Role-Based Access
Users see information according to organization, tenant, facility, program, and workflow permissions.
This policy explains how Elix handles information across care, operations, supply chain, administration, laboratory, billing, and onboarding workflows.
Effective date: May 17, 2026
Protected by Elix Security
Privacy controls work with authentication, role-based access, audit trails, and customer governance.
Applies to
Web and mobile
Primary use
Secure operations
Access model
Role based
Related policy
Cookies
Privacy Summary
Users see information according to organization, tenant, facility, program, and workflow permissions.
Authentication, passkeys, audit trails, permissions, monitoring, and operational safeguards help protect access.
Elix supports clinical, administrative, laboratory, billing, reporting, inventory, onboarding, and supply-chain workflows.
This Privacy Policy explains how Elix handles information in its web and mobile applications, including care operations, administrative workflows, billing, reporting, communication, onboarding, inventory, investigations, and supply-chain activity.
Many users access Elix through an employer, facility, government program, payer, or other organization. In those cases, that organization may be the controller or primary decision-maker for information processed in Elix, and Elix may act as a service provider or processor.
Depending on your role and organization configuration, Elix may process user profile details, account identifiers, role and permission assignments, facility or program access, audit trails, device details, authentication events, support activity, and security logs.
The platform may also process patient, clinical, appointment, laboratory, imaging, pharmacy, billing, payer, claims, inventory, supply-chain, dispatch, driver, notification, and reporting data entered or connected by authorized users.
For mobile supply-chain workflows, the app may process barcode or QR scan events, dispatch status, proof-of-delivery activity, device push tokens, and location updates when location features are enabled for active operational assignments.
When passkeys are enabled, your device, browser, or operating system stores private passkey material. Elix stores the public credential record, credential identifier, relying-party information, and verification metadata needed to authenticate you.
Production passkeys are configured for app.elix.ng, with app.elixiq.ng available as an alias where configured. Passkeys created for a different development or staging domain may not work in production.
Elix uses information to authenticate users, authorize access, operate clinical and administrative workflows, support patient care and supply-chain operations, process transactions, send notifications, generate reports, secure the platform, troubleshoot issues, and improve reliability.
Audit and diagnostic information may also be used to detect abuse, investigate errors, maintain compliance records, measure system health, and support authorized customer administrators.
Information may be shared with authorized users inside your organization according to their role, facility, tenant, program, or workflow permissions.
Information may also be exchanged with configured integrations such as identity providers, payment processors, insurance systems, communication providers, laboratory or blood-bank systems, reporting tools, cloud infrastructure providers, and customer-authorized implementation partners.
We may disclose information when required by law, court order, regulator request, security investigation, or to protect users, patients, customers, Elix, or the public.
Elix uses essential cookies and similar technologies for sign-in, session security, preferences, diagnostics, and platform reliability.
The Cookie Policy explains cookie categories, daily privacy prompts, analytics preferences, and browser controls in more detail.
Elix uses administrative, technical, and organizational safeguards designed to protect information, including authentication controls, role-based permissions, audit trails, encryption where appropriate, infrastructure controls, monitoring, and operational security processes.
No system can be guaranteed completely secure. Users should protect their devices, avoid sharing credentials, report suspected compromise promptly, and follow organization security policies.
Retention periods depend on the type of data, customer agreement, legal obligations, clinical governance requirements, financial record rules, security needs, and organization configuration.
Your organization may determine retention and deletion instructions for patient, operational, staff, inventory, and transaction records held in the platform.
Depending on applicable law and your relationship with the organization using Elix, you may have rights to access, correct, export, restrict, or delete certain information.
For organization-controlled data, requests should usually be directed first to your employer, facility, program administrator, or the organization responsible for the record. Elix will support authorized requests according to applicable agreements and law.
Elix may process information about pediatric patients or other dependents when entered by authorized healthcare or administrative users. The platform is not intended for unsupervised use by children.
Patient rights, guardian access, consent, and disclosure rules are governed by applicable law and the policies of the responsible healthcare organization.
Elix infrastructure, vendors, support personnel, or customer administrators may process information in different locations depending on hosting configuration, service region, support needs, and customer agreement.
Where required, appropriate contractual or operational safeguards are used for cross-border processing.
We may update this Privacy Policy to reflect product, legal, operational, or security changes. The effective date will show when the policy was last updated.
For privacy questions, contact your organization administrator or use the official Elix support channel provided to your organization.
This policy is a default public baseline. Customer-specific privacy terms, data processing agreements, health information rules, facility policies, and local laws may provide additional requirements.