Who this notice applies to
Scope — US users
The US section of this notice applies specifically to users accessing iHealix from the United States and describes how iHealix handles protected health information (PHI)in a manner consistent with HIPAA. iHealix is not itself a HIPAA “covered entity” but applies equivalent administrative, physical, and technical safeguards to all PHI it handles on behalf of covered providers using the platform.
For users in the United Kingdom, Canada, or the European Union, the applicable section below describes your data rights under UK GDPR, PIPEDA, or the EU GDPR respectively. Those versions are currently being reviewed by local counsel (see the banner above).
For a full description of how we collect, use, and protect all personal data — not just health data — see our Privacy Policy.
US users — HIPAA-aligned protections
When you use iHealix for a healthcare service in the United States, your health information is protected health information (PHI) and is handled with the following safeguards:
- Minimum necessary. We access, use, and disclose only the minimum amount of PHI necessary to accomplish the permitted purpose.
- Consent-first. We process health information only with your explicit consent or as permitted by applicable US federal and state law for the provision of health care services.
- Technical safeguards. PHI is encrypted in transit and at rest. Access is controlled on a need-to-know basis, and systems are monitored and audited.
- Business Associate agreements. Where we share PHI with third-party service providers who carry out functions on our behalf, we use written agreements requiring equivalent protection.
Subject to applicable law, you have rights to access, correct, and request deletion of your personal data. iHealix is not a covered entity under HIPAA but applies equivalent administrative, physical, and technical safeguards to all protected health information it handles on behalf of covered providers. You also have the right to receive a copy of this notice and, where applicable, an accounting of disclosures of your PHI.
Our Privacy Officer can be reached at info@innoedgetech.com. To file a complaint with the HHS Office for Civil Rights (OCR), visit www.hhs.gov/ocr/privacy.
Some service providers we rely on may process data in countries other than the United States. Where personal data is transferred internationally, we use appropriate contractual safeguards — such as Standard Contractual Clauses or transfers to jurisdictions with an adequacy determination — to protect it.
UK users — UK GDPR data rights
Pending legal review for UK market
The UK market version of this notice is being reviewed by qualified counsel for compliance with the UK GDPR and Data Protection Act 2018. The summary below reflects the iHealix Privacy Policy (which uses US/HIPAA defaults as the baseline). The UK-specific version will be updated before the UK market goes live.
Under the UK GDPR and Data Protection Act 2018, your health data is special category health data. We process special category health data under Article 9(2)(h) UK GDPR (provision of health or social care) and with your explicit consent.
Your rights under UK GDPR. Under the UK GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. You may also withdraw consent at any time.
You may exercise your rights by contacting us at info@innoedgetech.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Where personal data is transferred outside the UK, we use mechanisms approved by the ICO — such as the UK International Data Transfer Agreement (IDTA) or transfers to countries with UK adequacy regulations — to ensure equivalent protection.
Canadian users — PIPEDA rights
Pending legal review for Canadian market
The Canadian market version of this notice is being reviewed by qualified counsel for compliance with PIPEDA and applicable provincial health privacy legislation. The summary below is a placeholder. The Canadian-specific version will be updated before the Canadian market goes live.
Under the PIPEDA (Personal Information Protection and Electronic Documents Act) and applicable provincial health privacy legislation, your health data is personal health information. We collect and use personal health information only with your knowledge and consent, or as permitted by PIPEDA and applicable provincial health privacy legislation.
Your rights under PIPEDA. Under PIPEDA you have the right to access personal information we hold about you and to challenge its accuracy. You may also withdraw consent at any time, subject to legal or contractual restrictions.
You may exercise your rights by contacting our Chief Privacy Officer at info@innoedgetech.com. You also have the right to complain to the Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca.
Where personal data is transferred outside Canada, we take steps consistent with PIPEDA to ensure it is protected — including using contractual arrangements that require the recipient to provide comparable privacy protection.
EU users — GDPR data rights
Pending legal review for EU market
The EU market version of this notice is being reviewed by qualified counsel for compliance with the EU GDPR. The summary below is a placeholder. The EU-specific version will be updated before the EU market goes live.
Under the GDPR (General Data Protection Regulation) and applicable national law, your health data is special category health data. We process special category health data under Article 9(2)(h) GDPR (provision of health or social care) and with your explicit consent under Article 9(2)(a).
Your rights under GDPR. Under the GDPR you have rights to access, rectify, erase, restrict, port, and object to processing of your personal data. You may withdraw consent at any time without affecting the lawfulness of prior processing.
You may exercise your rights by contacting our Data Protection Officer (DPO) at info@innoedgetech.com. You also have the right to lodge a complaint with your national data-protection supervisory authority. A list of member-state authorities is available at edpb.europa.eu/about-edpb/board/members_en.
Where personal data is transferred outside the EEA, we rely on adequacy decisions, Standard Contractual Clauses (SCCs), or other approved transfer mechanisms under Chapter V GDPR.
How we use and disclose health information
Across all markets, we use your health information — symptoms, medical history, consultation notes, prescriptions, lab requests and results — only to:
- Provide your care. Share it with the independent provider treating you so they can deliver clinically appropriate care.
- Process your order. Share with a verified pharmacy or laboratory to fulfil a prescription or test order.
- Operate the platform. Store and transmit it securely via our technical infrastructure (encrypted LiveKit sessions for video, encrypted databases for records).
- Comply with the law. Disclose where required by applicable medical record-keeping rules, regulatory requirements, or a lawful order.
- Safety. Share with emergency services or law enforcement where there is an imminent risk of serious harm.
We do not sell, rent, or share your health information for advertising or unrelated commercial purposes.
Safeguards we apply
Regardless of the applicable legal framework, iHealix applies the following technical and organisational safeguards to health information:
- Encryption in transit (TLS 1.2+) and encryption at rest.
- Access controls: role-based access, least-privilege, and multi-factor authentication for staff.
- Network hardening, application security testing, and audit logging.
- Written data-processing agreements with all third-party processors who handle health information on our behalf.
- Breach response procedures: we act promptly and notify affected users and the relevant authority as required by law.
How to exercise your rights
To exercise any right described in this notice — access, rectification, erasure, restriction, portability, or objection — email us at info@innoedgetech.com with the subject “Data rights request”. Include your account email and a brief description of the right you wish to exercise. We may need to verify your identity before acting on the request.
To delete your account and personal data, see our Account Deletion page.
We will respond within the timeframe required by the law applicable to your region (e.g. 30 days under GDPR and UK GDPR, 30 days under PIPEDA, or as required under applicable US state law).
Complaints
If you are not satisfied with how we have handled your health information or a rights request, you have the right to lodge a complaint with the supervisory authority for your region:
- US: HHS Office for Civil Rights (OCR)
- UK: Information Commissioner's Office (ICO)
- Canada: Office of the Privacy Commissioner of Canada (OPC)
- EU: your national data-protection supervisory authority
We would appreciate the opportunity to address your concern before you contact a regulator. Please reach out to info@innoedgetech.com first.
Updates to this notice
We may update this notice as our practices change, as we expand to new markets, or as the law changes. When we make a material change we will update the “Last updated” date above and, where appropriate, notify you. Please review this notice periodically.
For the full privacy policy — covering all personal data, not just health data — see our Privacy Policy.