GDPR (General Data Protection Regulation) and Physitrack
Any company or organisation who handles or processes data about individuals associated with goods or services used within the EU must comply with GDPR.
Here at Physitrack, the protection our our customers' data, including all client data is paramount. Below, we describe how Physitrack complies with all 7 pillars set out by the GDPR. If you have any questions, please feel free to contact us using the link above.
In obtaining consent for data use, companies cannot use indecipherable terms and conditions filled with legalese. It must be as easy to withdraw consent as to give it.
In the event of a data breach, data processors have to notify their controllers and customers of any risk within 72 hours.
Physitrack has a communications infrastructure in place which will let us quickly communicate information in the event of a data breach.
Right to Access
Data Subjects have the right to obtain confirmation from the Data Controller of how their personal data is being processed by the Data Controller. On demand, the Data Controller should provide an electronic copy of personal data to Data Subjects at no charge.
Right to be forgotten
When data is no longer relevant to its original purpose, Data Subjects can request the Data Controller to erase their personal data and cease its dissemination.
- If you are a healthcare practitioner, you can remove any patient at any time, as well as remove your own Physitrack account.
- If you are a patient, you can request that your healthcare practitioner remove your data from their Physitrack account.
Allow individuals to obtain and reuse their personal data for their own purposes by transferring it across different IT environments.
A practitioner can quickly export all of a client's data for re-use in other applications.
Privacy by Design
Inclusion of data protection from the onset of the system's design, with the implementation of appropriate technical and infrastructural measures.
Physitrack is tested regularly for various security vulnerabilities, both during development, where static analysis algorithms check code before it is checked into our continuous integration pipeline, and on our production systems, where weekly scans are conducted for (among others) OWASP-10 vulnerabilities.
Data Protection Officer (DPO)
Physitrack's DPO is Breht McConville. He can be reached at firstname.lastname@example.org
Physitrack is registered with the UK Information Commissioner's Office (ICO) under number ZA396165.