Privacy Policy
Effective Date: September 24, 2026 • Version 1.0
1. Overview & Single Purpose
This Privacy Policy outlines how LamaniSync ("we", "our", or "the Extension"), operated by Lamanify Technologies ("Lamanify"), collects, handles, and safeguards information when authorized healthcare staff install and utilize the LamaniSync Chrome Extension.
LamaniSync serves a single, well-defined purpose: to provide a secure, authenticated synchronization bridge between certified cloud Clinic Management Systems (CMS) and the LamaniHub operational platform.
2. Zero Raw PHI Architecture (Healthcare Privacy)
We are committed to the highest standards of medical data privacy, including alignment with HIPAA data safeguards and the Malaysian Personal Data Protection Act (PDPA):
- No Raw Patient Health Information (PHI) Storage: LamaniSync does not store, harvest, or log patient clinical notes, medical histories, diagnosis records, or national identification credentials (such as NRIC or passport numbers) on local workstation disk storage or extension storage.
- In-Memory Ephemeral Processing: Operational appointment sync tasks (e.g., matching a schedule slot time, booking duration, and anonymous appointment UUID) are processed entirely in transient browser memory.
- Readback Verification Only: LamaniSync verifies appointment completion by reading back the confirmed slot status from the clinic's authenticated CMS session, guaranteeing zero ghost records without duplicating patient records.
3. Credential & Authentication Boundary
LamaniSync operates within the context of an already authenticated clinic staff session in the cloud CMS. Under no circumstances does LamaniSync:
- Access, copy, or log your clinic CMS login passwords or multi-factor authentication (MFA) codes.
- Transmit CMS session cookies, bearer tokens, or CSRF secrets to LamaniHub or any external third-party server.
4. Browser Permissions & Purpose Specification
In strict compliance with Google Chrome Web Store Developer Program Policies, every permission requested is strictly necessary to fulfill the single operational purpose:
| Permission | Exact Purpose |
|---|---|
storage | Persists non-PHI workstation pairing identifiers (installationId, clinicId, connectionId, target CMS origin, and session token) in chrome.storage.local across browser restarts. |
alarms | Schedules low-frequency internal background timers for leader-lease heartbeats (preventing multi-tab synchronization conflicts) and exponential retry backoff. |
declarativeNetRequest | Normalizes upstream edge proxy duplicate CORS response headers strictly for our canonical LamaniHub synchronization endpoint (https://app.lamanihub.com/v1/sync/*). It does not inspect request bodies or monitor user browsing. |
scripting | Dynamically registers pre-compiled, bounded observation and runner scripts exclusively inside the user-authorized tab of the paired Clinic Management System. |
host_permissions | Enables the background service worker to communicate with the canonical LamaniHub synchronization gateway (https://app.lamanihub.com/*) to exchange signed job requests. |
optional_host_permissions | Enables the user to grant access at runtime strictly to their clinic's certified web CMS origin. Wildcard host permissions are rejected at the architectural level. |
5. Remote Code Policy & Code Integrity
LamaniSync does not execute remote code. All executable JavaScript code (user interface, background service worker, and DOM runners) is statically packaged within the extension archive (.crx / .zip). Dynamic CMS adapters are distributed solely as immutable declarative JSON schema manifests signed with Ed25519 cryptographic signatures and verified by a local, bundled interpreter before execution.
6. Third-Party Sharing & Commercial Data Use
We strictly certify that:
- We do not sell, rent, or monetize user data, clinic data, or patient operational data to any third party or data broker.
- We do not use user data for advertising, retargeting, promotional profiling, creditworthiness evaluation, or lending purposes.
- We do not include third-party tracking scripts, analytics SDKs, or external advertising pixels.
7. Data Retention & Device Unpairing
Clinic administrators maintain complete control over LamaniSync. Clicking "Unpair Workstation" or uninstalling the extension immediately purges all pairing keys, session tokens, and local cache from chrome.storage.local and revokes all active synchronization leases.
8. Contact & Compliance Inquiries
If you have questions regarding this Privacy Policy, healthcare data safeguards, or our Chrome Web Store data practices, please contact our compliance and operations team:
Lamanify Technologies (LamaniSync Privacy & Compliance)
Email: [email protected]
Support: [email protected]
Official Website: https://lamanisync.com
Support Portal: https://lamanisync.com/contact