Unumed Privacy Policy

Last Updated: January 7th, 2025

1. Introduction

Welcome to Unumed, a software and data science company that works towards a world where the best technology supports, enables, and empowers healthcare professionals, health care administrators, and patients globally.

The Privacy Policy details Unumed's commitment to safeguarding the privacy and security of the data and other information entrusted to us by our customers, the patients our customers care for, prospective customers, business partners, third-party providers, and other users who engage with us through utilizing the Unumed Health Management Platform and related Patient portal (collectively referred to as Services) or visiting our website.

Unumed emphasizes the significance of contractual agreements, known as Provider Agreements, with our customers (health care providers). These agreements include specific provisions related to the use of health data and other information within our Services. In case of any conflict between the pro-visions of this Privacy Policy and the Provider Agreement, the terms specified in the Provider Agreement shall take precedence and control the processing of personal data.

We kindly ask that you carefully review this Privacy Policy to fully understand our practices concerning Personal Information you may choose to share with us through the Unumed Health Management Platform, the Patient portal or our website.

For further clarification on specific terms, please refer to the Definitions provided below.

2. Unumed Services - for Our Customers

Our Services, serves as a comprehensive Health Management Platform that supports and empowers clinical and financial staff alike.

In relation to health data and other information submitted to us through our Services, we establish contractual agreements (Provider Agreements) with our customers including, where relevant, Data Processing Agreements. These agreements contain detailed provisions governing the usage of such in-formation. While this Privacy Policy complements the terms outlined in the Provider Agreements and Data Processing Agreements, in the event of any conflict, the provisions stipulated in the Data Pro-cessing Agreement, subsequently, the Provider Agreement will take precedence.

At Unumed, we handle customer data with the utmost care, strictly complying to the direction and control provided by our Customers and applicable laws. It is important to note that we neither claim ownership of, nor exert control over the origin or validity of the personal data processed on behalf of our customers and subject to our Customers’ instructions. In managing Customer Databases integral to our services, we do not establish direct relationships with individuals whose personal data are stored, as we work as a Data Processor on behalf of the Customer, who is the Data Controller.
As a result, we do not actively seek, gather, or keep permissions or instructions to access, correct, up-date, or delete Personal Information as this is the responsibility of the Data Controller.

Any requests related to personal data maintained in our databases should be directed to our Custom-ers, and we fully commit to honouring and supporting any instructions they provide. Our role is to en-sure the secure and compliant processing of Customer Data in alignment with the directives and pref-erences of our customers.

2.1 Information processed on behalf of Customers

Data related to the Services are collected through different modules.

Clinical Modules (EHR)

  • • Patient health records: extensive health information, including clinical notes, nurse assessments, diagnostic imaging results, laboratory information, pharmacy data.

Financial Modules (ERP)

  • • Financial and billing Information: includes and is not limited to billing details, insurance claims, financial transactions, accounting data, and inventory information.

Telemedicine and Communication

  • Telemedicine data: information related to telemedicine consultations, including video calls and chats

Patient Administration

  • Patient administrative data: comprehensive patient registration data including personal identification numbers

2.2 Data sharing

Data collected within our Services may be shared with third parties on behalf of our Customers, subject to our Customers’ specific instruction. It is the responsibility of our Customers to ensure compliance with regulations and laws that mandate the provision of notice, disclosure, and obtaining consent before transferring the personal data to Unumed.

2.3 Security Measures

We prioritize the security of user data. Our measures include physical security, administrative controls, technical safeguards (with encryption, among others), a secure cloud environment, and access controls and logging.

All employees, contractors, consultants etc. who work for Unumed in connection with delivering the Services, are subject to appropriate confidentiality clauses ensuring their obligation to uphold secrecy regarding personal information that they may process or gain access to in connection with their work for Unumed.

2.4 Compliance and Incident Response

We are committed to compliance with GDPR and relevant international privacy legislation. In the event of a security threat or vulnerability, we will contact our Customers as soon as possible to recommend protective measures.

Incidents of suspected or actual unauthorized handling of Personal Information will promptly be directed to Unumed’s Legal and Compliance team and the Customer. The Legal and Compliance team is responsible for assessing and advising the Customer of the situation in order to make the Customer able to determine on necessary steps to be taken. Unumed will under all circumstances immediately initiate measures to mitigate the consequences of any incident.

2.5 Third-Party Embedded Technologies and Connected Services

It is important to note that third parties providing services may have different procedures for protecting Personal Information. Unumed takes measures to select reputable third-party service providers and – where applicable – enters into contractual agreements to ensure these providers comply with data protection laws.

However, Unumed cannot guarantee or be held responsible for the policies or compliance of third parties, even if we have integrated their solutions into our Services and/or made them available to you. We recommend reviewing the privacy policies of such third parties to understand their data protection practices. A list can be obtained from Unumed on request.

2.6 Sharing and Disclosure of Personal Information

Unumed is committed to safeguarding the privacy of Personal Information. We do not sell or rent personal information to third parties. We will only share Personal Information under the following circumstances:

2.6.1 Service Providers

We may engage service providers to facilitate and enhance our services. These service providers assist us in delivering the Services, managing data storage, conducting web analytics, and maintain-ing/growing our platform. These providers have access to Personal Information solely for the purpose of performing tasks on our behalf and are contractually obligated to uphold the same level of data protection as required by GDPR.

2.6.2 Legal Compliance and Protection

We may disclose Personal Information to law enforcement officials, governmental agencies, or other legal entities under the following conditions:

  1. In response to their request or
  2. In response to Customer request;
  3. When permitted or required by law;
  4. To establish our compliance with applicable laws, rules, regulations, or guidelines;
  5. To establish, protect, or exercise our legal rights or defend against legal claims or demands.

In instances where we are required by law to share data, involving the disclosure of Personal Information to legal entities, such as insurance companies related to claims, through APIs (Application Programming Interfaces), rest assured that only the data essential for the specified purpose will be shared.

2.6.3 Aggregated Non-Personal Information

In some instances, we may share certain aggregated non-personal information with third parties. This information does not identify individuals and is used for statistical analysis and improving our services.

2.6.4. Data Subjects’ Rights

As Data Processors, we assist Data Controllers in ensuring that Data Subjects can exercise their rights, including the right to access, correct, delete, restrict processing, and obtain data in a portable format. We encourage Data Subjects to reach out directly to their Data Controllers for exercising these rights, and we collaborate closely with Data Controllers to ensure a smooth and compliant process in ad-dressing these requests.

3. Processing of personal data controlled by Unumed

Unumed collects and process personal data as a Data Controller about customers´ contact persons, prospective customers, those reaching out through our website, job applicants and users of our soft-ware, excluding our customers. This includes care providers and contractors collaborating with our customers.

Unumed’s main purpose in collection, storing and processing personal data, is to provide - and on an ongoing basis develop and improve - the services that Unumed has agreed to provide to its customers and/or to ensure relevant and precise communication with you.

Such processing is carried out under one or more of the following legal bases:

  1. GDPR Article 6, paragraph 1, letter a – with your explicit consent
  2. GDPR Article 6, paragraph 1, letter b – to fulfil an agreement of which you are a party
  3. GDPR Article 6, paragraph 1, letter c – for Unumed to comply with a legal obligation imposed on Unumed, and/or
  4. GDPR Article 6, paragraph 1, letter f – to pursue a legitimate interest that outweighs your interest in not having the information processed.

Unumed only collects and stores personal information about you to the extent necessary and for as long as we need to fulfil the purposes mentioned above or as required by applicable law.

Personal information is otherwise deleted in accordance with Unumed’s deletion policy.

To the extent that the processing of personal information is based on your consent, you always have the right to withdraw your consent. However, such withdrawal does not affect the processing or disclosure of personal information that has occurred prior to the withdrawal of consent.

You also have the following rights, which you can learn more about in the Data Protection Agency's guidance on datatilsynet.dk

  1. The right to have personal information deleted in special cases
  2. The right to have your personal information restricted in certain cases
  3. The right to data portability of personal information we have obtained about you
  4. The right to opt-out of direct marketing
  5. If personal information is processed for direct marketing purposes, you have the right to object to the processing of your information at any time, after which personal information may no longer be processed for this purpose.
  6. The right to object to the processing of personal information, including automated individual marketing communications.
  7. The right to complain by contacting a competent supervisory authority, including the Danish Data Protection Agency, Borgergade 28, 1300 Copenhagen K, telephone +45 33 193 200

If you have any questions about our processing of your information or wish to exercise the above rights, you can contact us via our contact information provided on the website.

Unumed only shares your information with subcontractors or partners to the extent necessary to fulfil the purposes stated in this policy. Unumed always ensures that such subcontractors or partners are subject to contractual obligations that ensure compliance with the law, your confidentiality, and adequate security of the necessary technical and organizational security measures.

If personal information is shared with subcontractors or partners located outside the EU/EEA, a legal basis for such transfer is also ensured.

Information may be disclosed to others in cases where Unumed is required to disclose personal information by law or on the basis of a legitimate request from public authorities.

4. Public Website - Cookie policy

Upon visiting the Unumed website (www.unumed.com), visitors will receive a pop-up cookie banner informing them about the cookies collected during their navigation, if they consent. For further details on the cookies collected, please refer to our Cookie Policy (Section 4.2. Cookie Policy).

4.1. “Get In Touch” Option

When contacting us through our website, we kindly ask that you provide information about the organization you represent, your job title, personal name, contact and country of origin, along with your message. Rest assured, the information provided in this case will be used solely for feedback purposes and will not be shared with third parties.

4.2. Cookie Policy

Our Cookie Policy provides information about the types of cookies we use, their purposes, and how users can manage their preferences.

4.2.1. What are cookies and why do we use them?

Cookies are small text files that are placed on users’ devices when they visit any website. They serve various purposes, including functioning of the website, improving the browsing experience, and help-ing website owners to understand how users interact with the website.

4.2.2. Types of cookies we use

Unumed’s website only collects cookies upon user consent and the collection is only done by reCAPTCHA which is a protection service provided by Google that helps protect websites from spam and abuse. It may analyse traffic, (potentially containing Users’ Personal Data) with the purpose of filter-ing the parts of traffic recognized as bots or spam.

Any information collected by the cookies is used solely for the purposes outlined in this policy and is handled in accordance with our Privacy Policy.

The functionality implication if not providing consent is limited to not being able to contact Unumed through the Contact form on the website.

4.2.3. Changes to this Cookie Policy

As we modify our website, this Cookie Policy may be subject to updates and changes. Therefore, we encourage our users to review this policy periodically, but we will also show transparently in our cook-ie banner.

5. Changes to This Policy

As privacy regulations and practices change and we improve our services, we may update this Policy periodically. We will try to give advance notice of any changes, but in certain cases we also have the right to make changes without notice if required by law. We will make an effort to inform all users of any changes through our contracts and communication channels in our Services, but we also encourage them to review the "Last Updated" date to ensure they are aware of the latest version.

6. Contact Us

If you have any questions or concerns regarding this Privacy Policy, or if you wish to exercise your rights, please contact us at info@unumed.com.

Definitions

  1. Personal Information is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data. This includes, but is not limited to, names, contact details, identification numbers, online identifiers, and other data that can be linked to an individual.
  2. Data Controller refers to our Customers or any other entity that determines the purposes, conditions, and means of the processing of personal information. The data controller is responsible for com-plying with data protection laws and ensuring the rights of data subjects
  3. Data Processor is a party that processes personal information on behalf of and in accordance with the instructions of a Data Controller. The data processor is typically engaged to provide specific services outlined in contractual agreements.
  4. Data Subjects represent individuals whose personal data is processed through Unumed's services, encompassing patient information, staff data, and other related entities.
  5. Customers are health care providers who have entered into a business relationship or contractual agreement with Unumed for the provision of services, products, or access to platforms.
  6. Customer Databases refer to the specific databases managed by Unumed on behalf of its customers, containing personal information and healthcare data, with customers acting as Data Controllers.
  7. Connected Services: Encompasses external services, platforms, or applications that are integrated or interact with Unumed’s offerings, which may include but are not limited to third-party software, APIs, or plugins.
  8. Embedded Technologies are certain, specified software functions or related services provided by a third-party soft-ware developer or information system provider which Unumed embeds into its own software platform and makes it available for subscription by its Customers.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply