Privacy and Security at Halaxy

Privacy and Security

Halaxy Privacy Policy

Your Privacy is important.

Halaxy is committed to improving health outcomes for all. Placing your privacy at the forefront of what we do is central to realising this goal.

Halaxy’s Privacy Policy has been written to clearly detail:

  1. The data we collect
  2. How we use your data
  3. How we share your information
  4. Your rights to your data
  5. Other important information


This Privacy Policy applies to any user or visitor to our service located within the European Economic Area (EEA). If you reside outside the EEA, you are entering into the Non-EEA Privacy Policy, here. These policies can change, so it’s important that you review this policy from time to time.

1. Data we collect

1.1. Data you provide

When you use your Halaxy, you provide data to us so that we can provide you with our services to run your practice or manage your Patient Portal.

This information can include:

  1. your name, address, telephone and email contact details;
  2. your gender, date of birth or age and marital status;
  3. sensitive information (for some of our products and services);
  4. your bank account or credit card information;
  5. if you register for a premium service (as defined by Halaxy, such as paid services), you may be required to enter in personal payment and billing information;
  6. health information recorded in our system either by you or your healthcare provider including the treatment you have received, including date, service type, description of the service, which healthcare provider treated you, test results, current and past medical history, data uploaded by any of your connected health devices; government related identifiers;
  7. your device ID, device type, geo-location information, computer and connection information, statistics on page views, traffic to and from the sites, ad data, IP address and standard web log information;
  8. details of the products and services we have provided to you or that you have enquired about, including any additional information necessary to deliver those products and services and respond to your enquiries;
  9. any additional information relating to you that you provide to us directly through our website or indirectly through your use of our website or app or online presence or through other websites or accounts from which you permit us to collect information;
  10. information you provide to us through customer surveys; or
  11. any other personal information that may be required to facilitate your dealings with us.

We may collect these types of personal information either directly from you, or from third parties.

We may collect this information when you:

  1. register on our website;
  2. communicate with us through correspondence, chats, email, or when you share information with us from other social applications, services or websites;
  3. interact with our sites, services, content, and advertising.

1.1.1. Sensitive Information

If you handle data for the purposes of managing a Patient, this data may be considered Sensitive Information (such as health information).

If you are handling Sensitive Information, you must ensure that you are subject to the obligation of professional secrecy under a European Union or European Union Member state law or rules established by competent national bodies.

1.2. Halaxy use

We log your use of Halaxy, such as log-ins, and when particular features are used, to provide you with a better experience,

1.3. Feedback

Halaxy stores feedback that you send to us.

Halaxy welcomes ideas and feedback. This feedback will be used to administer and refine the service and may be shared with Halaxy partners either in anonymised form or with specific identifying characteristics removed

1.4. Data from others

We may receive data about you when you use our integrated services and when other users add your details to their Halaxy.

For example, we may collect your personal information when your healthcare practitioner provides you with services and records personal information about you in systems we administer.

Through your use of our services or website, we may also collect information from you about someone else. If you provide us with personal information about someone else, you must ensure that you are authorised to disclose that information to us and that, without us taking any further steps required by applicable data protection or privacy laws, we may collect, use and disclose such information for the purposes described in this Privacy Policy.

This means that you must take reasonable steps to ensure the individual concerned is aware of and/or consents to the various matters detailed in this Privacy Policy, including the fact that their personal information is being collected, the purposes for which that information is being collected, the intended recipients of that information, the individual's right to obtain access to that information, our identity, and how to contact us.

Where requested to do so by us, you must also assist us with any requests by the individual to access or update the personal information you have collected from them and entered into our website.

Halaxy uses cookies to provide you with a better experience.

A cookie is a small text file that many web sites write through your browser when you visit them. A cookie can only be read by the site that places it, so Halaxy cannot "see where you've been" based on any other cookies in your browser. These cookies and applets allow you to use specific services or to remember who you are for Auto Login if you choose this option.

Users who do not wish to receive cookies can instruct their web browsers to refuse them. However, doing so will prevent access to some areas of the site and limit your use of some of the Halaxy services. You may choose to disable cookies in your browser or use security software to prevent the storage of cookies. However, if you disable cookies, we may not be able to fulfil your request or provide you with an appropriate level of service in some areas of Halaxy.

2. How we use your data

We use your personal data to provide you with our service.

Ways we use your data:

  1. to enable you to access and use our website and our services;
  2. build the Halaxy practitioner directory so that health information can be more readily shared with you and your colleagues in a secure environment.
  3. to operate, protect, improve and optimise our website and our services, business and our users’ experience, such as to perform analytics, conduct research and for advertising and marketing;
  4. to send you service, support and administrative messages, reminders, technical notices, updates, security alerts, and information requested by you;
  5. for medical research purposes, including providing this information to third parties for this purpose;
  6. to send you marketing and promotional messages and other information that may be of interest to you, including information sent by, or on behalf of, our business partners that we think you may find interesting;
  7. to administer rewards, surveys, contests, or other promotional activities or events sponsored or managed by us or our business partners;
  8. to comply with our legal obligations, resolve any disputes that we may have with any of our users, and enforce our agreements with third parties; and to consider your employment application.

2.1. Anonymised data

We aggregate your non-personally identifiable data.

By using our services, you agree that we can access, aggregate, and use non-personally identifiable data we have collected from you.

This data is anonymised and will in no way identify you or any other individual. We may also use your personal information in such a way that it does not personally identify you, whether for our own use or for the use by third parties:

to audit, research, measure and analyse the information in order to maintain, administer, enhance and protect our products and services, including analysing usage trends and patterns and measuring the effectiveness of content, advertising, features or services; for contextual and cookie-based automated content delivery, such as tailored ads or search results; for health and medical research, public health and service activities, healthcare and medical related services; and to prepare aggregate reports for current or future advertisers, sponsors or other partners to show trends about the general use of our services. Such reports may include age, gender, geographic, demographic or other general user information, but do not include personal information that personally identifies you.

2.1.1. Patient data

We collect and anonymise patient data you provide to improve and develop features, and utilise for general research.

2.1.2. I.P. information

I.P. information is gathered in aggregate only and cannot be traced to an individual user.

Halaxy's web servers gather your IP address to ensure you’re accessing and storing data within our EU server, and to assist with the diagnosis of problems or support issues with our services.

2.1.3. Visitors

Visitor data is always used as aggregated, non-personal information.

Halaxy collects information on our site visitors collectively, including which sections of the site are most frequently visited, how often and for how long.

Halaxy utilises this information to improve and enhance our services by monitoring the areas on the site which are most popular. This aggregated information may be shared with Halaxy partners to provide them with an overview of how Halaxy visitors use the site. This is done for the purposes of providing you with the best online services.

2.2. Communications

We will communicate with you through notifications within Halaxy itself, by email, mobile phone, text messages, and other appropriate methods required by our Service.

We will send you updates about our security, features, and other-Service related issues.

You can change your communication preferences at any time by email us as the address located under Contact Us below.

2.3. Customer support

We take pride in the support that we offer.

If you contact our customer support, or we have reason to notify you of a change to your Service, we will contact you within Halaxy, or via email or phone.

3. How we share your information

3.1. With practitioners

To provide you with services or information you request from Halaxy, Halaxy may need to disclose your information to practitioners or other related health bodies.

3.2. Third parties

To provide, manage, and administer our products and services to you, we may be required to disclose your information to third parties.

This may include disclosure in the following circumstances:

  1. our employees and related bodies corporate;
  2. hospitals, medical and ancillary service providers (for example, healthcare providers); any persons acting on your behalf including those persons nominated by you, executors, trustees and legal representatives; lawyers, auditors and other advisors appointed by us or acting on our behalf;where disclosure is required by law, including compulsory notices from courts of law, tribunals or government agencies;
  3. third party suppliers and service providers (including data processors or providers for the operation of our websites and/or our business or in connection with providing our products and services to you);
  4. government and regulatory bodies;
  5. professional advisers, dealers and agents;
  6. payment systems operators (eg merchants receiving card payments);
  7. our existing or potential agents, business partners or partners;
  8. our sponsors or promoters of any competition that we conduct via our services;
  9. anyone to whom our assets or businesses (or any part of them) are transferred;
  10. specific third parties authorised by you to receive information held by us; and/or other persons, including government agencies, regulatory bodies and law enforcement agencies, or as required, authorised or permitted by law.

4. Your rights to your data

You can decide how your data is collected, used, and shared.

For personal data we have about you:

  1. Right to access and take your data: You can ask us for a copy of your personal data, which we can provide in machine readable form.
  2. Data deletion: You can ask us to erase or delete some or all of your personal data (i.e. if you no longer want our services provided to you).
  3. Data correction and updates: You can edit, update, or correct your personal data from within your Halaxy. If you are unable to do this, you can ask us to do so on your behalf by contacting our Data Protection Officer identified at the end of this Privacy Policy.
  4. Object to, or limit the use of data: You can ask us to stop using some, or all, of your personal data if your personal data is inaccurate or we have no legal right to do so.

5. Other important information

5.1. Data Controller and Data Processor

You as the Data Controller

If you sign up to Halaxy, you are classified as a Data Controller.

As a Data Controller, the General Data Privacy Regulations (GDPR) places obligations upon you to act in the interests of those you maintain data for. We provide tools that allow you to meet these obligations.

Halaxy as the Data Controller and/or Data Processor

Depending on the situation, Halaxy can act as either a data controller or a data processor.

With respect to your personal information, we act as a Data Controller, when handling your practice’s Patient Data, or your Patient Portal Data, we act as a Data Processor.

5.2. Security

Halaxy takes all reasonable steps to ensure the security of our system.

Halaxy allows you to access your information at any time to keep it accurate and up to date. Any information which we hold for you is stored on secure servers that are protected in controlled facilities. In addition, our employees and the contractors who provide services related to our information systems are obliged to respect the confidentiality of any personal information held by Halaxy. However, Halaxy will not be held responsible for events arising from unauthorised access of your personal information. You can also play an important role in keeping your personal information secure, by maintaining the confidentiality of any password and accounts used on the Halaxy site. Please notify us immediately if there is any unauthorised use of your account by any other Internet user or any other breach of security.

5.3. Data storage

EEA practice data is stored within the European Union (EU) on GDPR compliant cloud servers.

5.4. Confidentiality

Information provided by you will be treated as confidential, whether through email, the website, telephone, or by letter.

However, there are instances where confidentiality could be breached: However, the following exclusions to this confidentiality will apply. If it is deemed that you or an associate of you may be at risk of self-harm or harm to others, confidentiality may be breached.

Confidentiality may also be breached if required by law and records can be subpoenaed. During this time cases are discussed; however names and personal details are not disclosed. Confidentiality can also be excluded if expressed by the user, for example, when a referral is requested.

5.5. Contact us

Contact our Data Protection Officer with any privacy related questions you may have.

If you have queries, concerns or would like to revise your personal records maintained by Halaxy, please email our Data Protection Officer, by addressing your email “Attention: Halaxy Data Protection Officer” and sending this to

Effective: 22 January 2019