Skip to main content
Sigma Health is committed to protecting clinic and patient privacy in everything we build and operate. This page summarises the key points of our Privacy Policy in plain language so you can understand exactly how your data is handled. The full, authoritative Privacy Policy is available at sigmahmis.com/privacy.

What We Collect

Sigma collects three categories of data when you use the platform:

Account & Contact Information

Clinic name, administrator email address, country of operation, and other details provided during registration or account management. This data is used to create and maintain your account.

Clinical & Operational Data

Billing records, insurance claims, payment reconciliation entries, and related health information that your team enters into the platform. This is your data. Sigma processes it solely on your behalf and has no ownership claim over it.

System Diagnostics & Telemetry

Anonymised technical signals such as page load times, error rates, and feature usage patterns. This data contains no personally identifiable information and is used exclusively to improve platform performance and reliability.

How We Use Your Data

Sigma uses the data described above for the following purposes only:
1

Delivering and operating the service

Your account and operational data powers every feature of Sigma HMIS — from generating invoices and submitting claims to matching remittance payments. Without it, the service cannot function.
2

Security and compliance auditing

Access logs, authentication records, and system events are retained to detect threats, investigate incidents, and demonstrate compliance with applicable regulations.
3

Customer communications

Sigma uses your contact information to send support responses, product update notices, scheduled maintenance alerts, and material policy change notifications. You will not receive marketing communications unless you opt in separately.
4

System performance optimisation

Anonymised telemetry helps our engineering team identify slow queries, high-error workflows, and under-performing features so we can ship improvements that directly benefit your clinic.
Sigma does not sell, rent, trade, or license your data to any third party for commercial or marketing purposes — ever.

Cookies

Sigma HMIS uses a minimal and purposeful cookie policy:
Essential cookies are required for the platform to function. They handle authentication tokens, session security, and CSRF protection. These cookies cannot be disabled — without them, you cannot log in or use the platform. They contain no personally identifiable information beyond what is needed to maintain a secure session.
Sigma may use anonymised, aggregate analytics cookies to understand broad usage patterns — for example, which parts of the platform are most commonly accessed. These cookies do not track individual behaviour and are not linked to your identity. They contain no third-party advertising trackers, retargeting pixels, or cross-site tracking mechanisms of any kind.
Sigma HMIS does not use third-party advertising cookies, social media trackers, or any cookie that shares your activity with external advertising networks.

Data Security

All data stored in Sigma HMIS is encrypted with AES-256 at rest. All data transmitted between your device and our servers is protected by TLS 1.3 in transit. Access to your data is gated by strict role-based access control (RBAC) at every layer of the application. For a complete breakdown of our security architecture — including tenant isolation, backup rotation, sub-processors, and international transfer safeguards — see the Data Security and Privacy page.

Policy Updates

Sigma will notify you of any material changes to this Privacy Policy at least 30 days before the changes take effect. Notification will be delivered via email to your registered administrator address, an in-app banner visible to all administrators, or both. If you continue using the platform after the effective date of a change, you are considered to have accepted the updated policy. For minor, non-material updates (such as clarifications or formatting corrections), Sigma may update the policy without advance notice. The “last updated” date on the full policy page will always reflect the most recent revision.

Contact

If you have questions about this Privacy Policy, wish to exercise a data right, or want to request a list of current sub-processors, contact Sigma’s Data Protection team: Email: privacy@sigmaconnect.org Organisation: Sigma Health Technologies Inc., Data Protection Office
This page is a plain-language summary intended to help you understand our practices quickly. The authoritative Privacy Policy — which governs your legal relationship with Sigma — is published at sigmahmis.com/privacy. In the event of any conflict between this summary and the full policy, the full policy prevails.