Privacy, Safety & Identity Protection

BloodOS operates as a non-profit emergency humanitarian network. We handle health and contact records with extreme clinical restraint, automated privacy controls, and zero commercial monetization.

Version 2.4 (2026 Edition) Effective Date: January 1, 2026 DGHS & ICT Act Compliant

Algorithmic Phone Masking

All Bangladesh phone numbers are publicly redacted to 01XXX***XXX to stop scrapers and unsolicited harassment.

Direct match disclosure only

56-Day Cooldown Ledger

Post-donation biological lockout is calculated strictly by automated system rules to protect donor cardiovascular and erythropoietic recovery.

WHO biological safety rule

Zero Brokerage Guarantee

We never buy, sell, broker, or monetize blood or donor records. Commercial exchange of blood is strictly illegal and blocked on our platform.

100% Free Public Good

Permanent Data Erasure

Donors and recipients retain absolute sovereignty over their data with 1-click irreversible account erasure and clinical log de-identification.

Unconditional Right to Delete

1. Governance & Scope

BloodOS is an open humanitarian clinical coordination protocol purpose-built to accelerate emergency blood matching across Bangladesh. This Privacy Policy governs all interactions with the platform across web, mobile viewports, and automated emergency notification channels.

By accessing BloodOS or registering as a donor or requester, you acknowledge that your operational details (such as blood group, district, and emergency status) will be processed strictly in accordance with this document to facilitate life-saving blood transfers.

2. Information We Collect

Donor Profile Records

Collected upon voluntary registration to determine donation compatibility and geographic proximity:

  • Full Legal Name & Verified Email
  • Blood Group & Rh Factor (A+, B+, O+, AB+, etc.)
  • Primary Phone Number (Bangladesh 11-digit)
  • District & Upazila Jurisdiction
  • Last Donation Date (for 56-day cooldown)
  • Availability Flag (`isAvailable`)

Emergency Blood Request Records

Submitted when an urgent transfusion requirement is logged by a patient, attendant, or hospital coordinator:

  • Patient Name or Identifier
  • Hospital Name, District & Address
  • Units Required & Target Transfusion Date
  • Urgency Tier (STAT Emergency vs Standard)
  • Hospital Attendant Contact Number
  • Clinical Reason for Transfusion

3. How We Process Your Data

BloodOS enforces strict data minimalism. Data collected is used exclusively for the following operational workflows:

Triage Matching

Automated cross-checking of ABO/Rh compatibility and geographic proximity within 64 districts.

Emergency Broadcast

Delivering real-time alerts and notifications to eligible matched donors when STAT alerts trigger.

Abuse Prevention

Detecting duplicate requests, spam bots, and unauthorized commercial middlemen seeking blood products.

4. Automated Phone Masking Standard

To eliminate unsolicited commercial messages, identity theft, and harassment of female and vulnerable donors, BloodOS implements cryptographic server-side phone redaction:

Redaction StandardRegex: 01XXX***XXX
Public / Unauthenticated View:

01712***890

Only first 5 digits (operator/prefix) and last 3 digits remain visible for audit reference.

Unmasked Access Criteria:

Direct full contact is unveiled strictly after an authenticated donor formally commits via “I Can Help” or hospital coordinator verification.

5. 56-Day Cooldown & Clinical Integrity

Under standard clinical guidelines (Directorate General of Health Services & WHO), a whole-blood donor must rest for at least 56 days (8 weeks) between donations to allow complete red blood cell regeneration and hemoglobin recovery.

BloodOS maintains an automated biological ledger. When a donation is marked confirmed, the donor's profile is instantly flagged as ineligible until the 56-day cooldown reaches zero. This metric is computed deterministically and cannot be manually overridden without administrative clinical review.

6. Zero Brokerage & Non-Commercialization

Blood is a humanitarian gift, not a commodity.

BloodOS operates with an absolute zero-tolerance policy against commercial blood brokerage, extortion, or paid matching. We do not sell user data to pharmaceutical entities, insurance brokers, advertisers, or third-party marketing brokers. Any account found demanding financial compensation for blood will be permanently suspended and reported to law enforcement.

7. Your Data Rights & Right to Erasure

You hold complete legal sovereignty over your personal records stored within BloodOS:

Right to Access & Rectify

You can update your phone, district, availability, and donation history at any time from your Profile.

Right to Erasure (Delete)

You can request full account deletion. All contact information is wiped and historical logs are permanently anonymized.

8. Technical & Clinical Security Safeguards

Our production infrastructure deploys multiple defensive perimeters to secure your medical information:

  • End-to-End TLS 1.3 Encryption: All transit data between client browsers, Next.js servers, and MongoDB clusters is strictly encrypted.
  • Role-Based Access Control (RBAC): Administrative audit terminals require dual-factor authorization and maintain immutable tamper-evident logs.
  • No Plaintext Credential Storage: Passwords and session tokens utilize Argon2/Bcrypt cryptographic salting through Better Auth.

9. Data Protection Officer & Inquiries

For formal data access requests, clinical audit inquiries, or reporting unauthorized contact disclosures, reach our Data Protection & Ethics Committee:

Electronic Inquiriesprivacy@bloodos.org
Direct Support Deskbloodos.org/contact