Data Residency
Customer Data is hosted on infrastructure located in India. We take reasonable steps to keep patient data within India, aligned with the expectations of the Digital Personal Data Protection Act, 2023.
Encryption
- In transit: all traffic between your browser or mobile app and the Service is encrypted using TLS (HTTPS).
- At rest: data stored in our managed database and file storage is encrypted at rest by our hosting provider.
Tenant Isolation
Uyirly is multi-tenant by design. Every hospital operates on its own subdomain, and data access is scoped to the tenant at the database layer using row-level security. This is enforced on every request so one hospital cannot access another hospital’s data.
Access Control
- Role-based access control (RBAC): users are granted permissions based on their role (for example, doctor, nurse, pharmacist, billing, or administrator).
- Least privilege: staff see only the modules and data their role requires.
- Authentication: accounts are protected by passwords and secure session handling. Administrators control who has access and can revoke it at any time.
Audit Logging
Key actions within the Service are recorded in tamper-resistant audit logs, giving administrators visibility into who did what and when. This supports accountability, incident investigation and compliance.
Backups and Availability
Customer Data is backed up regularly by our managed infrastructure provider to support recovery in the event of a failure. We monitor the platform and work to maintain high availability, with maintenance scheduled to minimise disruption.
Secure Development
- Access to production systems is restricted and controlled.
- We use trusted, industry-standard infrastructure and payment providers.
- We apply security updates and improvements on an ongoing basis.
Payments
Subscription payments are processed by Razorpay, a PCI-DSS compliant payment provider. We do not store your card or bank account numbers on our systems.
Your Responsibilities
- Manage user accounts and remove access promptly when staff leave.
- Use strong, unique passwords and keep credentials confidential.
- Grant each user only the role and access they need.
- Follow your own regulatory and consent obligations as the Data Fiduciary.
Reporting a Vulnerability
If you believe you have found a security vulnerability, please report it responsibly to security@uyirly.com. We appreciate disclosures that give us a reasonable opportunity to investigate and address the issue before it is made public.
Contact
For security questions, contact security@uyirly.com.