1. Introduction & Scope
Medivo ("we," "our," or "the Platform") provides software designed for private medical centers, general practice clinics, surgeries, and healthcare facilities. We treat medical and practice data with the utmost confidentiality, adhering to regional data protection principles including the Zimbabwe Cyber and Data Protection Act, and international standards for electronic health record confidentiality.
2. Roles and Data Ownership
Your Medical Center is the Data Controller: Your clinic retains full, exclusive ownership of all patient records, consultation notes, diagnoses, prescriptions, and financial billing entered into your Medivo account.
Medivo is the Data Processor: We process healthcare information solely to provide system functionality, automated synchronization, backups, and customer support as authorized by your medical practice administrator.
3. Information We Collect
- Marketing & Inquiries: When requesting a demonstration, we collect your name, practice name, phone number, email address, and staff size.
- System Operational Logs: We collect technical logs (IP addresses, login timestamps, system errors) strictly for security verification, audit trails, and account lockout protection.
- Clinical Data: Patient demographics, vital signs, clinical consultation history, and prescriptions are encrypted and stored within your private medical center tenant database.
4. Data Isolation & Role-Based Access
Medivo incorporates strict role segregation within the application architecture:
- Reception and cashier accounts cannot access confidential clinical notes or doctor consultation records.
- Doctor accounts cannot modify finalized financial receipts or alter system audit logs.
- Every clinical action, record view, and prescription generation creates an immutable audit trail entry.
5. Offline Data & Synchronization Security
When operating in offline mode, local data is stored within an encrypted local queue on the clinic's local terminal. Once connection is re-established, records are transmitted via TLS 1.3 encryption to the central server with cryptographic verification to prevent tampering or data corruption.
6. Cookie Policy & Local Storage
We use essential cookies to maintain secure sessions and prevent CSRF attacks. Analytics cookies are optional and may be customized at any time using our Cookie Preferences settings.
7. Contact the Data Protection Officer
If you have questions regarding data retention, export of clinic records, or security practices, please contact us at privacy@medivo.live.