NetMed360 PACS

Privacy Notice

Last updated: 12 July 2026

1. Scope of this notice

This notice explains how this portal handles personal data about its users — the staff of the healthcare organization operating this instance ("the Operator"). Patient imaging data and clinical records are processed by the Operator as data controller under its own data-protection notices; this notice does not replace those. The software is licensed to Infocape LTD ("the Vendor"), which does not receive patient data in the normal operation of the portal.

2. What we process about you

  • Account data: your name, e-mail address, the centers and roles assigned to you, and your password (stored only as a salted hash — never in readable form).
  • Authentication data: sign-in timestamps, failed-login counts (for lockout), and, if enabled, two-factor settings.
  • Activity records: an audit trail of security-relevant actions you take in the portal (for example logging in, opening or sharing a study, changing settings, or accepting the Terms of Service), each recorded with your identity, a timestamp, and the originating IP address.
  • Preferences: interface settings you save, such as worklist filter presets.

3. Why we process it (legal bases)

Account and authentication data are processed to give you access and to keep that access secure (performance of the Operator's contract with you, and the Operator's legitimate interest in securing a system that handles health data). The audit trail is kept for security, accountability, and to help the Operator meet its obligations under Regulation (EU) 2016/679 (GDPR) and applicable health-data law.

4. Retention

Account data is kept while your account is active and for a reasonable period afterwards for security and audit continuity. Audit records are retained according to the Operator's retention policy and applicable legal requirements. The Operator sets and enforces these periods.

5. Who can see it

Your account and activity data are visible to the Operator's administrators. The Vendor accesses this data only when providing support at the Operator's request, under a data-processing agreement, and only for as long as needed to resolve the request. The portal does not sell personal data and does not use it for advertising or profiling. No personal data is transferred outside the European Economic Area in normal operation.

6. Your rights

Under the GDPR you have rights of access, rectification, erasure, restriction, objection, and data portability with respect to your personal data. Because the Operator controls this data, please direct such requests to the Operator's administrators or its Data Protection Officer. You also have the right to lodge a complaint with a supervisory authority — in Greece, the Hellenic Data Protection Authority (HDPA).

7. Security

Passwords are stored only as salted hashes; sessions expire after inactivity; administrative actions are logged; and access to patient data is scoped to the centers and studies you are authorized for. These safeguards protect your data and the patient data you work with.

8. Contact and changes

For questions about your account data, contact the Operator's administrators. For questions about the software itself, contact Infocape LTD. This notice may be updated with new releases of the software; the date above reflects the current revision.


See also the Terms of Service. © 2026. All rights reserved. Software licensed to Infocape LTD.