Privacy Policy

1. About this Policy

MedX Health Corp. (“MedX”, “we”, “us”) operates in Canada and provides SkinSecure™™, a cloud-hosted clinical imaging platform that captures, stores, processes and exports skin chromophore image data and related measurements through the SkinSecure™ / SIAscope™ V CRE multi-spectral imaging contact hardware device (the “Services”). This Policy explains how personal data is handled in connection with the Services.

This Policy applies to the SkinSecure™ platform and the SIAscope™ V CRE imaging device only. It does not cover any other MedX product, service or future offering, which will be addressed under separate documentation where required.

Who this Policy is for. Our customers are clinical research organisations (CROs), clinical investigational use sponsors, research facilities and clinical sites that use SkinSecure™™ to conduct clinical investigational cases only (each a “Customer”). This Policy is written for those Customers and for the individuals whose data flows through the platform, namely clinical investigation participants (subjects), and the Customer's authorized platform users. It also covers visitors to the MedX website on which this Policy is published.

Relationship to the use of MedX services in a clinical investigational use and to the DPA. For clinical investigation participants, this Policy is not your primary clinical investigational use privacy notice. The clinical investigational use sponsor, CRO, research facility or clinical site that enrolled you is the controller of your clinical investigational use data and is responsible for the participant information sheet and informed consent for the investigation. Your relationship as a participant is with that controller and is governed by the controller’s own privacy notice, informed consent and data protection arrangements, including, where the controller acts as a processor for an upstream sponsor, the controller’s own data processing agreement. Those arrangements, and not this Policy or the MedX DPA, govern the effective relationship between you and the controller of your clinical investigational use data. This Policy describes the role MedX plays as the technology provider and reflects, and is given effect by, the Data Processing Agreement (the “DPA”) that MedX enters into with each Customer. Where this Policy and the DPA address the same subject, the DPA governs the contractual relationship between MedX and the Customer.

2. Applicable data protection law

This Policy is framed by reference to the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and the UK GDPR and Data Protection Act 2018 (together, the “UK GDPR”), and the binding guidance of the competent supervisory authorities (each a “Supervisory Authority”). Terms such as controller, processor, sub-processor, data subject, processing, personal data and special category data have the meanings given to them in the GDPR.

3. Our role: processor, sub-processor and, in limited cases, controller

Understanding our role is central to how your data is protected. MedX acts in different roles depending on the data and the purpose.

Processor. Where a Customer (for example a CRO) is the controller, MedX processes the personal data captured and stored through SkinSecure™™ only as that Customer’s processor, on the Customer’s documented instructions and to provide the Services.

Sub-processor. Where a Customer is itself a processor acting on behalf of an upstream sponsor-controller, MedX acts as a sub-processor for that processing.

Controller, in limited cases only. MedX acts as a controller only in two defined situations: (a) for a narrow set of legitimate business purposes that are necessary to run MedX as a business (described in Section 5); (b) for the creation and subsequent use of irreversibly anonymized data (described in Section 6). MedX does not use identifiable participant clinical data for its own commercial purposes.

MedX does not determine the purposes of any clinical investigation, does not decide who is enrolled by the Customer, and does not process participant clinical data for any purpose of its own while that data remains identifiable.

Authorized sales agents. MedX may appoint authorized sales agents to introduce prospective Customers to MedX and to promote the Services and, where MedX and the agent agree and the applicable Statement of Work records it, an agent may invoice a Customer as invoicing party of record on MedX’s behalf. An authorized sales agent is not a processor or a sub-processor of MedX, has no access to participant data, clinical investigational data or any production environment, and performs none of the Services: MedX supplies, configures, calibrates, services, supports and warrants the Services and the device. Where MedX discloses limited business contact data to an agent, as described in Section 7, the agent acts as a controller in its own right for that data.

4. The personal data we process through SkinSecure™ 

The categories below describe the personal data that may be processed through the platform. The precise data captured in any given clinical investigational use is determined by the Customer and the clinical investigational use protocol.

Categories of data subject 

Categories of personal data 

The Customer's authorized platform users (including investigators, study coordinators, imaging operators, data managers, monitors and sponsors). 

Name, Email address, identity-provider subject identifier, job role and organisation, authentication and session data, audit-trail records of actions performed in the platform, including IP address, free-text notes on study team assignments.

Clinical investigation participants (subjects)

Subject Number, Year of Birth, Age at enrolment and age group, Ethnicity, Sex, Race, Monk Skin tone, Enrolment status and withdrawal reason, Chromophore measurement and derived chromophore maps- melanin, dermal melanin, haemoglobin, collagen, Images of the measured skin area captured by the Authorized Device (a contact measurement site of approximately 2.5 mm diameter), Spot measurements/Region of interest (ROI), Scan and device metadata- capture timestamps, device and operator identifiers, session records, audit-trail entries, Free-text assessment comments entered by study staff in relation to a subject, which may contain any information the author chooses to record.

Chromophore maps. SkinSecure™ measures specific chromophores in the skin, namely melanin, dermal melanin, collagen and haemoglobin, to a depth of no more than 2 mm using a contact lens of 2.5 mm diameter. This measurement data, when linked to a participant, is health data and is treated as special category data.

Special category data. Because SkinSecure™ is used in clinical investigations, the data processed may include special category data, in particular data concerning health. The chromophore measurements captured by the device (including melanin) are physiological skin measurements used for clinical imaging, and MedX does not use them to infer or derive a participant’s racial or ethnic origin. The platform may capture race, ethnicity and similar demographic information as a discrete data field where the Customer, as controller, elects to collect it for its protocol. Special category data is processed only on the Customer’s instruction and under the lawful basis and Article 9 condition established and maintained by the controller.

What SkinSecure™ does capture. SkinSecure™ captures localised chromophore and spot measurement data, together with scan and device metadata (such as scan timestamps, device and operator identifiers, and session and audit records) linked to the specific persons enrolled, for clinical investigational use only. The chromophore and spot measurement data is not processed for the purpose of uniquely identifying an individual and is not used as a biometric identifier. 

5. Why we process personal data and our lawful bases

5.1 Processing on behalf of the Customer

In its role as processor or sub-processor, MedX processes personal data to provide, maintain, secure and support the Services, in each case on the Customer’s documented instructions as set out in the DPA and the applicable Statement of Work. The lawful basis for the underlying clinical processing, and any Article 9 condition for special category data, is the responsibility of the controller (for example, the clinical investigational use’s research consent and ethics or institutional review board approvals). MedX does not select that basis and does not process the data for any independent purpose.

5.2 The in-platform per-scan attestation

MedX does not obtain consent from clinical investigation participants and does not operate its own participant consent mechanism. Consent, and any other lawful basis or authority required to capture and process participant data through SkinSecure™, is the responsibility of the Customer as controller, obtained through the Customer's own informed consent and ethics or institutional review board (IRB) approvals for the investigation, which identify MedX as the technology provider processing the data on the Customer's behalf. Under the DPA, the Customer warrants that it has obtained and maintains all participant consents, authorisations and approvals necessary for MedX to process the personal data in connection with the Services, and MedX processes that data in reliance on the Customer's documented instructions and that warranty. MedX is the Customer's processor in respect of this data and does not act as a controller for it.

5.3 MedX’s own limited purposes (where MedX is a controller)

MedX processes a limited set of personal data as a controller for the following legitimate business purposes, relying on its legitimate interests (Article 6(1)(f) GDPR) or, where applicable, on the performance of its contract with the Customer or compliance with a legal obligation:

  • billing, account management and customer administration, which may include disclosing a Customer’s business contact details to an z sales agent as described in Section 7;

  • securing the Services, including abuse, fraud and cyber-attack detection and prevention;

  • complying with legal obligations and asserting or defending legal claims;

  • internal auditing, financial reporting and business planning; and

  • analysing, maintaining and improving the performance and core functionality of the Services.

These purposes operate on operational and account data and on data that has been irreversibly anonymised. They do not extend to using identifiable participant clinical data for MedX’s own commercial ends.

6. Anonymization and anonymized data

On the Customer’s instruction and authorization under the DPA, MedX may create aggregated, anonymized and de-identified datasets (“Anonymized Data”). Anonymization is carried out so that individuals can no longer be identified, directly or indirectly, by any means reasonably likely to be used by MedX or any third party, in line with the standard under the GDPR and European Data Protection Board guidance. The anonymization process is irreversible.

Effect. Once anonymization is complete, the resulting Anonymized Data ceases to be personal data and falls outside the GDPR and UK GDPR. MedX is the owner of the Anonymized Data and may retain, use, disclose and commercialise it for its own lawful purposes, including software optimisation, product enhancement, machine learning model training, scientific research and industry benchmarking. Because Anonymized Data cannot be linked back to any individual, data subject rights and the return and deletion obligations do not apply to it.

7. How we share personal data

MedX does not sell personal data. We share personal data only as needed to deliver the Services and as described below.

Sub-processors. MedX engages sub-processors under written contracts that impose data protection obligations equivalent to those in the DPA. MedX remains responsible to the Customer for its sub-processors’ performance and gives the Customer prior notice of any intended addition or replacement, with an opportunity to object on reasonable data-protection grounds. The current list of sub-processors, the service each provides, the categories of personal data each processes, the processing location and the applicable transfer safeguard is set out in Schedule 3 to the DPA and is available to Customers and prospective Customers on request.

Authorizedsales agents. Where a Customer was introduced to MedX by an authorized sales agent, or where such an agent invoices the Customer as invoicing party of record, MedX discloses to that agent the identity of the Customer, the business contact details of the Customer’s commercial and billing contacts (name, job title, business email address and business telephone number) and the commercial terms and payment status of the applicable Statement of Work, in each case only so far as necessary to administer the introduction, the invoice or the agent’s commission. No participant data, chromophore data, image, clinical investigational data or special category data is disclosed to any authorized sales agent, and no agent has access to any production environment. Each agent is bound by written confidentiality and data protection obligations no less protective than those in the DPA, receives that data as a controller in its own right, and may not use it for any other purpose. A Customer may object to disclosure to a named agent on reasonable data protection grounds, in which case MedX invoices that Customer directly. The agent for a given deployment, if any, is named in the applicable Statement of Work, and this category of recipient is recorded in Schedule 3 to the DPA.

Disclosure to authorities. MedX discloses personal data to a law enforcement or other authority only where legally required. Where a request is received, MedX assesses its lawfulness, resists disproportionate or unnecessary requests to the extent permitted by law (including by seeking interim measures while challenging a request), discloses only the minimum necessary, and records the request and its response. Where permitted, MedX informs the relevant Customer.

8. International data transfers

MedX is established in Canada. Participant and clinical investigational data is hosted in the AWS region specified in the applicable Statement of Work. Two components remain in a United States region because AWS requires it or grants production access only there: the content-delivery edge certificate, which holds no personal data, and the transactional-email sending identity, which processes recipient names and email addresses for account invitations, password resets and multi-factor authentication messages. We use the following mechanisms so that personal data remains protected when it crosses borders:

  • Adequacy (Canada). to the extent personal data is processed by MedX in Canada: no additional transfer mechanism is required, because the European Commission and the UK have each adopted an adequacy decision covering commercial organisations subject to Canada’s PIPEDA;

  • EU SCCs. where no adequacy decision applies, the EU Standard Contractual Clauses are incorporated into the DPA, using Module Two where the Customer is a controller and MedX is a processor, and Module Three where the Customer is a processor and MedX is a sub-processor;

  • UK IDTA. for transfers protected under the UK GDPR where no UK adequacy finding applies, the EU SCCs as amended by the UK International Data Transfer Addendum apply;

  • Authorized sales agents. where MedX discloses business contact data to an authorized sales agent established outside the EEA or the United Kingdom in a country not covered by an adequacy decision, the transfer is made under the EU Standard Contractual Clauses using Module One (controller to controller) and, for personal data protected under the UK GDPR, those clauses as amended by the UK International Data Transfer Addendum. The country in which any current authorized sales agent is established, and a copy of the safeguards applied, are available from MedX on request using the contact details in Section 13;

  • Transfer impact assessment. On request, MedX will provide a transfer impact assessment considering whether the protection in the recipient country is essentially equivalent to that guaranteed in the EEA under the GDPR, having regard to the European Data Protection Board’s European Essential Guarantees. MedX implements the supplemental contractual, technical and organisational measures set out in the DPA where required.

9. How we keep personal data secure

MedX maintains a written information security program and the technical and organisational measures set out in the DPA, appropriate to the risk. These include:

  • encryption of personal data at rest using 256-bit AES, and encryption in transit across public networks;

  • tenant key management with regular key rotation;

  • role-based access control on the principle of least privilege, with unique credentials and multi-factor authentication;

  • vulnerability and threat management, and secure development practices, including automated scanning of application components before release;

  • event logging, and backup of production data; and

  • a duty of confidentiality binding all personnel authorized to process personal data.

10. Your data protection rights

Participant and clinical investigational use data. Where MedX acts as a processor or sub-processor, requests to exercise data subject rights (access, rectification, erasure, restriction, portability and objection) should be directed to the controller, that is the clinical investigational use sponsor, CRO, research facility or site. If MedX receives a request directly, it will not respond except on the controller’s documented instructions or as required by law, and will promptly forward the request and assist the controller in responding.

Data MedX holds as a controller. For the limited operational, account and website data that MedX processes as a controller, you may exercise your rights with MedX directly using the contact details in Section 13.  Where MedX has disclosed that data to a recipient, including an authorized sales agent, MedX will communicate any rectification, erasure or restriction to that recipient unless it proves impossible or involves disproportionate effort, and will tell you who those recipients are if you ask. You also have the right to lodge a complaint with a Supervisory Authority.

Rights cannot be exercised over Anonymised Data, because it can no longer be linked to any individual.

11. Data retention

  • Customer data. personal data processed on a Customer’s behalf is retained for the term of the engagement and is returned or securely deleted on termination, at the Customer’s election, except where retention is required by law or for the integrity of an active clinical investigation, in which case it remains protected under the DPA;

  • MedX controller data. operational, account and website data is retained only as long as necessary for the purpose for which it was collected and to meet legal, compliance, accreditation and accounting requirements; and

  • Anonymised Data. Anonymised Data may be retained indefinitely, as it is no longer personal data.

12. Personal data breaches

If MedX becomes aware of a personal data breach affecting personal data processed through SkinSecure™™, it will notify the affected Customer without undue delay, provide the information the Customer reasonably needs to meet its own notification obligations under Articles 33 and 34 GDPR, cooperate with the Customer, and document the breach.

13. How to contact us

Questions about this Policy or about how personal data is handled in SkinSecure™  can be sent to MedX at the address below.

MedX Health Corp.

Unit 1, 1495 Bonhill Road, Mississauga, ON, L5T 1M2, Canada

Privacy contact

dataprotection@medxhealth.com

14. Changes to this Policy

MedX may update this Policy from time to time. The version number and effective date at the top of the document indicate the current version. Material changes will be notified through the platform or to Customers as appropriate.

15. Website and cookies

Where this Policy is published on a MedX website, MedX processes limited information about visitors, such as data submitted through contact forms and standard technical and analytics data collected through cookies and similar technologies, as a controller and on the basis of consent or legitimate interests as applicable. A separate cookie notice on the website provides further detail and choices.

MedX Health Corp.
Unit 1, 1495 Bonhill Road, Mississauga, ON L5T 1M2
Email: privacy@medxhealth.com
905-670-4428 x223