Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Last modified on July 30, 2020

PLEASE READ THIS PRIVACY STATEMENT CAREFULLY BEFORE THE USE OF

...

openIMIS SERVICES.

The protection of your privacy and your personal data (as defined in Article 4(1) of the Data Protection Basic Regulation (EU) 2016/679 ("DSGVO") is very important to openIMIS ("us", "our" or "we"). It is extremely important for us that openIMIS users ("users") feel secure when using our services.

...

When you use our mobile applications "openIMIS Policies Demo" or "openIMIS Claims Demo" (the "App") or openIMIS web-based application ("Web-embed") (together with the App and Web-embed referred to as the "Services"), you might be asked to confirm that you have read and understood the information described in this Privacy Policy.

...

  • Last Name, Other Names

  • Address

  • Date Of Birth

  • ID number

  • Phone, Fax, Email

  • Geo Location

  • Photo

...

You are asked to provide us with the above listed information when you:

  • Create an account on the "Web-embed"

  • Create or update a family on the "Web-embed" or on the "app"

  • Create or update a family member on the "Web-embed" or on the "app"

  • Create or update a policy on the "Web-embed" or on the "app"

  • Create or update a contribution/payment on the "Web-embed" or on the "app"

  • Create or update a claim on the "Web-embed" or on the "app"

We highly recommend and expect that the data entered in the openIMIS Apps or Web-embeds is not your real personal data, but is fictitious.

3. Specific processing activities and the nature and purpose of data use

...

  • Categories of data: language, names, e-mail address and password, user id, main health facility (optional), location of works, phone (optional), permanent address (optional), date of birth (optional) and time and date of registration.

  • Purposes of processing: to grant access to the "app" and "Web-embed", to generate report reports for the enrolment officer(s) and the claim administrator(s), and to perform audits.

  • Legal basis: legitimate interest (Article 6 (1) (f) GDPR): processing is necessary for the purposes of legitimate interests.

  • Storage period: as long as the user is registered in the "Web-embed" and not more that one week after the registrationaccount is created.

3.2 If you create or update a family or a family member on the "Web-embed" or on the "app"

  • Categories of data for a family: id, head of the family, region, district, municipality, village, poverty status (optional), confirmation type (optional), family group type (optional), and time and date of registration.

  • Categories of data for family members: photo, id, insurance number, names, date of birth, gender, marital status (optional), beneficiary card (optional), region (optional), district (optional), municipality (optional), village (optional), current address (optional), profession (optional), education (optional), phone (optional), email (optional), identification type (optional), identification number (optional), first point of care (optional) and time and date of registration.

  • Purposes of processing: allow validation of the claim to be to validate claims generated by the health facilities on behalf of the family and its members.

  • Legal basis: legitimate interest (Article 6 (1) (b) GDPR): processing is necessary for the performance of a contract.

  • Storage period: as long as the user is registered in the "Web-embed" and not more that one week after the registrationfamily or family member is created.

3.3 If you create or update a policy, contribution/payment on the "Web-embed" or on the "app"

  • Categories of data for policy: id, enrolment date, product, start date, expiry date, enrolment officer, policy value and time and date of registration.

  • Categories of data for contributions/payment: id, payer (optional), contribution category (optional), amount, receipt no., payment date, payment type, and time and date of registration.

  • Purposes of processing: to activate a (insurance) contract with the family.

  • Legal basis: legitimate interest (Article 6 (1) (b) GDPR): processing is necessary for the performance of a contract.

  • Storage period: as long as the user is registered in the "Web-embed" and not more that one week after the creation of the registrationpolicy.

3.4 If you create or update claim on the "Web-embed" or on the "app"

  • Categories of data: health facility, claim administrator, diagnoses, insuree number, claim date, care dates, visit type, claim id, claim number, services and items claimed, guarantee number (optional).

  • Purposes of processing: enabling the calculation to calculate of the amount to be reimbursed to the health facility based on the service provided (claim valuation and capitation on claim number/amounts); also for auditing.

  • Legal basis: legitimate interest (Article 6 (1) (b) GDPR): processing is necessary for the performance of a contract.

  • Storage period: as long as the "Web-embed" is active and not more that one week after the registrationcreation of the claim.

4. Where are stored your personal information

The personal When you submit data using the Apps or the web interface, the data collected from you will be stored the "Web-embed" server.

...

In order to provide and maintain the services, the data recipient is the insurance scheme owner(s) who is entity managing the openIMIS server the mobile app is configured to connect to. By default, the mobile apps are configured to connect to the openIMIS demo server: https://demo.openimis.org . The data in this demo server is available to anyone accessing it, however, all data is erased every week.

...