1. Two kinds of data
We handle information in two different roles:
- Patient and clinical data entered by a hospital or clinic into the Service. The hospital decides what is collected and why. We process it only on the hospital's instructions, as its data processor.
- Account and website data about the people who sign up, sign in or contact us, such as name, work email, role and facility details. For this data we decide how it is used, as described below.
2. Patient and clinical data
What it includes
Registration details, appointments, consultation notes, prescriptions, nursing charts, lab results, pharmacy records, bills, insurance documents and follow-up schedules, as entered by authorised staff of the hospital.
How we use it
- To run the Service for the hospital: storing records, showing them to authorised users, and moving orders between departments.
- To generate AI drafts of notes, prescriptions and discharge summaries for a doctor to review. Drafts are not saved to the patient record until a doctor signs them.
- To send reminders, reports and summaries to patients only when the hospital chooses to send them.
What we never do
- We never sell patient data.
- We never use patient data for advertising or to build profiles of patients.
- We never use a hospital's identifiable patient data to train AI models for other customers.
- We never share patient data with insurers, pharmacies or anyone else unless the hospital sends it through the Service.
3. Account and website data
When you sign up for a sandbox or contact our sales team, we collect the details you enter: name, work email, role, hospital or clinic name, facility type, number of doctors and beds, city, country, the modules or departments you are interested in, and any message you write. We use them to create your account, send your login details, prepare your session or quote, and reply to you.
When staff use the Service, we record sign-in times, the device and browser used, and actions taken in the product. This forms the audit log available to the hospital administrator.
4. Security
- Data is encrypted in transit and at rest.
- Access is role-based. Each user sees only what their role allows.
- Every view, edit, print and share of a patient record is logged.
- Backups are encrypted and kept in a separate location.
- Our own staff access customer data only when a hospital asks for support, and that access is logged.
5. Sharing with service providers
We use a small number of providers to run the Service, such as cloud hosting, email and message delivery. They process data only to provide their service to us, under written agreements that require confidentiality and security. We do not allow them to use the data for their own purposes.
6. Retention
Patient data is kept for as long as the hospital keeps its account, or longer if the hospital is required by law to retain medical records. When an account ends, the hospital can export its data, after which we delete it from active systems and backups on a fixed schedule. Sandbox accounts and their sample data are deleted after the sandbox period ends unless converted to a paid account.
7. Your choices and rights
If you are a patient, please contact the hospital or clinic that treated you. They control your records and can help you access, correct or obtain a copy of them.
If you are a user or website visitor, you can ask us to access, correct or delete your account and enquiry details, or to stop sending you product emails, by writing to us through the contact page.
8. Cookies
This website uses only the cookies needed to run it, such as a session cookie for the security check on our forms. The product uses cookies to keep you signed in. We do not use advertising cookies.
9. Changes to this policy
If we change how we handle data in a way that matters, we will tell hospital administrators by email and in the product before the change takes effect.
10. Contact
Questions about privacy can be sent to us through the contact page on this website.