Privacy Policy

Product: Caresoft eICU  •  Version: 1.1  •  Effective:01/04/2026

This policy explains how Caresoft Systems Private Limited ("Caresoft", "we") handles personal data in connection with the Caresoft eICU platform (the "Platform"). It is written for three audiences: hospitals evaluating or using the Platform, clinical users who sign in to it, and patients and families who want to understand how the technology handles their information.

If you are a patient or a family member, the hospital treating you — not Caresoft — decides what is recorded, why, and who may see it.

Your hospital's own privacy notice governs your care. Caresoft is a technology supplier acting under the hospital's instructions. Any request about your records should go to your hospital first. Contact details for the hospital's grievance officer are in its own notice; ours are in Section 15 if you cannot reach them.

Contents
  1. Who is responsible for what
  2. Patient data we process
  3. Lawful basis, including emergencies
  4. Clinical user data
  5. Hospital account data
  6. Website visitors
  7. Why we process it
  8. Who can see patient data
  9. Notifications and identifiers
  10. Where data is held
  11. How long we keep it
  12. Security
  13. If something goes wrong
  14. Rights and how to exercise them
  15. Contact and Grievance Officer
  16. Changes

1. Who is responsible for what

DataHospitalCaresoft
Patient health and physiological data in the PlatformData Fiduciary / ControllerData Processor
Clinical user accounts, roles and access logsControllerProcessor
Hospital's contract, billing and support recordsCounterpartyController
Our website and enquiry formsController
System logs required by lawController

Processing terms between Caresoft and each hospital are set out in the Data Processing Addendum, which is stricter than this policy in several respects and prevails for hospital customers.

2. Patient data we process

Determined by the hospital, but typically:

All of this is health data. It is sensitive in every framework that applies to it, and we treat it as such throughout. We do not process any other special category of data.

3. Lawful basis, including emergencies

The hospital establishes the lawful basis. Under India's Digital Personal Data Protection Act, 2023 this will typically be consent, or one of the Act's specified legitimate uses.

Critically ill patients frequently cannot give consent. The Act recognises this: it permits processing for taking measures to provide medical treatment or health services during an epidemic, outbreak, threat to public health, or during a medical emergency involving a threat to the life or immediate health of the person concerned.

Where a patient lacks capacity, the hospital is responsible for obtaining consent from a lawful guardian where required, and for recording the basis relied upon. Caresoft does not make that determination and cannot make it on the hospital's behalf.

Where a patient is a child, the hospital is responsible for verifiable consent from a parent or lawful guardian, and for the Act's restrictions on tracking and targeted advertising directed at children. The Platform performs no tracking or advertising of any kind.

4. Clinical user data

For each user of the Platform we process: name, role, professional identifier where supplied, work email and phone, hospital and unit, account credentials (passwords stored only as salted and peppered one-way hashes), assigned permissions, and a full record of sign-ins, actions and data accessed.

Clinical users should be aware that their activity in the Platform is logged in detail and is auditable by their hospital. This is not surveillance of performance — it is a patient safety and medical-records requirement. Access to a patient's record without a care relationship is detectable and is a disciplinary matter for the hospital.

5. Hospital account data

Organisation name and address, CIN or registration details, GSTIN, named clinical, technical and data protection contacts, licensed bed and user counts, subscription and billing records, and support correspondence. For this data Caresoft is the controller.

6. Website visitors

Enquiry form submissions, IP address, browser and device information, pages viewed and referrer. Strictly necessary cookies for session and security, and analytics cookies where you consent. Our marketing site sets no advertising cookies. The Platform itself uses only necessary and functional cookies — no analytics or advertising within the clinical portals.

7. Why we process it

We do not use patient data for our own purposes. We do not sell it, share it for advertising, use it for research or marketing, or use it to train artificial intelligence or machine learning models of any kind. This is a contractual commitment in the Data Processing Addendum §17, not a policy statement we can quietly change.

8. Who can see patient data

8.1 Within the hospital

Only users the hospital has authorised, limited by their assigned role and unit. The hospital controls provisioning and revocation. The Platform enforces role-based permissions and separates the administrative, hospital-admin and clinical portals, with wrong-portal access attempts recorded.

8.2 Caresoft personnel

Access is restricted to what is necessary to deliver the service, and occurs only where:

Every such access is individually authenticated, requires multi-factor authentication, and is logged with the person, the time, the record and the stated reason. That log is available to the hospital on request. Production patient data is never copied into development, test, training or demonstration environments.

8.3 Others

9. Notifications and identifiers

The Platform can send alerts and reports by email, SMS and WhatsApp to hospital-designated recipients. These travel over third-party networks that we do not control.

Because of this, notification content is minimised and identifiers are masked. A notification is designed to tell a clinician that attention is needed and where, not to carry clinical detail through an insecure channel. Full information is available only after signing in to the Platform.

Hospitals configuring notification content and recipient lists are responsible for keeping those lists current and for ensuring recipients handle messages appropriately — including not forwarding them.

10. Where data is held

11. How long we keep it

DataRetention
Patient clinical and physiological dataAs instructed by the hospital, consistent with its medical-record obligations. We do not delete it on our own initiative
Audit trail of access and clinical entriesWith the associated record; immutable, amendments recorded rather than overwritten
System logs required by lawMinimum 180 days, held in India (Section 13)
Data relating to an open safety or security investigationPreserved until the investigation is formally closed, regardless of any deletion instruction
BackupsRolling [35] days; deleted data ages out with them
Hospital account, contract and tax recordsUp to 8 years as required by Indian tax law
Support correspondence[24] months from closure
Website enquiries[24] months, or until you ask us to remove them

On termination of a hospital's agreement, data is exported to the hospital and then deleted on written confirmation, with certification. See DPA §16.

12. Security

Measures include: encryption in transit and at rest; cryptographically signed device data with rejection of invalid signatures; role-based access with multi-factor authentication for administrative access; server-side portal separation; immutable audit logging; multi-tenant isolation; no production data in non-production environments; masked identifiers in notification channels; backup with tested restoration; vulnerability scanning and periodic penetration testing; and a documented incident response plan with a patient-safety severity ranked above critical.

The full measures are in DPA Annex II. Security is shared — the hospital is responsible for its network, its device segment, edge agent physical security, and user access hygiene, as set out in the Device Interfacing Policy.

13. If something goes wrong

14. Rights and how to exercise them

14.1 Patients

You may have the right to access your data, have it corrected, obtain information about processing, nominate someone to act for you, and raise a grievance. Exercise these with your hospital — it holds your record and decides what happens to it. It has a grievance officer and a defined response time.

If you contact us directly, we will not disclose your records to you; we will refer you to your hospital and tell them you have been in touch within [2] working days. This is not obstruction — we are not permitted to release a hospital's medical records, and we cannot verify your identity as your treating hospital can.

Erasure of a clinical record is limited. Medical records must be retained for periods set by law and accreditation standards, and audit trails are immutable for patient safety and evidential reasons. Your hospital can explain what can and cannot be removed and why.

14.2 Clinical users

Your account and activity data belongs to your hospital's record. Raise access or correction requests with your hospital administrator. We will assist them.

15. Contact and Grievance Officer

Grievance Officer (Information Technology Act, 2000; Digital Personal Data Protection Act, 2023)
Name: Rajeev Pillai
Email: [email protected]
Address: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107
Acknowledgement within 24 hours; resolution within 15 days.

You may complain to the Data Protection Board of India if you are dissatisfied with our response. If your complaint concerns your care or your medical record, your hospital and its accreditation body are the right route.

Caresoft Systems Private Limited, CIN : U72900MH2022PTC387875.

16. Changes

We may update this policy. The version date at the top will change. Hospitals are notified of material changes at least [30] days in advance; changes reducing protection require the hospital's agreement under the DPA. Where a change affects patients, hospitals are responsible for reflecting it in their own patient notices.

Home Book a Demo