FILAMENT SYSTEMS LIMITED
PRIVACY POLICY
Effective Date:
September 22, 2026
Last Updated:
September 22, 2026
System Name:
Syrup Health (v1.0)
Filament Systems Limited ("we," "us," or "our") is committed to protecting
the privacy, confidentiality, and security of personal data and health records
processed through our Health Management Information System (HMIS).
This Privacy Policy explains how we collect, use, disclose, and safeguard
information when healthcare facilities, healthcare providers, and patients
interact with Syrup Health.
1. Information We Collect
We collect information necessary to facilitate outpatient medical administration,
clinical consultation, diagnostic testing, pharmacy dispensing, and financial
billing across Level 2 and Level 3 healthcare facilities.
Patient Personal Identifiers:
Full name, national identity number/passport number, date of birth, age,
gender, phone number, residential address, and next-of-kin contact details.
Sensitive Personal Data (Health Information):
Clinical triage records (vital signs, BMI, blood pressure), chief complaints,
ICD-coded medical diagnoses, clinical consultation notes, laboratory test
requests/results, e-prescriptions, and medication dispensing logs.
Financial & Billing Information:
Invoice records, payment modes (cash, mobile money, insurance),
itemized service charges, and receipt logs.
System Usage & Technical Data:
User login credentials, role permissions, IP addresses, browser specifications,
access timestamps, and immutable audit trails of user activity within the application.
2. Lawful Basis and Purpose of Processing
We process personal and health data strictly under the following lawful bases:
1. Provision of Direct Healthcare:
To enable registered healthcare personnel to diagnose, treat, prescribe,
and manage patient health encounters.
2. Consent:
Explicit consent captured from patients or their legal guardians during intake/registration.
3. Legal & Regulatory Obligations:
To comply with mandatory public health reporting, such as Integrated Disease
Surveillance and Response (IDSR) submissions to national health databases.
4. Legitimate Facility Operations:
To enable accurate billing, inventory accounting, and administrative auditing
within the healthcare facility.
3. How We Store and Protect Your Data
Encryption Standards:
All data transmitted between user web browsers and Syrup Health is encrypted
using HTTPS with TLS 1.2/1.3 protocols. Data stored within our databases is
protected using AES-256 encryption at rest.
Access Control:
System access is governed by Role-Based Access Control (RBAC). Personnel can
only access data strictly necessary for their assigned role.
Network Security:
Database infrastructure is isolated within private cloud network zones protected
by cloud firewalls, preventing direct public internet access.
Audit Trails:
All record entries, updates, and accesses generate automated, immutable audit
logs containing timestamps, user IDs, and action types.
4. Data Sharing and Third-Party Disclosures
Syrup Health, and Filament Systems Limited, do not sell, rent, or trade personal
health data. We disclose data only in limited circumstances.
Authorized Healthcare Providers:
Clinical staff within the treating facility involved directly in the patient's care encounter.
Mandatory Public Health Reporting:
Transmission of anonymized or statutory reportable disease data to public health
authorities in accordance with national health surveillance regulations.
Legal Requirements:
When required by valid law enforcement orders, court summons, or regulatory mandates
under applicable data protection laws.
5. Data Subjects' Rights
Subject to statutory health record retention laws, data subjects (patients) have
rights regarding their personal data.
Right to Access:
The right to request copies of their health records and billing history.
Right to Rectification:
The right to request correction of inaccurate demographic information.
Right to Object:
The right to object to processing activities not strictly grounded in direct
medical care or legal obligation.
Right to Lodge a Complaint:
The right to raise concerns with the facility's Data Protection Officer or
the Office of the Data Protection Commissioner (ODPC).
6. Retention and Disposal
Personal health records are retained in compliance with statutory medical record
retention timelines. Upon expiration of the mandatory retention period, data is
archived securely or permanently purged in accordance with our Data Retention Policy.