Imaging International LLC ("the Company," "we," "us") provides remote diagnostic radiology reporting services (teleradiology) to healthcare institutions outside the United States. This policy describes how we handle personal data in connection with that work, and our commitment to the EU-U.S. Data Privacy Framework (DPF).
The Company's sole business activity is the professional interpretation of diagnostic radiology images (conventional skeletal radiography) on behalf of contracted healthcare institutions in the European Union. This work is performed by accessing the institution's own picture archiving and communication system (PACS) and radiology information system (RIS) remotely, over an encrypted connection. We do not develop, license, or sell any software, technology product, or data service.
Personal data processed in connection with our services consists of patient-identifiable diagnostic imaging data and associated clinical metadata (e.g., patient name, date of birth, clinical history relevant to the examination). This data is provided to us by, and remains the property of, the contracting healthcare institution, which acts as the data controller. The Company acts solely as a data processor for the limited purpose of producing a diagnostic report.
Because the Company does not collect personal data directly from individuals, and does not use personal data for any purpose beyond the diagnostic reporting service requested by the data controller, individuals' choice regarding use and disclosure of their data is exercised through the data controller (the contracting healthcare institution), in accordance with that institution's own privacy notices and applicable law (including the EU General Data Protection Regulation).
The Company does not transfer personal data onward to any third party. The only transmission of data occurs when the Company returns a completed diagnostic report to the contracting healthcare institution that supplied the underlying images, through the same secure channel by which the data was accessed.
Access to clinical data occurs exclusively through an encrypted virtual private network (VPN) connection into the data controller's own secured environment. The Company does not store, cache, download, or retain copies of clinical data on its own equipment at any point. Access credentials are subject to periodic mandatory rotation as required by the data controller's IT security policies.
Personal data is used solely for the purpose for which it was made available: the interpretation of a specific diagnostic imaging examination and the production of a corresponding clinical report. No data is repurposed, aggregated, or used for any secondary purpose, including research, marketing, or analytics.
Because the Company does not independently store personal data, requests for access, correction, or deletion of personal data should be directed to the relevant data controller (the contracting healthcare institution). The Company will provide reasonable assistance to the data controller in responding to such requests where necessary.
The Company commits to comply with the EU-U.S. Data Privacy Framework Principles with respect to personal data received from the European Union in reliance on the DPF. In compliance with the DPF Principles, the Company commits to resolve DPF Principles-related complaints about our collection and use of personal data. EU individuals with inquiries or complaints regarding our handling of personal data received in reliance on the DPF should first contact us at the address below.
The Company has further committed to refer unresolved DPF Principles-related complaints to an independent dispute resolution mechanism operated by the panel of European Data Protection Authorities (DPAs). If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact or visit dataprivacyframework.gov for more information and to file a complaint. This service is provided at no cost to you.
The Federal Trade Commission has jurisdiction over the Company's compliance with the DPF.
Imaging International LLC
3580 16th Street
Boulder, Colorado, USA
Email: jonas.rydberg@mac.com