Elephant Privacy Hub

You're in control of your data.

Our mission is to provide better healthcare for everyone.

As part of this mission, we are committed to providing every patient with the safety and peace of mind that their health information is secure and private.

Your data is safe with us

At Elephant, the safety and privacy of your health data and personal information is our top priority. We want you to feel confident that you understand the way in which your personal information is collected and used.

We do this by:
•  Using state of the art data security technology to keep data safe;
•  Committing to the highest standards of data privacy and ethics;
•  Giving individuals control over how their data is used and never sharing personal information without explicit consent; and
•  Being transparent about how any information we collect is used.

Transparency: making use of your data crystal clear

We know lots of information about data processing can be confusing and complicated. We want to change that. Elephant is committed to removing jargon when it comes to data usage so that you are clear about your data. Of course, we need to have legal terms and conditions about your data usage and those documents are available to you, but we are also committed to making them easy to understand.

If you are a patient, professional or provider using our software applications, then you agree to be bound by our Software Terms of Use, which can be found here.

You can use the links on the left to navigate to information relevant to your relationship with Elephant. You can also read our full Privacy Policy here.

If your healthcare provider uses Elephant they may have asked to register you on the Elephant platform and given you an Elephant card that links to your digital health record.

If you have done this then we look after your personal data on behalf of your healthcare provider, in accordance with our Privacy Policy. Below is a summary of the key points of our Privacy Policy which you can also review in full here.

What personal data Elephant collects about you and why

Your healthcare provider uses Elephant’s operating system to create digital health records. Your record will include personal data about you such as your name and address, your medical history, medications you take, and any diagnosis about your physical and mental health.


Where Elephant stores your personal data

Elephant uses end to end encryption to securely store your personal data on servers in tier 3 data centres. Your personal data is never held on any computer, laptop, or mobile device, including your own.


Who has access to your personal data and how is it used

Elephant processes your personal data on behalf of your healthcare provider so they can provide you with medical care. We also anonymise your personal data so it can be used by your healthcare provider or Elephant to improve healthcare services.

Elephant has strict procedures, security features and audit processes to prevent unauthorised access to your personal data, and is fully compliant with all local and international data protection laws and regulations.


Elephant at Home

You will have also been asked if you would like us to store a copy of your data for you to access from home. If you agreed to this you will have been given a PIN number, and you can scan the QR code on your Elephant card and see your digital health record. In future you will be able to manage your information through the Elephant patient app. You can find out more information about accessing your digital health record in our Patient Hub.


Consent: what does it mean?

When it comes to personal data, the legal meaning of consent depends on your home country. At Elephant, we ensure that when we collect your personal data we adopt that legal meaning and ensure that any consent we collect is express, specific, informed and unequivocal. When you give Elephant your consent to do certain things with your data we don't do anything else with it without your further consent. That means that you know who has access to your data and why.  
Elephant will always ask for your consent before using your health record or sharing it with anyone.


Our commitment to let you have control

Your health data is sensitive, and we understand that you want to be in control of it. When you use Elephant’s applications, we are transparent with you about how your data is being used and why. At the very least, your healthcare provider will use that data to provide you with medical care. Elephant can offer you additional benefits when you provide your specific consent: but the choice is yours.


For patients of providers who no longer use Elephant

If your healthcare provider stops using Elephant to power your Digital Health Records, you will no longer have access to your Digital Health Record via ele.health.  Please speak to your doctor or facility administrator to find out how they will securely manage your personal data that was previously stored on Elephant, and how you can access it. After your healthcare provider ceases using Elephant, we will continue to securely store Digital Health Records only as long as reasonably necessary under a legal agreement or as required by law.

Elephant is designed by doctors, for doctors. Healthcare systems that use Elephant enable digitisation of the hospitals and clinics in which healthcare professionals work and provide patients with digital health records.

This means that Elephant securely stores and processes the data of healthcare professionals, your patients and your healthcare system:

•  Elephant processes your patient’s information to help you provide them with the best care. More information about the personal information we collect about your patients, including their digital health records, can be found here

•  Elephant may collect your personal information, including your name, email address and job title to enable you to use our applications. Any personal information that we collect is processed in accordance with our Privacy Policy.


Where Elephant stores your personal information  

Elephant uses end to end encryption to securely store your personal information on servers in tier 3 data centres. Your personal information is never held on any computer, laptop, or mobile device, including your own.


Who has access to your personal information and how is it used

Your personal information is only accessible by Elephant for the purpose for which it was collected: to enable you to use Elephant’s applications. Your personal information may be visible to people within your organisation to facilitate the use of Elephant’s products. We never pass your personal information to a third party without your explicit consent. We never send you correspondence without your explicit consent.

Elephant has strict procedures, security features and audit processes to prevent unauthorised access to your personal information, and is fully compliant with all local and relevant international data protection laws and regulations.

Healthcare providers run health systems. Elephant helps providers manage the vast quantities of health system data and patient health information they collect to enable their important work. It does this by digitising healthcare systems at scale and securely and responsibly managing patient and healthcare data on behalf of its partners.


As an Elephant partner:

•  You remain in control of your data: Elephant acts as a secure data processor on your behalf.

•  All data we process for you is stored in state of the art (tier 3) data centres, and protected with advanced encryption technology.

•  Elephant has strict procedures, security features and audit processes to prevent unauthorised access to the personal information that we process on your behalf, including carefully managed user permissions to ensure healthcare workers can only see the information that they need to do their jobs.

•  You will ensure a high bar for access to personal information - dashboards and reports are anonymised to protect the personal information of individual patients.

•  You are partnering with a company who is committed to helping you integrate services and harness the power of data science and machine intelligence to improve outcomes and reduce costs in your healthcare system.

• You can be assured that Elephant  is fully compliant with all local and international data protection laws and regulations, and have access to  the local expertise to guide health care systems in compliance matters as required. Elephant subscribes to the highest global standard of information security management and is ISO 27001 certified.


As well as working for you as the healthcare provider, Elephant is also serving your patients, healthcare workers, and the wider community.

•  We ask your patients if they would like us to store a copy of their data for them, which they can manage themselves and access from home.

•  We also store personal information about your healthcare workers who use our platform to enable them to access our applications securely and to provide you with statistics.

• More information about the personal information we collect about your employees can be found here, and about your patients can be found here.

•  Elephant uses anonymised statistics to enable work to improve healthcare and our platform - we never use patient-identifiable information for these purposes without an individual patient’s consent.

•  By partnering with Elephant, you are unlocking access to a global network of digitised health care systems, with the possibility of accessing knowledge, education and training at scale.