Privacy Policy
1. Overview
Privacy policy is a legal statement that discloses how personal data is used, disclosed, managed, stored and disposed of by MEDFIND+.
2. Purpose
This policy provides information, procedures and protocols to assist employees and contractors on requirements on processing personal data.
3. Scope
This policy applies to all MEDFIND+ employees and contractors.
4. Policy
4.1. Collection and use of personal data
4.2.a. Personal information MEDFIND+ processes the following personal data:
- - If you contact us by e-mail for a general question, we will save your contact details to give you further information and to provide you the most adequate answer to your question.
- - If you contact us for a Service or a product, we will save the following personal data you give to us: name, family name, phone number, email address, address and company.
- - If you contact us for a Service or a product, we will save the following personal data you give to us: name, family name, phone number, email address, address, vehicle model, vehicle registration number and company.
- - If you contact us for a job application, we will save the following personal data you give to us: name, family name, phone number, email address, address, picture, company, current employment, termination of the employment, career, academic curriculum, professional competence and professional experience. MEDFIND+ collects personal data directly from clients or customers.
- Build customer profiles and build relationships to ensure client service satisfaction;
- Assess eligibility of clients for credit;
- Creating awareness of products and drive the sales;
- Meet legal, tax and other regulatory compliance requirements;
- Appraisals and Provision of employee support services;
- Provision of critical service infrastructure for all internal users data.
4.3. Technical and organizational measures to secure data MEDFIND+ regards information and personal data as very important assets. Within this context, all information systems on which information and personal data is stored will be treated in line with internationally accepted standards that ensure the privacy, security and confidentially of all personal data.
This Policy contains the security & privacy measures, who are based on 3 basic principles, namely:
- - MEDFIND+ information systems are only to be used for only business purposes and access is restricted on a need-to-know basis.
- - Unauthorized access to MEDFIND+ information and information assets must be prevented at any and all times.
- - The privacy of personal data must be protected at any moment and during any process, in line with the applicable privacy legislations.
MEDFIND+ ensures that users are protected against unauthorized access, modification or use and loss, disclosure or destruction of personal data in its possession. We take the appropriate physical, legal, technical and organizational measures to ensure personal data is protected.
All safety measures are subject to regular internal and external audits to assess their effectiveness. The employees of MEDFIND+ undertake that all reasonable efforts to respect the provisions of the internal and external privacy regulations of MEDFIND+. Employees are also subject to the signing of a confidentiality declaration, which must be respected even when the employee leaves MEDFIND+
4.4. Sharing of personal data with third parties MEDFIND+ will not share your personal data with third parties other than the accepted third Party list below or only with the explicit, prior consent of the user.
MEDFIND+ always considers that your personal data needs to be processed in a fair, lawful, proportional and transparent manner.
Your personal data will never be used for advertising purposes, nor will it be passed on to third parties who would use this data for such purposes.
MEDFIND+ provides the necessary personal data if these are requested by an authorized person or body based on a legal provision (examples: police services, authorized municipal or order from a court of competent jurisdiction).
Third parties:
4.5. Rights of the data subject By means of the contact possibilities mentioned below, you can exercise the following rights regarding the processing of your personal data by MEDFIND+, except in cases where this would require a disproportionate effort on the part of MEDFIND+:
- - To ask information about and access to your personal data;
- - To ask for rectification of your personal data or restriction of processing;
- - To ask for removal of your personal data. In some cases, there may be a legal requirement to hold your data;
- - Right to file a complaint with the supervisory authority.
- - You can submit a written, dated and signed application to MEDFIND+ through Escripts Solutions Ltd., No. 53 3A & 3B Dr. F.A. Boateng Avenue, Joshua Industrial Complex, Kpone, Tema-Ghana.
- - You can send an email to medfindplus@escripts-solutions.com
Contact options to exercise your rights:
MEDFIND+ will ensure that your personal data will not be stored longer than necessary. The retention period depends on the purpose for which they were collected. In many cases, personal data are kept for an additional period to ensure their availability in case of questions or disputes. Because MEDFIND+ strives to meet obligations imposed by Data Protection Act, 2012 (Act 843) in such a way that personal data is protected against accidental or malicious destruction, it is possible that MEDFIND+, after your personal data have been removed from our systems and applications, remaining copies are not immediately removed from our backup systems.
MEDFIND+ shall treat your personal data in accordance with this Privacy Policy as long as these data are stored.
4.7. How does MEDFIND+ ensure compliance with this Privacy Policy?
MEDFIND+ assigns an external auditor or a privacy consultant to ensure that the provisions listed in this Policy are effective and in place. When MEDFIND+ receives formal complaints via the mentioned contact possibilities, they contact the person who submitted the complaint to discuss follow-up actions.
4.8. In case of Data breach
A data breach occurs when a breach of security leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In such a situation, all employees and contractors that become aware of the breach are required to report the breach immediately to MEDFIND+’s IT manager or any senior management personnel.
5. Enforcement
Employees found in policy violation may be subject to disciplinary action, which may include the termination of employment. Contractors that violate provisions of this policy may also have their contract terminated.
6. Distribution
This policy is to be distributed to all employees and contractors that process or handle personal data.
7. Policy Version History
Version | Date | Description | Approved By |
---|---|---|---|
1.0 | 05/12/2022 | Draft and Commencement of Initial Policy | The Board of ESCRIPTS SOLUTIONS LTD. |