Clinical Pathway Engine™ · Patient information
Privacy Policy
Version 1.0 · Last updated 23 July 2026
Controller and contact
Integrative Medicine Group — Gerry Ivanov (Gergan Dzhondzhorov), Rue de Fribourg 7, 1201 Geneva, Switzerland, is responsible for the processing described in this policy.
Questions, access requests, corrections, objections, or withdrawal requests may be sent to img.geneva@gmail.com. Quote your assessment reference when available, but do not include detailed health information in ordinary email.
Information collected
The beta assessment may collect identity and contact details, date of birth, relevant sex information, symptoms, function, medical history, medications, investigations, previous treatment, priorities, insurance and cost considerations, uploaded clinical documents, consent records, and the resulting clinician-reviewed report.
Health information is sensitive personal data. The form deliberately avoids unnecessary identity information and does not request a passport, national identification number, or payment information.
Purposes and use
- to conduct safety screening and reject emergency use;
- to review the submitted health and functional information;
- to ask for clarification where necessary;
- to prepare and deliver a clinician-reviewed treatment-pathway report;
- to keep an access, status, and report-delivery record;
- to respond to correction, withdrawal, deletion, or anonymization requests;
- to measure only aggregate product use, such as starts, completion, abandonment stage, device category, and referral source.
No automated diagnosis, automated clinical recommendation, or solely automated decision is made.
Consent and withdrawal
Before health information is collected, the patient must actively accept every consent statement. No consent box is pre-selected. Consent is recorded with the form version and date.
Consent may be withdrawn by contacting IMG Clinic. Withdrawal does not undo processing already lawfully performed and may be subject to legal or professional record-retention duties. Where permitted, the submission can be deleted or permanently anonymized.
Storage and access
Structured submissions are stored in an access-controlled application database. Uploaded documents and completed reports are stored in private object storage and are not given public file addresses. Administrative access requires ChatGPT sign-in and an explicit owner allowlist. Report links use a high-entropy expiring token and the token is removed from the browser address after verification.
Current technical infrastructure is provided through OpenAI Sites and Cloudflare application, database, and object-storage services. Technical providers may process security and delivery data needed to operate the service. The controller must maintain and periodically review the applicable provider terms, processing locations, subprocessors, and cross-border safeguards.
International processing
Depending on the providers’ service configuration, technical processing may occur outside Switzerland. Before routine use with real patient data, the controller must verify the actual countries involved, the applicable data-processing agreements, confidentiality obligations, and the safeguards used for any destination that does not benefit from an adequate level of protection under Swiss law.
This beta page does not represent that a Swiss, EU, or other jurisdictional storage restriction has been independently verified. Patients may ask IMG Clinic for the current infrastructure and transfer information before submitting.
Email and notifications
Ordinary emails contain only the patient’s name, submission date, assessment reference, safety reminder, and a secure link when a report is ready. The questionnaire, medications, diagnoses, medical history, uploaded files, and report are not attached to ordinary notification emails.
A verified transactional email provider may process the minimum contact and delivery information required to send these messages. If email delivery is unavailable, the notification remains in a restricted administrative outbox for manual handling.
Analytics
The assessment records first-party product events only: assessment opened, started, stage reached, completed, coarse device category, and referral source. Medical answers, symptoms, diagnoses, medications, uploaded documents, and health-related free text are never sent to advertising platforms or ordinary analytics services.
No advertising pixel or behavioural profiling tool is installed on the clinical form.
Retention
The beta system assigns a retention-review date. The current operational default is 180 days. When a submission is marked Closed or Withdrawn, the review date is recalculated from that date. Authorized administrators can delete or permanently anonymize the submission earlier where lawful.
If information becomes part of a clinical record or must be retained for a legal, insurance, professional, or dispute-related reason, a different retention period may apply. The controller must confirm the final retention schedule through an independent legal and professional review.
Backup and recovery
The structured database uses the hosting provider’s point-in-time recovery capability where available. Authorized administrators can also export an individual assessment for controlled operational recovery or data-access purposes. Recovery procedures must be tested periodically without using real patient data.
Private uploaded documents and reports are stored separately from database records. Provider durability does not replace an independently reviewed clinic backup and continuity policy.
Security and limitations
Controls include HTTPS, restricted administration, server-side authorization, private document storage, input and file validation, anti-spam controls, duplicate-submission protection, access logs, expiring report tokens, no-store response headers, and deletion/anonymization functions.
No internet service can guarantee absolute security. Native malware scanning of uploaded documents is not presently available in this beta; files are restricted to PDF, JPG, and PNG, validated by declared type and file signature, stored privately, and delivered as downloads rather than public inline content.
Your rights
Subject to applicable law, a person may request information about processing, access to their data, correction of inaccurate data, delivery of a usable copy, deletion or anonymization, withdrawal of consent, or restriction of processing. Identity may need to be verified before fulfilling a request.
Individuals may also contact the Swiss Federal Data Protection and Information Commissioner or another competent authority.
Official Swiss references: Federal Act on Data Protection · FDPIC cloud-processing guidance · FDPIC cross-border guidance.
Return to the assessment