Privacy Policy.

At Pin.Health our mission is to put an accessible and affordable tools in the hands of every doctor and health service in the hands of every person on earth. We are passionate about high-quality and convenient healthcare. We are also passionate about privacy. We strive to comply with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA), and to be market leaders when it comes to healthcare and privacy.

The Pin.Health is part of Iksanika llc. registered address is 60 South Market Street, Suite 1200, San Jose, CA 95113, United States (“Company”), provides digital health services, to doctors registered with its local National Health Service / Ministry practice in accordance with its GMS contract. The Pin.Health offers a digital-first service to doctors, which is provided by Iksanika under a sub-contract arrangement.

This policy explains how we use your personal data. We want to help you understand how we work with your data, so that you can make informed choices and be in control of your information. We invite you to spend a few moments understanding this policy. We may update this policy from time to time and, if we make any material changes, we will notify you when we do so. We will provide you with the opportunity to review such changes. By continuing to use our products and services after the changes have been made and we have notified you of them, the way we use your personal data will be subject to the terms of the updated policy.

This policy explains how we use your personal data for our healthcare services and products, including, amongst others, our private service, and our digital health services. It also governs the use of your data through our App, or any of our websites, including the pin.health website (and any reference to our App in this policy shall also include a reference to our websites).

This policy covers:

If you have any further questions about how we process your information, please don't hesitate to get in touch by contacting our Data Protection Officer:

Address: 60 South Market Street, Suite 1200, San Jose, CA 95113, United States

Email: support@iksanika.com

Who we are

Our health services are delivered by two companies within our group which are both registered in: Iksanika llc. provides the technology to doctors with digital health/medical tools. The registered office and principal place of business is 60 South Market Street, Suite 1200, San Jose, CA 95113, United States.

Your relationship is with Iksanika llc. When this policy talks about ‘Pin’, 'Pin.Health', 'Pin Health', ‘us’ or ‘we’, it means Iksanika llc. We provide your data to other companies within our corporate group, including Iksanika llc., which develops and maintains our software.

What personal data we hold and how we get it

We use the following categories of personal data:

Health and medical information

The main type of information we hold about you is health and medical information: information about your health, symptoms, treatments, consultations and sessions, medications and procedures. This includes details of your consultations with our doctors, and interactions with our digital services.

We get some of this information directly from you, when you register with us and when you use our healthcare services. If you use our tools we will receive your medical history from your previous GP. If you use our other services (including our private service), and if you have given consent for us to do so, we will send the consultation notes that we take during your use of the private service to your GP (for minors, we will share such notes, in line with medical guidelines, without such consent). Any correspondence we receive from you is uploaded electronically to your Pin.Health medical record.

We retain recordings of our consultations with you, in order to provide you with an easy way to re-watch your consultations where you wish to, so that we can ensure high quality care is provided to you, and, with your consent, to allow us to learn from them to improve our services. These recordings are held securely in accordance with our retention policy. You can access recordings of your consultations at any time through the App.

We may also hold information about you and your health from other apps, devices and services where you have given your consent to that data being shared with us. Examples include where you decide to share information collected from a smart watch or similar device with our App.

Financial information

If you make any payments on the App, your credit/debit card details are processed directly by a third party processor that will store all payment information and transaction details. We will only retain details of transactions on secure servers and we will not retain your credit or debit card information.

Technical information and analytics

When you use our App, we may automatically collect the following information where this is permitted by your device settings:

(a) technical information, including the address used to connect your mobile phone or other device to the Internet, your login information, system and operating system type and version, browser or app version, time zone setting, operating system and platform, and your location (based on IP address); and

(b) information about your visit, including products and services you viewed or used, App response times, interaction information (such as button presses) and any phone number used to call our customer service number.

We work with partners who provide us with analytics and advertising services (for our services only and not for third party advertising). This includes helping us understand how users interact with our services, providing our advertisements on the internet, and measuring performance of our services and our adverts. Cookies and similar technologies may be used to collect this information, such as your interactions with our services.

What we use your personal data for

The purposes for which we use your personal data and the legal grounds on which we do so are as follows:

Sharing your personal data with others

We may share your personal data with members of our corporate group and our partners. This is to help us deliver our services to you.

We may share your personal data with companies we have hired to provide services on our behalf, including those who act as data processors on our behalf, acting strictly under contract in accordance with Article 28 GDPR. Those data processors are bound by strict confidentiality and data security provisions, and they can only use your data in the ways specified by us.

We may share with our commercial partners aggregated data that does not personally identify you, but which shows general trends, for example, the number of users of our service.

Where you access our services through your health insurance provider or any of our commercial partners(including your employer) we may share with such partner your name, date of birth, email address, policy number, location, and the fact you have registered/used the service (and any other similar information). We will not without your consent share any details relating to the content of your consultation with us or your health/medical records. With your consent, we may share the date of the appointment, details of your diagnosis, prescription, pharmacy location, whether or not you had a referral made and other similar information about your appointment with us.

We will, where necessary, share your information with your other health and social care providers. For example, MD's or GP's (if you use our private service) and other local Health Service bodies, specialist referral services, therapists, pharmacists, hospitals, accident and emergency services, pathology service providers, diagnosis centres chosen by you for the purpose of imaging requests, and other health and care bodies. This may include sharing information with such services for safeguarding purposes in accordance with our legal obligations.

We may preserve or disclose information about you to comply with a law, regulation, legal process, or governmental request; to assert legal rights or defend against legal claims; or to prevent, detect, or investigate illegal activity, fraud, abuse, violations of our terms, or threats to the security of our services or the physical safety of any person.

Except as described above, we will never share your personal information with any other party without your consent.

Retention periods

We retain your medical records in accordance with local national best practice guidance - in particular in United Kingdom, advice provided by the Department of Health (2006) Records management: NHS code of practice, and summary guidance issued by the British Medical Association. The below is a summary of our retention policy, but we may retain records for other periods as required by law or regulation.

Type of record Retention period
GP records GP Records retained for 10 years after death or after the patient has permanently left the country unless the patient remains in the European Union. In the case of a child, if the illness or death could have potential relevance to adult conditions or have genetic implications for the family of the deceased, the advice of clinicians should be sought as to whether to retain the records for a longer period. Electronic patient records (EPRs) must not be destroyed, or deleted, for the foreseeable future.
Maternity records 25 years after the birth of the last child.
Records relating to persons receiving treatment for a mental disorder within the meaning of mental health legislation 20 years after the date of the last contact; or 10 years after the patient's death if sooner.

Data storage, security and transfers

We do not store your personal health data on your mobile device. We store all your personal health data - including your primary care information, medication information and diagnostic information - on secure servers.

Where you have chosen a password that enables you to access certain parts of our App, you are responsible for keeping this password confidential. We ask you not to share the password with anyone.

We do not store any credit or debit card information. Payments are processed via a third party payment provider that is fully compliant with Level 1 Payment Card Industry (PCI) data security standards. Any payment transactions are encrypted using SSL technology.

We encrypt data transmitted to and from the App. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy.

Your data may be processed or stored via destinations outside of the UK and the European Economic Area, but always in accordance with data protection law, including mechanisms to lawfully transfer data across borders, and subject to strict safeguards. For example, we work with third parties who help deliver our services to you, whose servers may be located outside the UK or EEA.

Your rights

As indicated above, whenever we rely on your consent to process your personal data, you have the right to withdraw your consent at any time by accessing the privacy settings in the App.

You also have specific rights under the GDPR and DPA to: