CliviQue
Privacy Notice
Effective date: July 31, 2026
1. Scope of this notice
This notice explains how CliviQue may handle information through the public website, authenticated HMIS, support communications, implementation activities, subscription billing, and related services.
Hospitals and other healthcare organizations usually determine why patient and workforce information is collected and used in CliviQue. Depending on the agreement and applicable law, the hospital may act as the data controller or equivalent responsible organization, while CliviQue may act as a processor or service provider. The written agreement and applicable law control where they differ from this general notice.
2. Information handled by the service
Public website information may include basic request information, browser and device details, security logs, referrer information, and communications you send to CliviQue.
Staff account information may include names, usernames, contact details, authentication identifiers, roles, permissions, organization and facility assignments, account status, and security events.
Hospital records may include patient identity and demographic information, encounters, triage and consultation notes, diagnoses, observations, medications, orders, referrals, admissions, ward and bed history, theatre, ambulance, mortuary, billing, payment, document, and operational workflow information entered by authorized hospital users.
Implementation and subscription information may include organization details, facilities, licensed staff capacity, package assignments, add-ons, billing contacts, currency, invoices, payment status, and provider identifiers. CliviQue does not need complete card details from Stripe checkout to manage subscription status.
3. How information is used
Information may be used to authenticate users, enforce roles and facility scope, provide configured HMIS workflows, maintain patient and operational records, generate documents, support billing and subscriptions, respond to requests, protect the service, diagnose failures, prevent abuse, and improve reliability.
CliviQue does not use the public website to expose patient records. Clinical information is intended for authorized hospital workflows and must be used according to the hospital's instructions, access policies, professional obligations, and applicable law.
4. Hospitals, users, and legal authority
The hospital is responsible for determining an appropriate legal basis or other lawful authority for collecting, using, retaining, sharing, correcting, and deleting information within its care and employment context. It is also responsible for notices, consent where required, access assignments, and responding to patient or workforce requests unless the agreement assigns a task to CliviQue.
Authorized users must access only information required for their duties and must not export, disclose, alter, or use records for an unauthorized purpose.
5. Service providers and disclosures
CliviQue may use hosting, database, authentication, email, observability, payment, support, and security providers necessary to operate the service. Those providers may process information only for the services they provide and subject to applicable contractual and security obligations.
Information may also be disclosed when required by law, to protect patients, users, CliviQue, or others, to investigate misuse or security incidents, to enforce agreements, or as part of a lawful corporate transaction with appropriate safeguards.
CliviQue does not sell patient information or personal information for advertising. Advertising pixels and generic session-replay tools are not intended to run inside the authenticated HMIS workspace.
6. International processing
Infrastructure or service providers may process information in countries other than the user's location. Deployment location, transfer mechanisms, contractual safeguards, and any data-localization requirements should be agreed during implementation and assessed under applicable law.
7. Retention and deletion
Retention depends on the record type, hospital instructions, clinical and financial requirements, legal obligations, dispute and fraud prevention, backup cycles, and the applicable agreement. Healthcare records may need to be retained longer than ordinary account data.
Hospitals should define retention schedules and authorized deletion procedures. Requests to correct, access, restrict, export, or delete patient or workforce information should usually be directed first to the responsible hospital. CliviQue may assist the hospital as required by the agreement and law.
8. Security
CliviQue uses administrative, technical, and organizational safeguards designed to protect information. Current web controls include separated public and authenticated route layouts, HttpOnly session cookies, server-side authorization, organization and facility scoping, restrictive security headers, no-store responses, authentication throttling, and cross-tab session isolation.
No system can guarantee absolute security. Hospitals also remain responsible for secure devices, networks, passwords, role assignments, physical records, exports, backups, staff training, incident response, and timely reporting of suspected compromise.
9. Children and vulnerable patients
CliviQue is a hospital staff system and not a public service directed to children. Hospitals may lawfully record information about pediatric or vulnerable patients as part of care. The hospital must apply appropriate authority, safeguards, access restrictions, guardian or representative processes, and professional standards.
10. Privacy rights and requests
Rights vary by country and context and may include access, correction, objection, restriction, portability, or deletion. Clinical, legal, public-interest, safeguarding, and record-retention obligations may limit some requests.
Public website and CliviQue account questions may be sent to the contact below. Patient-record requests should identify the responsible hospital without sending the underlying medical record by ordinary email.
11. Changes to this notice
CliviQue may update this notice as the product, providers, agreements, or legal requirements change. Material changes will be reflected by revising the effective date and, where appropriate, communicating through the service or implementation contacts.
12. Contact
Privacy questions may be sent to mbakajoe26@gmail.com. Do not send patient records, diagnoses, passwords, session tokens, secret keys, or other sensitive health information by ordinary email.