Privacy Policy
This Privacy Policy explains how the SireeNova platform handles data entered by participating hospitals and their authorized users. It applies to hospitals and authorized personnel using the platform.
Scope
This Privacy Policy applies to data processed within the platform, including donor information, donation and screening records, blood inventory, blood transfer requests, and user account information required for authentication and access management.
Data We Process
The platform processes data entered by participating hospitals for operational and clinical purposes related to blood services. This may include donor identification details, donation records, medical or laboratory screening results, blood unit records, blood inventory data, and operational activity within the system. The platform is not intended to use this information for marketing or commercial purposes outside the operation of blood services.
Hospital Data Isolation
The platform uses access controls designed to isolate each hospital's data from other participating hospitals. Authorized users can access only the information associated with their own hospital, according to the permissions assigned to their role. Platform administrators or authorized national authorities may be granted broader access where required for supervision, support, reporting, or regulatory compliance, depending on the system configuration.
Role-Based Access Control
Access to information is governed by user roles, such as Doctor, Hospital Administrator, or Platform Administrator. Each user is granted only the permissions required to perform their assigned responsibilities.
Authentication and Account Security
The platform uses secure authentication mechanisms. Multi-Factor Authentication (MFA) may be required for certain user accounts or sensitive operations, depending on the organization's security policies and system configuration.
Audit Logging
The platform maintains audit logs for important system activities, including user sign-ins, record creation, data modifications, and selected sensitive operations. These logs are used for security monitoring, auditing, and investigating authorized system activity.
Data Storage and Protection
The platform implements technical and organizational measures to help protect data. These include encrypted communications using TLS, role-based access controls, and security features provided by the underlying cloud infrastructure.
Data Retention
Data is retained for as long as necessary to support blood service operations, comply with hospital policies, or satisfy applicable legal and regulatory requirements. Audit logs may be retained for an appropriate period to support security and compliance activities.
Rights of Donors and Users
The platform does not share data with third parties except where necessary to operate the platform, provide technical support, comply with applicable legal or regulatory obligations, or when authorized by the participating hospital or the responsible authority.
Contact
If you have questions regarding privacy or the processing of personal data, please contact your hospital administrator or the SireeNova platform team through the Contact page.
