01Who this page is for#
This page explains how Modulon Health meets the EU General Data Protection Regulation (GDPR), the UK GDPR and the UK Data Protection Act 2018, and the Swiss Federal Act on Data Protection. It is for clinics in the European Economic Area, the United Kingdom and Switzerland, for their patients and staff, and for anyone in those countries who visits our website or contacts us.
It adds to our Privacy Policy, which describes what we collect and why. Where the two differ for people in Europe, this page applies.
02Our role#
| Information | Our role |
|---|---|
| Patient data we handle for a clinic: calls, texts, bookings, forms, notes, billing | Processor,for the clinic |
| Clinic staff accounts and their activity in the platform | Processor,for the clinic |
| Website visitors, enquiries, sales and our own customer records | Controller |
When we act for a clinic, the clinic decides how patient data is used, and its own privacy notice applies. We process that data only on its instructions, under our Data Processing Agreement.
03Our lawful bases#
Where we are the controller, we rely on these lawful bases under Article 6 of the GDPR:
- Contract. To set up and run a clinic's subscription and give its staff access.
- Legitimate interests. To answer enquiries, arrange demos, keep the website and service secure, prevent fraud, and understand how the website is used. We have weighed these interests against your rights, and you can object at any time.
- Legal obligation. To keep financial records and respond to lawful requests.
- Consent. To send product news by email, where the law requires consent. You can withdraw it at any time.
Health data processed for clinics is a special category of personal data. The clinic relies on its own basis under Article 9 of the GDPR, usually the provision of health care under Article 9(2)(h), and we process it only on its behalf, under a duty of professional secrecy.
04Where your data is kept#
- Data for clinics in the European Economic Area and Switzerland is stored in the European Union.
- Data for clinics in the United Kingdom is stored in the United Kingdom.
- Our AI providers process requests in Europe, under zero data retention, and do not use the data to train their models.
The providers we use in each region are listed on our subprocessors page.
05International transfers#
Modulon is based in the United States. Patient data stays in the clinic's region, but some information is handled from the United States: our own business records, enquiries made through the website, and remote support our team gives when a clinic asks for it.
Where personal data is transferred out of the EEA, the UK or Switzerland, we protect it with the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and their Swiss equivalent, and with the supplementary measures our transfer assessments call for, such as encryption and strict access controls. You can ask us for a copy of the safeguards that apply.
06AI and automated decisions#
- When you call or text a clinic and an AI assistant responds, it tells you so, as the EU AI Act requires, and you can ask for a person at any time.
- The assistant handles routine tasks, such as booking an available appointment, within rules the clinic sets. It does not make decisions that have legal or similarly significant effects on you, and it does not diagnose, triage or give medical advice. Anything clinical goes to the clinic's staff.
- Visit notes drafted by the AI note taker are reviewed and signed by your provider, and the visit is recorded only with your agreement.
We assess our AI features under the EU AI Act and keep the documentation clinics need for their own assessments.
07Your rights#
Under the GDPR and UK GDPR, you have the right to:
- Access the personal data held about you, and get a copy.
- Have inaccurate data corrected, and incomplete data completed.
- Have your data erased, where there is no good reason to keep it.
- Restrict how your data is used, or object to its use based on legitimate interests or for marketing.
- Receive data you provided in a portable format, or have it sent to another organization.
- Withdraw consent at any time, where processing is based on it.
- Not be subject to decisions based solely on automated processing that significantly affect you.
If you are a patient, make requests about your health information to your clinic; if you send them to us, we will pass them on within five business days and help the clinic respond within one month. For anything else, write to hello@modulonhealth.com. We will answer within one month.
08How long data is kept#
Data we handle for a clinic is kept for as long as the clinic instructs, then returned or deleted as our Data Processing Agreement sets out. Records we keep as controller are kept for the periods in our Privacy Policy.
09For clinics#
To support your own compliance, we provide:
- Our Data Processing Agreement, with the Standard Contractual Clauses and UK Addendum built in, signed before any patient data is shared.
- Our data protection impact assessment of the service, to inform your own.
- A record of our processing on your behalf, and our list of subprocessors for your region.
- Breach notices within 48 hours, so you can meet the 72-hour deadline to notify your authority.
- The security and incident information you need for your supply-chain obligations under NIS2, where it applies to you.
10Contacts and complaints#
Our data protection officer can be reached at hello@modulonhealth.com. Where Article 27 of the GDPR or UK GDPR requires it, we appoint a representative in the European Union and in the United Kingdom, whose details we will provide on request and in our Data Processing Agreement.
You have the right to complain to the data protection authority in the country where you live or work, or where you believe your rights were infringed. In the United Kingdom, that is the Information Commissioner's Office at ico.org.uk. We would welcome the chance to address your concern first.
Questions about this page? Write to hello@modulonhealth.com.