Privacy Policy of openIMIS

Last modified on July 30, 2020

PLEASE READ THIS PRIVACY STATEMENT CAREFULLY BEFORE THE USE OF openIMIS SERVICES.

The protection of your privacy and your personal data (as defined in Article 4(1) of the Data Protection Basic Regulation (EU) 2016/679 ("DSGVO") is very important to openIMIS ("us", "our" or "we"). It is extremely important for us that openIMIS users ("users") feel secure when using our services.

This Privacy Policy forms the basis on which personal data are collected from you. Please read this Privacy Policy carefully to understand the categories of personal information we collect from you, the circumstances in which we may disclose it to third parties and your rights regarding the personal information you provide to us.

When you use our mobile applications "openIMIS Policies Demo" or "openIMIS Claims Demo" (the "App") or openIMIS web-based application ("Web-embed") (together the App and Web-embed referred to as the "Services"), you might be asked to confirm that you have read and understood the information described in this Privacy Policy.

1. Who we are

This Privacy Policy applies to the processing of personal data by the openIMIS software as well as the openIMIS Initiative. The copyright for the openIMIS software is held by the Swiss Agency for Development and Cooperation (SDC), and is licensed as open-source software using the AGPL3 licence. Details on the license can be found in openIMIS Software License. The openIMIS Initiative, to promote and streamline the further development of the software, is currently financed by the German Federal Ministry for Economic Cooperation and Development (BMZ) and the Swiss Agency for Development and Cooperation (SDC), and is managed by Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ).

Questions, comments and inquiries regarding this data protection and privacy declaration are welcome and should be directed to openIMIS Service Desk (https://openimis.atlassian.net/servicedesk).

2. General overview of our data processing activities in connection with the Services

openIMIS will collect and process the following data from you:

You are asked to provide us with the above listed information when you:

We highly recommend and expect that the data entered in the openIMIS Apps or Web-embeds is not your real personal data, but is fictitious.

3. Specific processing activities and the nature and purpose of data use

3.1 If you create an account on the "Web-embed"

3.2 If you create or update a family or a family member on the "Web-embed" or on the "app"

3.3 If you create or update a policy, contribution/payment on the "Web-embed" or on the "app"

3.4 If you create or update claim on the "Web-embed" or on the "app"

4. Where is your personal information stored

When you submit data using the Apps or the web interface, the data collected from you will be stored the "Web-embed" server.

If collected via the app, they will be:

Those data are erased after synchronisation with the service of generation of an export archive (encrypted via password, stored in the IMIS folder).

Sensitive information exchanged between your browser and our website is transmitted in encrypted form using Transport Layer Security ("TLS").

5. Recipient of your personal data

In order to provide and maintain the services, the data recipient is the entity managing the openIMIS server the mobile app is configured to connect to. By default, the mobile apps are configured to connect to the openIMIS demo server: https://demo.openimis.org . The data in this demo server is available to anyone accessing it, however, all data is erased every week.

6. How long we store your personal data

openIMIS will retain any, including personal, data entered into the openIMIS demo server for a maximum period of one week.

7. Your rights

According to the basic data protection regulation (EU) 2016/679, you have various rights with regard to your personal data.

These rights can be exercised by sending a service desk request to https://openimis.atlassian.net/servicedesk.

If you request us to stop processing your personal data or to delete them, this will mean that you will no longer be able to use our services or at least those parts of the services which require the processing of the types of personal data you have asked us to delete, which may mean that you will no longer be able to use the services as a whole.

8. Changes to this privacy policy

Any changes we make to our privacy policy in the future will be posted on this page and, where appropriate, notified to you by email or by notification via the App. Therefore, we encourage you to check this page from time to time so that you are kept informed of how we are processing your information.