Privacy Policy — Passport Mobile Platform
CTI Global · International Edition (GDPR + HIPAA Aligned) · Effective Date: 16/07/2026 · Last Updated: 16/07/2026
1. Introduction
The LifeHealth Mobile Application is operated by CTI Global. It functions as a secure digital health platform that enables patients to communicate with licensed healthcare professionals using smartphones and tablets.
This policy covers how personal data, health information, and protected health information gets collected, processed, stored, transferred, and safeguarded when using the app.
Standards alignment includes GDPR, UK GDPR, HIPAA Privacy/Security/Breach Notification Rules, U.S. privacy legislation, and international healthcare privacy principles.
2. Company Information
CTI Global — 44 Wall Street, New York, NY 10005, United States.
General privacy enquiries: support@lifehealth.global
3. Scope
This policy covers the LifeHealth Mobile Application including the patient app, clinician app, caregiver app, secure messaging, appointment scheduling, prescription management, lab requests, electronic health records, payment functionality, and communications.
Third-party applications or linked services remain outside this policy's scope.
4. Our Role
CTI Global provides technology services facilitating communication between providers and patients. The company does not provide diagnosis, treatment, or emergency services.
Healthcare providers remain independently responsible for diagnosis, treatment, prescriptions, clinical decisions, medical record accuracy, licensing, and regulatory compliance. No physician-patient relationship exists between CTI Global and users.
5. Categories of Information Collected
Account Information
Full name, email, telephone, date of birth, username, encrypted passwords.
Health Information
Consultation notes, prescriptions, diagnoses, laboratory results, referral letters, allergies, medications, medical history, vaccination records, treatment plans.
Device Information
Manufacturer, model, operating system version, application version, language, time zone, IP address, device identifier, crash logs, diagnostic logs, authentication logs.
Network Information
IP address, connection timestamps, session identifiers, authentication tokens, security event logs.
Payment Information
Processed through PCI DSS-compliant providers; complete card details are not stored by CTI Global.
6. Mobile Permissions
Camera
Used for video consultations, document scanning, prescription uploads, laboratory report uploads, and profile photos. Access is revocable through device settings.
Microphone
Used for voice and video consultations. Required for voice communication features.
Photo Library
Used when uploading medical images, prescriptions, referral letters, laboratory reports, or insurance documents.
Notifications
For appointment reminders, prescription updates, clinician messages, and account security alerts. Marketing notifications require legal permission and consent.
Location
Used to identify nearby healthcare providers, pharmacies, laboratories, verify jurisdictional licensing, and improve scheduling. Disabling location access removes certain location-based services.
Biometric Authentication
Uses device Face ID, Touch ID, fingerprint, or facial recognition if enabled. Biometric templates stay exclusively on devices; CTI Global never receives or processes them.
7. How We Use Information
Information supports account creation, user authentication, consultation scheduling, telemedicine services, secure messaging, payment processing, application performance improvement, fraud detection, unauthorized access prevention, healthcare regulation compliance, security maintenance, incident investigation, legal request responses, customer support, and user experience improvement through anonymized analytics.
The company does not sell Personal Information or Protected Health Information, and does not permit advertiser access to clinical data.
8. Mobile Analytics and Crash Reporting
The app may use trusted service providers collecting limited technical data including application crashes, performance metrics, device compatibility, operating system version, and diagnostic information.
Analytics minimize Personal Information collection where practicable. Non-essential analytics require consent where legally required.
9. Third-Party Software Development Kits (SDKs) and Service Providers
Third-party SDKs and service providers support cloud hosting, authentication, secure messaging, push notifications, payment processing, customer support, error logging, performance monitoring, fraud prevention, content delivery, security monitoring, and analytics.
Service providers receive only necessary information and cannot use data for unrelated commercial purposes. A list of significant providers is available upon request.
10. Sharing of Personal Information
CTI Global does not sell Personal Information or Protected Health Information. Information sharing occurs only when reasonably necessary for Platform operation or legally required.
Healthcare Providers
Licensed physicians, nurses, specialists, psychologists, pharmacists, hospitals, laboratories, imaging facilities, and other healthcare professionals involved in care.
Healthcare Partners
Authorized laboratories, diagnostic centers, pharmacies, specialists, referral facilities, and emergency providers.
Technology Providers
Cloud infrastructure, cybersecurity, payment processors, authentication, email, SMS, video consultation, customer support, document storage, and backup providers.
Regulatory Authorities
Information disclosed where required to comply with law, court orders, subpoenas, law enforcement, public health reporting, regulatory investigations, public safety protection, and contractual enforcement.
Corporate Transactions
Personal Information may transfer during a merger, acquisition, restructuring, asset sale, financing, bankruptcy, or reorganization, subject to confidentiality obligations and legal safeguards.
11. International Data Transfers
Personal Information may be processed in countries other than the country of origin. Safeguards include European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement, binding contractual safeguards, vendor due diligence, data encryption, role-based access controls, data minimization, and transfer impact assessments.
Consent for transfers is obtained where legally required. Recipients maintain substantially equivalent privacy protections.
12. HIPAA Uses and Disclosures
Where HIPAA applies, Protected Health Information may be used or disclosed without additional authorization for:
Treatment
Supporting healthcare professional diagnosis, treatment, referral, prescription, coordination, or monitoring.
Payment
Insurance verification, claims processing, billing, payment collection, financial reconciliation.
Healthcare Operations
Quality assurance, credential verification, fraud prevention, auditing, accreditation, security monitoring, risk management, operational improvement, training.
Legal Compliance
Public health reporting, judicial proceedings, law enforcement requests, government investigations, mandatory reporting, health and safety protection.
Patient authorization is obtained where HIPAA requires it for specific disclosures.
13. Data Retention
Information retention follows legal, regulatory, accounting, contractual, and healthcare obligations.
Retention Schedule
- Account information: duration of account plus six years
- Clinical records: minimum ten years after final clinical entry, or longer per law/professional standards
- Payment/billing records: seven years
- Security logs: up to twenty-four months
- Device/crash logs: up to eighteen months
- Consent records: ten years following withdrawal or closure
- Marketing preferences: until withdrawn, plus suppression period
Unnecessary information gets securely deleted, anonymized, or irreversibly de-identified per legal requirements and industry standards.
14. Information Security
CTI Global maintains comprehensive information security protecting data against unauthorized access, disclosure, alteration, destruction, or loss.
Safeguards include encryption of data in transit using TLS 1.2 or higher and stored data using AES-256 or equivalent standards, multi-factor authentication, role-based access controls, secure token management, automatic session expiration, device integrity verification, API authentication, vulnerability scanning, penetration testing, continuous monitoring, audit logging, disaster recovery, and employee training.
Mobile devices receive additional protections including platform-native hardware security, encrypted caches, certificate pinning, and remote invalidation.
No electronic transmission or storage is completely secure. Users should protect devices, passwords, and credentials.
15. Your Privacy Rights
Depending on jurisdiction and applicable law, individuals may have rights including:
- Being informed about information processing
- Accessing held Personal Information
- Requesting correction of inaccurate or incomplete information
- Requesting deletion, subject to retention obligations
- Restricting certain processing
- Objecting to legitimate interest processing
- Withdrawing consent-based processing
- Receiving information in structured formats
- Avoiding solely automated decision-making with legal effects
- Lodging complaints with applicable supervisory authorities
Requests are submitted through the application, account settings, or by contacting CTI Global. Reasonable identity verification may be required.
