Legal
Privacy Policy
Last updated: January 2026 · Maintained by Jomur Health
Scope of this policy
This page is maintained by Jomur Health to answer common security and privacy questions about the platform. It is app-owned editable content, not an independent certification or audit report.
Information we process
The platform processes organization configuration, user account details, role assignments, and the clinical or occupational records that customer organizations choose to store. Customer organizations remain the data controllers for records they upload.
Access controls
Access is scoped by organization profile and active role. Administrators, care coordinators, and occupational physicians see different fields based on the role selected for the session.
Audit logging
Record access and configuration changes are written to an append-only audit ledger with the acting user, timestamp, and source context.
Subprocessors and integrations
Hosting, database, and authentication services are provided through the platform infrastructure configured by the app owner. A current subprocessor list is available on request.
Retention and deletion
Retention periods are configured per organization. Deletion requests are handled by the app owner through the administrative console.
Privacy requests and contact
Individuals may submit access, correction, or deletion requests to the organization that holds their records. Security concerns can be reported to the Jomur Health security contact listed in your service agreement.
Shared responsibility
Jomur Health provides platform capabilities; each customer organization is responsible for its own configuration, staff training, lawful basis for processing, and internal policies.