1. Our Role
We handle personal data in two capacities:
- As a Data Processor for the patient and clinical data your hospital enters into the Service. Your organisation is the Data Fiduciary and decides why and how that data is processed; we process it on your instructions to provide the Service.
- As a Data Fiduciary for the limited account data we collect directly from your administrators and staff to operate our business (for example, name, work email, and billing details).
2. Data We Process
- Account & staff data: names, work email addresses, phone numbers, role, and authentication data of Authorised Users.
- Customer Data (including patient data): patient demographics, clinical records, prescriptions, lab and radiology data, billing, insurance and operational data your organisation enters into the Service.
- Billing data: plan, subscription status, and payment references. Card and bank details are handled by our payment processor and are not stored by us.
- Technical & usage data: log data, device and browser information, IP address, and audit records used for security, troubleshooting and improving the Service.
3. How We Use Data
- To provide, secure, maintain, and improve the Service;
- To authenticate users and enforce access controls and audit trails;
- To process subscriptions and payments;
- To provide support and communicate with you about the Service;
- To detect, prevent and respond to fraud, abuse and security incidents;
- To comply with legal obligations.
We process patient and clinical Customer Data only on your documented instructions and to provide the Service. We do not sell personal data, and we do not use patient data for advertising.
4. Where Data Is Stored
Customer Data is stored on infrastructure located in India through our hosting partner. We take reasonable steps to keep patient data within India.
5. Sub-Processors and Sharing
We use trusted third parties to deliver the Service. They may process data only to provide services to us and are bound by appropriate obligations. These currently include:
- Cloud hosting and database — to host the application and store Customer Data in India;
- Payment processing (Razorpay) — to process subscription payments;
- Messaging providers — to send transactional email, SMS and WhatsApp notifications you enable.
We may also disclose data if required by law, to enforce our Terms, or to protect the rights, safety and security of Uyirly, our users, or the public. We do not otherwise sell or rent personal data.
6. Data Retention
- Customer Data is retained for as long as your account is active.
- After a trial ends without subscription, or after account termination, Customer Data may be retained for a limited window to allow export and then deleted (typically within 30 days), unless a longer period is required by law.
- Certain records (for example, invoices and audit logs) may be retained as required for legal, tax and security purposes.
7. Security
We implement technical and organisational measures to protect data, including encryption in transit, tenant data isolation, role-based access control, and audit logging. See our Security page for details. No system is completely secure, and we cannot guarantee absolute security.
8. Rights of Data Principals
Under the DPDP Act, individuals (data principals) have rights regarding their personal data, including access, correction, and erasure, and the right to grievance redressal. Because patient data is controlled by your hospital, patient requests should be directed to the hospital (the Data Fiduciary), which uses the tools within the Service to fulfil them. For account data we control directly, you may contact us using the details below.
9. Cookies and Similar Technologies
We use strictly necessary cookies and local storage to keep you signed in, maintain your session, and operate core features. We do not use third-party advertising cookies within the application.
10. Children’s and Sensitive Data
The Service is intended for use by healthcare organisations and their staff, not the general public. Patient records may include data about children and sensitive health information; responsibility for the lawful basis and any required consent for such data rests with your hospital as the Data Fiduciary.
11. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will provide reasonable notice by email or in-product notice. The “Last updated” date above reflects the latest revision.
12. Contact and Grievances
For privacy questions or to raise a grievance, contact our privacy team at privacy@uyirly.com. We will acknowledge and respond to grievances within the timelines required by applicable law.