Privacy Policy
1. Who we are
WeCoMed is an application for healthcare professionals, developed and operated by WECOAP CO., LTD. ("WeCoAp", "we", "us"). This policy explains what personal data we collect, what we use it for, who we share it with and what rights you have over it.
WeCoMed is not a medical records application. It does not collect, store or process patient health data. The data in WeCoMed is the user's own professional data: professional profile, medical event attendance history and continuing medical education (CME) credits.
2. Your organisation's role
WeCoMed accounts are issued through a medical organisation — a professional association, hospital or training provider ("organisation"). Each organisation has its own isolated data space in the system.
- Your organisation determines the purposes of most activity data (events, check-ins, evidence, CME credits) and is the controller of that data.
- WeCoAp processes that data on the organisation's behalf under a service agreement, and is the controller for account data, security data and the technical logs needed to run the platform.
Your organisation's administrators can view your professional profile, attendance history, evidence and CME credits within that organisation. If you wish to complain about how your organisation uses your data, please contact its administrators directly; we will assist where needed.
3. Data we collect
3.1. Account and professional profile
Provided by you or your organisation:
- Full name, phone number, email address
- Date of birth
- Academic title, specialty, workplace
- Practice licence number
- Biography, profile photo
- Self-declared education and work experience
- Role and account status within the organisation
3.2. Professional activity data
- Event registrations, waitlist entries and approval status
- Check-in and check-out history per session, with timestamps
- Attendance evidence you upload (images, PDF, office documents)
- Accumulated CME credits and WeCo points, with their history
3.3. NFC card data
- Card identifier, card type, activation status and card-to-account link
- Card write and lock operation history
Card protection keys are managed per card and are never shown to end users.
3.4. Location data
The app reads your location only at the moment you tap check in, and only when the event organiser has enabled geofence verification. The location is used to verify that you are within the event area.
- WeCoMed does not track location in the background.
- WeCoMed does not build a movement history.
- You may decline the location permission; you then need to use another check-in method.
3.5. Device and session data
- An app-generated device identifier, platform and OS version
- App version
- Last sign-in time and the list of active sessions
- Push notification token (if you enable notifications)
This powers the "Session management" screen, which lets you spot and sign out unfamiliar devices.
3.6. Technical logs
Our servers record IP address, timestamp, the API path called and error codes, in order to detect faults and abuse. Logs are stored separately from business data.
3.7. Data we do NOT collect
- Patient records, diagnoses or any patient health data
- Biometric data — see section 4
- Payment details from individual users; the app contains no in-app purchases
- Data for advertising, ad measurement or marketing profiling
- Your contacts, messages or browsing history
We do not sell personal data to anyone.
4. Device permissions
| Permission | What it is used for | Required? |
|---|---|---|
| Camera | Scanning QR codes to check in; photographing attendance evidence | No — requested only when you use the feature |
| Photo library | Choosing a profile photo and evidence files | No |
| NFC | Reading and writing NFC doctor cards to check in, activate and lock | No |
| Location (while using the app) | Verifying you are within the event area at check-in | No — only when the organiser enables geofencing |
| Face ID / fingerprint | Unlocking sign-in credentials stored securely on the device | No |
| Calendar | Adding events you register for to your device calendar | No |
| Notifications | Event reminders, evidence approval and CME credit notifications | No |
About biometrics: when you enable Face ID or fingerprint sign-in, the match is performed entirely on-device by iOS/Android. The app receives only a success/failure result, which unlocks credentials held in the device's secure storage (Keychain / Keystore). Your face or fingerprint data is never sent to or stored on our servers.
5. Purposes and legal bases
We process personal data under Decree 13/2023/ND-CP on personal data protection and other applicable Vietnamese law.
| Purpose | Data | Basis |
|---|---|---|
| Creating and running your account, OTP authentication | Account, device | Performance of the service agreement |
| Recording event attendance and CME credits | Activity, evidence, NFC card | Performance of contract; organisation requirement |
| Geofence verification at check-in | Location at the time of check-in | Your consent (via the system permission) |
| Account security, check-in fraud prevention | Device, session, logs | Legitimate interest in system integrity |
| User support | Information you provide when contacting us | Performance of contract |
| In-app AI assistant | The text you type into the chat box | Your consent by actively using the feature |
6. Data sharing
Your data is shared with:
- Your organisation — administrators and event coordinators, within that organisation only.
- Infrastructure providers — hosting and file storage services running WeCoMed, processing data under contract and only on our instructions.
- Google LLC — when you use the AI assistant (see section 7).
- Competent state authorities — on a lawful request under applicable law.
Profile content you deliberately share publicly (for example via an NFC card or a profile link) is visible to whoever holds that link. You control this sharing in the app.
7. AI assistant
The app includes a question-and-answer assistant powered by Google Gemini, a service of Google LLC. When you send the assistant a message:
- The message and that session's conversation history are sent to Google's servers to generate a reply.
- Google's processing is governed by Google's terms of service and privacy policy.
- We do not send your professional profile, check-in data or identity along with the message.
Do not enter patient information or sensitive data into the AI chat. The assistant's answers are informational guidance about using the app and are not medical advice, diagnosis or treatment recommendations.
8. Retention
| Data type | Retention period |
|---|---|
| Account and professional profile | While the account remains active |
| Attendance history and CME credits | As required by your organisation's retention policy — typically to substantiate continuing-education certification |
| Evidence files | Per the organisation's policy, at most as long as the CME record |
| Sessions and push tokens | Until you sign out or the session expires |
| Technical logs | Up to 12 months |
| Data after account deletion | See section 11 |
9. Security
- All traffic between the app and our servers is encrypted with TLS.
- On-device credentials are held in the operating system's secure storage (iOS Keychain / Android Keystore), never in plain storage.
- Data access is role-based; each organisation's data sits in a separate space.
- Evidence files are served through short-lived signed links.
- Each backend service connects to the database with its own least-privilege account.
No system is perfectly secure. If an incident affects your personal data, we will notify you and the competent authorities as required by law.
10. Your rights
Under Decree 13/2023/ND-CP you have the right to:
- Be informed about the processing of your personal data
- Give or withhold consent to processing
- Access, view and request a copy of your data
- Request correction of inaccurate data
- Withdraw consent previously given
- Request deletion of your data
- Request restriction of, or object to, processing
- Complain, denounce, litigate and claim damages as provided by law
You can edit your profile yourself in the app. For other requests, email privacy@wecoap.com from your registered address. We respond within 72 working hours and complete requests within 30 days at the latest.
11. Account and data deletion
You can request deletion of your WeCoMed account at any time, either inside the app or through our website — no reinstall required.
That page details exactly which data is deleted, which data is retained under legal obligations, and the timelines involved.
12. Children
WeCoMed is a professional tool for healthcare workers and medical students aged 18 or over. We do not knowingly collect children's data. If we find an account belonging to someone under 18, we will lock and delete it. If you believe your child has provided us with data, contact privacy@wecoap.com.
13. International transfers
WeCoMed business data is stored and processed primarily in Vietnam. The AI assistant feature is the exception: it sends conversation content to Google LLC infrastructure, which may sit outside Vietnam. If you would rather your data was not processed abroad, simply do not use the AI assistant — every other feature works normally.
14. Changes to this policy
When we update this policy we change the "Last updated" date at the top of the page. For material changes affecting your rights, we notify you in the app or by email at least 15 days in advance.
15. Contact
- Data controller
- WECOAP CO., LTD. — Tax code 0319463820
- Privacy & data
- privacy@wecoap.com
- General support
- support@wecoap.com
- Phone
- +84 345 240 627
- Address
- 88/4S, Hamlet 58, Ba Diem Commune, Ho Chi Minh City, Vietnam