User accounts and access
Match approved users to the staff directory, authenticate sessions, assign permissions, review account status, and support users.
Blood Bank Hub · Pilot
How the Blood Bank Hub controlled staff pilot handles account, workforce, operational, communication, quality, and audit information.
Information is used to provide, secure, and support the approved pilot workflows.
Personal information is not sold and is not used for third-party advertising.
Access is limited by account status, role, permission, and operational need.
01 · Scope
Blood Bank Hub is a controlled internal staff pilot. This policy explains what information the pilot may handle, why it is used, who may access it, and the choices available to users.
The pilot supports workforce coordination and approved quality and operational workflows. It is not designed as a public social network, an advertising service, or a system for patient clinical records.
02 · Information handled
The categories below mirror the data types disclosed for Blood Bank Hub in App Store Connect. Depending on a user’s role and enabled workflows, not every category will apply to every user. These categories may be linked to the user’s account, are used for App Functionality, and are not used for tracking.
| Declared data type | Examples in Blood Bank Hub | Primary purpose |
|---|---|---|
| Name | Full name shown in the approved staff account and directory. | Identity matching, staff coordination, and workflow attribution. App Functionality |
| Email Address | Work or account email used for sign-in, account administration, and service communication. | Authentication, account support, and operational communication. App Functionality |
| Phone Number | Mobile number included in the staff profile where authorized. | Staff contact and account support. App Functionality |
| Emails or Text Messages | Operational messages, announcements, handover notes, acknowledgements, and related communication content entered in enabled workflows. | Staff communication and operational coordination. App Functionality |
| Photos or Videos | Permitted photos or media submitted as quality, incident, statement, or workflow attachments. Patient imagery must not be submitted. | Documenting and reviewing authorized operational workflows. App Functionality |
| Other User Content | Leave reasons, shift-swap details, comments, quality records, incident/CAPA descriptions, statements, inventory notes, attachments, and other content users submit. | Completing approved staff, quality, and operations workflows. App Functionality |
| User ID | Account identifier and identifiers used to connect an approved user to the staff directory and their actions. | Authentication, authorization, and reliable record attribution. App Functionality |
| Other Usage Data | Access events, acknowledgements, workflow actions, timestamps, status changes, and audit activity. | Security, accountability, troubleshooting, and audit integrity. App Functionality |
| Other Data | Employee number, National ID, unit, job title, role, leave/work group, approval status, active status, and related workforce or operational metadata. | Directory matching, role-based access, workforce coordination, and administration. App Functionality |
Information may be provided directly by users through registration, profile fields, forms, messages, comments, and permitted uploads. Authorized administrators may also add or import approved staff-directory, schedule, inventory, quality, or operational records. Account IDs, access events, timestamps, status changes, and audit activity are generated automatically when the service is used.
Core identity, account, directory, role, and security information is required to approve an account and provide authorized access. Other information—such as a mobile number, comments, photos, videos, or attachments—may be optional unless a particular approved workflow requires it. Choosing not to provide optional information may limit the related feature without affecting unrelated features.
03 · How information is used
Blood Bank Hub uses information only as reasonably necessary to operate, secure, and support the pilot and its enabled modules.
Match approved users to the staff directory, authenticate sessions, assign permissions, review account status, and support users.
Support quality records, KPI inputs and outputs, follow-up actions, attachments, review status, and accountable approvals.
Deliver announcements, operational messages, handovers, acknowledgements, comments, and related internal communication.
Publish schedules and duty hours, coordinate leave and shift swaps, record revisions, and support day-to-day workforce planning.
Where enabled, record inventory status, near-expiry information, component-processing notes, adjustments, and accountable operational actions.
Document incidents, investigation details, root causes, corrective and preventive actions, responsible users, due dates, evidence, and closure.
Record significant access and workflow events to protect the service, support review, investigate misuse, and preserve accountability.
Troubleshoot errors, respond to support requests, maintain continuity, and improve the approved pilot experience.
Information is processed as needed to provide requested account and pilot functionality, administer approved workforce and operational activities, protect the service and its users, preserve quality and audit integrity, and meet applicable legal or recordkeeping obligations. Where a genuinely optional feature relies on consent, that consent may be withdrawn for future processing, subject to records that must be retained for another valid reason.
04 · Information that must not be submitted
Blood Bank Hub is not intended to store patient identifiers, medical record numbers, test results, diagnoses, treatment information, or other patient clinical data. Users must not enter or upload that information to the pilot, including within free-text fields, photos, videos, or attachments.
The pilot does not use personal information for advertising or cross-app tracking. It is not intended to collect precise location, personal contacts, purchase history, browsing history, search history, payment information, or health and fitness data.
05 · Access and sharing
Access is controlled through authenticated accounts, approval status, roles, and permissions. Regular users do not receive unrestricted access to administrative information. Supervisory or administrative users receive only the access configured for their responsibilities.
Blood Bank Hub does not sell personal information. Information may be available to authorized pilot users and service providers only when needed to operate, secure, maintain, or support the service, or when disclosure is required by applicable law.
06 · Service providers
Supabase supports authentication, database, and storage functions for the application. Cloudflare is used to deliver and secure this public privacy page and its custom domain. These providers may process limited technical information as needed to provide their services and are subject to their own contractual and security obligations.
Service providers may process information in locations where they operate. Any cross-border processing is subject to applicable transfer requirements and appropriate contractual, organizational, and technical safeguards. This policy does not claim that all pilot information is stored in a single country.
This public page contains no advertising or analytics script and does not intentionally set advertising cookies. Cloudflare may process standard request and security information to deliver and protect the page. No advertising network or cross-app tracking service is used for the purposes described in this policy.
07 · Retention
Information is retained for the period reasonably needed to operate and evaluate the pilot, complete active workflows, maintain operational and audit integrity, protect the service, resolve disputes, and meet approved legal or recordkeeping requirements.
Retention periods vary by record type and are determined by the approved purpose, the status of the related workflow, the need to preserve an accurate audit history, and applicable retention requirements. Account and profile information is reviewed when access ends; active operational records remain available while their workflow or follow-up is open; and audit, security, and finalized quality records may be kept longer to preserve integrity and accountability.
Deactivating an account or requesting deletion does not automatically remove records that must be preserved for audit, security, workflow integrity, or legal reasons. When information is no longer required, it is deleted, securely destroyed, or de-identified through an approved process.
08 · Security
The pilot uses authenticated accounts, role-based permissions, restricted administrative fields, and audit controls designed to reduce unauthorized access, alteration, or disclosure. Access may be reviewed, limited, suspended, or removed when necessary to protect the service.
No system can guarantee absolute security. Users must protect their credentials, use only their own account, and avoid sharing pilot information with unauthorized persons.
09 · Choices and rights
Subject to applicable requirements and appropriate identity verification, users may ask to be informed about processing, request access to and a readable copy of their personal information, request correction of inaccurate information, or request destruction of eligible information when it is no longer needed. Some profile fields may be available for self-service updates; administrator-controlled fields require an authorized review.
Deletion requests are assessed against operational, audit, security, and legal retention requirements. A valid request may therefore result in account deactivation, deletion of eligible data, or restriction and retention of records that cannot yet be removed.
We aim to respond to a verified rights request within 30 days. If an additional period is permitted and reasonably necessary, the requester will be informed in advance of the extension and the reason. Where consent is the basis for an optional activity, users may withdraw it for future processing.
If a privacy concern is not resolved through the contact below, the user may submit a complaint through the official channel of the competent data protection authority.
10 · Children
Blood Bank Hub is a workforce pilot intended for authorized staff users. It is not directed to children and does not knowingly solicit information from children.
11 · Policy changes
This policy may be updated as the pilot, its enabled modules, hosting, or distribution model changes. The current version will remain available at this address, with the effective date shown at the top of the page. Material changes may also be communicated through the app or another appropriate channel.
12 · Contact
Contact the Blood Bank Hub pilot team for privacy questions, access or correction requests, or eligible account and data deletion requests. Please do not include passwords, National ID numbers, patient information, or other unnecessary sensitive details in your first message.
Account, data, and privacy support