数据隐私安全保护声明
数据隐私安全保护声明
一、信息收集
1. 收集原则:我们遵循合法、正当、必要、诚信、公开、透明的原则,仅基于明确、合理的目的收集和使用您的个人信息。所有收集的信息范围均限于提供服务和开展业务所必需的最小必要范围。
2. 收集方式:在您使用我们的服务时,我们会通过合法合规的方式收集您的个人信息,并在收集前明确告知您收集数据的范围、目的及使用方式。
二、信息存储
1. 存储期限:我们依据国家、行业主管部门及内部规章有关规定及与您约定的时限,设定不同类型数据的保存期。超过保存期限的数据,将执行删除操作。
2. 存储安全:采用加密存储方式,确保数据在存储介质中的安全性。
三、信息处理
1. 数据使用:支持全体员工的统一身份鉴别,身份标识具有唯一性。对应用账号、操作系统账号、数据库账号均按照“最小权限”原则进行授权管理并定期审计。同时,根据数据的重要性及敏感程度进行分类分级,并要求业务系统对敏感数据的显示进行脱敏处理,严格限制用户查看和下载权限。
2. 数据共享:除特定情形及相关法律另有规定外,我们不会向第三方公司、组织或个人提供或转移您的个人信息。若涉及必要的数据共享,我们会提前向您明确并获得您的同意,并会进行个人信息安全影响评估,对第三方个人信息安全防护能力水平提出要求。
四、信息保护
1. 访问控制:从数据传输、存储、使用、展示、共享等方面进行了严格的访问控制,并建立相关数据安全保护机制。数据传输均使用加密协议,对传输数据进行保护;平台页面增加背景水印,降低个人敏感数据截图泄露风险。
2. 安全措施:部署敏感数据监控系统,对员工处理用户信息的行为进行系统监控。同时,采用安全加密算法对敏感数据进行加密存储与加密传输。
五、用户权益
1. 查阅与管理:您有权查阅、复制、转移、更正、删除、更改或撤回授权同意的范围、注销账户、拒绝个性化推荐,以及《中华人民共和国个人信息保护法》等规定的其他权利。
2. 联系方式:我们设立了专门的个人信息保护团队和个人信息保护负责人,您可以通过客服热线和客服邮箱随时联系我们。
六、技术保障
1. 先进技术应用:我们积极采用人工智能、区块链等先进技术,提升数据安全防护能力。例如,利用人工智能的异常检测和预测性分析及时发现和应对数据安全威胁;通过区块链技术的去中心化、不可篡改和可追溯特点,提高医疗数据的安全性和可信度。
2. 持续改进:我们不断优化隐私保护技术,如同态加密技术,允许直接处理加密数据,无需解密,从而进一步提升数据安全性。
七、合规与监督
1. 法律法规遵守:我们严格遵守国家相关法律法规,确保数据处理活动合法合规。
2. 内部审计:积极开展信息安全认证和审计工作,定期进行内部审计,同时委托外部专业机构进行外部审计,持续开展全员数据安全培训,严格规范供应链数据安全管控措施。
我们深知数据隐私安全的重要性,将持续致力于保护您的个人信息安全,为您提供安全、可靠的服务。
Data Privacy and Security Protection Statement
I. Information Collection
1. Collection Principles: We adhere to the principles of legality, propriety, necessity, good faith, openness, and transparency. We collect and use your personal information only for clear and legitimate purposes, and the scope of information collected is limited to the minimum necessary for providing services and conducting business.
2. Collection Methods: When you use our services, we will collect your personal information through lawful and compliant means, and we will clearly inform you of the scope, purpose, and usage methods of the data collection in advance.
II. Information Storage
1. Storage Duration: In accordance with relevant national and industry regulatory provisions and internal regulations, as well as the agreed-upon time limits with you, we have set the retention periods for different types of data. Data exceeding the retention period will be deleted.
2. Storage Security: We use encrypted storage methods to ensure the security of data stored on storage media.
III. Information Processing
1. Data Usage: We support unified identity authentication for all employees, with unique identity markers. We manage and regularly audit the authorization of application accounts, operating system accounts, and database accounts according to the "minimum privilege" principle. In addition, we classify and grade data based on its importance and sensitivity, and require business systems to desensitize sensitive data when displaying it, strictly limiting user viewing and download permissions.
2. Data Sharing: Except for specific circumstances and as otherwise provided by relevant laws, we will not provide or transfer your personal information to third-party companies, organizations, or individuals. If necessary data sharing is involved, we will obtain your consent in advance, conduct a personal information security impact assessment, and set requirements for the personal information security protection capabilities of the third party.
IV. Information Protection
1. Access Control: We have implemented strict access control from data transmission, storage, usage, display, and sharing, and have established relevant data security protection mechanisms. Data transmission uses encrypted protocols to protect the data being transmitted. We have also added background watermarks to the platform pages to reduce the risk of personal sensitive data leakage through screenshots.
2. Security Measures: We have deployed a sensitive data monitoring system to monitor employees' handling of user information. At the same time, we use secure encryption algorithms to encrypt sensitive data for storage and transmission.
V. User Rights
1. Access and Management: You have the right to access, copy, transfer, correct, delete, change, or withdraw consent, cancel accounts, refuse personalized recommendations, and other rights as stipulated by the Personal Information Protection Law of the People's Republic of China.
2. Contact Information: We have established a dedicated personal information protection team and a personal information protection officer. You can contact us at any time through our customer service hotline and email.
VI. Technical Safeguards
1. Application of Advanced Technologies: We actively use advanced technologies such as artificial intelligence and blockchain to enhance data security protection capabilities. For example, we use artificial intelligence for anomaly detection and predictive analysis to promptly identify and address data security threats. We also use the decentralized, tamper-proof, and traceable features of blockchain technology to improve the security and reliability of medical data.
2. Continuous Improvement: We continuously optimize privacy protection technologies, such as homomorphic encryption, which allows direct processing of encrypted data without decryption, thereby further enhancing data security.
VII. Compliance and Supervision
1. Compliance with Laws and Regulations: We strictly comply with relevant national laws and regulations to ensure that data processing activities are legal and compliant.
2. Internal Audits: We actively conduct information security certification and audit work, regularly perform internal audits, and also commission external professional institutions for external audits. We continuously conduct data security training for all employees and strictly regulate supply chain data security control measures.
We are fully aware of the importance of data privacy and security and will continue to strive to protect your personal information security and provide you with safe and reliable services.