Data Protection Notice
Last updated: January 2025
1. Purpose of this notice
This notice explains, in more technical and legal detail than our Privacy Policy, how Intelligent Care Inc. protects personal and health data processed through ICOS, CarePal, and the ICOS External Healthcare Network. It should be read alongside our Privacy Policy, not in place of it.
2. Governing law
Intelligent Care Inc. is headquartered in Navrongo, Upper East Region, Ghana, and processes data in accordance with Ghana's Data Protection Act, 2012 (Act 843), and is registered with the Data Protection Commission of Ghana. Where we process data on behalf of health organisations operating under other jurisdictions, we take reasonable steps to align our practices with internationally recognised standards for health data protection.
3. Controller and processor roles
For patient health records entered by a hospital, clinic, pharmacy, or laboratory using ICOS, that organisation is the data controller and determines why and how the data is used. Intelligent Care Inc. acts as the data processor, and only processes that data according to the controller's instructions and this notice. For a patient's own CarePal account and the choices they make within it — such as which external pharmacy or laboratory to use — the patient is the controller of their own data.
4. The External Healthcare Network specifically
When a hospital refers a prescription or lab order to the ICOS Network because it cannot be fulfilled internally, only the minimum information needed to fulfil that specific referral is shared with the pharmacy or laboratory the patient chooses. The choice of which provider to use always belongs to the patient — no provider is ever selected on their behalf. A result or dispensing record only flows back to the referring hospital when it originated from a real, traceable referral; a patient's own independent use of the network is never shared with any hospital without the patient's separate authorization.
5. Technical and organisational safeguards
We apply encryption to data in transit and at rest, role-based access control so that staff only see the data relevant to their function and organisation, row-level data isolation so that one hospital, pharmacy, or laboratory can never query another's records, time-limited signed URLs for sensitive documents rather than permanent public links, and a permanent audit log of administrative and financial actions taken on the platform.
6. Cross-border data transfer
ICOS is built to operate across multiple countries. Where a provider or hospital operates outside Ghana, their operational data is associated with that country's own currency and regulatory settings, and we take reasonable steps to ensure any cross-border transfer of personal data complies with applicable data protection law in both the country of origin and Ghana.
7. Data breach notification
In the event of a data breach affecting personal or health data, we will notify the affected data controller (the relevant hospital, pharmacy, or laboratory) without undue delay, and will support that controller in meeting any legal obligation they have to notify affected individuals or the Data Protection Commission of Ghana.
8. Your rights and how to exercise them
Ghana's Data Protection Act gives you the right to be informed about how your data is processed, to access your own data, to request correction of inaccurate data, and to request deletion where legally permitted. To exercise any of these rights, or to raise a data protection concern, contact us at privacy@intelligentcareos.com.
9. Data Protection Officer
Intelligent Care Inc. maintains a designated point of contact for data protection matters. You can reach them at privacy@intelligentcareos.com, or by writing to Intelligent Care Inc., Navrongo, Upper East Region, Ghana.