Privacy Policy

HealthQuarters LIS — AffordaDev Software Development Service
Last updated: August 11, 2026

1. Overview

This Privacy Policy describes how AffordaDev Software Development Service (“AffordaDev,” “we,” “us”) collects, uses, stores, discloses, and protects personal information when you use HealthQuarters LIS (the “Application”).

We process personal information in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173, “DPA”), its Implementing Rules and Regulations, issuances of the National Privacy Commission (NPC), the DOH Patient’s Bill of Rights (Administrative Order No. 147, Series of 2004), applicable Department of Health requirements on medical records, and professional medical confidentiality rules in the Philippines.

2. Personal Information Controller

For personal information processed through HealthQuarters LIS, AffordaDev Software Development Service acts as the Personal Information Controller (PIC) under the DPA.

Service providers that host, maintain, or support the Application may act as Personal Information Processors (PIPs) and process personal information only on our documented instructions and subject to confidentiality and security obligations. For privacy-related inquiries, requests, or complaints, contact healthquarterslis@gmail.com.

3. Information We Collect

The Application may process the following categories of information:

  • Account and employment information — usernames, credentials, role assignments, and activity logs of authorized Application users.
  • Patient personal information — names, dates of birth, contact details, identifiers, and other registration data entered by authorized users.
  • Medical and clinical records — laboratory results, radiology and X-Ray findings, ECG records, test orders, diagnoses, and related health information. Under Section 3(l) of the DPA, this health information constitutes sensitive personal information.
  • Google account information — when an administrator connects Google Drive, we receive the connected Google account email address to confirm the connection.
  • Google Drive data — when Google Drive is connected, the Application may upload, organize, read, move, share, and delete radiology image files and folders within the Google Drive account and folders authorized by Application administrators.
  • Technical data — IP address, browser type, device information, and request timestamps for security, audit, and troubleshooting.

4. Purpose and Legal Basis of Processing

We use information to operate the Application and provide healthcare-related services, including to:

  • Register patients and manage laboratory, radiology, ECG, and other diagnostic workflows.
  • Encode, review, approve, release, and report clinical results.
  • Store and deliver radiology imaging files through Google Drive when that integration is enabled.
  • Send operational emails such as radiology notifications when configured.
  • Maintain audit logs, security controls, and system reliability.
  • Comply with legal, regulatory, and medical record-keeping obligations.

Processing of personal information is based on one or more conditions under Section 12 of the DPA, such as:

  • the data subject’s consent, where required;
  • compliance with a legal or regulatory obligation;
  • protection of vitally important interests of the data subject, including life and health;
  • processing necessary to respond to national emergency or public order and safety;
  • processing necessary for the purposes of the legitimate interests of the PIC or a third party, where permitted by law.

Processing of sensitive personal information, including medical records, is additionally based on permitted grounds under Section 13 of the DPA, such as processing necessary for purposes of medical treatment, carried out by a medical practitioner or a medical treatment institution, with an adequate commitment to keep the information confidential; processing necessary for compliance with a legal obligation; or the data subject’s consent, where required, including for optional integrations such as Google Drive.

5. Medical Records and Confidentiality

Patient medical records are confidential and handled in line with the DPA, the DOH Patient's Bill of Rights (Administrative Order No. 147, Series of 2004), applicable Department of Health record-keeping requirements, and professional medical confidentiality rules.

Access to patient medical records in HealthQuarters LIS is limited to authorized Application users according to their assigned roles and only for legitimate clinical, administrative, and operational purposes. Access is limited to authorized users of the Application. Unauthorized access, use, or disclosure of patient information is prohibited.

Medical records are retained for as long as necessary to support patient care, meet applicable Department of Health and other regulatory retention requirements, and satisfy legal, audit, and accounting obligations, after which records are securely disposed of or anonymized where appropriate.

6. Google OAuth and Google Drive

If Google Drive integration is enabled, an authorized Application administrator connects a Google account through Google OAuth. The Application requests access to Google Drive so it can upload and manage radiology files in folders selected by authorized users.

OAuth tokens are stored on the Application server configuration. Files uploaded through the Application are stored in the connected Google Drive account. Because Google may process or store information outside the Philippines, such transfer is handled in accordance with Section 19 of the DPA and applicable NPC guidance, using appropriate safeguards where required.

Google’s use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google Drive access can be disconnected in Application settings or revoked at Google Account permissions.

7. Data Sharing and Disclosure

We do not sell personal information or Google user data.

We may share information only when necessary:

  • With authorized Application users based on role-based access controls.
  • With Personal Information Processors that host, maintain, or support the Application, subject to confidentiality and security obligations.
  • With referring physicians, radiologists, or other healthcare professionals involved in patient care, when authorized and appropriate.
  • When required by law, court order, regulatory request, or valid government authority.
  • When necessary to protect the vital interests of a patient or other person, such as in a medical emergency.

8. Security Measures

In line with the DPA and NPC guidance, we implement reasonable and appropriate organizational, physical, and technical security measures designed to protect personal information against accidental or unlawful destruction, alteration, disclosure, or unauthorized access. These may include access controls, authentication, audit logging, and secure configuration of systems and integrations. No method of transmission or storage is completely secure.

9. Personal Data Breach

In the event of a personal data breach affecting information processed through the Application, we will respond in accordance with applicable NPC requirements, including NPC Circular No. 16-01 on personal data breach management. This may include assessing the breach, implementing containment and recovery measures, notifying the NPC within seventy-two (72) hours where required, and informing affected data subjects when the breach is likely to pose real risk of serious harm.

10. Your Rights Under the Data Privacy Act

Subject to applicable law, medical record rules, and the exceptions under Section 16 of the DPA, data subjects may exercise the following rights:

  • Right to be informed — to be furnished with information before entry of personal information into the processing system.
  • Right to access — to reasonable access to personal information and how it has been processed.
  • Right to object — to withhold consent or object to processing in cases allowed under the DPA.
  • Right to erasure or blocking — to suspend, withdraw, or order the blocking, removal, or destruction of personal information where processing is unauthorized or no longer necessary.
  • Right to damages — to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal information.
  • Right to file a complaint — to lodge a complaint with the NPC.
  • Right to data portability — where applicable under the DPA and NPC issuances.

Patients and other data subjects may submit requests through the contact details below. We may need to verify identity and may decline requests that are manifestly unfounded, repetitive, or incompatible with medical record retention and healthcare legal requirements.

11. Contact and NPC Complaints

For privacy questions, access requests, or concerns about medical records processed in HealthQuarters LIS, contact: healthquarterslis@gmail.com

Data subjects may also contact the National Privacy Commission if they are unsatisfied with our response to a privacy concern.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, regulation, or our practices. The updated version will be posted on this page with a revised date.