At One Medical Center, we are committed to safeguarding the privacy and security of our customers' personal and health-related data. This policy outlines our data processing practices in strict compliance with the Lao Law on Protection of Electronic Data (No. 33/NA, 2017) and the Law on Drugs and Medical Products.
1. Information Collection
We collect only the information necessary to verify your identity and fulfill specialized medical orders:
-
Personal Identification: Full name, gender, date of birth, and a copy of your National ID or Passport (required for the purchase of controlled substances).
-
Contact & Logistics: Precise GPS coordinates or physical address (Village, District, Province), phone number, and email address.
-
Pharmaceutical Records: Digital uploads of medical prescriptions, including the prescribing physician's name and the clinic of origin.
-
Transaction & Warranty Data: Purchase history, medical equipment serial numbers for warranty tracking, and payment confirmation receipts.
-
Technical Log Data: IP address, browser type, and "Cookies" to enhance user experience, manage shopping carts, and secure login sessions.
2. Purpose of Data Processing
Your data is processed exclusively for the following professional and legal purposes:
-
Order Verification: Ensuring that Prescription-Only Medicines (POM) are dispensed safely and legally to the rightful owner.
-
Logistics & Fulfillment: Sharing essential contact and location details with our internal delivery team or authorized third-party couriers within Laos.
-
Equipment Maintenance & Support: Utilizing serial numbers to track warranty periods and provide technical assistance for specialized medical devices (e.g., oxygen concentrators).
-
Regulatory Compliance: Maintaining a "Pharmacy Register" for mandatory audits by the Ministry of Health (Food and Drug Department).
3. Data Retention and Deletion
-
Retention Period: In accordance with Lao healthcare regulations, pharmaceutical sales records and prescriptions are retained for a minimum of 5 years.
-
Secure Deletion: Upon the expiration of the legal retention period, or when data is no longer required for its original purpose, all records will be securely purged or anonymized.
4. Security & Confidentiality
-
Data Encryption: All sensitive uploads, including medical prescriptions, are protected using industry-standard SSL/TLS encryption protocols.
-
Access Control: We implement a strict "need-to-know" access hierarchy. Delivery personnel can access address details only; full access to medical files and prescriptions is restricted to licensed Pharmacists and authorized medical staff.
-
Breach Notification: In the event of an unauthorized data disclosure, One Medical Center will notify affected users and the relevant Lao authorities within the timeframe mandated by law.