Data Protection & Confidentiality

Privacy Policy

Your health information is sensitive and deeply personal. We treat your blood sugar logs, blood pressure readings, and vital medical records with hospital-grade cryptographic security.

Last updated: September 4, 2026Version 2.4

Our Core Privacy Commitments at a Glance

  • We never sell your health or personal data to advertisers or insurers.
  • All telemetry and vital data is encrypted using AES-256 and TLS 1.3.
  • You maintain complete control to export or permanently delete your data anytime via our Deletion Portal.
  • Doctor sharing is explicitly opt-in and can be revoked with a single click.

1. Scope & Who We Are

Diabetos Health ("Diabetos", "we", "us", or "our") provides an integrated chronic care management platform, including our mobile application (iOS and Android), web portal, connected Bluetooth health monitors, clinical consultation workspaces, ambulance dispatch services, and automated WhatsApp health telemetry assistant.

This Privacy Policy explains how we collect, process, store, and safeguard your personal information and sensitive health telemetry when you access or interact with any of our services.

2. Information We Collect

To provide safe, accurate, and personalized diabetes and hypertension tracking, we collect the following categories of information:

Account & Identity Data

Full name, email address, mobile phone number, date of birth, biological sex, emergency contact details, and account credentials.

Health & Telemetry Data

Blood glucose readings (fasting, pre/post-prandial), continuous glucose monitor (CGM) streams, systolic/diastolic blood pressure, pulse, HbA1c lab values, medication schedules, insulin dosage logs, and traditional meal food logs.

Telehealth & Consultation Records

Direct messages with your linked doctor, clinical notes, uploaded lab prescription reports, and ambulance emergency dispatch coordinates.

Device & Telemetry Diagnostics

IP address, device OS version, Bluetooth glucometer hardware IDs, push notification tokens, and application performance crash reports.

3. How We Use Your Information

We process your data strictly for legitimate health and clinical management purposes:

  • Personalized Chronic Care: Calculating target blood sugar ranges, glycemic variability graphs, and blood pressure risk zones.
  • Emergency Distress Alerts: Alerting designated family caregivers or local emergency responders when severe hypoglycemia (< 3.9 mmol/L) or hypertensive emergency values are detected.
  • Medication Adherence Reminders: Providing scheduled push notifications or WhatsApp alerts for insulin and anti-hypertensive doses.
  • Traditional Nutritional Guidance: Calibrating glycemic loads for local staple dishes (such as Finger Millet Sadza, sorghum, and leafy relishes).
  • Clinical Synchronization: Transmitting trend summaries directly to your selected physician or clinic with your permission.

4. Data Sharing & Third Parties

Diabetos does not sell, rent, monetize, or disclose your health information to third-party data brokers, marketing agencies, or health insurance underwriters.

Data is shared only under the following tightly regulated circumstances:

  • Authorized Medical Practitioners: When you connect your account to your doctor, clinic, or diabetes educator.
  • Emergency Responders & Ambulance Drivers: When an active distress signal or ambulance dispatch request is initiated, your GPS location and current vitals are securely routed to the attending paramedic.
  • Infrastructure Service Providers: Trusted cloud infrastructure partners (e.g. AWS, Supabase, Twilio) operating under strict Business Associate Agreements (BAAs) and confidentiality covenants.
  • Legal Compliance: When required by enforceable court order, regulatory mandate, or applicable statutory laws.

5. Security & Storage

We implement state-of-the-art administrative, technical, and physical safeguards designed to prevent unauthorized access, accidental alteration, or disclosure of your protected health records.

Cryptographic Standards: 256-bit AES encryption at rest and TLS 1.3 encryption in transit for all network traffic.

Access Controls: Multi-factor authentication (MFA) and strict role-based access control (RBAC) across our clinical and support dashboards.

Compliance: Designed in accordance with international healthcare privacy standards (HIPAA security rules, General Data Protection Regulation / GDPR, and national data protection statutory frameworks).

6. Your Rights & Data Deletion

You retain complete ownership of your personal health data. Under applicable privacy regulations, you have the right to:

  • Access and export a digital copy of all your blood sugar and BP logs (CSV / PDF format).
  • Correct inaccurate or outdated personal profile details.
  • Revoke access previously granted to doctors, clinics, or family caregivers.
  • Request the complete and permanent erasure of your account and health records.

7. Contact Our Data Protection Officer

If you have questions, concerns, or inquiries regarding this Privacy Policy or how your personal health data is handled, please contact our Data Protection Office:

Diabetos Health Compliance & Privacy Office
Helpline: +263 77 123 4567 / 999 (Emergency)