Back to Sign Up
Privacy Policy for EndoGraph Pro
Last Updated: [Date]

LEGAL NOTICE: This is a placeholder privacy policy. You MUST replace this content with a comprehensive policy drafted by a legal expert, especially considering GDPR and French health data laws (HDS).

1. Introduction

Welcome to EndoGraph Pro. We are committed to protecting your privacy and handling your data in an open and transparent manner. This privacy policy sets out how we collect, use, and protect the personal information of our users (practitioners) and the data of their patients.

2. Data Controller

[Your Company Name], located at [Your Company Address], is the data controller for the practitioner's personal data.

For patient data, the practitioner is the Data Controller, and [Your Company Name] acts as the Data Processor on their behalf.

3. Information We Collect

3.1. Practitioner Data

We collect the following information upon registration: [List practitioner data collected, e.g., First Name, Last Name, Email, Phone, Clinic Address, Specialty, RPPS Number].

3.2. Patient Data (as processed on your behalf)

The application is designed to store patient information entered by the practitioner, which includes sensitive health data: [List patient data fields, e.g., Name, Gender, DOB, SSN, Exam Results, Diagnostics, Treatments].

4. Purpose of Data Processing

We process data to provide and improve our service, including account management, application functionality, security, and customer support. We do not use patient data for any purpose other than providing the service as instructed by the practitioner.

5. Legal Basis for Processing

[Explain the legal basis, e.g., Contractual necessity for practitioner data, and the practitioner's own legal basis for processing patient health data].

6. Data Security

We implement robust technical and organizational measures to protect data, including access control via Firebase Authentication, Firestore Security Rules, and data encryption in transit.

7. User Rights under GDPR

As a user, you have the right to access, rectify, or erase your personal data, restrict processing, and the right to data portability. You can manage your data in the 'Settings' section of the app.

8. Data Retention

[Describe your data retention policy. E.g., practitioner data is retained as long as the account is active. Deleting an account will permanently erase all associated practitioner and patient data.]

9. Contact Us

If you have any questions about this privacy policy, please contact us at [Your Contact Email].