A summary of how Al Jawad Software House, which provides Ventrecs, processes personal data, including patient data, on behalf of healthcare providers that use the products. The signed data processing agreement is provided to customers during procurement.
Roles
The healthcare provider is the controller of the personal data it puts into a Ventrecs product. Al Jawad Software House acts as processor and handles that data only to provide the service and on the provider’s documented instructions.
Confidentiality
Everyone at Al Jawad who can access customer data is bound by a duty of confidentiality.
Security
Access is role-based and limited to the facility the user is authorised for, enforced on the server.
Patient sensitivity levels restrict access to sensitive records.
Every access, update and clinical action is recorded in an audit trail.
Safety-critical actions need the right role and, in some cases, a second person.
More detail is on the Security & Delivery page.
Where data is hosted
The hosting location and model are agreed with each customer for its deployment, and written into the contract.
Subprocessors
We use subprocessors only where needed to deliver the service and we are responsible for them. The list is on the Subprocessors page, and customers are told in advance of changes that affect their deployment.
Requests and incidents
We help customers respond to requests from the people the data is about.
If we become aware of a personal-data breach affecting customer data, we tell the customer without undue delay.
End of service
When a contract ends, we return or delete customer data as the customer chooses, unless the law requires us to keep it.
Questions and the signed agreement
Write to [email protected] and we will send the data processing agreement for your review.