Contact for data requests: support@1clickaway.xyz
Requests are identity-verified and handled under applicable law and the relevant hospital agreement.
| Category | Data fields | Purpose | Deployment requirement |
|---|---|---|---|
| Marketing website visitors | Name, email, hospital name, message (contact form); anonymised usage data via Google Analytics (page views, session duration, browser type) | Respond to demo requests; understand which content is useful | Purpose and lawful basis documented before collection |
| Hospital staff accounts | Full name, role, department, mobile number (optional); device push notification token; login timestamps | Account authentication, request dispatch, push notifications | Hospital instructions and signed service agreement |
| Operational requests | Room number, language required, department, request status, timestamps at each stage | Dispatch, tracking, audit reporting for the hospital | Hospital instructions and approved workflow |
Data minimisation: The platform is designed for operational coordination rather than clinical records. Patient identifiers, diagnoses, and treatment notes are not required fields. The deployment data inventory and staff training must prevent unnecessary clinical content from being entered into free-text fields.
| Data type | Retention period |
|---|---|
| Contact form submissions | Defined in the marketing data-retention schedule |
| Staff account data | Defined in the hospital agreement and deprovisioning procedure |
| Operational request records | Defined by the hospital's approved retention schedule |
| Website analytics, where enabled | Configured and documented before collection |
| Audit logs | Defined by security, legal, and operational requirements |
| Provider Category | Processing Scope | Purpose |
|---|---|---|
| Cloud Hosting & Delivery | Deployment-specific | Secure hosting and delivery of web application interfaces |
| Identity & Datastore Services | Deployment-specific | Staff authentication, operational message routing, and audit records |
| Push Notification Gateways | Deployment-specific | Operational alerts and dispatch notifications to authorized staff devices |
| Website Analytics (Marketing Only) | Marketing site only | Aggregated, anonymized website traffic analysis (never in hospital app) |
| Inquiry Processing | Marketing site only | Receiving and responding to hospital demo requests |
Data residency: Data residency commitments are established in the written agreement for each hospital deployment. Regional cloud hosting and dedicated environments are reviewed during technical due diligence.
- Analytics cookies are used on the marketing site only — never inside the operational hospital app.
- No advertising or retargeting cookies are used.
- You can opt out of Google Analytics at any time via your browser settings or the Google Analytics Opt-out Browser Add-on.
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Deletion — request deletion where the right applies, subject to legal and contractual retention duties.
- Restriction — request that we limit how we use your data in certain circumstances.
- Portability — request your operational data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Supported production traffic is intended to use HTTPS/TLS in transit.
- Operational access is designed to be restricted by authenticated identity, hospital scope, and role.
- Vendor assurance evidence is reviewed as part of deployment due diligence.
- Production staff access is intended to be provisioned and deprovisioned by authorised administrators.