GDPR Compliance

Last updated: 2026-08-08 · Policy version: 2026-08-08

This page explains how elaj ™ by Quality Systems LLC approaches GDPR. For broader detail, see our Privacy Policy.

1. Our role in processing

Organization account, usage, and security data: we may act as controller. Patient and clinic operational data: we typically act as processor for the organization (controller), under the service contract and DPA.

2. Categories of data

Account and role data, security logs, contact messages, and patient, appointment, invoice, and health-document data entered by clinic users (special category where applicable).

3. Legal bases

Contract performance, legal obligation, legitimate interests in operating and securing the platform, and consent where required. For health data, clinics rely on applicable healthcare bases; we process on their instructions.

4. Data subject rights

Access, rectification, erasure or anonymization, restriction, objection, and portability. Patient-data requests are handled through the clinic; the platform provides DSAR tools for authorized staff (JSON export and anonymization while retaining legally required records).

5. Organization account closure (tenant)

The primary platform user is the organization (tenant) account, not the patient. Organization admins can close the account from Staff → Privacy & GDPR → Close account: password verification, download a JSON export (organization, staff, settings, patient directory), then deactivate the account. Final anonymization can run immediately or after a grace period. Medical document binaries are not deleted indiscriminately; they follow legal/medical retention after export.

6. Retention

Configurable retention by data category (communication logs, raw payloads, medical/accounting records). Anonymize/delete actions run through platform retention tools.

7. Security and audit

Tenant isolation, role-based access, and audit logging of patient chart access, DSAR actions, and account closure. For transfers outside the EEA we seek appropriate safeguards when required.

8. Data breaches

An internal incident register with a checklist, including whether to notify the authority within 72 hours and inform individuals when risk is high.

9. Sub-processors

We may rely on hosting, email, SMS, payment, and AI providers, limited to what is needed to deliver the service.

10. Contact

For GDPR requests, use the contact page or email [email protected]. We route requests to the platform or your organization based on the nature of the data.