Privacy Policy

1. Introduction

Welcome to VaidyaPlus, a cloud-based healthcare practice management platform owned and operated by VAIDYA PLUS (OPC) PRIVATE LIMITED (“VaidyaPlus“, “we“, “our“, or “us“).

We value the privacy and security of the information entrusted to us. This Privacy Policy explains how we collect, use, store, protect, and disclose personal information when you access or use our website, web application, mobile applications, and related services (collectively, the “Services“).

This Privacy Policy has been prepared in accordance with applicable laws of India, including the Digital Personal Data Protection Act, 2023 (DPDP Act), and other applicable legal and regulatory requirements.

By creating an account, accessing, or using the Services, you acknowledge that you have read and understood this Privacy Policy.


2. Scope of this Privacy Policy

This Privacy Policy applies to:

  • Visitors to our website.
  • Clinics, hospitals, healthcare institutions, and medical practices using VaidyaPlus.
  • Doctors, therapists, receptionists, pharmacists, and other authorized users of the platform.
  • Individuals who contact us regarding our Services.
  • Subscribers to our products and services.

This Privacy Policy applies to all VaidyaPlus websites, applications, and related services operated by VAIDYA PLUS (OPC) PRIVATE LIMITED.


3. Our Role

VaidyaPlus is a Software-as-a-Service (SaaS) platform designed to help healthcare providers manage their practice digitally.

Our Services include, among other things:

  • Patient Management
  • Appointment Scheduling
  • Electronic Medical Records
  • Therapy Management
  • Billing & Invoicing
  • Inventory Management
  • Prescription Management
  • Clinic Administration
  • Multi-Clinic & Multi-Doctor Management
  • Reporting and Analytics

VaidyaPlus is a technology platform only.

We do not:

  • provide medical advice,
  • diagnose illnesses,
  • prescribe medicines,
  • recommend treatments,
  • make clinical decisions,
  • replace the professional judgment of healthcare practitioners.

Medical decisions remain solely the responsibility of licensed healthcare professionals using the platform.


4. Roles and Responsibilities Regarding Personal Data

VaidyaPlus provides software that enables healthcare providers to securely manage information relating to their practice and patients.

4.1 Information relating to Clinics and Users

For information relating to:

  • clinic owners,
  • doctors,
  • therapists,
  • staff members,
  • administrators,
  • billing contacts,
  • subscribers,

VaidyaPlus determines how and why such information is processed for operating and improving the Services. For this information, VaidyaPlus acts as the entity responsible for processing personal information in accordance with applicable law.


4.2 Patient Information

Healthcare providers using VaidyaPlus determine:

  • what patient information is collected,
  • why it is collected,
  • how it is used,
  • and whether patient consent or notices are required under applicable laws.

Accordingly:

  • Healthcare providers are responsible for obtaining any patient consent, permissions, or authorizations required by applicable law before collecting or entering patient information into the Services.
  • Healthcare providers are responsible for ensuring that patient records entered into VaidyaPlus are accurate, lawful, and collected for legitimate healthcare purposes.

VaidyaPlus processes, stores, secures, transmits, and backs up such information solely for the purpose of providing the Services to the healthcare provider.

VaidyaPlus does not determine medical treatment decisions or the purpose for which patient information is collected by healthcare providers.


4.3 Responsibilities of Healthcare Providers

Healthcare providers are responsible for:

  • complying with applicable healthcare laws,
  • complying with applicable privacy laws,
  • obtaining patient consent where required,
  • maintaining the accuracy of patient records,
  • controlling access to patient information within their organization,
  • ensuring that only authorized personnel use the Services.

5. Information We Collect

The information we collect depends on how you interact with our Services and the features you use.


5.1 Information You Provide Directly

When you create an account, subscribe to our Services, contact us, or otherwise interact with VaidyaPlus, we may collect information such as:

Clinic Information

  • Clinic or hospital name
  • Clinic address
  • GST details (if applicable)
  • Registration details (if provided)
  • Contact information

Healthcare Professional Information

  • Name
  • Mobile number
  • Email address
  • Professional designation
  • Specialization
  • Profile photograph (optional)

Staff Information

Healthcare providers may create user accounts for authorized staff members, including:

  • Receptionists
  • Therapists
  • Pharmacists
  • Administrators
  • Other authorized employees

Information may include:

  • Name
  • Contact details
  • Role within the organization
  • Login credentials

5.2 Patient Information Entered by Healthcare Providers

Healthcare providers may enter patient information into the Services as part of managing their practice.

Depending on how the Services are used, this information may include:

  • Patient name
  • Age
  • Gender
  • Contact information
  • Address
  • Medical history
  • Symptoms
  • Clinical notes
  • Diagnosis
  • Prescriptions
  • Therapy records
  • Treatment plans
  • Laboratory reports
  • Uploaded medical documents
  • Appointment history
  • Billing records
  • Payment history
  • Follow-up schedules
  • Other healthcare-related information entered by the healthcare provider.

VaidyaPlus does not collect this information directly from patients. Patient information is entered into the Services by healthcare providers or their authorized staff as part of providing healthcare services.

Healthcare providers are responsible for ensuring they have the appropriate legal authority, patient consent, or other lawful basis, where required, before collecting or entering patient information into the Services.


5.3 Payment Information

When purchasing a subscription, payment transactions are processed through authorized third-party payment providers.

VaidyaPlus may receive limited payment-related information, such as:

  • Payment status
  • Transaction identifier
  • Subscription details
  • Invoice information

We do not store complete debit card numbers, credit card numbers, UPI PINs, CVV numbers, or internet banking credentials.


5.4 Technical Information

When you access the Services, we may automatically collect technical information, including:

  • IP address
  • Browser type
  • Operating system
  • Device type
  • Device identifiers
  • Login timestamps
  • Session information
  • Time zone
  • Error logs
  • Performance metrics
  • Security logs

This information helps us maintain the security, availability, and performance of the Services.


5.5 Usage Information

We may collect information regarding how the Services are used, including:

  • Features accessed
  • Pages visited
  • Login history
  • User preferences
  • Configuration settings
  • Application activity
  • Error reports

This information helps us improve functionality, reliability, and user experience.


5.6 Communications

If you contact VaidyaPlus through email, support requests, telephone, or other communication channels, we may retain:

  • Your contact information
  • Correspondence
  • Support requests
  • Feedback
  • Complaint details
  • Resolution history

These records help us provide customer support and improve our Services.


5.7 Cookies and Similar Technologies

Our website may use cookies and similar technologies necessary for:

  • User authentication
  • Session management
  • Security
  • Website functionality
  • Performance optimization

At the time of publication of this Privacy Policy, VaidyaPlus does not use third-party analytics or advertising cookies such as Google Analytics or Meta Pixel. If such technologies are introduced in the future, this Privacy Policy and, where applicable, our Cookie Policy will be updated accordingly.


5.8 Information We Do Not Intentionally Collect

We do not intentionally collect personal information beyond what is reasonably necessary to provide our Services.

We do not knowingly collect personal information directly from patients unless they interact with VaidyaPlus through a feature specifically intended for patient use.

Where patient information is processed within the Services, it is entered and managed by healthcare providers or their authorized personnel in connection with the healthcare services they provide.

6. How We Use Information

VaidyaPlus processes personal information only to the extent reasonably necessary to provide, maintain, secure, improve, and support the Services.

We do not sell personal information or use patient medical records for advertising or marketing purposes.

Depending on the nature of the information collected, we may use it for the following purposes.


6.1 To Provide the Services

We use information to:

  • Create and manage user accounts.
  • Authenticate users.
  • Operate healthcare practice management features.
  • Maintain patient records entered by healthcare providers.
  • Schedule appointments.
  • Generate prescriptions.
  • Manage therapies.
  • Generate invoices and billing records.
  • Support inventory and pharmacy management.
  • Enable multi-clinic and multi-user access.
  • Synchronize information across authorized devices.
  • Provide software updates and new features.

6.2 To Process Patient Information on Behalf of Healthcare Providers

Where healthcare providers enter patient information into the Services, VaidyaPlus processes that information solely to:

  • securely store patient records;
  • make patient records available to authorized users designated by the healthcare provider;
  • generate reports requested by the healthcare provider;
  • facilitate appointment management;
  • support clinical documentation;
  • maintain encrypted backups;
  • restore information when necessary;
  • provide technical support.

VaidyaPlus does not use patient medical records to:

  • advertise products or services;
  • create marketing profiles;
  • sell patient information;
  • make automated medical decisions;
  • determine treatment plans.

6.3 To Improve the Services

We may use technical and operational information to:

  • improve software performance;
  • identify bugs;
  • develop new features;
  • enhance usability;
  • improve system reliability;
  • optimize infrastructure;
  • improve customer experience.

Where possible, such analysis is performed using aggregated or de-identified information.


6.4 Customer Support

Information may be used to:

  • respond to inquiries;
  • resolve technical issues;
  • investigate reported problems;
  • provide implementation assistance;
  • communicate service-related updates.

6.5 Security

We process information to protect the Services and our users by:

  • detecting unauthorized access;
  • preventing fraud;
  • monitoring suspicious activities;
  • investigating security incidents;
  • protecting patient information;
  • protecting customer accounts;
  • maintaining audit records;
  • improving platform security.

6.6 Legal and Regulatory Compliance

We may process information where necessary to:

  • comply with applicable laws;
  • comply with lawful requests from government authorities;
  • respond to court orders;
  • establish, exercise, or defend legal claims;
  • comply with taxation and accounting obligations.

6.7 Service Communications

We may contact users regarding:

  • account verification;
  • password resets;
  • subscription renewals;
  • invoices;
  • payment confirmations;
  • maintenance notifications;
  • important security alerts;
  • changes to our Services;
  • updates to our policies.

These communications are considered part of the Services and cannot always be opted out of while an account remains active.


6.8 Product Updates and Marketing Communications

With your consent where required by applicable law, we may send information about:

  • new features;
  • product announcements;
  • educational content;
  • webinars;
  • promotional offers.

You may unsubscribe from promotional communications at any time using the unsubscribe option provided or by contacting us.

Service-related communications necessary for the operation of your account may continue to be sent.


6.9 Internal Administration

We may use information for legitimate internal business purposes, including:

  • maintaining business records;
  • financial reporting;
  • subscription management;
  • customer relationship management;
  • auditing;
  • compliance management;
  • disaster recovery planning;
  • service continuity.

6.10 We Do Not Sell Personal Information

VaidyaPlus does not:

  • sell personal information;
  • rent personal information;
  • trade personal information;
  • monetize patient medical records.

Patient information processed through the Services remains under the control of the healthcare provider that collected it and is processed by VaidyaPlus only for the purpose of delivering the Services.

 

7. How We Share Information

VaidyaPlus does not sell, rent, or trade personal information.

We only share personal information where it is reasonably necessary to provide the Services, comply with legal obligations, protect our rights, or with the authorization of the healthcare provider.


7.1 Sharing with Healthcare Providers

Patient information entered into the Services is accessible only to authorized users of the respective clinic, hospital, or healthcare organization as determined by that organization.

Depending on the permissions assigned by the healthcare provider, patient information may be accessible to:

  • Doctors
  • Therapists
  • Receptionists
  • Pharmacists
  • Administrators
  • Other authorized personnel

Healthcare providers are responsible for assigning appropriate access permissions and ensuring that only authorized personnel can access patient information.


7.2 Service Providers

We may share limited information with trusted third-party service providers that assist us in operating and delivering the Services.

These providers may include services for:

  • Secure website delivery and network protection
  • Cloud infrastructure and hosting
  • Payment processing
  • Data backup and disaster recovery
  • Customer support
  • Email delivery
  • Security monitoring

These service providers are permitted to process information only to the extent necessary to provide services to VaidyaPlus and are expected to maintain appropriate security and confidentiality measures.

At the time of publication of this Privacy Policy, our primary service providers include:

  • Cloudflare – Content delivery, website performance, and security.
  • PhonePe – Subscription payment processing.

Additional service providers may be added as our Services evolve. This Privacy Policy will be updated where appropriate.


7.3 Legal Requirements

We may disclose information where we believe such disclosure is necessary to:

  • comply with applicable laws;
  • comply with lawful requests from government authorities;
  • respond to court orders or legal process;
  • enforce our agreements;
  • protect the rights, safety, or property of VaidyaPlus, our users, or others;
  • investigate fraud, security incidents, or unlawful activities.

7.4 Business Transfers

If VaidyaPlus undergoes a business transaction such as:

  • merger,
  • acquisition,
  • corporate restructuring,
  • investment,
  • sale of assets,
  • insolvency,
  • or other transfer of ownership,

personal information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality obligations.

Where required by law, affected users will be notified.


7.5 Professional Advisors

We may disclose information to professional advisors where reasonably necessary, including:

  • legal counsel;
  • accountants;
  • auditors;
  • tax consultants;
  • compliance advisors.

Such disclosures will be limited to what is reasonably necessary for the services being provided.


7.6 With Your Instructions

We may share information where you, or an authorized representative of your organization, instruct us to do so.

Examples include:

  • exporting records;
  • migrating data;
  • integrating with third-party software;
  • providing technical assistance requested by your organization.

7.7 We Do Not Sell Personal Information

VaidyaPlus does not:

  • sell personal information;
  • rent personal information;
  • license personal information to advertisers;
  • share patient records for advertising purposes;
  • use patient medical information for behavioral advertising.

Patient information is processed solely for the purpose of providing the Services requested by healthcare providers.


7.8 No Public Disclosure

Patient information stored within VaidyaPlus is not publicly accessible.

Information is disclosed only:

  • to authorized users of the subscribing healthcare provider;
  • to trusted service providers acting on our behalf;
  • where required by applicable law;
  • or with appropriate authorization.

7.9 User Responsibility for Data Shared Outside the Platform

Healthcare providers and authorized users are responsible for ensuring that any patient information exported, downloaded, printed, emailed, shared, or otherwise disclosed outside the VaidyaPlus platform is handled in accordance with applicable laws, professional obligations, and organizational policies.

VaidyaPlus is not responsible for disclosures made by users after information has been exported or shared outside the Services.

7.10 Confidentiality and Protection of Platform Information

To protect the security, confidentiality, and intellectual property of the Services, users agree to use VaidyaPlus only for the legitimate operation of their healthcare practice.

Users shall not, except as expressly permitted by VaidyaPlus or required by applicable law:

  • Record, livestream, broadcast, or otherwise reproduce the VaidyaPlus interface, workflows, documentation, training materials, or proprietary features for commercial purposes or public distribution.
  • Copy, reproduce, modify, reverse engineer, decompile, scrape, or attempt to extract the source code, underlying algorithms, databases, or proprietary functionality of the Services.
  • Share screenshots, recordings, confidential documentation, or technical information that may expose security mechanisms or proprietary business information without prior written authorization from VaidyaPlus.
  • Use the Services to develop, promote, or support competing products or services.

Nothing in this section prevents users from creating screenshots or recordings solely for legitimate internal training, operational documentation, support requests, regulatory compliance, or legal purposes, provided such use does not disclose confidential patient information or infringe the intellectual property rights of VaidyaPlus.


7.11 Account Credentials and Authorized Access

Each user account is intended for use only by the individual or authorized personnel to whom it has been assigned.

Users shall:

  • Maintain the confidentiality of their login credentials.
  • Ensure that passwords are not shared with unauthorized persons.
  • Restrict access to authorized personnel within the subscribing clinic, hospital, or healthcare organization.
  • Immediately notify VaidyaPlus if they become aware of any unauthorized access or compromise of their account.

Healthcare providers are responsible for ensuring that former employees, contractors, interns, or other personnel who no longer require access have their accounts disabled or removed promptly.

Unauthorized sharing, transfer, sale, or misuse of login credentials may result in suspension or termination of access to the Services and any other remedies available under applicable law.

8. Data Security

VaidyaPlus is committed to protecting the confidentiality, integrity, and availability of the information processed through the Services.

We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, loss, misuse, or destruction.

However, no method of electronic transmission or storage can be guaranteed to be completely secure. While we continuously improve our security practices, we cannot guarantee absolute security.


8.1 Security Measures

Depending on the Services being used, VaidyaPlus may implement security measures including:

  • HTTPS/TLS encryption for data transmitted between users and the Services.
  • Encryption of sensitive data where appropriate.
  • Role-based access controls.
  • Secure authentication mechanisms.
  • Session management and automatic session expiration.
  • Password hashing using industry-accepted cryptographic methods.
  • Database access restrictions.
  • Firewall and network security controls.
  • Security monitoring and logging.
  • Automatic encrypted backups.
  • Disaster recovery procedures.
  • Periodic software updates and security patches.

Security measures are reviewed and updated as technology and operational requirements evolve.


8.2 Hosting and Infrastructure

At the time of publication of this Privacy Policy, VaidyaPlus primarily stores and processes customer information on infrastructure located in India, including servers hosted in Mumbai.

Our infrastructure providers are selected based on their ability to support secure and reliable service delivery.


8.3 Access Controls

Access to customer and patient information is restricted using role-based permissions.

Healthcare providers determine which authorized users within their organization may access different categories of information.

VaidyaPlus personnel are granted access to customer information only where reasonably necessary for:

  • providing technical support;
  • maintaining the Services;
  • investigating security incidents;
  • performing system maintenance;
  • complying with applicable laws;
  • protecting the security and integrity of the platform.

Such access is limited to authorized personnel who are subject to confidentiality obligations and appropriate internal access controls.


8.4 Account Security Responsibilities

Users are responsible for maintaining the security of their accounts.

Users should:

  • choose strong passwords;
  • keep passwords confidential;
  • avoid sharing login credentials;
  • sign out from shared or public devices;
  • promptly report suspected unauthorized access.

Healthcare providers are responsible for ensuring that only authorized personnel have access to their VaidyaPlus accounts.


8.5 Backup and Business Continuity

To help protect customer information against accidental loss, VaidyaPlus performs regular backups of system data.

Backups are intended to support:

  • disaster recovery;
  • business continuity;
  • restoration of services following technical failures.

Backup retention periods may vary depending on operational requirements and legal obligations.


8.6 Security Monitoring

We monitor our systems for activities that may indicate:

  • unauthorized access;
  • attempted intrusions;
  • fraud;
  • abuse of the Services;
  • malware;
  • denial-of-service attacks;
  • other security threats.

Where appropriate, security events may be investigated to protect our users, our platform, and applicable legal rights.


8.7 Security Incident Response

If VaidyaPlus becomes aware of a security incident affecting personal information under our control, we will investigate the incident and take appropriate measures to contain, assess, and remediate its impact.

Where required by applicable law, we may notify affected healthcare providers and relevant authorities.

Healthcare providers remain responsible for fulfilling any legal obligations that apply to patient information they control, including notifications they may be required to provide under applicable healthcare or privacy laws.


8.8 User Responsibilities

The security of patient information also depends on how users operate the Services.

Healthcare providers and authorized users should:

  • restrict access to authorized personnel;
  • maintain secure devices;
  • use updated operating systems and browsers;
  • protect passwords and authentication credentials;
  • avoid sharing accounts;
  • promptly revoke access for former employees or contractors;
  • ensure exported patient information is stored and shared securely.

VaidyaPlus cannot be responsible for security incidents resulting from unauthorized disclosure of credentials, insecure devices, or misuse of exported data by users.


8.9 Reporting Security Concerns

If you believe you have discovered a security vulnerability or unauthorized access relating to VaidyaPlus, please notify us as soon as possible.

Security concerns may be reported to:

Email: admin@vaidyaplus.com

We request that security concerns be reported responsibly and in good faith to allow us an opportunity to investigate and address the issue.

 

Simplifying Clinic Operations, Digitally

Company

About Us

Contact Us

Products

Services

Blog

Privacy

Terms

Privacy Policy

Conditions

Vaidya Plus™ © 2020 – Present | All Rights Reserved