“Georgia e-Health” app - Privacy policy

 

1.       Introduction

“Georgia e-Health” app is developed by the LEPL Information Technology Agency of the Ministry of Health, Labor and Social Affairs of Georgia (hereinafter referred to as the developer). In this privacy policy, the developer explains to what extent and under what conditions it processes personal data with regard to the use of the “Georgia e-Health” app. In addition to this privacy policy, the terms of use of the respective app must also be adhered.

 

2.      Personal data

The term personal data envisages all information that relates to an identified person. In this case, the health data which is regarded as sensitive personal data is processed. The processing here means any operation with personal data, irrespective of the means applied and the procedure and in particular the collection, storage, use, revision, disclosure, archiving or destruction of the data.

“Georgia e-Health” app only access personal and sensitive data required to directly support the public health emergency, and uses the data collected to support COVID-19-related efforts or epidemiological research.

 

3.      Accountability

Please refer to the following contact details for any possible violations for unauthorized access, loss, misuse or altering of the data.

 

LEPL Information Technology Agency of the Ministry of Health, Labor and Social Affairs of Georgia

144 Ak. Tsereteli Avenue 0119 Tbilisi Georgia

Tel. +995 32 2 51 00 26

appsupport@ita.gov.ge

www.moh.gov.ge

www.ita.gov.ge

 

4.      Data processing

The app is used for the secure access to health data on COVID-19, Hepatitis C, immunization, prescriptions & recipes. After successful registration & verification of a user, this health data is disclosed from the secured databases of the Ministry of Health, Labor and Social Affairs of Georgia and its legal entities of public law. The installation and use of this app are voluntary and free of charge. This health data is not shared with third parties by the developer. “Georgia e-Health” app data is stored solely on the mobile device. “Georgia e-Health” app requires from a registrant to provide following personal information in order to register successfully:

 

5.      Health data displayed

A user of “Georgia e-Health” app has an access only to her/his following health data:

 

Ø  C Hepatitis

·         Name and Surname

·         Screening Status (facility, date, result)

·         Confirmation Status (facility, date, result)

·         Treatment Status (Ongoing treatment)

 

Ø  Immunization

·         Given vaccinations (vaccine name, facility where the vaccination was given, vaccination date, age, side effects associated with the mentioned vaccination (if any))

·         Missed vaccinations (vaccine name, age - when a beneficiary had vaccination on the calendar, date - intermediate period when a beneficiary had to go to the facility for vaccination, reason for missing the vaccination (if any)

·         Future vaccinations (vaccine name, age - when a beneficiary has to be given a vaccine provided for by a calendar, date - intermediate period when a beneficiary should go to the facility for vaccination

 

The app allows to print out the certificate of vaccination.

 

Ø  Prescriptions & recipes

·         Prescription status: Active/Expired

·         Name of a remedy

·         Date of prescription creation

·         Recipe number (if any)

·         Quantity indicated in the prescription

·         Remaining quantity

·         Replacement: Possible/Not possible

·         Prescription form: Generic/Trading

·         Name and surname of a doctor

·         Prescription period (if there is a recipe, it implies the recipe period)

·         Rules of taking a medicine

 

Ø  COVID-19

·         Name and surname

·         ID number

·         COVID-19 status

·         Vaccination certificate

·         Title of the anti-COVID-19 vaccine injected

·         The dates when the vaccination occurred

·         Data about the latest PCR test results

·         Data about the latest Rapid test results

·         Data about the infection within the last 6 months

·         COVID-19 data about the underage children of the registered person as available at the local immunization portal

 

The app allows to print out the certificate of COVID-19 vaccination.

 

6.      Retention period

In case of deactivation of a user’s profile, personal information provided by a user is deleted immediately on the developer’s server.

 

7.      Operability

The developer operates information system that exchanges signature certificates with corresponding foreign systems, particularly within the framework of the EU digital COVID-19 certificate system of the European Union. The interoperable certificates of other countries can be checked in participating countries. The information system processes only signature certificates and no personal data, as the applications for checking COVID-19 certificates require list of signature certificates in order to be able to check the validity of the certificates they scan.

 

8.      Source of the displayed information

The information displayed by the app is based on the data stored on the secured databases of the Ministry of Health, Labor and Social Affairs of Georgia and its legal entities of public law.

 

9.      Legal basis

The legal basis for the development of the app is the Decree No 164 of the Government of Georgia on the Prevention of the Spread of the Novel Coronavirus and Response to the Disease Cases and the latest amendment to it.

 

Decree available at https://matsne.gov.ge/ka/document/view/4821121?publication=91

Amendment available at https://matsne.gov.ge/ka/document/view/5275367?publication=0

 

The Decree is the main instrument for the establishing of the tools for tackling the COVID-19 outbreak in Georgia. The decree No 164 was issued on January 28, 2021. Latest amendment No 1904 ordered the Ministry of Health, Labor and Social Affairs of Georgia, its LEPL Information Technology Agency, the Ministry of Justice of Georgia and its State Services Development Agency to cooperate and ensure the development of the internationally interoperable e-tools for the identification of the person and verification of the COVID-19 status for the purposes of international travel.

 

The features of the app were updated as a result of the decision of the Ministry of Health, Labor and Social Affairs of Georgia by LEPL Information Technology Agency. Pursuant to the Statute of the LEPL Information Technology Agency approved by the Order №01-48/n of the Ministry of Health, Labor and Social Affairs of Georgia on May 19, 2021, the Agency is entitled to develop and update a new app.

 

10.  Data security

In order to protect the data against unauthorized access, loss and misuse the developer takes appropriate security measures of both technical and organizational nature in accordance with the requirements of the Georgian data protection legislation.

 

11.  Data transfer

The developer will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy and no transfer of your personal data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

 

12.  The app permissions

 

The app does not use location tracking or geopositioning.

 

The app does not require access to the camera or microphone of the device.

 

13.  Rights of the persons concerned

Persons whose data is processed with the app have the right to information, rectification, erasure and surrender of their data. They as well, have the right to restrict and object to data processing. They additionally have the right to revoke consent. These rights apply only insofar as personal data is concerned. The encryption and the logic of the apps ensures as little as possible information is available on specific or identifiable persons.

 

The exercise of the relevant rights requires that the persons concerned provide clear evidence of their identity.

 

In the event of the breach, the persons concerned may contact the competent data protection authority or take legal action in accordance with the data protection legislation.

 

14.  Conclusive remarks

The privacy policy may be amended by the developer. The current published version or the version valid for the period in question shall apply.

 

The exclusive jurisdiction for all disputes is adjudicated by Georgian court. The applicable legislation will be Georgian, unless proven otherwise.

 

Changes in the terms of use will be notified to the users.

 

The provisions are provided in Georgian and English, in the event of any discrepancies, the Georgian version will prevail.