Legal

Privacy & Cookies Policy

PrimumAI — Ireland / EU. How we handle personal data as a controller, and how we handle patient data on behalf of the clinics we process for.

Effective date 11 September 2025

Controller
PrimumAi Limited (CRO 777714)
For PrimumAI’s own data
Processor
PrimumAi Limited
For Clinic patient data
DPO & privacy contact
harsh@primumai.eu
Also for deletion requests
Lead supervisory authority
Data Protection Commission
Ireland

Scope & Roles

Processor role
Patient data handled for Clinics. The Clinic is Controller; PrimumAI follows instructions.
Controller role
Our own business data (accounts, billing, service emails, product telemetry, website analytics and consents, vendor management, security logs). We do not act as Controller for patient records.

Contact Details & DPO

Email
harsh@primumai.eu — also for deletion requests.
Office
Apartment 31, Block B02, Roselawn, Knocksinna Court, Blackrock, Co. Dublin, A94 A4T8

Personal Data We Process (Controller role)

Identity and contact details; account and usage data; support tickets; billing (no card numbers stored); website and consent information. No patient records.

Our Purposes & Legal Bases

Contract
Provide the service, support, and billing.
Legitimate interests
Security, availability, and product improvement (aggregated).
Legal obligations
Tax and lawful disclosures.
Consent
Marketing communications and non-essential cookies.

Special Category Data

Not as Controller. As Processor, we handle patient health data on Clinic instructions under Article 9(2)(h).

Children

The service targets professionals. Clinics remain responsible if minors’ data is entered. The age of digital consent in Ireland is 16.

Sharing & Sub-processors (Controller role)

AWS EU, Microsoft Azure EU, AWS SES/SNS, Twilio (EU endpoints), analytics (consent-based), and payment providers (if used). All under DPAs. A live sub-processor list is available.

International Transfers

EEA by default. If a transfer is required: SCCs, TIAs, and supplementary measures. Regions are listed in Annex C.

Security (Summary)

We apply the Annex B TOMs: encryption, MFA, RBAC, tenant isolation, logging and monitoring, and incident response.

Retention

Controller data
Kept for the life of the account, then deleted or anonymised; backups purge within 30–45 days. Billing follows statutory rules.
Processor data
Retained only as instructed by the Clinic. Deletion requests should be sent to harsh@primumai.eu.

Your Rights (Controller data)

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Request via harsh@primumai.eu. We reply within one month (extensions possible).

How to Make a Request

Send an email to harsh@primumai.eu. We verify identity, assess scope, act, and confirm. For patient data, contact your Clinic — we assist them.

AI Transparency

AI suggestions are drafts; a clinician approves them. EU region AI services are configured not to train on Clinic data. Clinics can disable AI features.

Changes

We update this policy and notify you of material changes.

Complaints

Contact harsh@primumai.eu. You may escalate to the Data Protection Commission (dataprotection.ie). We will cooperate fully.

Addendum: Data Received from Third Parties (v1.1)

How we get personal data from other sources — Article 14 GDPR

Sometimes we receive personal data about you from other sources instead of directly from you. When this happens, we will tell you clearly and quickly about it. We do this to stay transparent and to respect your rights.

Typical sources

  • Your clinic or healthcare provider (for onboarding, appointment management, and care coordination)
  • Previous systems during data migration that your clinic asks us to perform
  • Telephony and messaging providers (e.g. Twilio) for call and SMS metadata and consent logs
  • Payment service providers (for tokenised payment confirmations and fraud prevention)
  • Referral partners or booking platforms used by your clinic
  • Public or professional directories (clinician details) where legally allowed
  • Our security and logging systems (technical and usage metadata)

What we get

Depending on the service, this can include: name, contact details, appointment details, billing references, call and SMS metadata, consent choices, and — only when your clinic instructs us — clinical note content or audio for transcription. We do not collect more than we need for the task.

Why we get it, and our legal bases

  • To provide services your clinic asked for (e.g. AI scribe, AI receptionist, booking and billing) — Contract, Art. 6(1)(b)
  • To protect our platform and comply with law — Legal obligation, Art. 6(1)(c), and Legitimate interests, Art. 6(1)(f)
  • For health-related processing under a clinic’s responsibility — Health care, Art. 9(2)(h)
  • Marketing only with your opt-in consent — Consent, Art. 6(1)(a); you can withdraw at any time

Who we share with

We use trusted providers to run our services: AWS (EU) for hosting and email, Microsoft Azure (EU) including Azure OpenAI EU, and Twilio for calls and SMS. Any international routing is protected by EU-approved safeguards (e.g. SCCs or BCRs).

How long we keep it

We keep data only as long as needed: appointment reminders ≤12 months, support tickets ≤24 months, consent and cookie logs 13 months, security logs 12 months, and clinical content as instructed by your clinic. Backups are encrypted and time-limited.

When and how we contact you about this

If we received your data from someone else, we will provide you with this information:

  • our details and contact, including the DPO
  • the purposes and legal bases
  • the types of data and the source
  • any recipients and transfers
  • retention and your rights (access, rectification, erasure, restriction, portability, objection)
  • how to complain to the Data Protection Commission

We will do this within one month of getting your data, or at the time of our first communication with you, or before sharing your data with anyone else — whichever happens first.

If we cannot contact you

If contacting you is impossible or would take a disproportionate effort (for example, no contact details, or a large archival dataset), we will keep a record of why we could not contact you and how we still protect your data, as allowed by Article 14(5).

Your choices

You can ask questions or use your rights at any time by emailing harsh@primumai.eu. We answer as quickly as we can, and always within legal timelines.

Version control

VersionDateReviewed byApproved byChange
1.110October 2025Harsh Mangla (DPO)ManagementAdded Article 14 section for third-party sources

Questions about this policy?

Our DPO answers privacy enquiries directly at harsh@primumai.eu. For patient records held on behalf of a clinic, contact the clinic — we assist them with the request. The contractual terms are set out in our Terms of Service.