> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sigmahmis.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Sigma Health HMIS Privacy Policy and Data Practices

> Sigma Health HMIS collects account info, clinical data, and anonymised telemetry — learn how each is used, our cookie policy, and your data rights.

Sigma Health is committed to protecting clinic and patient privacy in everything we build and operate. This page summarises the key points of our Privacy Policy in plain language so you can understand exactly how your data is handled. The full, authoritative Privacy Policy is available at [sigmahmis.com/privacy](https://sigmahmis.com/privacy).

## What We Collect

Sigma collects three categories of data when you use the platform:

<CardGroup cols={3}>
  <Card title="Account & Contact Information" icon="user">
    Clinic name, administrator email address, country of operation, and other details provided during registration or account management. This data is used to create and maintain your account.
  </Card>

  <Card title="Clinical & Operational Data" icon="hospital">
    Billing records, insurance claims, payment reconciliation entries, and related health information that your team enters into the platform. **This is your data.** Sigma processes it solely on your behalf and has no ownership claim over it.
  </Card>

  <Card title="System Diagnostics & Telemetry" icon="chart-line">
    Anonymised technical signals such as page load times, error rates, and feature usage patterns. This data contains no personally identifiable information and is used exclusively to improve platform performance and reliability.
  </Card>
</CardGroup>

## How We Use Your Data

Sigma uses the data described above for the following purposes only:

<Steps>
  <Step title="Delivering and operating the service">
    Your account and operational data powers every feature of Sigma HMIS — from generating invoices and submitting claims to matching remittance payments. Without it, the service cannot function.
  </Step>

  <Step title="Security and compliance auditing">
    Access logs, authentication records, and system events are retained to detect threats, investigate incidents, and demonstrate compliance with applicable regulations.
  </Step>

  <Step title="Customer communications">
    Sigma uses your contact information to send support responses, product update notices, scheduled maintenance alerts, and material policy change notifications. You will not receive marketing communications unless you opt in separately.
  </Step>

  <Step title="System performance optimisation">
    Anonymised telemetry helps our engineering team identify slow queries, high-error workflows, and under-performing features so we can ship improvements that directly benefit your clinic.
  </Step>
</Steps>

Sigma does not sell, rent, trade, or license your data to any third party for commercial or marketing purposes — ever.

## Cookies

Sigma HMIS uses a minimal and purposeful cookie policy:

<Accordion title="Essential Cookies (Required)">
  Essential cookies are required for the platform to function. They handle authentication tokens, session security, and CSRF protection. These cookies cannot be disabled — without them, you cannot log in or use the platform. They contain no personally identifiable information beyond what is needed to maintain a secure session.
</Accordion>

<Accordion title="Aggregate Analytics Cookies (Optional)">
  Sigma may use anonymised, aggregate analytics cookies to understand broad usage patterns — for example, which parts of the platform are most commonly accessed. These cookies do not track individual behaviour and are not linked to your identity. They contain no third-party advertising trackers, retargeting pixels, or cross-site tracking mechanisms of any kind.
</Accordion>

<Note>
  Sigma HMIS does not use third-party advertising cookies, social media trackers, or any cookie that shares your activity with external advertising networks.
</Note>

## Data Security

All data stored in Sigma HMIS is encrypted with AES-256 at rest. All data transmitted between your device and our servers is protected by TLS 1.3 in transit. Access to your data is gated by strict role-based access control (RBAC) at every layer of the application.

For a complete breakdown of our security architecture — including tenant isolation, backup rotation, sub-processors, and international transfer safeguards — see the [Data Security and Privacy](/security/data-security) page.

## Policy Updates

Sigma will notify you of any material changes to this Privacy Policy at least **30 days before** the changes take effect. Notification will be delivered via email to your registered administrator address, an in-app banner visible to all administrators, or both. If you continue using the platform after the effective date of a change, you are considered to have accepted the updated policy.

For minor, non-material updates (such as clarifications or formatting corrections), Sigma may update the policy without advance notice. The "last updated" date on the full policy page will always reflect the most recent revision.

## Contact

If you have questions about this Privacy Policy, wish to exercise a data right, or want to request a list of current sub-processors, contact Sigma's Data Protection team:

**Email:** [privacy@sigmaconnect.org](mailto:privacy@sigmaconnect.org)
**Organisation:** Sigma Health Technologies Inc., Data Protection Office

<Note>
  This page is a plain-language summary intended to help you understand our practices quickly. The authoritative Privacy Policy — which governs your legal relationship with Sigma — is published at [sigmahmis.com/privacy](https://sigmahmis.com/privacy). In the event of any conflict between this summary and the full policy, the full policy prevails.
</Note>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.