Privacy Policy

CertaCure Solutions Privacy Statement

Table of Contents

  • CertaCure Solutions Privacy Statement
  • How Your Information is Collected
  • How Your Information is Used
  • Recipients, Transfer, and Disclosure of Your Information
  • Controlling Your Information
  • Use of Cookies
  • Your Data Protection Rights
  • Transmitting Information to Us
  • Terms of Use
  • Our Data Protection, Privacy, and Security Approach
  • Patients of Our Client Healthcare Institutions
  • Regional Data Protection Considerations
  • Contact Us
  • Contacting Your Regional Data Protection Authority
  • Changes to Our Privacy Statement

CertaCure Solutions Privacy Statement

CertaCure Solutions (“CertaCure,” “we,” “us,” or “our”) is a healthcare technology company headquartered in Amman, Jordan, providing Hospital Information Systems (HIS), Picture Archiving and Communication Systems (PACS), Laboratory Information Systems (LIS), Electronic Medical Records (EMR), Revenue Cycle Management (RCM), and related software to hospitals, clinics, laboratories, and healthcare organizations across the region.

We interact with many types of people — website visitors, hospital and clinic staff, job applicants, business partners, and vendors — online, in person, and through phone and email. This Privacy Statement (this “Statement”) explains how we collect, use, and protect information regardless of your relationship with us. Depending on context, other materials may supplement this Statement — for example, a separate notice applies to patients whose health information is processed through our platforms on behalf of client healthcare institutions (see “Patients of Our Client Healthcare Institutions” below).

CertaCure respects your privacy and does not sell your personal information. If you have questions after reading this Statement, please contact us at info@certacure.com.

How Your Information is Collected

You directly provide CertaCure with most of the information we collect and maintain. We collect and process information when you:

  • Submit an inquiry, demo request, or message through our website's contact form
  • Email us at one of the addresses listed on our website
  • Provide your business card to us at a healthcare conference or exhibition
  • Submit a job application to us
  • Use or view our website via your browser's cookies
  • Interact with us on behalf of your organization — such as a hospital, clinic, laboratory, vendor, or business partner — in the course of implementing, using, or supporting our platforms
  • Are a registered user (e.g., doctor, nurse, administrator, IT staff) of a CertaCure platform deployed by your employer or healthcare institution
If you are a job applicant, we encourage you to contact us directly for details on how we handle recruitment-related information, as this may be governed by separate internal practices.

How Your Information is Used

We use the information you give us directly for the purpose(s) for which it was provided, unless you agree otherwise. CertaCure collects and processes your data so we can:

  • Respond to your inquiry, demo request, or "Contact Us" submission
  • With your agreement, send you product updates, newsletters, or information about upcoming events
  • Facilitate our business relationship with your organization, including entering into, managing, or fulfilling a services agreement
  • Provide, operate, secure, and improve our software platforms for the healthcare institutions we serve
  • Administer your job application, and, with your agreement, consider you for other roles
  • Understand which parts of our website visitors use and how frequently, to improve usability and troubleshoot issues.
Information we receive may be shared internally among CertaCure's departments and teams, but only where necessary and consistent with applicable law. We may also engage third-party providers (such as cloud hosting or IT infrastructure partners) to help us operate our services or distribute communications.We process your information for different reasons depending on the situation, including: when you've given us consent; when it is necessary to perform a contract with you or your organization; when required by law; or when it supports our legitimate business interests, such as improving our services or maintaining professional communication.We retain information only for as long as necessary to fulfill the purposes described above, including to provide and maintain our platforms, comply with legal or contractual obligations, resolve disputes, and enforce our agreements — unless a longer retention period is required by applicable law or agreed with a client.

Recipients, Transfer, and Disclosure of Your Information

CertaCure does not sell or share your information with third parties for their own direct marketing purposes. We may share information with:

  • CertaCure's internal teams and affiliates, where necessary to deliver our services
  • Client healthcare institutions, where the information relates to their own staff, operations, or patients
  • Technology and integration partners who support our platforms — such as cloud hosting providers, or partners including Microsoft, SAP, Philips, Oracle, and Nuance — strictly to the extent necessary to deliver our services and subject to confidentiality obligations
  • Government or regulatory entities, such as the Civil Status Department, where an integration has been authorized for the purpose of verifying or exchanging relevant records
  • Legal, regulatory, or law enforcement authorities, where required by law or to protect the rights, safety, or property of CertaCure, our clients, or others
CertaCure primarily operates in Jordan, Saudi Arabia, Kuwait, Iraq, Lebanon, and Egypt. Where your information is transferred between these jurisdictions or to other countries in connection with our services, we take reasonable steps intended to ensure your information continues to receive an appropriate level of protection consistent with applicable law and our contractual obligations.

Controlling Your Information

You are in control of the information you directly provide to us. You may:

  • Decline to provide certain information (though this may limit our ability to respond to your inquiry or provide services)
  • Manage cookie preferences through your browser settings or, where available, our website's cookie consent tool
  • Opt out of marketing communications at any time by using the unsubscribe link in our emails or contacting us directly

Use of Cookies

Our website uses cookies and similar tracking technologies to enhance the browsing experience, understand site usage, and improve our services. Where required by applicable law, we request your consent before using non-essential cookies. For more details on the types of cookies we use and how to manage your preferences, please see our [Cookie Policy].

Your Data Protection Rights

Subject to the laws applicable to you, you may have the right to:

  • Confirm whether we process your information
  • Access your information
  • Correct, update, or complete your information
  • Request deletion of your information
  • Request a copy of your information (data portability)
  • Restrict or object to certain processing
  • Withdraw consent, where we rely on consent as our basis for processing
To exercise any of these rights, please contact us using the details in the "Contact Us" section below. We will respond to your request within a reasonable timeframe and in accordance with applicable law.

Transmitting Information to Us

Any information you submit through our website, forums, or other channels we operate will generally be treated as business/professional information rather than confidential in nature (excluding patient health data processed under a client agreement, and any information shared under a signed confidentiality or services agreement). Submitting general inquiries or feedback through our website does not create any confidentiality obligation on CertaCure’s part, unless otherwise agreed in writing.

This Statement does not define or modify CertaCure’s obligations with respect to protected health information processed on behalf of client healthcare institutions — those obligations are governed by the applicable service agreement and data processing terms with each client, as well as applicable healthcare data protection law.

Terms of Use

This Statement should be read together with our [Terms & Conditions], which govern use of certacure.com and the submission of information through our site, including provisions on applicable law and dispute resolution.

Our Data Protection, Privacy, and Security Approach

CertaCure implements technical and organizational measures designed to protect information, including:

  • Encryption of data in transit and, where applicable, at rest
  • Role-based access controls, so users only access information relevant to their role
  • A microservices architecture that isolates system components to reduce the impact of any single point of failure
  • Regular monitoring, testing, and review of our security practices
No system can guarantee absolute security, and we encourage our clients and their users to follow good security practices, such as protecting login credentials and reporting suspicious activity promptly.

Patients of Our Client Healthcare Institutions

If you are a patient at a hospital, clinic, or laboratory that uses CertaCure’s software, please note:

  • The healthcare institution where you receive care is the data controller responsible for your medical information and for determining how it is used.
  • CertaCure acts as a data processor, handling your health information only on the institution's behalf and according to its instructions, in order to provide the software that supports your care (such as records, lab results, imaging, and billing).
  • Questions about your medical records, consent, or how your health information is used should be directed to your healthcare provider, not CertaCure directly.
This Statement describes CertaCure's own privacy practices as a company and software provider — it does not replace the privacy notice of the healthcare institution where you receive care.

Contacting Your Regional Data Protection Authority

If you feel CertaCure has not addressed your privacy concern satisfactorily, you may have the right to contact the data protection authority applicable in your country of residence.

    Regional Data Protection Considerations

    CertaCure operates across several jurisdictions, and we aim to align our practices with applicable data protection laws in each, including:

      • Jordan — CertaCure's home jurisdiction and headquarters
      • Saudi Arabia, Kuwait, Iraq, Lebanon, and Egypt — where we support client healthcare institutions
      Where local law provides additional or different rights than those described above (for example, specific health data handling requirements or breach notification timelines), those local requirements apply in addition to this Statement. If you have questions about the specific protections that apply in your country, please contact us using the details below.

      Changes to Our Privacy Statement

      CertaCure keeps this Privacy Statement under regular review and will post any updates on this page. This Statement was last updated on [Date].