Legal
Privacy Policy
This Policy explains what personal data CloudClinic collects, why, where it is stored, and what rights you have under Republic Act No. 10173 (Data Privacy Act of 2012).
1.Who We Are
CloudClinic is a clinical documentation platform for licensed Philippine physicians. We are the personal information controller for data collected through our platform under RA 10173.
Privacy Officer: cloudclinic.ph@gmail.com
2.What Personal Data We Collect
From physicians and clinic staff: full name, email address, password (stored as a one-way hash — we never see the plain text), PRC license number, PTR and S2 numbers (optional), specialization, digital signature image, clinic name and address, and usage data such as login timestamps and actions taken.
From patients (entered by the physician or authorized clinic staff): name, date of birth, sex, address, contact details, email address, clinical information (diagnoses, medications, consultation notes), and generated documents (medical certificates, prescriptions, DDE reports, referral letters, lab requests).
Automatically: session data (login times and IP address, collected by Supabase for security), audit log entries for every document action, browser and device information for each audited action (browser name and version, operating system, captured from the User-Agent string at the time of the action and stored in the audit log), and browser localStorage contents on the doctor's own device.
3.Why We Collect It
| Data | Purpose | Legal basis |
|---|---|---|
| Doctor credentials and account data | Account authentication; document signing identity | Performance of contract |
| Patient records | Generate clinical documents on behalf of the physician | Legitimate interest (clinical care); consent as applicable |
| Audit logs and document records | Regulatory compliance; dispute resolution; chain of custody | Legal obligation (RA 10173, RA 6675, DOH records requirements) |
| Email delivery data | Deliver documents to patients and third parties | Performance of contract |
| Session and usage data | Platform security and operation | Legitimate interest |
4.Where Data Is Stored
Supabase (database and authentication): Patient records, documents, audit logs, and account data are stored in Supabase on Amazon Web Services (AWS), Mumbai region (ap-south-1), India. Supabase acts as a data processor under a signed Data Processing Agreement (DPA) incorporating GDPR-standard contractual clauses, compatible with RA 10173. Supabase privacy policy.
Resend (email delivery): Document emails are sent via Resend. Resend processes recipient email addresses and message content only to deliver and confirm delivery. Resend acts as a data processor under its own DPA. Resend privacy policy.
Browser localStorage (doctor's device): CloudClinic stores patient records and drafts locally on the doctor's own device first, then syncs to Supabase when online. This data sits entirely on the physician's device — CloudClinic has no access to it. Physicians are responsible for securing their devices.
International data transfers: Data stored in Supabase resides in AWS Mumbai (India), constituting an international transfer under RA 10173. CloudClinic relies on Supabase's contractual protections to ensure appropriate safeguards.
5.How Long We Keep It
| Data type | Retention period |
|---|---|
| Patient medical records and documents | At least 15 years from last consultation (aligns with the audit trail's retention period below) |
| Audit logs | 15 years (RA 9165 requirement for DDE records; aligns with the most stringent applicable legal retention period) |
| Doctor and staff account data | Duration of subscription + 1 year after closure |
| System and session logs | 90 days |
Data is not permanently deleted without the account holder's explicit request, except as required by law or after the retention period expires.
6.Who Has Access
| Party | Access level |
|---|---|
| The treating physician | Full access to their own clinic's patients and documents |
| Authorized clinic staff | Limited access, scoped to patients assigned by the physician; no access to sensitive documents by default |
| CloudClinic platform operator | Access only for maintenance, bug resolution, and legal compliance; all operator access is logged |
| Supabase | As data processor — infrastructure operation only, subject to DPA obligations |
| Advertisers, data brokers, or other third parties | None. Patient data is never sold, rented, or shared for commercial purposes. |
7.Sensitive Personal Information
Medical records, diagnoses, medications, and DDE assessments are sensitive personal information under RA 10173. DDE reports, drug dependency assessments, and rehabilitation records are automatically flagged as sensitive and restricted to physicians with the view_sensitive_documents permission. Staff accounts cannot access sensitive documents without explicit physician authorization.
8.Document Verification
CloudClinic generates a unique verification QR code for each issued document. The public verification page shows only the document type, issuing physician, issue date, and a partially obfuscated patient identifier (e.g., "J. Santos"). Full patient information is not publicly disclosed through the verification system.
9.Your Rights Under RA 10173
| Right | What it means |
|---|---|
| Access | Request a copy of your personal data held by CloudClinic |
| Correction | Request correction of inaccurate or outdated data |
| Erasure | Request deletion of your data, subject to legal retention requirements |
| Portability | Receive your data in a machine-readable format |
| Object | Object to processing in specific circumstances |
| Withdraw consent | Where processing is consent-based, withdraw that consent at any time |
| Complaint | Lodge a complaint with the National Privacy Commission (NPC) |
Patients can submit Access and Erasure requests directly from the patient portal's "Privacy & My Data" section — access requests are fulfilled automatically, and erasure requests are reviewed by clinic staff since some records must be retained under the schedule above. For any other request, or if you don't have a portal account, email cloudclinic.ph@gmail.com — subject line: "Privacy Request — [Your Name]". We will respond within 15 business days.
10.Data Breach Procedure
In the event of a personal data breach, we will assess the scope within 24 hours of discovery. If the breach poses a real risk of serious harm, we will notify the National Privacy Commission (NPC) within 72 hours as required by RA 10173, and will notify affected data subjects without undue delay.
11.Cookies and Tracking
CloudClinic does not use advertising cookies, third-party trackers, or behavioral analytics. We use browser localStorage for offline record storage only. No data is shared with advertising networks or data brokers.
12.Updates to This Policy
We may update this Privacy Policy to reflect changes in law, regulatory requirements, or platform features. We will notify registered users of material changes by email. Continued use of CloudClinic after an update constitutes acceptance of the revised Policy.
Contact
Privacy Officer / Data Controller: CloudClinic
Email: cloudclinic.ph@gmail.com — subject line: "Privacy Request — [Your Name]"
National Privacy Commission (NPC)
Website: privacy.gov.ph
Helpline: (02) 8234-2228