1. Scope
This policy covers the qldd.vn website and the QLDD Service that hospitals use at hospital-name.qldd.vn. For data in the Service, the hospital decides the purposes of processing (data controller); the QLDD development team processes data on the hospital's instructions, in line with Vietnam's Decree 13/2023/ND-CP on personal data protection.
2. Data we process
- Accounts: full name, username, role, assigned departments and a hashed password (argon2id – no one can read the original password).
- Healthcare staff records: staff code, full name, department, job title, position, qualification, work area, whether they hold a practising certificate, and phone number (if the hospital enters it).
- Operational data: checklist evaluations, ward-round minutes, daily staffing reports, periodic reports and commentary.
- Patient surveys: ratings, gender, respondent type (patient/relative), comments, and the names of the counselling nurse and supervisor – no patient names.
- Patients: the Service does not store patient names or direct identifiers; evaluations only have an optional medical-record number field for internal traceability.
- System logs: write/delete actions (who, when, before and after values) and IP addresses at sign-in and on actions.
3. Purposes
To provide the Service's features (scoring, analytics, reporting), authenticate users and enforce permissions, keep the system secure and auditable, and give technical support at the hospital's request. We do not sell data, use hospital data for advertising, or use it to train AI models.
4. Artificial intelligence
QLDD servers do not send hospital data to any AI service. The Word checklist import feature only provides a prompt; users decide whether to paste a checklist document (professional guidance, containing no personal data) into the AI assistant of their choice.
5. Hosting and processors
The Service, the qldd.vn website, the domain and the admin@qldd.vn mailbox run on Cloudflare infrastructure. Each hospital's data is accessed through that hospital's own address. We share data only at the hospital's request or when required by law.
6. How we protect data
- HTTPS only; the database is never exposed to the Internet.
- argon2id password hashing; short-lived sessions with hashed, rotating refresh tokens; accounts lock for 15 minutes after 5 failed sign-ins.
- Role- and department-scoped access enforced server-side; an audit trail of every write and delete.
- Automatic database backup before every version upgrade.
7. Retention
Data is kept while the hospital uses the Service. Evaluations and minutes deleted in the interface are soft-deleted to preserve auditability; staff who leave are marked inactive rather than erased. When a hospital stops using the Service, its data is handed over and deleted upon written request.
8. Your rights
Healthcare staff who wish to access, correct or delete their data should contact their hospital's administrator (the data controller); we help hospitals fulfil such requests. You may also write to admin@qldd.vn and we will forward your request to the hospital concerned.
9. Cookies
The qldd.vn website uses no cookies, analytics or third-party resources (fonts and icons are served from qldd.vn itself). The Service only uses strictly necessary HttpOnly cookies to keep you signed in.
10. Contact
Questions or data incidents: admin@qldd.vn, with a subject starting with “[Security]”.