Deployment-specific roles
Data-controller and data-processor responsibilities depend on the selected deployment, the participating institutions and the applicable agreement.
Documented processing
Where Zyemed processes personal information on behalf of an institution, the permitted purpose, categories of data, security responsibilities, retention and authorised support access are defined contractually.
Institutional control
Healthcare institutions remain responsible for lawful collection, clinical use, access decisions and patient-facing obligations within their environment unless a written agreement states otherwise.
Contact
For data-processing documentation related to a proposed deployment, contact privacy@zyemed.com without sending patient identifiers or clinical records.
