Template for legal review
1Introduction
This Privacy Policy explains how Medyntra, a product of AMPDUO Studio (“we”, “us”), handles information when hospitals, clinics and other healthcare organizations (“Customers”) and their authorized users use the platform, and when visitors use our website.
Customers decide what patient information they record in the platform. For that information, the Customer is responsible for its lawful collection and use, and we process it on the Customer’s behalf under our agreement with them.
2Information we collect
We collect information that Customers and users provide, information generated when the platform is used, and limited information from website visitors, as described in the sections below.
3Hospital / organization information
Organization name, legal name, facility type, registration details, contact details, address, branding, timezone, departments and subscription details provided during onboarding and account management.
4Patient information
Patient records entered by the Customer’s authorized staff, such as demographics, contact details, appointments, visit notes, documents and billing records.
Patient information belongs to the Customer. We access it only to provide the service, as instructed by the Customer, or where required by law.
5User account information
Name, email address, password (stored only as a secure hash), role and organization memberships, and session information such as sign-in time, IP address and browser type.
6Usage & technical information
Technical logs needed to operate and secure the service, such as request identifiers, error reports and security events. Logs are designed to exclude patient information and secrets.
7How we use information
To provide, maintain and support the platform; to secure accounts and detect misuse; to communicate about the service, billing and security; and to meet legal obligations.
We do not sell personal information, and we do not use patient information as generic public content.
8How we protect information
The platform is designed with tenant isolation, role-based access control, encryption in transit, encryption at rest provided by our infrastructure services, audit logging and private document storage. See our Security page for details.
No system can be guaranteed to be completely secure; we continuously improve our controls.
9Data access controls
Customers control which of their users can access which information through roles and permissions. Access by our own staff is limited to what is necessary to operate and support the service, and administrative actions are recorded.
10Data retention
We keep Customer data for the duration of the agreement and for a limited period afterwards to allow export, unless a longer period is required by law. Specific retention periods are set out in the Customer agreement.
11Data storage
The platform is designed to store data with managed cloud providers, with a preference for data centres in India. The exact locations are confirmed in the Customer agreement.
12Third-party service providers
We use carefully selected providers for hosting, databases, storage, email and similar services. They process information only on our instructions and under appropriate agreements.
13SMS / email providers
To send notifications such as appointment reminders and one-time codes, recipient contact details and message content are shared with SMS and email delivery providers.
14Payment providers
Subscription payments may be processed by payment providers. We do not store full card details on our servers.
15AI processing
Where AI features are enabled for a Customer, relevant data may be processed by AI service providers to generate insights and answers. AI features operate within the requesting user’s permissions and the Customer’s tenant, and are not used to make clinical decisions.
17Data export
Customers can request an export of their data in a commonly used format, subject to the Customer agreement.
18Data deletion
After the agreement ends and any export period has passed, Customer data is deleted or anonymized, except where retention is required by law. Backups are overwritten on their normal schedule.
19Hospital / customer responsibilities
Customers are responsible for the patient information they record, for obtaining any required consents, for managing their users’ access, and for keeping account credentials confidential.
20Security incident handling
If we become aware of a security incident affecting Customer data, we will investigate, take steps to contain it and notify affected Customers as required by law and our agreements.
21Changes to this Privacy Policy
We may update this policy. Material changes will be communicated to Customers in advance, and the date and version at the top of this page will change.
22Contact information
For privacy questions or requests, please contact us through the Contact page. Patients should contact the hospital or clinic that holds their records.