Who is accountable
- Data controller
- Aslam Clinic & Sugar Center, Mohalla Masjid Siddique, Circular Road, Jalalpur Jattan 50780, Gujrat, Punjab, Pakistan — decides why and how information is used, and carries the responsibility for it.
- Privacy officer
- the clinic's privacy officer (privacy@aslam.clinic) — answers rights requests, assesses new processing, and leads the response to a breach.
- Medical director
- Dr Hammad Aslam, MBBS (Diabetologist) — accountable for clinical records, clinical content and the limits placed on the automated assistant.
- Responsible pharmacist
- the responsible pharmacist — accountable for prescription verification and dispensing records.
- Everyone else
- Every member of staff is responsible for confidentiality. It is a condition of working here, not a policy they were sent.
The rules we hold ourselves to
- Collect the least that will do the job. The strongest control on this website is what it does not hold.
- Use it only for what it was collected for. A new purpose needs a new decision, and usually a new consent.
- Keep it only as long as the schedule says, and enforce that schedule with a job rather than a reminder.
- Least privilege: access is granted per person, per need, and removed the day the need ends.
- Privacy by design. The question is asked before a feature is built, not audited after it ships.
- Nothing published is a claim we cannot evidence. If we cannot show it, we do not say it.
Before anything new is built
Any change that touches personal data — a new form, a new supplier, a new use of the WhatsApp thread, an analytics tool — is screened by the privacy officer first:
- What is collected, from whom, and why. If the purpose cannot be written in one sentence, it is not ready.
- What the lawful basis is, and whether consent is needed.
- Whether less data would do. It usually would.
- Who else would receive it, where they operate, and under what safeguard.
- How long it is kept, and which rule in the retention schedule covers it.
- What the worst plausible outcome for a patient is, and what reduces it.
Anything involving health data at scale, systematic monitoring, or a new automated system gets a full impact assessment before it launches, not after.
Suppliers
- Every supplier that touches personal data is named in the privacy notice. If we cannot name it, we do not use it.
- Each is engaged under a written agreement that limits them to our instructions, and each is checked for the transfer safeguard that applies to it.
- Suppliers are re-reviewed at least every 12 months, and immediately after a publicly reported incident at one of them.
- Consumer WhatsApp is the deliberate exception, and the one we are most open about: Meta offers no processing agreement for clinical use, so the residual risk stays with us and is disclosed to patients at /legal/whatsapp rather than papered over.
If something goes wrong
- Anyone who suspects a breach reports it immediately. Nobody is disciplined for raising one, including the person who caused it — a culture that punishes reporting is a culture that finds out late.
- It reaches the privacy officer within 24 hours.
- Contain first: revoke the access, take the system down, stop the spread.
- Assess what data, whose, how much, and what it means for them.
- Where there is a real risk to anyone, notify the relevant supervisory authority within 72 hours and the people affected without undue delay, in plain words.
- Fix the cause, write down what happened, and change whatever allowed it. The record is kept whether or not it was reportable.
Reportable or not, it is written down
A register of every incident — including the ones that turned out to be nothing — is what makes a pattern visible before it becomes a serious one.
Staff and training
- Confidentiality is part of every contract and is explained on the first day, not mailed as a PDF.
- Everyone who handles patient information is briefed at least annually on confidentiality, on this framework, and on what a breach looks like in practice.
- Clinic devices are locked and passcoded. Patient conversations are never forwarded, screenshotted into a group, or discussed outside care.
- Access to the admin console is granted by name, reviewed periodically, and revoked the day someone leaves.
How we check ourselves
- The retention schedule is executed by an automated sweep, not by memory.
- An automated compliance check runs against the site: it verifies that every policy is inside its review window, that every published contact is filled in, that every legal link resolves, and that no cookie is set which the notice does not declare.
- Every policy carries a version and a review date, both visible at the top of its page.
- The administrative audit trail records who did what, when, and from where.
- Complaints and incidents are reviewed together at least every 12 months, looking for the pattern rather than the case.
Ask us for the current state of any of this at privacy@aslam.clinic. We would rather answer a hard question than be trusted on the strength of a page.