DataMD Philippines
Privacy Policy
Last updated 24 July 2026
This policy explains how DataMD collects, uses, and protects information in line with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.
1. Our role: Data Processor, not Data Controller
For any patient-related information belonging to a client organisation (a clinic, hospital, or medical professional), that organisation is the Personal Information Controller. DataMD acts only as a Personal Information Processor, handling data strictly on the client's documented instructions.
This distinction matters: DataMD does not decide the purposes for which patient data is processed. We build and maintain the tools; the client organisation remains in control of its patients' data.
2. Patient data (PHI/PII) is never visible to DataMD
By design, identifiable patient information — names, addresses, contact numbers, birthdates, medical record numbers, and other direct identifiers — is accessible only to the client organisation's own authorised users. DataMD staff, developers, and administrators cannot view it.
To enforce this, our platform uses:
- Row-level security so each organisation sees only its own data;
- Encryption in transit (HTTPS) and at rest;
- Signed, time-limited URLs for any client-uploaded file;
- A rule that DataMD administrators cannot download raw client uploads that may contain patient identifiers;
- Audit logging of sensitive actions and the principle of least privilege throughout.
Patient registries we build for clients are delivered as separate, tenant-isolated applications owned by the client — they are not part of DataMD's own records.
3. What DataMD does collect
To run our business we process limited information such as:
- Account details of client users (name, work email, role);
- Organisation and project metadata;
- Billing and payment records (never card or wallet credentials);
- Scheduling and consultation details;
- Anonymised datasets and patient codes needed to deliver a project.
4. How we use information
We use the information above to deliver and support our services, issue proposals and invoices, schedule consultations, communicate with you, and meet legal obligations. We do not sell personal data.
5. Payments
Payments are processed by PayMongo via GCash, Maya, or online bank transfer. DataMD never stores your card or e-wallet credentials — only a payment reference, amount, status, and timestamps needed for accounting.
6. Data retention & security
We retain business records only as long as necessary for the purposes above or as required by law, then securely dispose of them. We apply appropriate organisational, physical, and technical safeguards consistent with RA 10173.
7. Your rights
Under the Data Privacy Act you have rights to be informed, to access, to object, to rectify, to erasure or blocking, to data portability, and to file a complaint with the National Privacy Commission. To exercise any of these, contact us at hello@datamd.ph. If your concern relates to patient data held by a client organisation, that organisation is the controller and we will refer your request to them.
8. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new “last updated” date. Continued use of our services after changes take effect constitutes acceptance.
9. Contact
For privacy questions or to reach our Data Protection Officer, email hello@datamd.ph. See also our Terms of Service.