O
OmniviewOSEnterprise HMS
Return to Portal
HIPAA•NDPR / NDPA Compliant•GDPR Ready

OmniviewOS Privacy Policy

Enterprise Governance, Multi-Tenant Health Data Protection, Protected Health Information (PHI) Processing Standards & Regulatory Safeguards.

Effective Date: August 4, 2026
Last Revised: August 4, 2026
Platform Version: 1.0.0
1

Executive Overview & Scope

This Privacy Policy describes how OmniviewOS (operated by Data Trans Limited, herein referred to as "OmniviewOS", "we", "us", or "our") processes, collects, protects, stores, and discloses personal information, Protected Health Information (PHI), and operational metadata through the OmniviewOS Enterprise Hospital Management Platform (the "Platform"). OmniviewOS operates as a multi-tenant B2B Software-as-a-Service (SaaS) healthcare platform designed for hospitals, healthcare networks, polyclinics, laboratories, and specialized care centers ("Healthcare Institutions" or "Tenants"). Entity Roles: • Healthcare Institution / Hospital Tenant (Data Controller / Covered Entity): The licensed healthcare facility operating a dedicated tenant instance. The Healthcare Institution determines the legal grounds, purposes, and retention criteria for processing patient data, medical records, and staff administrative files. • OmniviewOS (Data Processor / Business Associate): OmniviewOS acts as a Data Processor (under NDPR/GDPR) and Business Associate (under HIPAA) providing platform infrastructure, multi-tenant database isolation, application services, and technical operations under an executed Data Processing Agreement (DPA) or Business Associate Agreement (BAA). • End Users (Data Subjects): Individual patients accessing the Patient Portal (/patient-portal), hospital administrative staff, clinical providers (physicians, nurses, pharmacists, lab technicians), and system administrators.
2

Categories of Data We Process

OmniviewOS processes the following distinct categories of data: 1. Protected Health Information (PHI) & Clinical Data: • Master Patient Index (MPI) & Demographics: Full name, DOB, biological sex, blood group, genotype, NIN/SSN, address, primary phone, email, next-of-kin emergency contact, photo ID, and hospital registration numbers. • Clinical Records & Encounter Data: Physician consultation notes, clinical progress notes, diagnosis codes (ICD-10/ICD-11), vital signs telemetry (blood pressure, HR, SpO2, temp, BMI), triage priority scores (Red/Yellow/Green), and inpatient admission records. • Diagnostic & Imaging Data: Laboratory test requisitions, pathology result reports, specimen logs, Radiology PACS worklists, DICOM metadata, and attachments. • Medication & Treatment Records: eMAR nursing logs, inpatient bed assignments, outpatient prescriptions, drug allergy flags, and pharmacy dispensing logs. 2. Financial, Billing & Insurance Data: • Patient Financial Accounts: Invoice items, copays, deductibles, unearned deposit balances, payment receipts, and billing history. • Insurance & HMO Data: HMO policy IDs, pre-authorization codes, claim tariff codes, and adjudication clearance status. • Double-Entry General Ledger Data: Institutional Chart of Accounts (COA), journal entries, COGS adjustments, and reconciliation ledgers. 3. Hospital Staff & HR Data: • Staff Profiles: Employee full name, professional licenses, medical registration numbers, clinical department assignments, job titles, and contact details. • HR & Payroll Data: Shift rosters, attendance logs, appraisals, leave balances, compensation, and bank payout details. • Security Credentials & Audit Telemetry: Role-based access control (RBAC) capability assignments, clinical PIN override authorization logs, password hash metadata, and action logs. 4. Technical & Device Telemetry Data: • Session & Auth Data: Encrypted JSON Web Tokens (JWT), session cookies, authentication timestamps, multi-tenant edge subdomain headers (x-tenant-subdomain), and IP addresses. • System Diagnostics: Error tracebacks (via Sentry telemetry), API request latency, user-agent details, and device/browser characteristics.
3

Purpose of Data Processing

OmniviewOS processes data exclusively to execute legitimate, contracted healthcare operational and platform maintenance functions: • Clinical Care & Coordination: Facilitating patient triage, doctor consultations, eMAR nursing rounds, lab testing, radiology, and pharmacy dispensing. (Legal Basis: Healthcare Provision / Contract Performance) • Hospital Operations & Governance: Managing bed admissions, ward transfers, staff shift rosters, inventory levels, and general ledger double-entry accounting. (Legal Basis: Legal Compliance / Legitimate Operations) • Financial Settlement & Billing: Processing patient point-of-sale transactions, issuing insurance clearance claims, and managing HMO pre-authorizations. (Legal Basis: Contract Performance / Statutory Accounting) • Patient Empowerment & Access: Providing self-service access to lab results, appointment histories, and prescriptions via the Patient Portal (/patient-portal). (Legal Basis: Consent / Patient Right under HIPAA & NDPR) • Security & Regulatory Auditability: Maintaining immutable audit logs for clinical override events, role capability changes, financial waivers, and data access. (Legal Basis: HIPAA Security Rule / NDPR Mandate) • System Reliability & Observability: Monitoring system performance, catching runtime exceptions, resolving bugs, and enforcing rate limiting. (Legal Basis: Legitimate Interest in Platform Uptime)
4

Regulatory Compliance Architecture

OmniviewOS is architected for strict adherence to global health privacy standards: • Health Insurance Portability and Accountability Act (HIPAA): - Business Associate Agreement (BAA): Executed with covered entities, binding OmniviewOS to safeguard PHI in accordance with HIPAA Privacy, Security, and Breach Notification Rules. - Minimum Necessary Rule: Role-Based Access Controls (RBAC) and capability matrices enforce minimum necessary access for all staff roles. • Nigeria Data Protection Regulation (NDPR) & Data Protection Act (NDPA 2023): - Data Protection Principles: Full compliance with data minimization, accuracy, storage limitation, integrity, and confidentiality mandates. - Statutory Audits: Annual Data Protection Audits conducted and filed with the Nigeria Data Protection Commission (NDPC). • General Data Protection Regulation (GDPR): - International Transfers: Governed by Standard Contractual Clauses (SCCs) approved by the European Commission for cross-border infrastructure.
5

Technical Security & Data Isolation Safeguards

OmniviewOS implements zero-trust, defense-in-depth safeguards: • Multi-Tenant Row-Level Security (RLS): All PostgreSQL tables feature active RLS policies tied to the request context (x-tenant-subdomain), ensuring absolute multi-tenant database isolation. • Encryption Standards: - Data in Transit: Encrypted via Transport Layer Security (TLS 1.3). - Data at Rest: Encrypted via AES-256 across all database tables, backups, and storage buckets. • Authentication & Session Security: HTTP-only, SameSite cookies managed by Supabase Auth (@supabase/ssr). Step-up PIN verification required for high-risk clinical overrides. • Object Storage Protection: Lab reports, pathology files, DICOM images, and user avatars stored in private Supabase Storage buckets accessible only via time-limited signed URLs.
6

Data Sharing & Sub-Processors

OmniviewOS NEVER sells, rents, or monetizes patient, clinical, or institutional data. Authorized Sub-Processors: • Supabase, Inc. (Managed PostgreSQL Database, Auth Engine, & Object Storage) – USA / SOC 2 Type II, HIPAA Compliant Infrastructure • Functional Software, Inc. / Sentry (Application Performance Monitoring & Error Diagnostics) – USA / SOC 2 Type II, ISO 27001 • Resend Labs, Inc. (Transactional Email Infrastructure) – USA / HIPAA Compliant Email Gateway • Vercel, Inc. / Cloud Infrastructure (Edge Network Routing & SSL Offloading) – USA / Global Edge / SOC 2 Legal Disclosures: Disclosures occur only under compulsory court order, warrant, or statutory mandate. Affected Healthcare Institutions are notified immediately prior to disclosure unless legally prohibited.
7

Data Retention & Destruction

Retention Schedule: • Clinical EMR & Patient Records: Retained per Healthcare Institution policy and statutory medical record laws (typically 7 to 21 years). • Financial & Billing Records: Retained for 7 years to meet statutory double-entry general ledger tax audit laws. • System & Audit Logs: Retained for 2 years for security auditing and compliance reviews. Termination & Data Purging: Upon contract termination, Tenants receive a 30-day grace window to export all records. Following this, cryptographic data purging is executed across all tenant database schemas and storage buckets in accordance with NIST SP 800-88 standards.
8

Data Subject Rights

Patient & Staff Rights: • Right to Access: Patients can inspect demographic data, active prescriptions, lab results, and appointments anytime via the Patient Portal (/patient-portal). • Right to Rectification: Patients may request demographic updates through the portal or facility medical records department. • Right to Data Portability: Exportable clinical summary PDFs and diagnostic reports. • Right to Restriction & Complaint: Patients may lodge formal inquiries with the facility DPO or regulatory bodies (e.g., US HHS OCR, Nigeria Data Protection Commission).
9

Incident Response & Breach Notification

24/7 Security Incident Response Protocol: • Rapid Containment: Suspected incidents trigger automated containment and forensic investigation. • Breach Notification Timelines: - To Healthcare Institutions: Immediate notification within 24 hours of confirming a security breach involving PHI. - To Regulators & Data Subjects: Handled in coordination with Healthcare Institutions within HIPAA (60 days) and NDPR (72 hours) statutory limits.
10

International Data Transfers

Data transferred across national borders utilizes encrypted channels, Standard Contractual Clauses (SCCs), and ISO 27001 / SOC 2 certified data center facilities ensuring full data protection parity across jurisdictions.
11

Revisions & Policy Updates

OmniviewOS updates this policy periodically to reflect platform upgrades or statutory regulatory changes. Material updates will be communicated to Tenant Administrators via transactional email and in-app alerts at least 30 days prior to taking effect.
12

Contact Information & Data Protection Officer

For inquiries regarding this Privacy Policy, HIPAA BAAs, or Data Processing Agreements: • Data Protection Officer (DPO): Data Trans Limited / OmniviewOS Security Division • Email: privacy@datatranslimited.com / dpo@omniview.app • Corporate Website: https://datatranslimited.com • Security Desk: https://omniview.app/security

Data Protection Verification & Security Oversight

OmniviewOS is continuously audited for HIPAA, NDPR/NDPA, and SOC 2 Type II compliance. For institutional BAAs or customized data processing agreements, contact our security council.

Contact DPO Council
Engineered ByDATA TRANS LTD