Information Security Policy

Introduction

IONIC Health is committed to safeguarding the confidentiality, integrity, availability, and privacy of all data we manage — including personal, sensitive, and health-related information. This policy is guided by internationally recognized best practices defined in the ISO/IEC 27001:2022, ISO/IEC 27002:2022, and ISO/IEC 27701:2019 standards, as well as applicable data protection laws such as the LGPD (Lei Geral de Proteção de Dados), GDPR (General Data Protection Regulation), and other relevant local regulations.

Through this policy, we aim to foster a culture of trust, compliance, and transparency.

1. Scope

This policy applies to all individuals and entities interacting with IONIC Health systems or data, including employees, partners, service providers, and users of our digital platforms. It covers the management of both information security and privacy throughout the data lifecycle—from collection and access to storage and disposal.

2. Key Principles

We adopt the following principles to guide our information security and privacy program:

  • Risk-Based Approach: We continuously assess security and privacy risks to identify vulnerabilities and implement appropriate controls.
  • Data Protection by Design and by Default: Security and privacy are embedded in all our processes and technologies from the outset.
  • Minimization and Purpose Limitation: We collect only the data strictly necessary for the intended and lawful purposes.
  • Accountability and Transparency: We ensure data subjects are informed of how their data is handled and enable them to exercise their rights.
  • Incident Management: We maintain robust mechanisms for detecting, responding to, and learning from information security and privacy incidents.

3. Information Security Controls

To uphold our commitments, we implement preventive, detective, and corrective controls, including:

  • Access control and authentication based on least privilege;
  • Data encryption at rest and in transit;
  • Continuous monitoring of systems and infrastructure;
  • Secure software development and system maintenance;
  • Backup and recovery procedures;
  • Physical security for data centers and offices.

4. Privacy Commitments

IONIC Health ensures that personal data is processed lawfully, fairly, and transparently. We are committed to:

  • Informing individuals about data usage, legal basis, and data sharing;
  • Obtaining and managing consent where required;
  • Providing mechanisms for data access, correction, and deletion;
  • Ensuring third-party processors follow equivalent privacy and security practices;
  • Defining data retention periods and secure disposal methods.

5. Awareness and Training

All team members receive regular training on data protection, privacy rights, and secure handling of information. We promote awareness campaigns and incorporate security into the onboarding of employees and suppliers.

6. Compliance and Audits

We conduct regular audits and reviews of our policies, procedures, and controls to ensure alignment with ISO standards and data protection regulations. Compliance is continuously monitored, and corrective actions are implemented when necessary.

7. Policy Review and Continuous Improvement

This policy is reviewed periodically and updated as necessary to reflect technological changes, regulatory developments, and organizational goals. At minimum, it is reviewed annually or in the event of significant changes in applicable legislation or technology.

8. Third-Party Responsibilities

All third parties, including contractors, suppliers, and service providers, who access or process information on behalf of IONIC Health are required to:

  • Comply with this Information Security and Privacy Policy and any applicable security contractual clauses;
  • Demonstrate adherence to equivalent or higher information security and privacy controls;
  • Notify IONIC Health of any incidents, breaches, or vulnerabilities affecting shared data or systems;
  • Allow security and privacy assessments or audits when relevant;
  • Ensure that any subcontracted parties follow the same level of security and privacy standards;
  • Sign appropriate confidentiality and data processing agreements when applicable.

Failure to comply with these responsibilities may result in contractual termination and other appropriate actions as determined by IONIC Health.

9. Responsibility and Approval

This policy is approved by the executive leadership of Ionic Health and maintained by the Information Security and Privacy Office. It is reviewed periodically — at least once a year — or whenever significant legal, organizational, or technological changes occur.

Contact Us

For questions or to report a security or privacy concern, contact us at: cybersec@ionic.health