Privacy Notice
This Privacy Notice explains how Team OPS Inc. dba MYCURE (“MYCURE,” “we,” “us,” or “our”) processes personal data in connection with our websites, MYCURE CMS, patient-facing features, applications, integrations, support services, and related services.
Effective Date: August 11, 2026
This Privacy Notice should be read together with our Terms of Service, Security Overview, Subprocessor List, and any applicable Order Form, Data Processing Agreement, Business Associate Agreement, service agreement, or other written agreement.
Where a written agreement contains more specific privacy or data-processing terms, that agreement applies to the extent provided in that agreement.
1. Scope
This Privacy Notice applies to personal data processed in connection with MYCURE, including information relating to:
- •Customers;
- •Authorized Users;
- •patients and Patient Users;
- •Customer representatives;
- •website visitors;
- •prospective Customers;
- •support contacts; and
- •other individuals who interact with MYCURE.
For purposes of this Privacy Notice:
Customer means a clinic, healthcare organization, practice, company, or other entity that subscribes to, deploys, or uses MYCURE CMS or related services.
Authorized User means a physician, dentist, nurse, healthcare professional, employee, contractor, administrator, or other person authorized by a Customer to access MYCURE CMS.
Customer Data means information submitted to, stored in, transmitted through, generated through, or otherwise processed through MYCURE CMS for or on behalf of a Customer, including patient and clinical information.
Patient Data means personal data relating to a patient, including health, clinical, appointment, billing, communication, and care-related information.
Service Administration Data means personal data that MYCURE processes for its own legitimate business and service-administration purposes, such as account administration, authentication and security, Customer relationship management, billing, contractual administration, support administration, legal compliance, and permitted business communications.
This Privacy Notice does not replace a Customer's own privacy notice, patient notice, consent form, medical-record policy, or other legal obligation.
2. Our Role in Processing Personal Data
MYCURE may process different personal data in different legal capacities depending on the information, purpose, Customer relationship, deployment model, and applicable law.
Customer Data
For Patient Data and other Customer Data that a Customer submits to or processes through MYCURE CMS, the Customer generally determines why and how that information is processed.
In this context, the Customer generally acts as the data controller, personal information controller, healthcare provider, record custodian, or equivalent responsible party under applicable law.
MYCURE generally processes that Customer Data on behalf of the Customer as a data processor, personal information processor, service provider, or equivalent processing role.
MYCURE processes such Customer Data in accordance with the applicable Customer agreement, Customer instructions, configuration and use of MYCURE CMS, and applicable law.
Data Controlled by MYCURE
MYCURE may separately determine the purposes and means of processing Service Administration Data and other information relating to its own business operations.
This may include personal data used for:
- •account and Customer administration;
- •authentication and account security;
- •fraud and misuse prevention;
- •service administration;
- •billing and contractual administration;
- •business-contact management;
- •support administration;
- •legal and regulatory compliance;
- •security monitoring;
- •communications with Customer personnel; and
- •permitted sales, product, and business communications.
The same information may be processed in different capacities for different purposes.
For example, an Authorized User's email address may be processed on behalf of the Customer for access to MYCURE CMS while also being processed by MYCURE for security, account administration, or contractual communications.
3. Information We Process
Depending on the services used and the applicable relationship, we may process the following categories of information.
3.1 Customer and Account Information
This may include:
- •name;
- •work email address;
- •telephone number;
- •organization or clinic name;
- •position, role, or department;
- •account information;
- •user roles and permissions;
- •authentication and account-security information;
- •preferences and settings;
- •billing and contractual information; and
- •communications with MYCURE.
3.2 Patient and Clinical Information
When Customers use MYCURE CMS for healthcare or clinic operations, Customer Data may include:
- •patient identifiers and demographic information;
- •contact information;
- •appointments and visits;
- •medical history;
- •clinical notes;
- •diagnoses and assessments;
- •examination findings;
- •vital signs;
- •allergies;
- •medications and prescriptions;
- •treatment plans and procedures;
- •laboratory and diagnostic information;
- •imaging information;
- •dental information;
- •pharmacy information;
- •medical certificates;
- •referrals;
- •attachments and clinical documents;
- •billing, HMO, insurance, or claims-related information;
- •occupational-health information;
- •patient communications;
- •consent or representative information; and
- •other information entered into or generated through MYCURE CMS.
Patient and clinical information may constitute sensitive, special-category, protected, or otherwise regulated personal data under applicable law.
3.3 Patient-Facing Features
Where patient-facing functionality is enabled, MYCURE CMS may process information such as:
- •account-registration information;
- •appointment requests;
- •forms;
- •messages;
- •uploaded files and documents;
- •account and portal activity;
- •billing-related information;
- •representative, parent, guardian, or caregiver information; and
- •other information submitted through the applicable functionality.
3.4 Billing and Business Information
MYCURE may process information such as:
- •billing contact details;
- •subscription or service information;
- •invoices;
- •payment status;
- •transaction records;
- •tax or business registration information; and
- •related commercial records.
Where payment services are provided through an external provider, payment information may also be processed by that provider under the applicable arrangement.
3.5 Technical and Security Information
Depending on the service and deployment, MYCURE may process:
- •IP addresses;
- •browser and device information;
- •operating-system information;
- •authentication events;
- •access and session information;
- •timestamps;
- •application activity;
- •error information;
- •system and security events;
- •performance and diagnostic information; and
- •other information reasonably necessary for operation, security, troubleshooting, and service administration.
3.6 Support Information
If you or a Customer contacts MYCURE for support, onboarding, implementation, training, security, or another inquiry, we may process:
- •contact information;
- •organization information;
- •support-request information;
- •communications;
- •screenshots, attachments, files, or logs supplied to us; and
- •other information reasonably necessary to address the request.
Customers and users should avoid including Patient Data or other sensitive Customer Data in support communications unless reasonably necessary for the applicable support issue.
4. How We Obtain Information
Depending on the context, information may be provided or generated:
- •directly by you;
- •by a Customer or Authorized User;
- •by a patient or authorized representative;
- •through use of MYCURE CMS;
- •through our websites;
- •through devices or systems accessing the services;
- •through Customer-authorized integrations;
- •through service providers;
- •through business communications; or
- •through other lawful sources relevant to the applicable relationship.
5. How We Process Information
Customer Data
Where MYCURE processes Customer Data on behalf of a Customer, processing may include activities reasonably necessary to:
- •provide and operate MYCURE CMS;
- •store and retrieve Customer Data;
- •provide enabled functionality;
- •authenticate users;
- •secure the service;
- •provide support;
- •troubleshoot problems;
- •maintain and update the service;
- •perform backup and recovery;
- •respond to security incidents;
- •transmit information through Customer-authorized integrations;
- •perform Customer instructions; and
- •comply with obligations imposed by applicable law.
The Customer remains responsible for determining the purposes and lawful basis for its processing of Customer Data, including Patient Data, and for providing notices or obtaining consent or other authorization where required.
MYCURE-Controlled Data
Where MYCURE determines the purposes and means of processing, we may process personal data for purposes such as:
- •establishing and administering Customer relationships;
- •managing accounts;
- •authenticating users;
- •maintaining security;
- •preventing fraud and misuse;
- •managing subscriptions, billing, and contracts;
- •responding to inquiries;
- •providing Customer support;
- •administering our websites and services;
- •complying with law;
- •maintaining business and accounting records;
- •establishing, exercising, or defending legal rights;
- •communicating service or security information; and
- •conducting permitted business and marketing communications.
6. Lawful Bases
The lawful basis for processing depends on the applicable jurisdiction and context.
Where MYCURE acts as the controller or equivalent responsible party, processing may be based on grounds available under applicable law, which may include:
- •performance of a contract;
- •steps taken in connection with entering into a contract;
- •compliance with legal obligations;
- •legitimate interests where recognized and applicable;
- •consent where required;
- •protection of vital interests where applicable; or
- •another lawful basis available under applicable law.
Where MYCURE processes Customer Data on behalf of a Customer, the Customer is generally responsible for establishing the lawful basis for that processing.
Nothing in this Privacy Notice means that consent is required for every processing activity.
8. Artificial Intelligence and Automated Features
MYCURE may introduce AI-assisted, machine-learning, automation, or similar functionality as MYCURE CMS evolves.
The introduction of such functionality does not by itself authorize an external AI provider to process Customer Data.
Where a third-party AI or large-language-model provider will process Customer Data on MYCURE's behalf, MYCURE will address applicable Customer instructions or authorization, Subprocessor requirements, privacy and security review, and other requirements under the applicable agreement and law before or in connection with that processing.
Current material external Subprocessors are identified in our Subprocessor List.
Unless otherwise expressly authorized through an applicable Customer agreement or documented instruction, MYCURE does not authorize identifiable production Customer Data to be used to train general-purpose third-party AI or large-language models.
AI-assisted functionality is not a substitute for professional medical judgment. Customers and healthcare professionals remain responsible for reviewing information used for clinical, professional, or regulated purposes.
9. Aggregated, Statistical, and De-Identified Information
Where permitted by applicable law and the applicable Customer agreement or instructions, MYCURE may generate aggregated, statistical, or de-identified information for legitimate purposes such as:
- •service operation;
- •reliability and performance;
- •security;
- •capacity planning;
- •product and service analysis; and
- •development and improvement.
Information treated as de-identified or anonymized for these purposes must not identify an individual where applicable law requires that status.
MYCURE does not treat identifiable Patient Data as anonymized merely because direct identifiers have been removed where the information remains reasonably capable of being linked to an individual.
10. Data Retention
Retention depends on the type of information, MYCURE's role in processing it, the applicable Customer agreement, Customer instructions, legal requirements, operational requirements, and applicable law.
Customer Data
Customers are responsible for determining the retention requirements applicable to their medical records and other regulated records.
Export, return, archival, retention, backup, and deletion of Customer Data following expiration or termination of MYCURE CMS are governed by the applicable Customer agreement and Service terms.
Deletion from active systems may not result in immediate deletion of residual information contained in ordinary backup cycles or information that must lawfully be preserved.
MYCURE-Controlled Data
MYCURE retains Service Administration Data and other information processed for its own purposes for as long as reasonably necessary for the applicable business, contractual, security, legal, accounting, dispute-resolution, or compliance purpose, subject to applicable law.
11. Security
MYCURE maintains reasonable technical and organizational safeguards appropriate to the nature of the service, information, deployment model, and reasonably foreseeable risks.
These may include measures concerning:
- •authentication;
- •access control;
- •encryption;
- •logging;
- •monitoring;
- •backups;
- •personnel access;
- •incident response; and
- •other applicable security controls.
No information system or security control can eliminate all risk, and MYCURE does not represent that unauthorized access, security incidents, vulnerabilities, or service interruptions can never occur.
Customers remain responsible for matters under their control, including their:
- •Authorized Users;
- •roles and permissions;
- •passwords and authentication factors;
- •email accounts;
- •devices;
- •networks;
- •exported information;
- •third-party integrations; and
- •other Customer-controlled security matters.
More information is available in our:
Security Overview
https://mycure.md/security-overview
12. MYCURE Personnel and Support Access
Access to production Customer Data by MYCURE personnel is restricted to authorized personnel with an appropriate operational need.
Such access may occur where reasonably necessary for:
- •support;
- •maintenance;
- •troubleshooting;
- •security;
- •incident investigation or response;
- •backup or recovery;
- •service administration;
- •compliance with applicable law; or
- •other activities necessary to provide the applicable service.
Support access does not make MYCURE the controller of Patient Data that MYCURE processes on behalf of a Customer.
13. Security Incidents and Personal Data Breaches
Where MYCURE processes Customer Data on behalf of a Customer and becomes aware of an applicable Security Incident or Personal Data Breach, MYCURE will provide notice and cooperation as required by the applicable Customer agreement and applicable law.
The Customer, as controller or equivalent responsible party for its Customer Data, generally remains responsible for determining and carrying out notifications to patients, data subjects, regulators, or other parties where that obligation rests with the Customer.
MYCURE remains responsible for any notification or other obligation imposed directly upon MYCURE by applicable law.
Where MYCURE acts as the controller of affected personal data, MYCURE will address notification obligations applicable to MYCURE in that capacity.
Security and privacy concerns relating to MYCURE may be reported to:
14. International Processing
MYCURE may serve Customers and users in multiple jurisdictions.
Personal data may therefore be processed or accessed in countries other than the country in which the Customer or individual is located, depending on:
- •deployment model;
- •Customer requirements;
- •hosting location;
- •enabled services;
- •Subprocessors;
- •support arrangements; and
- •applicable written agreements.
Where cross-border processing is subject to specific legal requirements, MYCURE and the applicable Customer will address the required safeguards, contractual mechanisms, instructions, or other measures as applicable to their respective roles.
Current material Subprocessors and applicable processing locations are identified in our:
Subprocessor List
https://mycure.md/subprocessors
MYCURE does not represent that MYCURE CMS is approved, certified, or legally suitable for every jurisdiction merely because it is technically accessible there.
Jurisdiction-specific requirements may be addressed through an Order Form, Data Processing Agreement, Business Associate Agreement, local terms, deployment arrangement, or other written agreement.
15. Children and Minor Patients
MYCURE CMS may process information relating to children or minor patients where used by healthcare Customers for authorized healthcare or related purposes.
Where such Patient Data is processed on behalf of a Customer, the Customer is generally responsible for determining:
- •the lawful basis for processing;
- •who may access the minor's information;
- •whether parental, guardian, representative, or other authorization is required; and
- •applicable healthcare and recordkeeping requirements.
MYCURE may apply reasonable identity, authorization, access, or security requirements to patient-facing functionality where appropriate.
16. Privacy Rights
Privacy rights vary by jurisdiction and depend on MYCURE's role in processing the applicable information.
Subject to applicable law, individuals may have rights relating to matters such as:
- •access;
- •correction;
- •deletion or erasure;
- •objection;
- •restriction;
- •portability;
- •withdrawal of consent where processing is based on consent; and
- •complaints to an applicable privacy or data-protection authority.
These rights may be subject to legal exceptions, verification requirements, medical-record retention requirements, contractual restrictions, or other limitations under applicable law.
Requests Concerning Customer or Patient Data
If a request concerns Patient Data or other Customer Data controlled by a clinic, healthcare organization, employer, insurer, or other Customer, the request should ordinarily be directed to that Customer.
MYCURE may refer or forward the request to the applicable Customer and may assist the Customer as required by applicable law and the applicable agreement.
Requests Concerning Data Controlled by MYCURE
For information for which MYCURE determines the purposes and means of processing, requests may be submitted to:
MYCURE may request reasonable information necessary to verify identity, authority, or the scope of a request.
17. Philippines
For processing subject to the Philippine Data Privacy Act of 2012, its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission, the legal roles and responsibilities of MYCURE and its Customers are determined according to the applicable processing activity and agreement.
For Customer Data processed through MYCURE CMS on behalf of a Philippine healthcare Customer, the Customer will generally act as the Personal Information Controller (PIC) and MYCURE as the Personal Information Processor (PIP).
MYCURE may separately act as a PIC for Service Administration Data and other personal data for which MYCURE independently determines the purposes and means of processing.
Philippine Customers may also have a separate Data Processing and Security Agreement or other written agreement governing MYCURE's processing of Customer Data. Where that agreement contains more specific terms, those terms apply according to the agreement's provisions.
Questions or privacy requests concerning processing for which MYCURE acts as PIC may be directed to:
Requests concerning Patient Data controlled by a Customer should ordinarily be directed to the applicable clinic, healthcare organization, or other Customer.
18. Marketing and Service Communications
MYCURE may send communications necessary or appropriate for:
- •account administration;
- •authentication;
- •security;
- •billing;
- •support;
- •service operation;
- •contractual administration; and
- •important service updates.
Where permitted by applicable law, MYCURE may also send product, business, educational, or marketing communications to appropriate Customer representatives, users, or business contacts.
Recipients may opt out of marketing communications through the mechanism provided in the communication or by contacting MYCURE.
Opting out of marketing communications does not prevent MYCURE from sending necessary account, security, billing, transactional, contractual, or service-related communications.
Identifiable Patient Data is not used for third-party advertising.
20. Third-Party Websites and Services
MYCURE websites or services may contain links to, or integrations with, services operated by third parties.
This Privacy Notice does not govern independent third-party services that are not operated by MYCURE.
Third parties may maintain their own terms, privacy notices, security practices, and processing arrangements.
21. Changes to This Privacy Notice
MYCURE may update this Privacy Notice from time to time to reflect changes in:
- •our services;
- •processing activities;
- •technology;
- •security practices;
- •legal or regulatory requirements; or
- •business operations.
The current version will be posted at:
https://mycure.md/privacy-policy
The effective date shown above indicates when the current version took effect.
Where applicable law or an applicable agreement requires additional notice or another mechanism for a material change, MYCURE will follow that requirement.
An update to this Privacy Notice does not by itself override a more specific obligation contained in an applicable written Customer agreement.
22. Relationship to Customer Agreements
This Privacy Notice describes MYCURE's general privacy practices.
It does not:
- •replace a Customer's own privacy obligations;
- •expand the purposes for which MYCURE may process Customer Data beyond applicable Customer instructions and agreements;
- •reduce protections specifically established in an applicable Data Processing Agreement or other written agreement; or
- •create a representation that MYCURE CMS complies with every law or regulatory framework in every jurisdiction.
Contractual rights, obligations, liability provisions, data-processing instructions, retention requirements, processing locations, and other Customer-specific requirements remain governed by the applicable written agreement and Terms of Service.
23. Contact
For privacy, data-protection, or security matters concerning MYCURE:
Team OPS Inc. dba MYCURE
201 Malayan Plaza
ADB Avenue corner Opal Road
Ortigas Business Center
Pasig City, Philippines 1600
Privacy & Security Contact:
privacy@mycure.md
If your inquiry concerns a medical record or Patient Data controlled by a Customer, you should ordinarily contact the applicable clinic, healthcare organization, or other Customer directly.