Privacy Policy
GIA Healthcare ("GIA", "we", "our", "us") operates a digital healthcare platform
consisting of a mobile application, a corporate website at giahealthcare.ph,
and a Super Admin portal at giahealthcare.ph/admin. This Privacy Policy explains
how we collect, use, share, store, and protect personal information — including sensitive
health information — in accordance with the Philippine Data Privacy Act of 2012
(R.A. 10173), its Implementing Rules and Regulations, and relevant Department of
Health (DOH) circulars.
1. Information we collect
- Identity & contact information: full name, mobile number, email address, city, date of birth.
- Account credentials: hashed password, OTP verification timestamps, login history.
- Health information: symptoms you submit to the AI assistant, consultation notes, prescriptions, lab results, medication history, allergies, and uploaded medical documents.
- Doctor profile data (clinicians only): PRC license number, PTR number, education, hospital affiliation, fees, photo.
- Payment metadata: transaction reference numbers and amount only — we never see or store card numbers; these are handled by our PCI-DSS compliant payment partners.
- Device & usage: device model, OS, app version, IP address, push token, in-app event logs (for crash reporting and abuse prevention).
2. How we use your information
- To deliver core services: AI symptom checks, doctor consultations, pharmacy fulfilment, lab booking.
- To verify your identity and prevent fraud or abuse.
- To process payments and issue digital receipts.
- To send service notifications (consult reminders, prescription readiness) via push, SMS, or email.
- To improve clinical accuracy of our AI — always using de-identified, aggregate data only.
- To comply with legal, tax, audit, and regulatory obligations.
3. Who we share information with
We share the minimum data necessary, only with:
- Your treating doctor during a consultation — they see only the information you submit and approve.
- Licensed pharmacies and laboratories when you place an order — limited to fulfilment details.
- Payment processors (PayMongo, Maya) for transaction handling.
- Cloud infrastructure providers under contractual data protection commitments.
- Regulatory bodies (DOH, NPC, courts) only when legally compelled, and we will notify you when permitted.
We do not sell personal or health information to any third party for marketing purposes.
4. AI symptom check disclaimer
GIA's AI assistant is an informational triage tool, not a substitute for professional medical diagnosis. Inputs you share with the AI are stored to your personal health record so a licensed physician can review them during a consultation. We do not use identifiable AI conversations to train external models.
5. Data retention
- Account & consultation records: retained for the duration of your account plus 10 years (DOH requirement for medical records).
- Prescription & pharmacy orders: 5 years from issue date.
- Audit and security logs: 24 months.
- Push tokens and device IDs: deleted within 30 days of logout.
You may request deletion of your account at any time — see Section 7 below or email dpo@giahealthcare.ph.
6. Security measures
- Transport encryption (TLS 1.2+) for all client-server traffic.
- At-rest encryption of database fields containing sensitive health data.
- Role-based access control (RBAC); least-privilege admin access; full audit logging.
- Multi-factor verification (OTP) for account registration and high-risk actions.
- Annual third-party security assessments and penetration testing.
7. Your rights under the Data Privacy Act
- Right to be informed — you are reading this notice.
- Right to access — request a copy of your data.
- Right to rectify inaccurate or outdated information.
- Right to erasure (subject to legal retention).
- Right to data portability — receive your records in a machine-readable format.
- Right to object to direct marketing and certain processing.
- Right to file a complaint with the National Privacy Commission (NPC).
To exercise any right, contact our Data Protection Officer at dpo@giahealthcare.ph.
8. Children
GIA is intended for users aged 18 and above. Minors may use GIA only when added as a dependent under a parent or legal guardian's account, with full consent.
9. International transfers
Your data is primarily processed in the Philippines. Some cloud infrastructure may be hosted in Singapore or the United States; in all cases we use providers with appropriate contractual safeguards and NPC-compliant cross-border transfer agreements.
10. Changes to this policy
We may update this Privacy Policy. Material changes will be communicated through the app and via email at least 14 days before they take effect.
11. Contact us
Data Protection Officer — dpo@giahealthcare.ph
General support — hello@giahealthcare.ph