Security & compliance
InnoCare FEM processes sensitive health information. This page summarises the technical and organisational measures we apply, our GDPR commitments and our HIPAA-aligned safeguards.
Access control
- Every in-app screen requires an authenticated account; nothing loads before sign-in.
- Records are isolated per account by row-level security in the database — a request can only ever read or write rows belonging to the signed-in user.
- Administrator actions are re-verified server-side and never grant access to member health records.
- Sessions sign out automatically after 30 minutes of inactivity.
Data protection
- Data is encrypted in transit (TLS) and at rest by our infrastructure provider.
- Health data is never included in URLs, notification text or application logs.
- On-device storage is namespaced per account and wiped on sign-out.
Your GDPR rights
- Explicit, granular consent (art. 6 and art. 9) captured before any processing.
- Export a machine-readable copy of your data at any time (art. 20).
- Erase your account and all associated health records permanently (art. 17).
- Withdraw analytics or marketing consent without losing access to the service.
HIPAA-aligned safeguards
- Administrative: role-based access, least privilege, and an immutable admin audit log.
- Technical: unique user identification, automatic logoff, audit controls, encryption.
- Physical: managed cloud hosting with certified data-centre controls.
- Business associate agreements are available for clinical partners — contact us before transmitting protected health information on behalf of a covered entity.
Incident response
- Suspected incidents are triaged within 24 hours.
- Notifiable personal-data breaches are reported to the relevant supervisory authority within 72 hours and to affected members without undue delay.
Privacy requests and security reports: privacy@innocare.example. See also our Privacy Policy and Terms.