Privacy Policy for AR International Holdings Ltd

Effective Date: January 01, 2025

Company Name: AR International Holdings Ltd

Application Use for Diagnosis Software for Training and Practice under Trade Name of ALCROEN.

Registered Address: 128, City Road, London EC1V 2NX

AR International Holdings Ltd (“we,” “us,” or “our”) is committed to safeguarding the privacy and security of personal data in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA). This Privacy Policy outlines how we collect, use, store, and protect personal data related to our AI-powered diagnosis software.

1. Data We Collect

We collect and process the following categories of personal data :

  • Patient Data : Name, contact information, medical history, diagnostic information, and any other data necessary for diagnosis and treatment.

  • Healthcare Provider Data : Name, contact information, professional credentials, and facility details.

  • Technical Data : IP addresses, device information, and usage data for system optimization and security.

  • Communication Data : Any information provided during customer support interactions or consultations.

2. Purpose of Data Processing We process personal data for the following purposes :

  • To provide accurate and effective AI-powered diagnostic services.

  • To ensure compliance with medical and regulatory standards.

  • To improve our software through research and development.

  • To maintain security and prevent unauthorized access.

  • To communicate with healthcare providers and patients about our services.

3. Legal Basis for Data Processing (GDPR Compliance)

Under GDPR, we process personal data based on :

  • Consent : When explicit consent is obtained for processing sensitive health data.

  • Contractual Necessity : To fulfill service agreements with healthcare providers.

  • Legal Obligation : To comply with regulatory and legal requirements.

  • Legitimate Interests : To enhance service delivery and system functionality while ensuring data security.

4. HIPAA Compliance

As a provider of healthcare-related software, we comply with HIPAA requirements by :

  • Implementing strict access controls and encryption to protect Protected Health Information (PHI).

  • Signing Business Associate Agreements (BAAs) with covered entities. Conducting regular risk assessments to identify and mitigate potential vulnerabilities.

  • Conducting regular risk assessments to identify and mitigate potential vulnerabilities.

  • Training our employees on HIPAA regulations and security best practices.

5. Data Sharing and Transfers

We do not sell personal data. We share data only with :

  • Authorized Healthcare Providers : To facilitate diagnostic services.

  • Service Providers: : Third-party vendors under strict confidentiality agreements for IT support, data hosting, or analytics.

  • Regulatory Authorities : To comply with regulatory and legal requirements.

  • Legitimate Interests : When required to comply with legal obligations.

Where data transfers occur outside the European Economic Area (EEA), we ensure adequate safeguards, such as Standard Contractual Clauses (SCCs) or equivalent mechanisms.

6. Data Retention

We retain personal data only as long as necessary to fulfill the purposes outlined in this policy or as required by law. Specific retention periods include :

  • Patient Data : Retained for [insert period] in compliance with medical record-keeping requirements.

  • Technical Data : Retained for [insert period] to ensure system optimization and security.

7. Data Security

We implement robust security measures, including :

  • Encryption of data at rest and in transit.

  • Regular security audits and vulnerability assessments.

  • Role-based access controls to limit data access.

  • Incident response protocols to address breaches promptly.

8. Data Subject Rights (GDPR)

Individuals have the following rights:

  • Access : To request a copy of their personal data.

  • Rectification : To correct inaccurate or incomplete data.

  • Erasure : To request deletion of data, subject to legal obligations.

  • Restriction : To limit processing under certain circumstances.

  • Data Portability : To receive personal data in a machine-readable format.

  • Objection : To object to data processing for specific purposes.

Requests can be made by contacting us at support@alcroen.com.

9. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. Updates will be posted on our website, and significant changes will be communicated directly to affected individuals where applicable.

    10. Contact Us

    For questions or concerns about this Privacy Policy or our data protection practices, please contact us :

    • Email : rajiv@arholdings.co.uk

    • Phone : +447776715106

    • Address : 128, City Road, London EC1V 2NX.

    This Privacy Policy ensures compliance with GDPR and HIPAA standards while prioritizing the privacy and security of all personal data processed by AR International Holdings Ltd for its use in platform under its registered trademark ALCROEN