PragmaConnect Privacy Policy
PragmaConnect (a JAWK Softwares platform) is committed to protecting your privacy and securing your data. We collect only the information necessary to provide and improve our healthcare integration services. This may include account and contact details (such as names, emails, and company information), usage data (such as IP addresses, logs, and cookies), and, when acting on behalf of a customer, clinical data which may include Protected Health Information (PHI).
We do not sell personal information. We comply with applicable privacy laws and healthcare regulations (including HIPAA in the United States, GDPR in the European Union, and CCPA in California, where applicable) and implement safeguards such as encryption and access controls to protect data.
Information We Collect
We collect information you provide directly (for example, through account registration or contact forms) and information automatically (such as IP addresses, usage logs, and cookies).
When enabling healthcare integrations, we may process clinical information or PHI on behalf of our customers. This occurs only under a HIPAA Business Associate Agreement (BAA) and strictly according to the instructions of the healthcare organization using the platform.
Customer data is used only to deliver the requested services and is not used for unrelated purposes.
How We Use Information
We use information to operate, maintain, and improve PragmaConnect services. Examples include using contact details to communicate with users, and usage data to monitor system performance, troubleshoot issues, and enhance reliability. If clinical data or PHI is processed as part of integration workflows, it is handled only as permitted by applicable healthcare regulations and Business Associate Agreements. PragmaConnect acts solely as a technology platform facilitating secure healthcare data exchange between authorized systems.
Aggregated or de-identified data (with all personal identifiers removed) may be used for analytics or service improvement. Such information cannot be traced back to any individual.
Sharing of Information
We do not sell or rent personal information.
Information may be shared only in limited circumstances, such as:
- With trusted service providers (for example, cloud infrastructure or operational services) under strict contractual safeguards.
- With our affiliates, where necessary to operate the platform.
- To comply with legal obligations or regulatory requirements.
- To protect the rights, safety, or security of users or our services.
- In connection with a business transaction, such as a merger or acquisition.
When PragmaConnect is used for healthcare integrations, patient health information may be transmitted between healthcare providers, systems, or partners authorized by the healthcare organization using the platform and in accordance with applicable healthcare regulations and patient consent or other lawful authorization (such as treatment, payment, or healthcare operations under HIPAA).
All recipients are required to maintain appropriate confidentiality and security safeguards.
Patient Consent and Healthcare Data Exchange
PragmaConnect facilitates secure interoperability between healthcare providers and healthcare information systems.
Healthcare organizations using the platform are responsible for ensuring that appropriate patient consent, authorization, or other lawful basis for data sharing is obtained before transmitting patient information through the platform.
PragmaConnect does not independently determine how patient data is shared. The platform processes healthcare information only as instructed by the healthcare organization acting as the data controller or covered entity.
Security Measures
We employ administrative, technical, and physical safeguards to protect data. These include encrypted communications (HTTPS/TLS), encryption of stored data, access controls based on least-privilege principles, and regular security reviews.
Our personnel are trained in privacy and security practices. While we implement strong safeguards, no system can guarantee absolute security. Users are responsible for protecting their account credentials and should use strong passwords and multi-factor authentication where available.
Data Retention
We retain personal information only as long as necessary to provide services and meet legal or regulatory obligations.
Operational logs and integration records may be retained temporarily for troubleshooting, support, or compliance purposes and are then securely deleted or anonymized. If an account is closed, we will delete associated data within a reasonable period, except where retention is required by law.
Your Privacy Rights
Depending on applicable laws, individuals may have rights to access, correct, delete, or restrict the use of their personal information.
Requests related to patient health information should generally be directed to the healthcare provider or organization responsible for the data. Where applicable, individuals may also withdraw consent for data processing through their healthcare provider.
HIPAA Compliance
When handling PHI on behalf of healthcare organizations, PragmaConnect operates as a HIPAA Business Associate.
The healthcare organization using the platform acts as the covered entity or data controller, while PragmaConnect processes information only as directed by them. We implement the safeguards required by HIPAA’s Security and Privacy Rules and notify customers of any security incidents involving PHI as required by law.
Policy Updates
We may update this Privacy Policy from time to time to reflect operational, legal, or regulatory changes. Updated versions will be posted on our website or platform. Continued use of PragmaConnect after updates indicates acceptance of the revised policy.
Contact Information
If you have questions or wish to exercise your privacy rights, please contact us at:
Email: contact@pragmaconnect.com