MiMIAT Health Professional Terms of Use
Version 1
Effective date: 27 August 2026
These Professional Terms of Use (“Terms”) govern access to and use of the MiMIAT Health professional platform and related professional-facing services provided by MIMIAT HEALTH SL (“MiMIAT Health”, “MiMIAT”, “we”, “us” or “our”).
These Terms apply to healthcare professionals and other authorised professional users who access or use the MiMIAT Health professional platform (“Professional Users”).
1. Acceptance and scope of these Terms
By creating, activating or using a Professional Account and accepting these Terms when presented to you, you agree to be bound by them.
If you do not agree to these Terms, you must not create, activate or use a Professional Account or access the professional Service.
These Terms govern your individual use of MiMIAT Health as a Professional User.
Where you use MiMIAT Health through or on behalf of a healthcare organisation, clinic, institution or professional practice, your organisation may have a separate agreement with MiMIAT Health governing the institutional provision of the Service. Such an agreement may impose additional requirements relating to your access and use.
Where organisational policies or a separate institutional agreement impose stricter requirements concerning patient confidentiality, information security or professional use, you must comply with those requirements.
If you have questions about these Terms, you may contact us using the details provided in Section 19.
2. Professional eligibility and account information
The MiMIAT Health professional Service is intended for adults acting in a professional healthcare or other specifically authorised professional capacity.
You must provide accurate, current and complete information relating to your identity, professional status and, where applicable, your healthcare organisation.
Depending on the registration or verification process available, MiMIAT Health may request information such as your:
identity and contact details;
professional title or role;
specialty;
professional licence, registration or membership number;
healthcare organisation or professional practice; and
other information reasonably necessary to establish your identity or professional eligibility.
You must not:
create an account using a false or misleading identity;
impersonate another professional;
falsely claim a professional qualification, licence, specialty or affiliation;
use credentials belonging to another person; or
continue representing yourself through MiMIAT Health under professional credentials or organisational authority that are no longer valid.
You must keep relevant professional and account information reasonably up to date.
If your professional licence, registration, employment, organisational affiliation or authority to access MiMIAT Health changes in a way that affects your eligibility to use the Service, you must update the relevant information or notify MiMIAT Health or your healthcare organisation, as appropriate.
MiMIAT Health may verify professional information directly, through appropriate public professional registers or through authorised verification providers where reasonably necessary.
3. Purpose and permitted professional use
MiMIAT Health provides Professional Users with access to professional-facing functionality designed to support the review and continuity of health information made available through the Service.
Depending on the functionality available, the professional platform may allow you to:
establish authorised connections with patients;
review longitudinal health information entered or provided by patients;
review patient-uploaded clinical documents, files or images;
review information imported by patients from compatible connected devices or health services;
review longitudinal trends and visualisations; and
use other professional functionality made available by MiMIAT Health.
You may use the Service only for legitimate professional purposes within the scope of your professional role and authority.
Access to MiMIAT Health does not give you a general right to access the information of any patient using the platform.
4. Patient connections, invitations and authorised access
Patient access through MiMIAT Health is based on the access and connection mechanisms made available through the Service.
You may access a patient's information only where you have appropriate authorisation and a legitimate professional purpose for doing so.
Where MiMIAT Health allows Professional Users to invite or connect with patients, you must only use that functionality where you are lawfully entitled to use the relevant patient's contact or identifying information for that purpose.
You must not send invitations to individuals where you do not have an appropriate professional reason or lawful basis to do so.
Where the patient controls the relevant connection, the patient may withdraw or revoke your access through MiMIAT Health.
Once access has been revoked, you must not attempt to circumvent that revocation or regain access through another account, credential or unauthorised method.
Revocation of access through MiMIAT Health does not require deletion of information that your healthcare organisation or professional practice has lawfully incorporated into its own medical record and is independently required or permitted to retain.
A connection between a patient and Professional User through MiMIAT Health does not, by itself, create or replace a healthcare-provider relationship that does not otherwise exist.
5. Clinical responsibility and intended use
MiMIAT Health is designed to support continuity, accessibility and professional review of patient health information.
It does not replace professional clinical judgement, medical assessment or the independent responsibilities of healthcare professionals.
The MiMIAT Health professional platform, as currently provided, is not intended to independently diagnose disease, determine treatment or replace clinical decision-making by appropriately qualified healthcare professionals.
Professional Users remain responsible for:
their own clinical assessments;
determining what information is relevant to a clinical decision;
obtaining any information required for the appropriate provision of healthcare;
verifying information where appropriate;
making diagnoses or treatment decisions within their professional competence; and
complying with the professional, ethical and legal requirements applicable to their practice.
MiMIAT Health should not be treated as the sole source of clinical information about a patient or as a replacement for the medical record independently maintained by the relevant healthcare provider.
Technical organisation, calculations, trends, graphs or visualisations made available through MiMIAT Health do not constitute independent clinical interpretation by MiMIAT Health.
MiMIAT Health is not an emergency service.
The existence of a patient connection or the availability of patient information through MiMIAT Health does not mean that the Professional User is continuously monitoring the platform or that MiMIAT Health guarantees professional review within any particular period.
Professional Users must continue to use the appropriate clinical and emergency communication channels for urgent patient care.
6. Account and device security
Your Professional Account is personal to you unless MiMIAT Health expressly provides another authorised account structure.
You must:
keep your password and authentication credentials confidential;
use multi-factor authentication where required or enabled as part of the Service;
take reasonable measures to prevent unauthorised access to your account;
log out or otherwise secure your session when leaving a device unattended;
not share your account or credentials with another person;
access MiMIAT Health only through devices and networks that are reasonably secured and, where you use the Service under the authority of a healthcare organisation, permitted under that organisation's applicable security requirements; and
promptly notify MiMIAT Health and, where applicable, your healthcare organisation if you suspect unauthorised access or compromise of your account.
You should maintain appropriate device security controls, including access protection and relevant operating-system, browser and security updates.
You must not allow assistants, colleagues or other individuals to access patient information through your credentials simply because they work with you.
Where another individual requires access, they must use an appropriately authorised account and permissions applicable to their own role.
Where your account is associated with a healthcare organisation, that organisation may administer, restrict or terminate your organisational access in accordance with its authority and applicable arrangements with MiMIAT Health.
7. Patient confidentiality and handling of patient information
Patient information accessible through MiMIAT Health is confidential and must be handled in accordance with applicable data-protection law, healthcare confidentiality requirements, professional duties and relevant organisational policies.
You must access patient information only where necessary for an authorised professional purpose.
Accessing patient information out of curiosity, personal interest or for any purpose unrelated to your authorised professional activity is prohibited.
You must take appropriate measures to prevent patient information from being exposed to unauthorised persons.
Reproduction, screenshots, printing and exports
You must not take screenshots or photographs of patient information, print, download, export, copy or otherwise reproduce patient information outside MiMIAT Health unless:
the relevant functionality is expressly supported by MiMIAT Health; or
the reproduction is necessary and lawful for the provision of healthcare or fulfilment of a professional or legal obligation and is permitted by the relevant healthcare organisation or professional practice.
Where patient information is lawfully reproduced outside MiMIAT Health, you and/or the relevant healthcare organisation are responsible for protecting that information in accordance with applicable data-protection law, professional confidentiality obligations and organisational security requirements.
Patient information must not be stored or transferred through unauthorised locations or services, including:
personal email accounts;
personal cloud-storage accounts;
consumer messaging applications;
unauthorised personal devices; or
other systems not approved for the relevant healthcare or professional purpose.
You must not circumvent technical restrictions implemented by MiMIAT Health to prevent or restrict downloading, exporting, copying or other handling of patient information.
External artificial-intelligence tools and third-party software
You must not enter, upload, transmit, copy or otherwise disclose patient information obtained through MiMIAT Health to an external artificial-intelligence system, language model, transcription service or other third-party software unless:
its use has been appropriately authorised by the relevant healthcare organisation or is otherwise lawfully permitted within your professional practice;
there is an appropriate legal basis for the processing;
applicable confidentiality, data-protection and security requirements are satisfied; and
the external service has been approved for that healthcare or professional purpose where such approval is required.
Security and data incidents
If you become aware of or reasonably suspect any unauthorised access to, disclosure of, loss of, misdirection of or other compromise involving patient information accessed through MiMIAT Health, you must promptly notify MiMIAT Health and, where applicable, the relevant healthcare organisation in accordance with applicable organisational procedures.
You must reasonably cooperate with measures necessary to investigate, contain or remediate the incident.
8. Source and presentation of patient information
MiMIAT Health presents and organises information according to the source from which that information is provided to the Service.
Patient information may include:
information entered directly by the patient;
clinical documents, files or images uploaded by the patient; and
measurements or information imported by the patient from compatible connected devices or third-party health services.
MiMIAT Health does not independently alter the underlying source health information or provide independent clinical validation of that information.
Information originating from a connected device or third-party service is presented on the basis of information received from the relevant source, subject to technical processing necessary to organise and display it.
Where MiMIAT Health provides source or provenance information, Professional Users should take that information into account when reviewing the patient's record.
Professional Users remain responsible for verifying information that is material to medical assessment, diagnosis or treatment through the appropriate clinical sources and processes.
9. Data protection and privacy
MiMIAT Health's processing of personal data relating to you as a Professional User is described in the MiMIAT Health Professional Privacy Notice.
That Privacy Notice forms part of the information provided to you regarding use of the professional Service but does not replace these Terms.
Where you or your healthcare organisation process patient information for the provision of healthcare or other professional purposes, you and/or the relevant healthcare organisation remain responsible for the data-protection obligations applicable to that processing.
Where you act under the authority of a healthcare organisation, you must process patient information in accordance with the responsibilities, instructions and policies applicable within that organisation.
Where you act independently as a Data Controller for particular patient-data processing, you are responsible for establishing and complying with the applicable legal basis, transparency, security, retention and other data-protection requirements.
For certain institutional services or processing activities, MiMIAT Health may act as a Data Processor on behalf of a healthcare organisation or other Data Controller. Such processing will be governed by the relevant data-processing or data-governance agreement.
Nothing in these Terms changes the respective controller, processor or joint-controller status of any party where that status is determined by applicable data-protection law and the actual processing activities concerned.
10. Professional conduct and prohibited use
You must not use MiMIAT Health to:
access a patient record without appropriate authorisation or professional purpose;
access patient information after your authority to do so has ended;
impersonate another person or professional;
provide deliberately false or misleading professional credentials;
disclose patient information in breach of confidentiality or data-protection requirements;
establish an unauthorised secondary or “shadow” database of patient information obtained through MiMIAT Health;
upload or transmit patient information to unauthorised third-party systems;
share your account credentials or permit another individual to use your account;
attempt to bypass access controls, patient revocations or security restrictions;
introduce malware, malicious code or other material intended to damage or compromise the Service;
attempt to obtain unauthorised access to MiMIAT Health systems, servers, networks, databases or other accounts;
scrape, systematically extract or harvest information from the Service except through functionality expressly provided or authorised by MiMIAT Health;
reverse-engineer, decompile, disassemble or attempt to derive the source code or underlying technical components of the Service except to the extent that such restriction is prohibited by applicable law;
use MiMIAT Health or patient information obtained through it for advertising, solicitation, profiling or other purposes unrelated to the authorised provision of healthcare or professional services; or
use the Service in violation of applicable law, professional standards or regulatory obligations.
Material or repeated violation of these requirements may result in restriction, suspension or termination of access under Section 15.
11. Audit and security records
MiMIAT Health may record and, where reasonably necessary, review account, access and activity information generated through the professional Service for purposes including information security, auditability, patient confidentiality, technical support, investigation of suspected misuse and compliance with applicable legal or contractual obligations.
Such processing is carried out in accordance with the MiMIAT Health Professional Privacy Notice.
Where a Professional Account is associated with a healthcare organisation, MiMIAT Health may notify an appropriately authorised representative of that organisation where reasonably necessary to investigate or address suspected unauthorised access, misuse or a security incident.
12. Intellectual property and permitted licence
All intellectual-property rights in the proprietary elements of the MiMIAT Health Service, including MiMIAT Health's software, interfaces, designs, branding, logos, texts, graphics, documentation and other content created by MiMIAT Health, belong to MIMIAT HEALTH SL.
Subject to these Terms, MiMIAT Health grants you a limited, non-exclusive, non-transferable and revocable right to access and use the professional Service for its intended professional purposes.
This right does not permit you to commercially exploit, sublicense, resell, reproduce or distribute MiMIAT Health's proprietary Service or documentation except where expressly authorised.
Third-party software, libraries, technologies or materials incorporated into or used in connection with the Service remain subject to the rights and applicable licences of their respective owners.
Nothing in this Section transfers to MiMIAT Health ownership of patient personal data, health information, clinical documents, images or other patient content.
Nothing in this Section transfers to you ownership of MiMIAT Health's software or proprietary materials.
13. Availability, maintenance and support
MiMIAT Health applies appropriate technical and organisational measures designed to protect the security and integrity of the Service.
Like any digital service, MiMIAT Health may occasionally be affected by:
scheduled or emergency maintenance;
technical incidents;
connectivity issues;
synchronisation delays;
third-party infrastructure failures; or
other circumstances outside MiMIAT Health's reasonable control.
We will take reasonable measures to maintain and restore the proper functioning of the Service.
Where reasonably practicable, we may provide advance notice of scheduled maintenance that is expected to materially affect availability.
Professional Users may contact MiMIAT Health for technical or general support using the support mechanisms made available through the Service or the contact details provided in Section 19.
Where a healthcare organisation has a separate service-level or support agreement with MiMIAT Health, that agreement governs the applicable institutional service commitments.
14. Changes to the Service and these Terms
MiMIAT Health may update the professional Service where reasonably necessary to:
improve functionality or security;
maintain technical compatibility;
address technical issues;
comply with legal, professional or regulatory requirements;
introduce, modify or discontinue functionality; or
otherwise develop the Service.
We may update these Terms to reflect changes to the Service, applicable law, regulatory requirements, security practices or the way MiMIAT Health operates.
Where reasonably practicable, MiMIAT Health will provide at least 15 calendar days' prior notice before a material change to these Terms takes effect.
This notice period may not apply where a change must take effect sooner in order to comply with a legal or regulatory requirement or to address an unforeseen and material security, fraud or patient-safety risk.
Where required by applicable law or appropriate given the nature of the change, MiMIAT Health may require you to review and affirmatively accept the updated Terms before continuing to use the affected Service.
The current version of these Terms and its effective date will remain accessible through the professional platform and/or MiMIAT Health website.
15. Restriction, suspension and termination
You may stop using MiMIAT Health at any time.
Where your account is associated with a healthcare organisation, termination or modification of your professional role, employment, affiliation or authorisation may result in restriction or termination of your organisational access.
MiMIAT Health may restrict or suspend access where reasonably necessary to:
respond to an actual or suspected unauthorised access to patient information;
address a material or repeated breach of these Terms;
respond to compromised credentials or an account-security risk;
investigate suspected unlawful or fraudulent activity;
protect patients, Professional Users or the security of the Service;
respond to loss, suspension or material change of professional eligibility;
comply with a legal, regulatory or professional obligation;
give effect to an organisation's lawful administration of professional access; or
address a serious technical or patient-safety risk.
Where the circumstances permit, MiMIAT Health will inform the Professional User of the reason for a restriction or suspension and may provide an opportunity to remedy a breach that is capable of remedy.
MiMIAT Health may restrict or suspend access immediately where reasonably necessary to protect patient confidentiality, information security, patient safety or the integrity of the Service.
MiMIAT Health may terminate a Professional Account where:
there is a material or repeated breach of these Terms;
the account was created using fraudulent or materially inaccurate professional information;
the Professional User is no longer eligible or authorised to use the Service;
continued access would be unlawful or create a material security or patient-safety risk; or
MiMIAT Health discontinues the relevant professional Service.
Following termination or deactivation, personal data relating to the Professional User will be handled in accordance with the Professional Privacy Notice and applicable data-protection law.
16. Liability and professional responsibility
Nothing in these Terms excludes or limits any responsibility or liability that cannot lawfully be excluded or limited.
MiMIAT Health remains responsible for its obligations under applicable data-protection, contractual and other mandatory law.
To the extent permitted by applicable law, MiMIAT Health is not responsible for clinical decisions, diagnoses, treatments or other professional actions independently taken by Professional Users or healthcare organisations.
Professional Users and healthcare organisations remain responsible for their own professional practice and use of patient information.
To the extent permitted by applicable law, MiMIAT Health is not responsible for consequences arising solely from:
unauthorised or unlawful use of the Service by a Professional User;
information incorrectly entered or provided by a user;
failures or inaccuracies originating exclusively from a third-party device or service;
failure by a Professional User to follow these Terms or applicable professional obligations; or
use of MiMIAT Health as a substitute for appropriate clinical assessment or emergency-care pathways.
Where a Professional User accesses MiMIAT Health under a separate agreement between MiMIAT Health and a healthcare organisation, any agreed commercial liability limitations between MiMIAT Health and that organisation are governed by the relevant institutional agreement.
17. Electronic acceptance and records
These Terms are intended to be accepted electronically.
By selecting an acceptance checkbox, button or other affirmative electronic mechanism presented by MiMIAT Health, you confirm your acceptance of the version of these Terms presented to you.
MiMIAT Health may maintain an electronic record of acceptance, including information such as:
the Professional Account concerned;
the version of the Terms accepted; and
the date and time of acceptance.
The current Terms will remain available in a format that Professional Users can access and review through the professional platform and/or MiMIAT Health website.
Where updated acceptance is required, MiMIAT Health may record acceptance of the updated version separately.
18. Applicable law, institutional agreements and severability
These Terms are governed by Spanish law.
Any dispute arising from these Terms or use of the professional Service will be submitted to the courts having jurisdiction under applicable law, without prejudice to any valid jurisdiction provision contained in a separate institutional agreement between MiMIAT Health and a healthcare organisation.
These Terms govern the Professional User's individual access to and use of the MiMIAT Health professional Service.
They do not replace any applicable:
institutional services agreement;
Order Form;
data-processing agreement;
data-sharing or data-governance agreement;
service-level agreement; or
other written agreement between MiMIAT Health and a healthcare organisation.
Where such an agreement governs the institutional provision of MiMIAT Health, that agreement governs the contractual relationship between MiMIAT Health and the relevant organisation.
If any provision of these Terms is found to be invalid, unlawful or unenforceable under applicable law, that provision will be applied to the maximum extent permitted by law and the remaining provisions will remain in effect.
19. Contact
MiMIAT Health is operated by:
MIMIAT HEALTH SL
CIF: B19773761
C/La Rambla, 11, PRAL-1
08002 Barcelona, Spain
For questions relating to these Terms or general support:
support@mimiathealth.com
For privacy or data-protection matters:
legal@mimiathealth.com