1. About this policy
Ideal Shift AI ("Ideal Shift", "we", "our" or "us") is committed to protecting the confidentiality and security of personal data. This policy explains how the IdealShift GGZ Assistant Chrome Extension processes information when authorised healthcare professionals use it within supported electronic patient record (EPR) systems.
The extension provides administrative support. It does not replace professional judgement and does not independently make decisions about diagnosis, treatment or other medical care.
2. Who is responsible?
The healthcare organisation using the extension generally determines why and how EPR data is processed and will usually be the data controller. Ideal Shift generally processes this data as a processor on the healthcare organisation's instructions and under the applicable service agreement and data processing agreement.
Ideal Shift may act as an independent controller for limited data it processes for its own security, abuse prevention and business operations. The exact allocation of roles may differ by implementation and is set out in the agreement with the healthcare organisation.
3. Information we process
Depending on the feature used, the extension may read and process the following information from a supported EPR form:
- contact type, contact code and visible contact description;
- travel time;
- client status;
- reporting or registration text;
- client number;
- appointment type and selected activity;
- technical routing information, such as enabled checks, source and timestamp.
Because this information may come from an EPR, it can include personal data and special-category health data. The extension is not designed to collect information outside supported EPR pages and the functions activated by the authorised user.
For security and technical operation, limited technical information may also be processed, including error messages, response statuses, browser or extension information, and the IP address used to access the backend.
4. Why we process information
Information is processed only to deliver, secure and support the agreed functionality, including:
- checking and validating EPR registrations;
- identifying possible registration issues, for example relating to travel time or attendance;
- displaying administrative feedback or recommendations within the EPR;
- supporting and automating administrative workflows;
- troubleshooting, securing the service and preventing misuse.
We do not use EPR data for advertising, marketing, selling data or commercial profiling.
5. Legal basis and healthcare organisation instructions
The healthcare organisation is responsible for identifying a valid legal basis for processing personal data and, where applicable, special-category health data. Ideal Shift processes EPR data only on the healthcare organisation's documented instructions unless applicable law requires otherwise.
For its own limited security and operational data, Ideal Shift relies, depending on the circumstances, on performance of a contract, a legal obligation, or its legitimate interest in providing a secure and reliable service.
6. Local storage, backend and retention
Local Chrome storage
For troubleshooting, the extension stores technical log entries in chrome.storage.local. The current version keeps up to 500 entries and then overwrites the oldest entry. Log entries may contain form values and technical request information. They remain locally in the Chrome profile until overwritten, the extension's data is cleared, or the extension is removed.
Backend and Power Automate
The current Ideal Shift backend forwards the information needed for processing and does not intentionally write EPR content to a separate Ideal Shift database. Hosting and workflow services may retain technical logs, error information and run history. Specific retention periods depend on the configuration and agreements with the healthcare organisation and are not set for longer than necessary for the agreed purpose or a legal obligation.
The healthcare organisation determines retention periods for information stored in its EPR or Microsoft environment.
8. Security
We use technical and organisational safeguards appropriate to the risk, including encrypted transmission over HTTPS, limiting transmitted fields and field lengths, access restrictions, secure storage of technical secrets, and security and troubleshooting logs. No method is completely risk-free, so safeguards are periodically reviewed and adjusted where needed.
10. Your privacy rights
Depending on applicable law, individuals may have rights of access, rectification, erasure, restriction, objection and data portability. Because the healthcare organisation is generally responsible for EPR data, requests relating to patient or record data should first be submitted directly to that organisation. Ideal Shift assists the healthcare organisation where contractually and legally required.
For questions about processing for which Ideal Shift is responsible, contact privacy@idealshift.ai. You also have the right to lodge a complaint with the Dutch Data Protection Authority or another competent supervisory authority.
11. Changes to this policy
We may update this policy when the extension, technical setup or applicable law changes. The current version and revision date will always be published on this page. We will notify customers through an appropriate channel if changes are material.
12. Contact
Ideal Shift AI
Website: idealshift.ai
Privacy enquiries: privacy@idealshift.ai