Privacy Policy
Scope of This Policy
This Privacy Policy applies to:
- Authorized users of the Midwire 20/20 platform, including eye bank staff, tissue bank personnel, transplant coordinators, technicians, and administrators.
- Visitors to our website at midwire2020.com.
- Prospective clients who submit inquiry or demo request forms.
This Policy does not apply to third-party services or platforms linked from our website. We encourage you to review the privacy policies of any third parties you engage with.
Information We Collect
2.1 Platform Users (Institutional Accounts)
When your organization subscribes to Midwire 20/20, we may collect and process the following categories of information on behalf of your institution:
- User account information: name, role/title, email address, login credentials.
- Workflow and operational data including donor referral records, recovery documentation, serology results, eligibility determinations, tissue inventory data, shipping and distribution records, post-operative outcomes, and QI/CAPA entries.
- System activity logs: login timestamps, actions performed, module access, and audit trail data.
- Integration data from connected systems such as Vision Share, EBAA ONE, Konan, HubSpot, and reporting tools (Power BI, Tableau).
Midwire 20/20 operates as a data processor for institutional clients. Your organization, as the data controller, is responsible for ensuring appropriate consents and authorizations are in place for any personal or health-related data entered into the platform.
2.2 Website Visitors
When you visit midwire2020.com, we may automatically collect:
- IP address and general geographic location.
- Browser type, device type, and operating system.
- Pages visited, time spent, and referring URL.
- Cookies and similar tracking technologies (see Section 7).
2.3 Contact and Demo Request Forms
If you submit a "Contact Us" or "Request a Demo" form, we collect the information you voluntarily provide, which may include your name, organization, email address, phone number, job title, and your inquiry details.
How We Use Your Information
We use the information we collect for the following purposes:
- Platform delivery: To operate, maintain, and improve the Midwire 20/20 clinical workflow platform and all of its modules.
- User authentication and access control: To verify identity, manage permissions, and maintain role-based access.
- Compliance and audit support: To generate audit trails, maintain documentation, and support regulatory compliance with AATB, FDA, and EBAA standards.
- Customer support: To respond to support requests, troubleshoot issues, and communicate platform updates.
- Sales and marketing: To respond to demo requests, send product communications, and follow up with prospective clients. Marketing communications are sent only with appropriate consent or legitimate interest.
- Analytics and improvement: To analyze usage patterns and improve platform performance, user experience, and feature development.
- Legal compliance: To comply with applicable laws, regulations, and contractual obligations.
Legal Basis for Processing
For users and contacts in jurisdictions with formal data protection laws (including GDPR and applicable state privacy laws), we process personal data on the following legal bases:
- Contract performance: Processing necessary to fulfill our services agreement with your institution.
- Legitimate interests: Processing for analytics, platform improvement, and business development, where not overridden by your rights.
- Legal obligation: Processing required to comply with applicable regulations.
- Consent: Where you have provided explicit consent, such as for marketing communications.
Data Sharing and Disclosure
We do not sell personal information. We may share information in the following circumstances:
- Service providers: With trusted third-party vendors who assist in platform hosting, infrastructure, analytics, or communications, under data processing agreements that limit use to defined purposes.
- Platform integrations: With systems your organization has authorized for integration, such as Vision Share, EBAA ONE, Konan, and HubSpot.
- Regulatory compliance: Where required by applicable law, court order, or regulatory authority.
- Business transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, with notice provided to affected parties.
- With your consent: For any other purposes with your explicit authorization.
Data Security
Midwire 20/20 implements industry-standard security measures appropriate for an enterprise healthcare technology platform, including:
- Encryption of data in transit and at rest.
- Role-based access controls and multi-factor authentication support.
- Comprehensive audit logging across all platform modules.
- Regular security assessments and vulnerability management.
While we implement robust safeguards, no system is completely immune to risk. We encourage institutional clients to implement their own security policies governing user access, credential management, and data handling practices within the platform.
Cookies and Tracking Technologies
Our website uses cookies and similar technologies to improve the browsing experience and gather analytics. These may include:
- Strictly necessary cookies: Required for basic website functionality.
- Analytics cookies: To understand how visitors interact with our website (e.g., page views, session duration). We may use tools such as Google Analytics.
- Preference cookies: To remember your settings and preferences.
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of our website.
Data Retention
We retain personal data for as long as necessary to fulfill the purposes described in this Policy, comply with legal and regulatory obligations, resolve disputes, and enforce agreements.
For platform data, retention schedules are generally governed by the terms of our agreement with your institution and applicable regulatory requirements (including AATB and FDA recordkeeping standards). Upon termination of a service agreement, we will work with your organization on a structured data export and deletion process.
Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your personal data, subject to legal and contractual retention requirements.
- Object to or restrict certain types of processing.
- Data portability, where technically feasible.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact us at the details provided in Section 12. We will respond to verified requests within the timeframes required by applicable law.
Children's Privacy
Our Services are intended for enterprise use by healthcare and eye/tissue banking professionals. We do not knowingly collect personal information from individuals under the age of 18.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, platform capabilities, or legal requirements. The updated policy will be posted on our website with a revised effective date. We encourage you to review this Policy periodically.
Contact Us
If you have questions, concerns, or requests related to this Privacy Policy, please contact us at:
- Midwire 20/20
- Website: www.midwire2020.com
For privacy-related inquiries, please use the Contact Us form on our website or reach out directly to your designated account representative.
Have a Privacy Question?
Our team is here to help. Reach out through our contact form and we'll respond promptly.
Contact Us