← Back to norma33.ru
8 (49234) 77577 · 08:00–20:00 daily
NORMA IT

Privacy Policy

Privacy and data processing rules for the “Norma IT” mobile application.

Last updated: September 6, 2026

General provisions

This Privacy Policy explains how information is processed when using the “Norma IT” mobile application.

The application operator is TSENTR NOVYKH MEDITSINSKIKH TEKHNOLOGI, OOO (the “Organization”, “we”, “us”).

Norma IT is an internal work application for authorized employees, doctors, IT specialists, and administrators of Medical Center Norma. Depending on the user’s role and permissions, the application provides access to IT requests and tasks, comments, internal news, physician schedules, administrative functions, and service notifications.

The application does not provide public self-registration. User accounts are provisioned and managed by the Organization through its internal portal and/or medical information system (MIS).

1. Data processed by the application

1.1. Account and authentication data

The application may process:

  • login / username;
  • employee first and last name;
  • user ID and/or MIS ID;
  • role, specialty, and other account attributes required to determine permissions;
  • password during authentication;
  • server session identifiers or authentication tokens.

The password is transmitted to the Organization’s server over HTTPS for authentication and is not stored by the application. A server session token may be stored locally in the iOS Keychain so the authenticated session can be restored between launches.

1.2. Work tasks and user-generated content

The application may process information related to IT requests and tasks, including:

  • task ID, title, description, category, date, status, author, and assignee;
  • comments and task history;
  • information about completion, reassignment, or deletion of a task;
  • an internal phone number or extension associated with a task, where provided;
  • other free-form information entered by authorized users in task fields or comments.

Users should enter only information necessary for legitimate work purposes and should avoid unnecessary personal, medical, or other sensitive information.

1.3. Push notifications and device identifiers

For push notifications and device registration, the application may process:

  • Apple Push Notification service (APNs) device token;
  • a stable application-generated device UUID;
  • device name;
  • information required to synchronize unread notification counts and app icon badges;
  • information identifying the task, comment, or news item associated with a notification.

APNs is used to deliver notifications on Apple devices. Apple may process technical information required to deliver notifications in accordance with Apple’s own terms and privacy practices.

1.4. Technical data

The application and the Organization’s server infrastructure may process technical information necessary to operate and secure the service, such as application version, operating system version, device type or name, request date and time, IP address, and technical error or server log information, where such information is generated or retained by the infrastructure.

1.5. How data is obtained

Information may be:

  • entered directly by the user;
  • provided by the Organization through the internal portal or MIS;
  • created as a result of the user’s actions in Norma IT;
  • generated automatically by the application or device for application functionality and security;
  • generated by server infrastructure when processing application requests.

2. Local PIN and biometric authentication

Norma IT can protect an already authenticated local session with a local PIN and, when enabled by the user, Face ID or Touch ID.

Face ID and Touch ID are handled by Apple’s LocalAuthentication framework and the device security system. Norma IT does not receive or store biometric templates, fingerprint images, facial images, or other underlying biometric authentication data. The application receives only the result needed to determine whether local authentication succeeded or failed.

Biometric authentication is used only as a local unlock mechanism. If biometric authentication is unavailable or declined, the application can use the available PIN or other supported authentication flow.

3. Physician schedules and patient-related information

Norma IT includes physician schedule functionality. Authorized doctors may view their work schedules, and users with administrative permissions may view schedules of selected physicians.

Schedule information received from the Organization’s MIS may include a patient’s name and information about the scheduled appointment, such as date and time, to the extent required for the employee’s work duties. Such information may constitute personal data and, depending on its content, health-related information.

Norma IT is not intended to maintain complete electronic medical records, provide diagnosis, or replace the Organization’s medical information system. Access to schedule and patient-related information is limited by organizational roles and server-side permissions.

Patient-related information must be used only for authorized work purposes and must not be disclosed outside the Organization except where permitted or required by applicable law and internal policies.

4. Purposes of processing

Information is processed for application functionality and the Organization’s authorized work processes, including:

  • authenticating users and maintaining server sessions;
  • determining roles and permissions;
  • creating, viewing, assigning, updating, commenting on, completing, and deleting tasks where permitted;
  • displaying internal news;
  • displaying physician schedules to authorized users;
  • sending and synchronizing service and push notifications;
  • protecting local access with PIN and optional biometrics;
  • security, fraud prevention, troubleshooting, and maintaining service availability;
  • supporting internal operational processes of the Organization.

5. Disclosure and third-party services

The Organization does not sell personal data and does not disclose it to advertising networks, data brokers, or third parties for targeted advertising.

The audited application does not use third-party advertising or analytics SDKs.

Apple Push Notification service is used to deliver push notifications. Technical information required for APNs delivery is processed by Apple under Apple’s applicable terms and privacy practices.

Data may also be disclosed where required by applicable law or to service providers acting on behalf of the Organization where necessary to operate or protect the service. Any such provider is required to provide the same or an equivalent level of protection for user data as described in this Privacy Policy and required by applicable law.

6. Data retention and deletion

Account information, task history, comments, schedules, notification registration information, and related operational records may be retained for as long as required for the relevant work process, information security, internal recordkeeping, and applicable legal obligations.

There is no single retention period that applies to every category of information. When information is no longer required for the applicable purpose and there is no legal or organizational requirement to retain it, it may be deleted, anonymized, or archived in accordance with the Organization’s procedures.

APNs tokens and device registration information may be retained while they are required to deliver notifications and may be removed or invalidated when the device is unregistered, the token becomes invalid, or access is revoked.

7. Data security

The Organization uses reasonable organizational and technical measures to protect information from unauthorized access, alteration, disclosure, loss, or destruction.

The application communicates with the Organization’s backend over HTTPS. Access to application functionality and patient-related schedule information is controlled through organizational accounts, roles, and permissions. Authentication tokens intended for local persistence are stored using iOS Keychain.

8. Organizational accounts and access termination

Norma IT does not support creation of a new user account inside the application. Employee accounts are created, changed, disabled, and deleted by the Organization through its internal systems.

A user may request termination of application access, correction of account information, or deletion of personal data by contacting the responsible administrator or support@norma33.ru.

Some work records may need to be retained after access is terminated where retention is required by law, information-security requirements, or legitimate organizational recordkeeping obligations.

9. Advertising, analytics, and tracking

Norma IT does not:

  • display third-party advertising;
  • use personal data for targeted advertising;
  • sell user data;
  • use third-party advertising or analytics SDKs;
  • link application data with third-party data for advertising measurement or advertising targeting;
  • use data brokers.
Norma IT does not use user or device data for cross-app or cross-website tracking.

10. User rights and privacy requests

Subject to applicable law, users may request:

  • information about processing of their personal data;
  • correction of inaccurate personal data;
  • restriction or termination of application access;
  • deletion of personal data where deletion is legally and operationally permitted;
  • information about retention or disclosure of their data.

Where processing is based on consent, the user may withdraw that consent by contacting support@norma33.ru. Withdrawal does not affect processing lawfully performed before the withdrawal.

11. Children

Norma IT is an organizational work application for authorized personnel and is not intended for children. The Organization does not knowingly provide Norma IT accounts to children for consumer use.

12. Changes to this Privacy Policy

This Privacy Policy may be updated when application functionality, data processing practices, server infrastructure, legal requirements, or services used by the application change. The current version is published at this URL and the update date is shown at the top of the page.

13. Contact information

TSENTR NOVYKH MEDITSINSKIKH TEKHNOLOGI, OOO

Application: Norma IT

Website: https://norma33.ru/

Email: support@norma33.ru