PRIVACY POLICY
Polygon Digital Ltd. — polygondigital.co
Version 1.0 | Effective Date: 1 March 2026 | Covering: Polygon Health EHR, Telehealth Platform & Website
|
Controller |
Polygon Digital Ltd., Dublin, Ireland |
|
Contact |
[email protected] | +353 89 981 5670 |
|
Products Covered |
Polygon Health EHR, Polygon Telehealth Platform, polygondigital.co website |
|
Health Data |
We process special category health data (GDPR Art. 9) as a Data Processor on behalf of healthcare provider clients |
|
Applicable Law |
EU GDPR (2016/679), Irish Data Protection Act 2018, ePrivacy Directive |
|
Markets Served |
Ireland, European Union, Africa (selected jurisdictions) |
1. About This Policy
This Privacy Policy explains how Polygon Digital Ltd. (‘we’, ‘us’, ‘our’) collects, processes, stores, and protects personal data in connection with (a) the polygondigital.co website, (b) the Polygon Health EHR and practice management platform, and (c) the Polygon Telehealth platform.
Polygon Digital operates as a B2B software provider. Our customers are healthcare organisations — clinics, hospitals, GP practices, nursing homes, and allied health providers. These organisations are the Data Controllers of patient and client data. Polygon Digital acts as a Data Processor in respect of patient data and as a Data Controller in respect of customer account data and website visitor data.
2. About Our Products & Data Roles
Polygon Health EHR / Telehealth (B2B SaaS)
Polygon Digital provides EHR and Telehealth software to healthcare organisations. Patient personal data — including special category health data — is entered into our systems by our healthcare provider customers. In this context:
- The healthcare provider (our customer) is the Data Controller — they determine why and how patient data is processed
- Polygon Digital is the Data Processor — we process patient data only on the documented instructions of the healthcare provider
- We do not use patient data for any purpose other than providing the contracted service
- We do not have a direct legal relationship with patients — all patient rights requests should be directed to the treating healthcare provider
Website (polygondigital.co)
When you visit our website, we collect limited data (see Section 4). For website visitors, Polygon Digital acts as a Data Controller.
3. Special Category Health Data (GDPR Article 9)
Our EHR and Telehealth platforms process health data, which is classified as special category personal data under GDPR Article 9. This includes patient medical history, diagnoses (ICD-11 coded), prescribed medications, lab results, clinical notes, and telehealth consultation records.
We process this data strictly on behalf of healthcare provider customers under GDPR Art. 9(2)(h) (healthcare purposes) and Art. 9(2)(b) (obligations in employment and social security/protection law), as documented in our Data Processing Agreements. Healthcare provider customers are responsible for establishing a valid legal basis for collecting and uploading this data.
Polygon Digital does not use patient health data for AI model training, advertising, profiling, research, or any purpose not authorised by the treating healthcare provider.
4. Data We Collect
4.1 From Healthcare Provider Customers (Account Data)
- Organisation name, registration number, and address
- Administrator and user names, email addresses, job titles
- Billing and payment information (processed via Stripe — PCI-DSS compliant)
- System configuration and usage data
4.2 Patient/Client Data (Processed as Data Processor)
- Patient identifiers: name, date of birth, contact details, NHS/PPS number or equivalent
- Medical history, diagnoses (ICD-11), medications, allergies
- Clinical notes, consultation records, and practitioner observations
- Investigation and lab results
- Appointment and scheduling records
- Telehealth session metadata (not session content, unless recording is enabled by the provider)
- e-Prescription records (in supported jurisdictions)
4.3 Website Visitor Data (polygondigital.co)
- IP address, browser type, pages visited, session duration
- Contact form submissions (name, email, enquiry details)
- Cookie data — see Section 11
5. How We Use Data
5.1 For EHR/Telehealth Platform Customers
- Providing, maintaining, and improving the EHR and Telehealth software
- Processing clinical data as instructed by the healthcare provider
- Billing, invoicing, and subscription management
- Technical support and platform security
- Compliance auditing and access logging
5.2 For Website Visitors
- Responding to enquiries and demo requests
- Improving website content and user experience
- Sending marketing communications (with explicit consent only)
5.3 Legal Bases for Processing (GDPR Article 6)
|
Legal Basis |
Processing Activity |
|
Contract (Art. 6(1)(b)) |
Account management, EHR/Telehealth service delivery, billing |
|
Legitimate Interest (Art. 6(1)(f)) |
Security, fraud prevention, platform improvement, audit logging |
|
Legal Obligation (Art. 6(1)(c)) |
Tax, healthcare regulation compliance, data breach obligations |
|
Consent (Art. 6(1)(a)) |
Marketing emails, optional analytics cookies |
|
Art. 9(2)(h) + Art. 6(1)(b) |
Patient health data — processed under healthcare provider instruction and DPA |
6. Data Retention
|
Data Type |
Retention Period |
Note |
|
Customer account data |
Subscription term + 12 months |
Then deleted on request |
|
Patient health records |
Per healthcare provider instruction |
Minimum per national law (e.g., 8 yrs Ireland) |
|
Clinical notes / EHR data |
Per DPA with healthcare provider |
Provider determines retention |
|
Billing records |
7 years |
Irish Companies Act requirement |
|
Audit logs |
3 years |
Security and compliance |
|
Website enquiry forms |
2 years |
Then deleted |
|
Marketing consent |
Until withdrawn + 3 years |
Consent record retained |
7. International Transfers
Our primary data infrastructure is hosted in the EU. Where we engage sub-processors that operate outside the EEA (e.g., certain cloud or analytics providers), we ensure that appropriate safeguards are in place pursuant to GDPR Chapter V:
• EU Standard Contractual Clauses (SCCs) — Commission Decision 2021/914
• Adequacy decisions issued by the European Commission
For African market customers, data may be stored in EU data centres or in-country infrastructure depending on contractual arrangement and local regulatory requirements. We ensure appropriate contractual protections are in place in all cases.
8. Disclosure to Third Parties
We do not sell personal data. We share data only in the following circumstances:
• Sub-processors: Cloud hosting, database, payment, security, and support tools — all bound by DPAs
• Law enforcement: Where legally required by Irish, EU, or applicable national law
• Business transfers: In the event of a merger or acquisition, with appropriate data protections applied
• Healthcare regulators: Where required by applicable healthcare law (e.g., HIQA in Ireland)
9. AI-Assisted Features
Polygon Health EHR includes AI-assisted features designed to support administrative efficiency and clinical workflow documentation. These features are designed as decision-support tools — they assist healthcare professionals but do not replace clinical judgment. All clinical decisions remain the responsibility of the treating healthcare professional.
We do not use patient data to train AI models without explicit informed consent from both the healthcare provider and, where required by law, the patient. AI processing activities are logged in our audit trail.
10. Your Rights (GDPR)
If you are a website visitor or customer account holder, you have the following rights as a Data Subject under GDPR Articles 15–22: access, rectification, erasure, restriction of processing, data portability, and objection. Contact us at [email protected] to exercise these rights.
If you are a patient whose data is held in our EHR, your rights must be exercised directly with your healthcare provider (the Data Controller). We will cooperate with healthcare providers to facilitate Data Subject rights requests within the timeframes required by GDPR. We cannot fulfil patient rights requests directly without instruction from the treating healthcare provider.
You have the right to lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie) at any time.
11. Cookies
polygondigital.co uses essential cookies (session management, security) and, with your consent, analytics cookies to understand website usage. We do not use advertising or tracking cookies. Our cookie consent banner allows you to accept or decline non-essential cookies in compliance with the ePrivacy Directive.
12. Security
• TLS/SSL encryption for all data in transit
• AES-256 encryption for data at rest
• Role-based access control (RBAC) across all platform environments
• FHIR-compliant data handling with audit trails
• EU-based hosting infrastructure with SOC 2-aligned controls
• 72-hour breach notification to the Data Protection Commission per GDPR Art. 33
• Annual penetration testing and security audits
13. Updates to This Policy
We may update this Policy periodically. Material changes will be communicated to registered customers by email at least 30 days before the changes take effect. The current version is always available at polygondigital.co/privacy-policy/.
14. Contact
For privacy enquiries, Data Subject requests, or DPA queries:
Email: [email protected]
Phone: +353 89 981 5670
Polygon Digital Ltd., 3 The Grove, Donabate, Co. Dublin, K36 KD27, Ireland | polygondigital.co
