report Writer provided from the Company to You from time to time;
  • Health Report Writer, Company, us, we, and our: Health Report Writer, its director/s, employees, agents, and any other related parties;
  • Services: Means the products and services that are made available by the Company to You, including any Documentation, Websites and associated offline component;
  • Website: Means Health Report Writer's website located at https://www.healthreportwriter.com and/or other web pages designated by the Company;
  • You, your, your users: Means anyone who visits and/or uses the Website and/or the Services, and affiliates of that company or entity.

Information We Collect

We collect and store the following types of information (collectively, "Your Information") from you and users:

  • Personal Information: Any identifiable information provided from using our Services, the forms on our Company's Website(s), product pages, and includes but is not limited to you or your users' names, contact details, credit card and/or bank account information.
  • Usage Data: Information when you visit, use or interact with our Services, such as access times and pages viewed.
  • Third Party Data: Information obtained through other third-party sources, such as LinkedIn and public databases. We also obtain and/or purchase lists from third parties about individuals and companies interested in our products.
  • Anonymised Data: We use tracking pixels and cookies to analyse the effectiveness of our online ads in driving traffic to our Website. This data, collected anonymously by third parties, includes your server address, domain name, visit details, accessed pages, referral source. You can disable cookies in your browser settings, but our Website remains accessible without them.
  • Client Data: Your clients' information uploaded onto our application website, and includes but is not limited to your customers' names, contact details, health information, medical history and other sensitive information, as well as your inputs (e.g. prompts, notes) and generated outputs from using Health Report Writer's Services.

We may collect Your Information from You at various stages, including but not limited to when you use any of our Services, including our Website(s), when you register for an account or trial on our Website, when you contact us via social media, when authorised people provide us with your personal information on your behalf, when we obtain it from third parties, including in our marketing campaigns.

If you choose to provide us with Your User's or Your customer's information (the person's name, email and company) when using our services (including a trial), you represent that you have the party's permission to do so.

If you choose to provide us with a third party's personal information (the person's name, email and company) when taking part in our referral program, you represent that you have the third party's permission to do so.

If you choose not to provide the personal information outlined in the "Collection of Personal Information" section, the following may occur: we may be unable to deliver the requested products or services at the expected standard or at all, process third-party discounts or benefits, notify you of any updates to policies, products and / or services.

How We Use Your Information

We use Your Information, excluding Client Data, to:

  • Provide, operate, and maintain our Services.
  • Improve, personalize, and expand our Services.
  • Communicate with you, including for customer service, updates, and marketing.
  • Process your transactions and manage your orders.
  • To ensure compliance with legal and regulatory obligations.
  • To enhance security and prevent fraud.

We use Client Data only for the purpose for which you collected, i.e., providing health services.

We will not use Your Information for any purpose beyond what you would reasonably anticipate. Furthermore, we will not share Client Data without Your explicit consent, except when necessary to deliver the health services for which the platform is being used.

Disclosure of Your Information

We do not sell, trade, train on or otherwise transfer Your Information to outside parties except as described in this Privacy Policy. We may share Your Information in the following situations:

  • With Service Providers: We may share Your Information with third-party service providers that perform services on our behalf, such as report writing. These providers are bound by Business Associate Agreement, which include a Zero-Data Retention Policy, and are not permitted to use your information for any purpose other than providing services to us or to identify abuse. These providers will not use the shared information to train their models.
  • For Legal Reasons: We may disclose Your Information if required to do so by law or in response to valid requests by public authorities.
  • Billing: Health Report Writer uses a third-party service provider to manage credit card processing. This service provider is not permitted to store, retain, or use Your Information except for the sole purpose of credit card processing on the Company's behalf. We do not share Client Data with third-party services for billing purposes.

We are not responsible for the privacy policies of any third party, and we accept no liability on behalf of any third party. Third parties are responsible for informing you about their own privacy practices. The third-party providers (i.e., the subprocessors) that are used by Health Report Writer are: Supabase for user management, Stripe and Wise for payment services, OpenAI for data processing services.

Data Retention, Security and Breach

Data Retention

We will store Your Client Data only for the purpose for which you collected, i.e. providing health services.

Please note that by default, we will only store Client Data for the duration of your subscription with our Services for the primary purpose of providing health services for which You use Health Report Writer. The stored Client Data will be deleted once You end Your subscription with us, or if You request that we do so, whichever is earlier.

If You wish for the Company to store Client Data for a different duration of time compared to the default, please let us know via a call, e-mail or written message. The stored Client Data will be deleted once the duration as otherwise agreed between You and Health Report Writer lapses, or if You request that we do so, whichever is earlier.

We will retain Your Information (except for Client Data which is governed by the above), only for as long as necessary to provide our service to you or for other legitimate business purposes, such as (but not limited to) resolving disputes, ensuring safety and security, or complying with legal obligations, or until you request that we remove the information by contacting us. The duration of retention will depend on various factors, including the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, our purposes for processing the information, and applicable legal requirements. In any case, Your Personal Information will not be retained for more than seven years after your last interaction with our services, unless a longer retention period is required by law.

Personal Information and Client Data are stored in cloud-based servers located in Singapore, as provided by Supabase.

We will immediately remove your Personal Information or Client Data from our database if requested by you and we are not required by law to retain it.

Data Security

We implement a variety of security measures to ensure the safety of Your Information. However, while we implement a variety of physical, administrative and technical security measures to protect your data from unauthorized access, use and disclosure, we cannot guarantee absolute security. Users are advised to take their own precautions to protect their data.

Data Breach

If we become aware that there has been unauthorised access, disclosure, or loss of Your Information (Data Breach), and the Data Breach is likely to result in serious or significant risk or harm, we will notify you of the Data Breach within 72 hours of us becoming aware of such breach and provide necessary support to mitigate risks.

Third-Party Confidentiality

We use OpenAI's GPT API to provide our Services. By using our service, you acknowledge that your data will be sent to OpenAI for the performance of our services.

Health Report Writer has an enterprise agreement with OpenAI ensuring that Your Information provided by You to Health Report Writer for the primary purpose of providing the expected services to your clients will not be used by OpenAI to train its models and will not be stored on its servers and its subprocessors. OpenAI is SOC2, SOC3, and GDPR compliant.

OpenAI's use of your data is governed by their privacy and security policies, which ensure confidentiality and data security. For more information, please refer to: https://trust.openai.com

Your Rights

You have the right to:

  • Access and update your personal information.
  • Be notified of Your Information we collect about you and how we use it, disclose it and protect it.
  • Request the deletion of Your Information.
  • Object to the processing of Your Information.
  • Ask us to restrict the processing of Your Information.
  • Withdraw consent at any time where we rely on your consent to process Your Information.
  • Receive your personal information in a structured, commonly used, and machine-readable format and to have it transmitted to another controller.

To exercise any of these rights, please contact us at privacy@healthreportwriter.com.

We make diligent efforts to ensure that your personal information remains accurate and current whenever we collect or utilize it. This may involve cross-referencing data with third-party sources to verify its correctness.

If you discover that the personal information we have on file is inaccurate, incomplete, or outdated, please notify us promptly, and we will take appropriate measures to update or rectify it.

Indemnity

Due to factors beyond our control, data transmitted to us via the Internet may not be completely secure. Health Report Writer cannot be held accountable for the disclosure of information resulting from transmission errors. We do not accept any liability for the improper actions of unauthorised third parties.

You agree to defend, indemnify, and hold harmless Health Report Writer, our officers, directors, employees, agents, subcontractors, licensors, and suppliers from and against all claims, actions, demands, liabilities and settlements arising in connection with your use of the Website and Services.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time without notice. All information held by us will be governed by the latest version of our Privacy Policy which will be posted on this page. We will let you know as soon as reasonably practicable after our Privacy Policy has changed. We encourage you to review this Privacy Policy periodically for any changes.

Complaints

If you suspect a breach of your privacy, please contact us promptly at privacy@healthreportwriter.com using the details provided below and furnish us with all relevant information about the incident to facilitate an investigation.

We ask that privacy-related complaints be submitted in writing to ensure clarity and accuracy of the details, enabling us to conduct a comprehensive investigation. Where appropriate, we will confirm your understanding of the issue and your desired resolution. Following our investigation, we will inform you of the findings and outcomes in writing.

Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Email: support@healthreportwriter.com