MiMIAT Health Professional Privacy Policy
Version 1
Effective date: 27 August 2026
MIMIAT HEALTH SL and the management of your personal data
At MIMIAT HEALTH SL, protecting the privacy, security and confidentiality of personal information is a fundamental part of how we provide MiMIAT Health.
This Professional Privacy Policy explains how we process personal data relating to healthcare professionals and other authorised professional users who create or use an account on the MiMIAT Health professional platform.
It explains what information we process about you, where that information comes from, why we process it, the legal bases we rely on, who may receive or process it, how long we retain it, and the rights available to you.
This Professional Privacy Policy concerns personal data relating to you as a professional user.
It does not govern the clinical or health information relating to patients that you may access through MiMIAT Health. The processing of patient information is subject to the applicable patient privacy information, the respective data-protection roles of the parties and, where relevant, contractual arrangements between MiMIAT Health and the healthcare professional or healthcare organisation.
If you have questions regarding this Professional Privacy Policy, the processing of your personal data, or wish to exercise your data-protection rights, you may contact us at:
legal@mimiathealth.com
1. Who is responsible for processing your personal data?
The Data Controller is:
MIMIAT HEALTH SL
CIF: B19773761
C/La Rambla, 11, PRAL-1
08002 Barcelona, Spain
For privacy and data-protection matters:
legal@mimiathealth.com
For the purposes of this Professional Privacy Policy, “MiMIAT Health”, “MiMIAT”, “we”, “us” and “our” refer to MIMIAT HEALTH SL.
This Professional Privacy Policy applies to healthcare professionals and other authorised professional users who register for, are provided access to, or use the MiMIAT Health professional platform.
2. Data protection roles
The role of each party under data-protection law depends on the specific processing activity concerned.
MIMIAT HEALTH SL acts as Data Controller for processing activities for which it determines the purposes and essential means of processing, including the creation, authentication, security and administration of professional MiMIAT Health accounts and MiMIAT Health's own operation of the professional platform.
Where technology or service providers process personal data on behalf of MiMIAT Health to provide infrastructure, storage, communications, security, technical monitoring or other supporting services, they act as Data Processors where applicable and are subject to contractual and data-protection obligations appropriate to their role. Such providers may engage authorised sub-processors in accordance with applicable data-protection law.
Where patient information is accessed or otherwise processed for the provision of healthcare or other professional services, the relevant healthcare organisation or independent healthcare professional determines its own purposes and means of processing where it acts as Data Controller.
Healthcare professionals working under the authority of a healthcare organisation process patient information in accordance with the responsibilities, instructions, professional duties and organisational policies applicable within that organisation.
MiMIAT Health does not determine the independent clinical purposes, medical judgement or professional decisions of healthcare providers.
For certain institutional services or specific processing activities, MiMIAT Health may also act as a Data Processor on behalf of a healthcare organisation or other Data Controller. Where MiMIAT Health acts as a Data Processor, the relevant processing will be governed by an appropriate data-processing agreement in accordance with Article 28 GDPR.
Where two or more parties jointly determine the purposes and means of a particular processing activity, their respective roles and responsibilities will be determined in accordance with applicable data-protection law.
3. What personal data do we process about professional users?
Depending on how your professional account is created and used, we may process the following categories of personal data.
Account and contact information
This may include:
first name and surnames;
professional or personal email address used for your account;
telephone number;
preferred language;
country;
account identifiers; and
authentication information necessary to create and secure your account.
Identity and verification information
Where requested for registration, verification or security purposes, this may include:
date of birth;
identification-document type;
identification number;
country information; and
other information reasonably necessary to establish or verify your identity.
Professional and credential information
This may include:
professional title;
healthcare profession or role;
specialty;
medical or professional licence or registration number;
educational institution; and
other professional information you provide or that is necessary to establish your eligibility to use professional functionality.
Organisation information
Where you use MiMIAT Health in connection with a healthcare organisation, clinic, institution or professional practice, we may process information such as:
organisation name;
professional or institutional address;
institutional email address;
telephone number;
website;
business or service hours;
relevant contact person; and
other organisation information provided in connection with your account.
Account, authentication and security information
This may include:
authentication credentials;
multi-factor authentication status and temporary verification information;
password-reset and account-recovery information;
account status;
login dates and timestamps;
IP address where processed;
security events; and
information relating to suspected unauthorised access or misuse.
Platform and audit information
When you use the professional platform, we may process information relating to your activity within MiMIAT Health, including:
actions performed through your professional account;
dates and times of relevant actions;
patient connections or access permissions associated with your account;
records of access to relevant platform functionality;
account changes;
security and authentication events; and
other audit information necessary to maintain security, accountability and traceability.
Audit information may refer to a patient record or connection where necessary to identify the professional action concerned.
Patient health information itself is not governed by this Professional Privacy Policy merely because it is accessed through your professional account.
Technical and diagnostic information
We may process limited technical information necessary to operate, secure and troubleshoot the professional platform, including:
browser and operating-system information;
IP address where required for technical or security purposes;
platform version;
technical logs;
error reports;
diagnostic information; and
information concerning the performance and reliability of the Service.
Certain account, identity and professional information may be necessary to create, verify or maintain a professional MiMIAT Health account. Where particular information is required, we will indicate this when it is requested.
If required information is not provided, professional access or particular functionality may not be available.
4. How do we obtain your personal data?
We may obtain personal data from the following sources.
Directly from you
For example, when you:
create or activate a professional account;
provide professional or credential information;
update your profile;
configure account security;
contact MiMIAT Health;
request support; or
otherwise provide information through the professional platform.
From your healthcare organisation or institution
Where your access to MiMIAT Health is associated with an organisation, relevant account, employment, professional or credential information may be provided or confirmed by that organisation where necessary to create, administer, verify or manage your professional access.
Through patients and platform connections
Where a patient chooses to connect with or authorise a professional through MiMIAT Health, we may receive and process information necessary to establish and manage that connection.
Through your use of the professional platform
Technical, authentication, security, diagnostic and audit information may be generated when you access or use MiMIAT Health.
5. Why do we process your personal data?
We process professional-user personal data for the following purposes.
Creating and managing your professional account
To:
create and maintain your account;
authenticate you;
manage account access;
maintain your professional profile;
enable password recovery and multi-factor authentication; and
communicate essential account information.
Establishing professional eligibility
Where applicable, we may process identity and professional information to:
confirm the identity of a professional user;
establish professional status or credentials;
determine eligibility for professional functionality; and
reduce the risk of unauthorised individuals accessing patient information.
Providing the professional platform
We process information necessary to provide functionality made available to professional users, including managing authorised patient connections and displaying information made available through those connections.
Security, auditability and traceability
We may process appropriate account, access and technical information to:
protect professional and patient accounts;
prevent unauthorised access;
investigate suspected misuse;
maintain auditability and accountability;
identify which professional account performed a relevant action;
detect and respond to security incidents; and
protect MiMIAT Health systems and users.
Technical monitoring and service reliability
We may process limited diagnostic and technical information to:
identify errors;
troubleshoot technical problems;
monitor platform reliability;
maintain availability and security; and
improve the technical performance of MiMIAT Health.
Support and communications
Where you contact us, we process information necessary to respond to your request, investigate technical issues and provide support.
Managing institutional relationships
Where your professional account is associated with an organisation that uses MiMIAT Health, we may process appropriate professional contact, organisational and account information to administer that relationship and manage authorised access.
Legal and regulatory obligations
We may process information where necessary to comply with applicable legal, regulatory, judicial, security or other mandatory obligations.
6. What legal bases do we rely on?
Different legal bases may apply depending on the processing activity concerned.
Performance of a contract
Under Article 6(1)(b) GDPR, we process personal data where necessary to provide the MiMIAT Health professional Service requested by you or to take steps connected with providing that Service.
This may include professional account creation, authentication, account administration and provision of professional functionality.
Where an organisation, rather than the individual professional, is the contracting party, other appropriate legal bases described in this Professional Privacy Policy may apply to processing concerning individual professional users.
Legitimate interests
Under Article 6(1)(f) GDPR, we may process personal data where necessary for legitimate interests including:
securing MiMIAT Health;
preventing unauthorised access or misuse;
verifying professional eligibility where appropriate;
maintaining auditability and accountability;
investigating technical or security incidents;
administering professional and institutional relationships;
providing support; and
improving the reliability and performance of the professional platform.
Before relying on legitimate interests, we consider whether those interests are overridden by your rights and freedoms.
Legal obligations
Under Article 6(1)(c) GDPR, we may process personal data where necessary to comply with a legal obligation applicable to MiMIAT Health.
Consent
Where we introduce a processing activity for which applicable law requires consent, we will request that consent separately.
You may withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
7. Professional access to patient information
Your professional MiMIAT Health account may allow you to access patient information where the relevant patient has authorised access or where another lawful institutional access mechanism applies.
Access to patient information must be limited to the purposes for which you are authorised to access it and must comply with applicable healthcare, confidentiality, professional, organisational and data-protection obligations.
MiMIAT Health may maintain records of professional access and relevant account actions for security, traceability, accountability and legal purposes.
This Professional Privacy Policy concerns MiMIAT Health's processing of personal data relating to you as the professional user.
It does not determine the legal basis on which you or your healthcare organisation process a patient's health information for clinical or other professional purposes.
The rules governing permitted access, confidentiality, reproduction, export and other use of patient information through a professional account are set out in the applicable MiMIAT Health Professional Terms of Use and, where relevant, the contractual and organisational arrangements applicable to your use of the Service.
8. Who can receive or access your personal data?
We do not sell professional users' personal data.
Personal data may be disclosed only where necessary for the purposes described in this Professional Privacy Policy, where required in connection with an institutional deployment, or where disclosure is required or permitted by law.
Patients using MiMIAT Health
Where necessary for patients to identify, connect with or manage access involving a healthcare professional, relevant professional information may be displayed to the patient.
This may include information such as your:
name;
professional title;
specialty; and
healthcare organisation.
Your healthcare organisation
Where your account is associated with a healthcare organisation, authorised representatives of that organisation may receive or manage information relating to your professional identity, role, account status or authorised access where necessary for the institutional use of MiMIAT Health.
Technology and service providers
MiMIAT Health uses specialist providers to operate, secure and maintain the professional Service.
These may include providers of:
cloud infrastructure;
databases and storage;
web-hosting infrastructure;
security and authentication;
error and technical monitoring;
communications; and
technical support.
Current platform infrastructure and technical services may include services provided by:
Amazon Web Services (AWS)
MongoDB
Vercel
Sentry
Where these or other providers process personal data on behalf of MiMIAT Health, they are subject to contractual and data-protection obligations appropriate to their role.
Professional advisers and authorities
We may disclose personal data where necessary to:
comply with applicable law or binding legal process;
respond to competent regulatory, judicial or law-enforcement authorities;
establish, exercise or defend legal claims; or
obtain appropriate legal, accounting or auditing advice.
Corporate transactions
If MiMIAT Health undergoes a merger, acquisition, investment, restructuring or transfer of business assets, professional-user personal data may be disclosed where reasonably necessary for the transaction and subject to appropriate confidentiality and data-protection safeguards.
9. International data transfers
MiMIAT Health uses infrastructure designed to store core platform information within the European Union where configured for that purpose, including AWS infrastructure located in Ireland.
Some technology providers may nevertheless process or access limited personal data from countries outside the European Economic Area.
Where personal data is transferred outside the EEA to a country that has not been recognised by the European Commission as providing an adequate level of protection, MiMIAT Health uses an appropriate transfer mechanism required by applicable data-protection law.
This may include the European Commission's Standard Contractual Clauses together with supplementary safeguards where appropriate.
Information regarding applicable transfer safeguards may be requested by contacting:
legal@mimiathealth.com
10. How long do we retain your personal data?
We retain personal data only for as long as necessary for the purposes for which it is processed, taking into account the nature of the information, your relationship with MiMIAT Health, security and audit requirements and applicable legal obligations.
Professional account information
We generally retain information necessary to operate and administer your professional account while that account remains active or while your professional relationship with MiMIAT Health or an applicable healthcare organisation requires access to the Service.
Professional and verification information
Information used to establish professional identity, eligibility or credentials may be retained for as long as reasonably necessary to administer professional access and demonstrate appropriate account governance.
Account closure or deactivation
When your professional account is closed or permanently deactivated, we will delete or restrict personal data that is no longer required, subject to applicable legal, security, audit and claims-related retention requirements.
Audit and security information
Certain access, audit and security records may need to be retained beyond the active life of an account where necessary to:
preserve security and accountability;
investigate incidents;
establish, exercise or defend legal claims;
demonstrate authorised access to patient information; or
comply with applicable legal or contractual obligations.
Technical backups
Limited copies of personal data may remain temporarily in secure technical backups until those backups are overwritten or expire in accordance with applicable backup-management procedures.
When personal data is no longer required, it will be deleted or rendered anonymous in accordance with applicable requirements.
11. How do we protect professional-user personal data?
MiMIAT Health implements appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss or destruction.
These measures include, as appropriate:
encryption of information in transit and at rest;
account authentication and access controls;
multi-factor authentication functionality;
restricted access based on operational need;
technical monitoring and security controls;
audit and traceability mechanisms;
secure infrastructure and development practices; and
processes for responding to security incidents.
Professional users are also responsible for protecting their account credentials and must not permit unauthorised individuals to access their professional accounts.
If you believe your credentials or account have been compromised, you should notify MiMIAT Health promptly.
12. Your data-protection rights
Subject to the conditions provided by applicable law, you may have the following rights.
Access
You may request confirmation as to whether we process your personal data and obtain access to that information.
Rectification
You may request correction of inaccurate or incomplete personal data.
Erasure
You may request deletion of your personal data where the requirements for erasure under applicable law are met.
Restriction of processing
You may request restriction of processing in circumstances provided by law.
Objection
You may object to processing based on legitimate interests in circumstances provided by law.
Data portability
Where applicable, you may request eligible personal data in a structured, commonly used and machine-readable format and request transmission to another controller where the legal requirements for portability are met.
Withdrawal of consent
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
To exercise your rights, contact:
legal@mimiathealth.com
We may need to verify your identity before completing a request to prevent unauthorised access or disclosure.
Where the GDPR applies, we will respond to requests to exercise data-protection rights within one month of receipt.
Where permitted by law, this period may be extended by up to two additional months where necessary, taking into account the complexity or number of requests.
If an extension is required, we will inform you within the initial one-month period and explain the reasons for the extension.
You also have the right to lodge a complaint with a competent supervisory authority.
In Spain, this includes the Agencia Española de Protección de Datos (AEPD).
13. Automated decision-making
MiMIAT Health does not currently make decisions about professional users based solely on automated processing that produce legal effects or similarly significant effects concerning them.
Where MiMIAT Health introduces processing falling within applicable automated decision-making requirements, this Professional Privacy Policy and the relevant information provided to professional users will be updated accordingly.
14. Changes to this Professional Privacy Policy
We may update this Professional Privacy Policy to reflect:
changes to the professional platform;
changes in the personal data we process;
changes in account or professional-verification functionality;
new service providers or processing activities;
changes in applicable law or regulatory guidance; or
improvements to how we explain our privacy practices.
The current version and its effective date will be made available through the MiMIAT Health professional platform and/or our website.
Where a change materially affects how we process your personal data or your applicable rights, we will provide appropriate notice as required by law.
Where a new processing activity requires consent, we will request that consent separately.
15. Contact
For privacy, data-protection rights or questions regarding this Professional Privacy Policy:
MIMIAT HEALTH SL
CIF: B19773761
C/La Rambla, 11, PRAL-1
08002 Barcelona, Spain
legal@mimiathealth.com
For general product or technical support:
support@mimiathealth.com