LifeHealth — Beyond the Future of Healthcare

Privacy Policy — Passport Mobile Platform

CTI Global · International Edition (GDPR + HIPAA Aligned) · Effective Date: 16/07/2026 · Last Updated: 16/07/2026

1. Introduction

The LifeHealth Mobile Application is operated by CTI Global. It functions as a secure digital health platform that enables patients to communicate with licensed healthcare professionals using smartphones and tablets.

This policy covers how personal data, health information, and protected health information gets collected, processed, stored, transferred, and safeguarded when using the app.

Standards alignment includes GDPR, UK GDPR, HIPAA Privacy/Security/Breach Notification Rules, U.S. privacy legislation, and international healthcare privacy principles.

2. Company Information

CTI Global — 44 Wall Street, New York, NY 10005, United States.

General privacy enquiries: support@lifehealth.global

3. Scope

This policy covers the LifeHealth Mobile Application including the patient app, clinician app, caregiver app, secure messaging, appointment scheduling, prescription management, lab requests, electronic health records, payment functionality, and communications.

Third-party applications or linked services remain outside this policy's scope.

4. Our Role

CTI Global provides technology services facilitating communication between providers and patients. The company does not provide diagnosis, treatment, or emergency services.

Healthcare providers remain independently responsible for diagnosis, treatment, prescriptions, clinical decisions, medical record accuracy, licensing, and regulatory compliance. No physician-patient relationship exists between CTI Global and users.

5. Categories of Information Collected

Account Information

Full name, email, telephone, date of birth, username, encrypted passwords.

Health Information

Consultation notes, prescriptions, diagnoses, laboratory results, referral letters, allergies, medications, medical history, vaccination records, treatment plans.

Device Information

Manufacturer, model, operating system version, application version, language, time zone, IP address, device identifier, crash logs, diagnostic logs, authentication logs.

Network Information

IP address, connection timestamps, session identifiers, authentication tokens, security event logs.

Payment Information

Processed through PCI DSS-compliant providers; complete card details are not stored by CTI Global.

6. Mobile Permissions

Camera

Used for video consultations, document scanning, prescription uploads, laboratory report uploads, and profile photos. Access is revocable through device settings.

Microphone

Used for voice and video consultations. Required for voice communication features.

Photo Library

Used when uploading medical images, prescriptions, referral letters, laboratory reports, or insurance documents.

Notifications

For appointment reminders, prescription updates, clinician messages, and account security alerts. Marketing notifications require legal permission and consent.

Location

Used to identify nearby healthcare providers, pharmacies, laboratories, verify jurisdictional licensing, and improve scheduling. Disabling location access removes certain location-based services.

Biometric Authentication

Uses device Face ID, Touch ID, fingerprint, or facial recognition if enabled. Biometric templates stay exclusively on devices; CTI Global never receives or processes them.

7. How We Use Information

Information supports account creation, user authentication, consultation scheduling, telemedicine services, secure messaging, payment processing, application performance improvement, fraud detection, unauthorized access prevention, healthcare regulation compliance, security maintenance, incident investigation, legal request responses, customer support, and user experience improvement through anonymized analytics.

The company does not sell Personal Information or Protected Health Information, and does not permit advertiser access to clinical data.

8. Mobile Analytics and Crash Reporting

The app may use trusted service providers collecting limited technical data including application crashes, performance metrics, device compatibility, operating system version, and diagnostic information.

Analytics minimize Personal Information collection where practicable. Non-essential analytics require consent where legally required.

9. Third-Party Software Development Kits (SDKs) and Service Providers

Third-party SDKs and service providers support cloud hosting, authentication, secure messaging, push notifications, payment processing, customer support, error logging, performance monitoring, fraud prevention, content delivery, security monitoring, and analytics.

Service providers receive only necessary information and cannot use data for unrelated commercial purposes. A list of significant providers is available upon request.

10. Sharing of Personal Information

CTI Global does not sell Personal Information or Protected Health Information. Information sharing occurs only when reasonably necessary for Platform operation or legally required.

Healthcare Providers

Licensed physicians, nurses, specialists, psychologists, pharmacists, hospitals, laboratories, imaging facilities, and other healthcare professionals involved in care.

Healthcare Partners

Authorized laboratories, diagnostic centers, pharmacies, specialists, referral facilities, and emergency providers.

Technology Providers

Cloud infrastructure, cybersecurity, payment processors, authentication, email, SMS, video consultation, customer support, document storage, and backup providers.

Regulatory Authorities

Information disclosed where required to comply with law, court orders, subpoenas, law enforcement, public health reporting, regulatory investigations, public safety protection, and contractual enforcement.

Corporate Transactions

Personal Information may transfer during a merger, acquisition, restructuring, asset sale, financing, bankruptcy, or reorganization, subject to confidentiality obligations and legal safeguards.

11. International Data Transfers

Personal Information may be processed in countries other than the country of origin. Safeguards include European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement, binding contractual safeguards, vendor due diligence, data encryption, role-based access controls, data minimization, and transfer impact assessments.

Consent for transfers is obtained where legally required. Recipients maintain substantially equivalent privacy protections.

12. HIPAA Uses and Disclosures

Where HIPAA applies, Protected Health Information may be used or disclosed without additional authorization for:

Treatment

Supporting healthcare professional diagnosis, treatment, referral, prescription, coordination, or monitoring.

Payment

Insurance verification, claims processing, billing, payment collection, financial reconciliation.

Healthcare Operations

Quality assurance, credential verification, fraud prevention, auditing, accreditation, security monitoring, risk management, operational improvement, training.

Legal Compliance

Public health reporting, judicial proceedings, law enforcement requests, government investigations, mandatory reporting, health and safety protection.

Patient authorization is obtained where HIPAA requires it for specific disclosures.

13. Data Retention

Information retention follows legal, regulatory, accounting, contractual, and healthcare obligations.

Retention Schedule

  • Account information: duration of account plus six years
  • Clinical records: minimum ten years after final clinical entry, or longer per law/professional standards
  • Payment/billing records: seven years
  • Security logs: up to twenty-four months
  • Device/crash logs: up to eighteen months
  • Consent records: ten years following withdrawal or closure
  • Marketing preferences: until withdrawn, plus suppression period

Unnecessary information gets securely deleted, anonymized, or irreversibly de-identified per legal requirements and industry standards.

14. Information Security

CTI Global maintains comprehensive information security protecting data against unauthorized access, disclosure, alteration, destruction, or loss.

Safeguards include encryption of data in transit using TLS 1.2 or higher and stored data using AES-256 or equivalent standards, multi-factor authentication, role-based access controls, secure token management, automatic session expiration, device integrity verification, API authentication, vulnerability scanning, penetration testing, continuous monitoring, audit logging, disaster recovery, and employee training.

Mobile devices receive additional protections including platform-native hardware security, encrypted caches, certificate pinning, and remote invalidation.

No electronic transmission or storage is completely secure. Users should protect devices, passwords, and credentials.

15. Your Privacy Rights

Depending on jurisdiction and applicable law, individuals may have rights including:

  • Being informed about information processing
  • Accessing held Personal Information
  • Requesting correction of inaccurate or incomplete information
  • Requesting deletion, subject to retention obligations
  • Restricting certain processing
  • Objecting to legitimate interest processing
  • Withdrawing consent-based processing
  • Receiving information in structured formats
  • Avoiding solely automated decision-making with legal effects
  • Lodging complaints with applicable supervisory authorities

Requests are submitted through the application, account settings, or by contacting CTI Global. Reasonable identity verification may be required.