This Privacy Policy describes how Sanjeevani Software ("we", "us", or "our") collects, uses, shares, stores, and safeguards information when you visit our website, register for an account, or use our Electronic Medical Records (EMR) and clinic management platform (collectively, the "Services"). By using the Services, you consent to the practices described in this Policy.
This Policy is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act (DPDP Act), 2023 of India, and is aligned with the administrative and security expectations set by the Health Insurance Portability and Accountability Act (HIPAA) framework for digital healthcare entities.
1. Your Consent and Legal Roles
Consent: By creating an account, signing in, or otherwise using the Services, you confirm that you have read this Privacy Policy and consent to the collection, storage, processing, and disclosure of your information.
Data Principal: Under the DPDP Act, 2023, you are a Data Principal in respect of your own personal data. Your consent is free, specific, informed, unconditional, and unambiguous. You may withdraw your consent at any time through your account settings or by contacting our Grievance Officer.
Clinical Patient Data & HIPAA Compliance: When you input, upload, or manage health information about your patients (including clinical symptoms, rubrics, repertorization, and medical histories), you act exclusively as the Data Fiduciary (and Covered Entity / Controller) under applicable law. You confirm that you have obtained the necessary verifiable consent from those patients or their lawful guardians. Sanjeevani Software acts strictly as a Data Processor. We process such patient data solely on your documented instructions and in full compliance with the business associate protection requirements under HIPAA and the DPDP Act.
2. Information We Collect
Information You Provide Directly: Name, email, phone number, professional clinical registration / council details, clinic name, physical branch addresses, and designations of your authorized staff members.
Patient and Clinical Information You Input: Patient identifiers (name, age, gender, contact details) and sensitive clinical data (chief complaints, homeopathic symptom analysis, modalities, miasm scores, rubrics, diagnoses, prescriptions, and electronic investigation attachments).
Information Collected Automatically: Device model, operating system, browser type, IP address, approximate location connection metadata, and usage data logs (features accessed, session duration, and error diagnostics).
3. How We Use and Share Your Information
We use the collected information to execute your software subscription, operate your multi-tenant clinic dashboards, securely generate prescriptions, and provide technical customer support.
We do not sell your personal information or your patients' data, and we do not use patient health data for advertising or tracking.
Data is shared only with trusted, legally contract-bound sub-processors (such as cloud hosting infrastructure, database engines, or secure payment processing gateways) necessary to maintain the Services.
4. Data Security, Residency, and Retention
Security & HIPAA Safeguards: We employ industry-standard security protocols, including AES-256 encryption for data at rest and TLS 1.2+ for data in transit. We use strict logical multi-tenant isolation to ensure each clinic's clinical data is strictly segregated.
Residency: All production patient records and clinical databases are strictly hosted within India. Health records are not exported outside India for routine operations.
Retention: We retain clinical information for as long as your account is active and for the periods legally mandated under Indian clinical-records retention guidance and international health standards. Residual data is permanently securely deleted or de-identified once retention obligations expire.
5. Data Breach Notification
In the event of a personal data breach, we maintain a documented incident-response plan. We will promptly notify the affected clinics (as Data Fiduciaries) so you can meet your obligations to patients.
Cyber-security incidents will be reported to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of awareness, as per applicable regulations, and to the Data Protection Board of India as required under the DPDP Act, 2023.
6. Grievance Officer and Contact Details
For any privacy requests, questions, or consent withdrawals under the DPDP Act, you may contact our designated Grievance Officer:
Grievance Officer: Meghna P. J. — Sanjeevani Software
Address: 103, Crystal Heights, Madhavdas Pasta Road, Dadar East – Mumbai, Maharashtra, Mumbai 400014
Tel: 9082150055 — Email: meghnapj@gmail.com
We acknowledge all grievances within 48 hours and aim to resolve them within 30 days of receipt.