CTI GLOBAL

Privacy Policy – Passport Mobile Platform

International Edition (GDPR + HIPAA Aligned)

Effective Date: 16/07/2026
Last Updated: 16/07/2026

1. Introduction

Welcome to the LifeHealth Mobile Application (“App”), owned and operated by CTI Global (“CTI Global,” “LifeHealth,” “we,” “our,” or “us”).

LifeHealth is a secure digital health platform that enables patients to communicate with licensed healthcare professionals using smartphones and tablets.

This Privacy Policy explains how Personal Information, Health Information, and Protected Health Information (“PHI”) are collected, processed, stored, transferred, and protected when you use the LifeHealth Mobile Application.

This Policy is designed to align with internationally recognized privacy standards, including:

  • General Data Protection Regulation (GDPR)
  • UK GDPR
  • HIPAA Privacy Rule
  • HIPAA Security Rule
  • HIPAA Breach Notification Rule
  • Applicable U.S. privacy legislation
  • International healthcare privacy principles

By installing, accessing, or using the App, you acknowledge that you have read and understood this Privacy Policy.

2. Company Information

LifeHealth is operated by:

CTI Global

Registered Office

44 Wall Street

New York, NY 100005

United States

General Privacy Enquiries

support@lifehealth.global

3. Scope

This Privacy Policy applies only to the LifeHealth Mobile Application, including:

  • patient mobile app
  • clinician mobile app
  • caregiver mobile app
  • secure messaging
  • appointment scheduling
  • prescription management
  • laboratory requests
  • electronic health record access
  • payment functionality
  • in-app communications
  • push notifications

This Policy does not govern third-party applications or services linked from the App.

4. Our Role

CTI Global provides technology services that facilitate communication between healthcare providers and patients.

CTI Global does not itself provide medical diagnosis, treatment, or emergency healthcare services.

Healthcare providers using the Platform remain independently responsible for:

  • diagnosis
  • treatment
  • prescriptions
  • clinical decisions
  • medical record accuracy
  • professional licensing
  • compliance with applicable healthcare laws

Nothing in this Policy creates a physician-patient relationship between CTI Global and App users.

5. Categories of Information Collected

Depending on your use of the App, we may collect:

Account Information

  • Full name
  • Email address
  • Telephone number
  • Date of birth
  • Username
  • Password credentials (encrypted)

Health Information

Healthcare providers may create or upload:

  • consultation notes
  • prescriptions
  • diagnoses
  • laboratory results
  • referral letters
  • allergies
  • medications
  • medical history
  • vaccination records
  • treatment plans

Device Information

The App may collect:

  • device manufacturer
  • device model
  • operating system version
  • application version
  • language
  • time zone
  • IP address
  • device identifier
  • crash logs
  • diagnostic logs
  • authentication logs

Network Information

To maintain secure communications we may process:

  • IP address
  • connection timestamps
  • session identifiers
  • authentication tokens
  • security event logs

Payment Information

Payments are processed through PCI DSS compliant payment providers.

CTI Global does not store complete payment card details.

6. Mobile Permissions

The App may request permission to access certain device functions.

These permissions are requested only when required for specific functionality.

Camera

Used for:

  • video consultations
  • scanning documents
  • uploading prescriptions
  • uploading laboratory reports
  • profile photographs

Camera access can be revoked at any time through device settings.

Microphone

Used for:

  • voice consultations
  • video consultations

Without microphone permission, voice communication features may not function.

Photo Library

Used only when you choose to upload:

  • medical images
  • prescriptions
  • referral letters
  • laboratory reports
  • insurance documents

Notifications

Used for:

  • appointment reminders
  • prescription updates
  • clinician messages
  • account security alerts

Marketing notifications are sent only where permitted by law and, where required, with your consent.

Location

Location services may be used to:

  • identify nearby healthcare providers
  • locate pharmacies
  • identify laboratories
  • verify jurisdictional licensing requirements
  • improve appointment scheduling

Location sharing may be disabled through device settings.

Certain location-based services may become unavailable if location access is disabled.

Biometric Authentication

If enabled by you, the App may use your device’s biometric authentication system, including:

  • Face ID
  • Touch ID
  • Fingerprint authentication
  • Device facial recognition

Biometric templates remain stored exclusively on your device.

CTI Global never receives, stores, or processes biometric templates.

7. How We Use Information

We use information to:

  • create accounts
  • authenticate users
  • schedule consultations
  • facilitate telemedicine services
  • provide secure messaging
  • process payments
  • improve application performance
  • detect fraud
  • prevent unauthorized access
  • comply with healthcare regulations
  • maintain security
  • investigate incidents
  • respond to legal requests
  • provide customer support
  • improve user experience through anonymized analytics

We do not sell Personal Information.

We do not sell Protected Health Information.

We do not permit advertisers to access clinical information.

8. Mobile Analytics and Crash Reporting

To improve stability and performance, the App may use trusted service providers to collect limited technical information, such as:

  • application crashes
  • performance metrics
  • device compatibility
  • operating system version
  • diagnostic information

Analytics are configured, where practicable, to minimize the collection of Personal Information.

Where required by applicable law, consent will be obtained before enabling non-essential analytics.

9. Third-Party Software Development Kits (SDKs) and Service Providers

To operate, maintain, and improve the Mobile Application, CTI Global may integrate third-party software development kits (“SDKs”) and service providers. These providers perform services on our behalf and are contractually required to maintain appropriate administrative, technical, and organizational safeguards to protect Personal Information.

Depending on the services enabled, third-party providers may support:

  • Cloud hosting and infrastructure
  • Authentication and identity verification
  • Secure messaging
  • Push notification delivery
  • Payment processing
  • Customer support
  • Error logging and crash reporting
  • Performance monitoring
  • Fraud prevention
  • Content delivery
  • Security monitoring
  • Analytics (where permitted by applicable law)

Third-party providers are granted access only to the information reasonably necessary to perform the contracted services and may not use such information for their own marketing or unrelated commercial purposes.

A current list of significant service providers may be made available upon request or through our website.

10. Sharing of Personal Information

CTI Global does not sell Personal Information, Protected Health Information (PHI), or other health-related information.

We may disclose information only where reasonably necessary to operate the Platform or where required by law.

Information may be shared with:

Healthcare Providers

Licensed physicians, nurses, specialists, psychologists, pharmacists, hospitals, laboratories, imaging facilities, and other healthcare professionals involved in your care.

Healthcare Partners

Authorized laboratories

Diagnostic centers

Pharmacies

Medical specialists

Referral facilities

Emergency medical providers where appropriate

Technology Providers

Cloud infrastructure providers

Cybersecurity providers

Payment processors

Authentication providers

Email providers

SMS providers

Video consultation providers

Customer support providers

Secure document storage providers

Backup and disaster recovery providers

Regulatory Authorities

We may disclose information where required to:

  • comply with applicable law;
  • respond to court orders;
  • satisfy lawful subpoenas;
  • cooperate with law enforcement;
  • comply with public health reporting obligations;
  • respond to regulatory investigations;
  • protect public safety;
  • enforce our contractual rights.

Corporate Transactions

If CTI Global undergoes:

  • merger
  • acquisition
  • restructuring
  • sale of assets
  • financing transaction
  • bankruptcy
  • corporate reorganization

Personal Information may be transferred as part of the transaction, subject to applicable confidentiality obligations and legal safeguards.

11. International Data Transfers

Because LifeHealth operates internationally, Personal Information may be processed in countries other than the country in which it was originally collected.

Where required by applicable law, CTI Global implements appropriate safeguards, including:

  • European Commission Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Agreement (IDTA)
  • Binding contractual safeguards
  • Vendor due diligence
  • Encryption of data in transit and at rest
  • Role-based access controls
  • Data minimization
  • Transfer impact assessments where applicable

Where consent is required by law for certain international transfers, we will obtain such consent before the transfer occurs.

We take reasonable steps to ensure that recipients maintain privacy protections substantially equivalent to those described in this Privacy Policy.

12. HIPAA Uses and Disclosures

Where HIPAA applies, CTI Global may use or disclose Protected Health Information without additional patient authorization where permitted by law for:

Treatment

Supporting licensed healthcare professionals in diagnosing, treating, referring, prescribing, coordinating, or monitoring patient care.

Payment

Insurance verification

Claims processing

Billing

Payment collection

Financial reconciliation

Healthcare Operations

Quality assurance

Credential verification

Fraud prevention

Auditing

Accreditation

Security monitoring

Risk management

Operational improvement

Training

Legal Compliance

Public health reporting

Judicial proceedings

Law enforcement requests

Government investigations

Mandatory reporting obligations

Protection of health and safety

Where HIPAA requires patient authorization for a specific disclosure, CTI Global will obtain the appropriate authorization before such disclosure occurs.

13. Data Retention

Personal Information is retained only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy or to comply with applicable legal, regulatory, accounting, contractual, or healthcare obligations.

Unless a longer retention period is required by law or an active legal hold applies, our general retention practices include:

Data Category

Typical Retention

Account information

Duration of account plus six (6) years

Clinical records

Minimum of ten (10) years after the last clinical entry, or longer where required by applicable law or professional standards

Payment and billing records

Seven (7) years

Security logs

Up to twenty-four (24) months

Device and crash logs

Up to eighteen (18) months

Consent records

Ten (10) years following withdrawal or account closure

Marketing preferences

Until withdrawn, plus a reasonable suppression period to honor opt-out requests

Where information is no longer required, it will be securely deleted, anonymized, or irreversibly de-identified in accordance with applicable legal requirements and industry standards.

14. Information Security

CTI Global maintains a comprehensive information security program designed to protect Personal Information against unauthorized access, disclosure, alteration, destruction, or loss.

Our safeguards include, where appropriate:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of stored data using AES-256 or equivalent standards
  • Multi-factor authentication for privileged users
  • Role-based access controls following the principle of least privilege
  • Secure authentication token management
  • Automatic session expiration
  • Device integrity verification
  • Secure API authentication
  • Routine vulnerability scanning
  • Penetration testing
  • Continuous security monitoring
  • Audit logging and security event management
  • Disaster recovery and business continuity planning
  • Employee confidentiality obligations and regular security awareness training

For mobile devices, additional protections may include secure storage using platform-native hardware security features, encrypted local caches, certificate pinning where technically appropriate, and remote session invalidation.

Although we employ commercially reasonable safeguards, no method of electronic transmission or storage is completely secure. Users should also take reasonable steps to protect their devices, passwords, and account credentials.

15. Your Privacy Rights

Depending on your country of residence and applicable law, you may have one or more of the following rights:

  • The right to be informed about how your information is processed.
  • The right to access Personal Information held about you.
  • The right to request correction of inaccurate or incomplete information.
  • The right to request deletion of Personal Information, subject to legal and clinical record retention obligations.
  • The right to restrict certain processing activities.
  • The right to object to processing based on legitimate interests.
  • The right to withdraw consent where processing is based on consent.
  • The right to receive your Personal Information in a structured, commonly used, and machine-readable format where legally applicable.
  • The right not to be subject solely to automated decision-making producing legal or similarly significant effects, except where permitted by law.
  • The right to lodge a complaint with the applicable supervisory authority or regulator in your jurisdiction.

Requests to exercise privacy rights may be submitted through the application, your account settings, or by contacting CTI Global using the contact details provided in this Policy. We may request reasonable information to verify your identity before responding to a request.