ClinMate Privacy Policy

Last Updated: July 17, 2026

Effective Date: July 17, 2026

Scope: This policy applies to the "ClinMate" Android and iOS clients provided by Hangzhou Trizen Medical Technology Co., Ltd.; for processing of patient medical data in hospital private deployments or SaaS services, please refer to Chapter IX "Regarding Commissioned Processing by Medical Institutions" for special provisions.

ClinMate is provided by Hangzhou Trizen Medical Technology Co., Ltd. (hereinafter referred to as "we" or "us"). We highly value the protection of your personal information and privacy, and commit to following the principles of legality, legitimacy, necessity, and good faith, processing your personal information in accordance with requirements for openness and transparency, clear purposes, minimum necessity, quality assurance, security protection, principal participation, and clear responsibilities.

Please carefully read and fully understand this policy before using ClinMate, especially the clauses highlighted in bold or red, as well as content involving sensitive personal information, system permissions, and account deletion. We will only process your personal information in accordance with this policy after you click "Agree and Continue"; before your consent, we will not request camera, microphone, photos/album permissions, nor will we collect your personal information.

For sensitive personal information such as medical health data, as well as processing activities involving public disclosure and automated decision-making that significantly impact personal rights and interests, we will obtain your separate consent through prominent methods such as pop-ups, separate checkboxes, or secondary confirmation, which will not be conflated with the overall consent to this policy.

Applicable Subjects

This policy applies to: (1) medical personnel who register and use ClinMate, including certified users such as physicians, nurses, pharmacists, and technicians; (2) institutional users such as medical institution administrators and institutional operators; (3) cooperative operation personnel who need to use this product for business cooperation, customer service support, operations and maintenance support, etc.

Patient personal information processed by medical personnel in medical workflows is subject to the medical institution as the personal information processor bearing primary responsibility, and we only act as a commissioned processor to assist with processing according to the medical institution's instructions. See Chapter IX of this policy for details.

This Policy Will Help You Understand the Following

I. How We Collect and Use Your Personal Information

II. How We Process Sensitive Personal Information

III. How We Use Cookies and Similar Technologies

IV. Automated Decision-Making and Algorithmic Processing

V. How We Share, Transfer, and Publicly Disclose Your Personal Information

VI. Storage and Cross-Border Transfer of Personal Information

VII. How We Protect Your Personal Information

VIII. Your Rights and How to Manage Your Information

IX. Regarding Commissioned Processing by Medical Institutions

X. Personal Information Security Incident Emergency Response

XI. Updates to This Policy

XII. How to Contact Us

I. How We Collect and Use Your Personal Information

Personal information refers to various types of information recorded electronically or by other means that are related to identified or identifiable natural persons, excluding information that has been anonymized. We process your personal information based on the legal bases specified in Article 13 of the Personal Information Protection Law, including obtaining your consent, as necessary for concluding or performing contracts, as necessary for fulfilling statutory duties or obligations, as necessary to respond to public health emergencies or to protect the life, health, and property safety of natural persons in emergency situations, processing within reasonable limits in accordance with the law personal information that you have made public yourself or that has been legally made public, and other circumstances prescribed by laws and regulations.

1.1 Account Registration, Login, and Medical Personnel Identity Verification

When you register, log in, complete account information, undergo medical personnel identity verification, bind to your affiliated institution, or use business functions that require identity verification, we will collect the following information based on specific functions. This information is actively filled in and submitted by you within the app. If you refuse to provide it, you may not be able to complete verification, institutional binding, or use related functions, but it will not affect your use of basic functions that do not require verification.

Information Type Specific Scenarios and Necessity Explanation Collection Method Impact of Refusal or Withdrawal
Phone number, verification code, account password Used for registration and login, account identification, security verification, account recovery, customer service verification; necessary information for creating and protecting accounts. Actively filled in and submitted by you, or verified through SMS verification code. Unable to register, log in, recover account, or complete security verification.
Name, work unit, employee ID, department, title, specialty Used to verify the identity of medical personnel or institutional personnel, bind to affiliated medical institutions, configure institutional business permissions, and ensure accuracy of medical business records. Actively filled in and submitted by you, or imported by your medical institution administrator. May not be able to complete real-name verification, institutional binding, or use institutional business functions.
Avatar, nickname Used for account information display and identification for internal institutional collaboration. You can independently decide whether to supplement non-required information. Actively filled in, uploaded, or modified by you. Does not affect basic use, but may affect complete information display.
Device information, login logs, operation logs, network information Used for login security, anomaly detection, troubleshooting, audit trails, and ensuring stable service operation. Device information may include device model, device brand, operating system version, application version, network type, IP address, etc. Automatically generated or recorded within the necessary scope by the client or business server when you agree to this policy and use the services. This information is necessary to ensure account and service security; refusal may result in inability to use services safely.

1.2 Feature Usage and System Permissions

The ClinMate client only requests necessary permissions through system pop-ups when you actively use corresponding functions, and explains the purpose, method, and scope of use before requesting. You can refuse authorization; refusal will only affect the corresponding function and will not affect other unrelated functions. You can also close related permissions at any time through your phone's system settings. This application only requests the following three types of system permissions.

Permission or Information Purpose Usage Method Scope of Use
Camera permission Used for functions actively triggered by you such as scanning codes, taking feedback photos or avatars, and taking business-required photos. After you click functions such as scanning codes, taking photos, or uploading avatars, authorization is requested through a system pop-up; after authorization is obtained, the camera is only called during the operation of the corresponding function and will not be activated in the background. Only processes real-time scanning images, photos or avatars you confirm to take or upload. Not used for unrelated analysis or marketing.
Photos and album permission Used to upload avatars, upload business materials, select files, submit feedback images, and write images to the album when you actively save. Called through the system album, file picker, or permission pop-up when you click upload, select, or save related functions; we only read or write content that you actively select or that is necessary for business. Limited to images and files you actively select, as well as content you actively save; we will not traverse, read, or upload unrelated content in your album.
Microphone permission Used when you actively use functions such as voice input, voice recognition, and audio recording upload. After you click functions such as voice input, recording, or uploading audio, authorization is requested through a system pop-up; after authorization is obtained, the microphone is only called from when you start recording until you stop recording or leave the related page. Only processes audio content required for the current voice function; will not record in the background and will not use microphone permission for profiling or marketing.

除上述三类权限外,ClinMate will not request or read permissions or information unrelated to current services such as location, contacts, SMS, call records, calendar, etc.

1.3 Pre-Consent Processing Rules

Before you agree to this policy, we will not request system permissions such as camera, microphone, photos/albums, nor will we collect personal information or initialize components that would collect personal information.

After you agree to this policy, we will process corresponding information within the necessary scope based on the functions you use, only for providing ClinMate related services.

1.4 Third-Party SDKs and Embedded Content

The ClinMate client itself does not additionally integrate third-party SDKs for statistical analysis, advertising, message push, or location tracking. The client only uses basic development frameworks and their provided system capability calling components for camera, album, microphone, etc. The framework itself does not transmit your personal information to third parties as its purpose.

Component Name Provider Purpose and Necessity Explanation Information That May Be Processed
Capacitor Basic Development Framework Ionic (Drifty Corporation) Used for application interface rendering and calling system capabilities such as camera, album, and microphone. Only calls relevant system capabilities when you actively trigger corresponding functions; not used for profiling or marketing. When corresponding functions are triggered, may involve camera images, images or files you actively select from the album, microphone audio; basic operating information such as device model and system version.

The actual capability components used may differ based on App version, operating system, and feature usage. We will configure based on the principle of minimum necessity; if a capability is not necessary to implement current business functions, we will disable or remove related calling capabilities and update the explanation in this policy. Before you click "Agree," the client will not call system APIs to obtain your personal information, camera, album, or microphone content.

II. How We Process Sensitive Personal Information

Sensitive personal information refers to personal information that, once leaked or illegally used, can easily cause harm to the dignity of natural persons or endanger personal or property safety. We only process sensitive personal information after having a specific purpose and full necessity, adopting strict protection measures, and obtaining your separate consent.

Sensitive Personal Information Category Processing Purpose and Necessity Retention Period or Deletion Rules Impact of Refusal or Withdrawal
Medical health information, medical records, examination and test results, prescriptions, medical insurance codes, diagnosis and treatment records Used in medical institution business scenarios for clinical assistance, quality control, medical insurance coding, document generation, medical business collaboration; usually processed by the medical institution as the personal information processor, with us acting as commissioned processor to assist. Retained according to medical institution instructions, medical industry regulations, and contractual agreements; outpatient records, inpatient records, prescriptions, etc. are executed according to laws, regulations, and medical institution management requirements, and deleted, returned, or anonymized upon expiration. May not be able to use related medical business functions; patient rights requests should in principle be submitted to the affiliated medical institution.

Before collecting sensitive personal information, we will inform you in a prominent manner of the processing purpose, method, necessity, retention period, and impact on your rights and interests. You can withdraw your consent to the processing of sensitive personal information at any time; after withdrawal, we will stop the corresponding processing, but it will not affect processing that has already been conducted based on your consent prior to withdrawal.

III. How We Use Cookies and Similar Technologies

The ClinMate client mainly uses local storage space, including SharedPreferences, NSUserDefaults, local cache, etc., to save login status, user settings, small amounts of business cache, and crash recovery information. Application-related pages may use necessary Cookies, preference Cookies, and statistical Cookies.

Necessary Cookies and local storage are used for login, security, and basic services; closing them may cause services to be unavailable; preference Cookies are used to record language, display settings, etc.; statistical Cookies are used to understand page visits and performance, and we will use de-identification or anonymization methods as much as possible.

You can clear related data through system settings: on Android, go to "System Settings → Apps → ClinMate → Storage → Clear Data/Clear Cache"; on iOS, you can delete and reinstall the App. After clearing, it may affect login status, page loading, and some service processes.

IV. Automated Decision-Making and Algorithmic Processing

ClinMate related business may involve algorithm or automated processing functions such as doctor assistant, intelligent coding, clinical decision support, document generation, and medical knowledge Q&A. According to Article 24 of the Personal Information Protection Law, we explain the following:

4.1 Basic Algorithm Principles

Related functions are usually based on model capabilities trained or fine-tuned on medical specialty corpora, combined with retrieval-augmented generation (RAG), rule engines, medical knowledge bases, and access control, to analyze, retrieve, reason, and generate structured output from business data that you actively input or that medical institutions authorize for processing.

4.2 Processing Purposes and Possible Impacts

Processing purposes include clinical decision support, medical record or document generation, medical insurance coding assistance, medical knowledge Q&A, quality control, and work efficiency improvement. All AI or algorithm outputs are only for reference to assist medical personnel and do not constitute final diagnosis, treatment, medical orders, prescriptions, or medical treatment decisions; final medical actions should be independently judged by medical personnel with appropriate qualifications who bear responsibility.

4.3 Your Rights

You have the right to request that we explain the processing rules, basis, and impact on results of automated decision-making; you have the right to refuse decisions that significantly impact your personal rights and interests made solely through automated decision-making, and to request manual intervention or review; we will not implement unreasonable differential treatment toward you in terms of transaction conditions, etc., through automated decision-making.

4.4 Algorithm and Deep Synthesis Filing

If related algorithms, deep synthesis, or generative artificial intelligence services require filing, security assessment, or other administrative procedures according to law, we will fulfill corresponding obligations before the function goes online or within the period required by law, and publicly announce filing information in the App, official website, or on the query page of the national competent authority's filing system. If filing information changes, we will promptly update this policy or notify you through prominent means.

V. How We Share, Transfer, and Publicly Disclose Your Personal Information

5.1 Sharing

We will not provide, sell, rent, share, or trade your personal information to unrelated third parties. We will only share necessary personal information in the following circumstances: (1) obtaining your prior separate consent; (2) as necessary to conclude or perform a contract to which you are a party; (3) as necessary to fulfill statutory duties or obligations; (4) as necessary to respond to public health emergencies or to protect the life, health, and property safety of natural persons in emergency situations; (5) other circumstances prescribed by laws and regulations.

Sharing Object Sharing Purpose Scope of Shared Information Necessity Explanation
Your affiliated medical institution and its authorized administrators Account verification, institutional binding, permission configuration, medical business collaboration, audit management. Name, phone number, work unit, employee ID, department, title, specialty, verification status, business operation records. Necessary for fulfilling institutional business services and medical institution management requirements.
SMS, cloud services, customer service, and security service providers Send verification codes, provide cloud resources, customer support, security protection, troubleshooting. Phone number, verification code sending records, service logs, ticket information, necessary device and network information. Necessary for account login, security verification, service operations, and customer support.
Regulatory, judicial, administrative agencies, or legally authorized institutions Fulfill legal and regulatory requirements for reporting, auditing, investigation, evidence collection, or regulatory obligations. Information necessary as required by law or to fulfill statutory obligations. Required by laws and regulations, regulatory requirements, or judicial and administrative procedures.

We will sign data processing agreements or confidentiality agreements with third parties involved in personal information processing, requiring them to process personal information only according to the agreed purpose, method, and scope, and to adopt security protection measures no less stringent than this policy.

5.2 Transfer

We will not in principle transfer your personal information. If it is necessary to transfer personal information due to merger, division, dissolution, bankruptcy declaration, or other reasons, we will inform you of the name and contact information of the recipient and require the recipient to continue to be bound by this policy; if the recipient changes the original processing purpose or method, they will obtain your consent or separate consent again.

5.3 Public Disclosure

We will not in principle publicly disclose your personal information. If public disclosure is truly necessary, we will inform you of the purpose of public disclosure, the type of information, and possible impacts, and obtain your separate consent, except where laws and regulations provide otherwise or where consent is not required by law.

VI. Storage and Cross-Border Transfer of Personal Information

6.1 Storage Location

Personal information collected and generated during our operations within the People's Republic of China is stored within the People's Republic of China. In hospital private deployment scenarios, related medical business data is usually stored in the hospital's local server room, hospital-designated cloud resources, or domestic environments agreed upon in bilateral contracts.

6.2 Storage Period

Information Category Retention Period or Determination Method
Account registration, login, verification, and institutional binding information Retained during account existence; deleted or anonymized within 15 working days after account cancellation, except where laws, regulations, regulatory audits, or dispute resolution require otherwise.
Login logs, operation logs, security audit logs Usually retained for no less than 6 months; for security incidents, audits, medical business trails, or regulatory requirements, retention is extended according to laws, regulations, and contractual requirements.
Customer service tickets, complaint feedback, and communication records Retained for 3 years from the date of ticket completion, or according to dispute resolution, audit, and legal and regulatory requirements.
Medical business data, medical records, prescriptions, examination and test results, medical insurance codes Retention period determined by the medical institution as the personal information processor; we act as commissioned processor and process according to medical institution instructions and contracts. For medical records, prescriptions, and other medical documents, executed according to regulations such as "Medical Institution Medical Record Management Provisions" and "Prescription Management Measures" and medical institution systems.

After exceeding the retention period, we will delete or anonymize your personal information; if temporary deletion is not possible due to legal and regulatory requirements or technical reasons, we will stop all processing except storage and necessary security protection.

6.3 Cross-Border Transfer of Personal Information

We commit that we do not currently actively provide your personal information abroad; personal information collected and generated within China is stored within China.

If it becomes necessary in the future to provide personal information abroad due to business needs, we will inform you in advance of the name and contact information of the overseas recipient, processing purpose, processing method, types of personal information, retention period, and the method and procedure for you to exercise rights with the overseas recipient, complete procedures such as security assessment, personal information protection certification, or standard contract filing according to law, and obtain your separate consent.

VII. How We Protect Your Personal Information

We adopt technical and management measures that match the risks of personal information processing to protect your personal information, including but not limited to:

Please properly keep your account, password, and verification code, and do not disclose them to third parties. If you discover personal information leakage, especially account or password leakage, please immediately contact us using the methods in Chapter XII of this policy.

VIII. Your Rights and How to Manage Your Information

According to Articles 44 to 50 of the Personal Information Protection Law, you have the right to be informed, right to decide, right to limit or refuse processing, right to access and copy, right to portability, right to correct and supplement, right to delete, and right to cancel your account regarding your personal information.

8.1 Access, Copy, and Portability

You can view some account information on the "Account Information" page in the app; if you need to obtain a copy of your personal information or request that your personal information be transferred to another personal information processor you designate, please submit a request to us via the email address listed in Chapter XII. If the conditions specified by the national cyberspace administration are met and it is technically feasible, we will provide a copy or transfer file in an industry-standard format within 15 working days.

8.2 Correction, Supplementation, and Deletion

You can self-correct or supplement some information in "Account Information" in the app; for fields involving real-name verification, institutional binding, etc., please process through customer service or your institution's administrator. When circumstances arise such as the processing purpose has been achieved, cannot be achieved, or is no longer necessary, we stop providing products or services, the retention period has expired, you withdraw consent, or we violate laws, regulations, or agreements in processing personal information, you can request deletion. If the retention period specified by laws and regulations has not expired, or deletion is technically difficult to achieve, we will stop all processing except storage and necessary security protection.

8.3 Account Cancellation

You can cancel your account in "Account and Security → Cancel Account" in the app. After account cancellation, we will delete or anonymize your account-related personal information according to laws and regulations; where retention is required by law, it will only be used for statutory obligations, auditing, security, and dispute resolution purposes.

8.4 System Permission Management

You can manage camera, photos/album, and microphone permissions through your phone's system settings: on Android, the path is usually "System Settings → Apps → ClinMate → Permissions"; on iOS, the path is usually "System Settings → ClinMate → Permissions". After closing permissions, corresponding functions may not work properly, but other unrelated functions will not be affected.

8.5 Response Method and Period

Please submit requests through the methods listed in Chapter XII of this policy. To ensure security, we may require you to undergo identity verification. We will reply and process according to law within 15 working days; if we refuse your request, we will explain the reasons and the avenues you can seek for relief. If you are not satisfied with our reply, you can file complaints with competent authorities such as cyberspace administration, industry and information technology, public security, and market regulation, or file a lawsuit in a people's court with jurisdiction according to law.

IX. Regarding Commissioned Processing by Medical Institutions

In scenarios such as hospital SaaS services, private deployments, institutional management backends, and medical AI platforms, for medical business data such as patient data, medical records, prescriptions, examination and test results, medical insurance data, and medical quality management data, the medical institution to which you belong usually acts as the personal information processor determining the processing purpose and method, and we act as a commissioned processor to assist with processing according to the medical institution's instructions.

We commit to: (1) not processing commissioned data beyond the scope authorized by the medical institution; (2) not using commissioned data for purposes unrelated to the medical institution's instructions; (3) not sub-commissioning without the medical institution's consent, except where otherwise provided by laws and regulations; (4) deleting, returning, or anonymizing relevant data according to the medical institution's instructions when the commissioned relationship terminates; (5) cooperating with the medical institution to fulfill personal information protection impact assessment, security incident response, and personal information rights response obligations.

Requests by patients themselves to exercise personal information rights regarding the above medical business data should in principle be submitted to the affiliated medical institution; we will cooperate with the medical institution to respond according to law.

X. Personal Information Security Incident Emergency Response

When a personal information security incident such as leakage, tampering, or loss occurs or may occur, we will immediately initiate emergency response and take measures such as isolating risk sources, blocking attacks, repairing vulnerabilities, tracing the scope of impact, and preserving evidence. Depending on the nature of the incident and legal and regulatory requirements, we will report to relevant competent authorities such as cyberspace administration, industry and information technology, and public security within 24 to 72 hours.

We will notify affected users through in-app messages, SMS, email, phone, or announcements, informing them of the incident type, cause, possible impacts, remedial measures taken or to be taken, suggestions for you to independently prevent and reduce risks, and our contact information. If it is difficult to notify individually or if measures can be taken by individuals to avoid harm expansion, we will issue warnings through reasonable and effective announcement methods.

XI. Updates to This Policy

We may revise this policy from time to time. When the following material changes occur, we will inform you through prominent methods such as App pop-ups, in-app messages, SMS, or email, and obtain your consent or separate consent again when required by laws and regulations:

For non-material changes, we will provide notice through updates and prompts on this page. We will retain at least the last 3 historical versions for your review, which you can request to obtain through the contact methods in Chapter XII.

XII. How to Contact Us

If you have any questions, comments, or suggestions regarding this policy or personal information processing, or wish to exercise your personal information rights, you can contact us through the following methods:

Personal Information Processor: Hangzhou Trizen Medical Technology Co., Ltd.

Company Address: Room 1402, Building A, Hang Seng Building, No. 3588 Jiangnan Avenue, Puyan Street, Binjiang District, Hangzhou, Zhejiang Province

Customer Service Phone: 0571-81608291

Personal Information Protection Officer Phone: 183-5713-5938

Email: service@trizen.ai

We will reply to your request within 15 working days. If you are not satisfied with our reply, you can file complaints with competent authorities such as cyberspace administration, industry and information technology, public security, and market regulation, or file a lawsuit in a people's court with jurisdiction according to law.