This policy explains how Caresoft Systems Private Limited ("Caresoft", "we") handles personal data in connection with the Caresoft eICU platform (the "Platform"). It is written for three audiences: hospitals evaluating or using the Platform, clinical users who sign in to it, and patients and families who want to understand how the technology handles their information.
If you are a patient or a family member, the hospital treating you — not Caresoft — decides what is recorded, why, and who may see it.
Your hospital's own privacy notice governs your care. Caresoft is a technology supplier acting under the hospital's instructions. Any request about your records should go to your hospital first. Contact details for the hospital's grievance officer are in its own notice; ours are in Section 15 if you cannot reach them.
| Data | Hospital | Caresoft |
|---|---|---|
| Patient health and physiological data in the Platform | Data Fiduciary / Controller | Data Processor |
| Clinical user accounts, roles and access logs | Controller | Processor |
| Hospital's contract, billing and support records | Counterparty | Controller |
| Our website and enquiry forms | — | Controller |
| System logs required by law | — | Controller |
Processing terms between Caresoft and each hospital are set out in the Data Processing Addendum, which is stricter than this policy in several respects and prevails for hospital customers.
Determined by the hospital, but typically:
All of this is health data. It is sensitive in every framework that applies to it, and we treat it as such throughout. We do not process any other special category of data.
The hospital establishes the lawful basis. Under India's Digital Personal Data Protection Act, 2023 this will typically be consent, or one of the Act's specified legitimate uses.
Critically ill patients frequently cannot give consent. The Act recognises this: it permits processing for taking measures to provide medical treatment or health services during an epidemic, outbreak, threat to public health, or during a medical emergency involving a threat to the life or immediate health of the person concerned.
Where a patient lacks capacity, the hospital is responsible for obtaining consent from a lawful guardian where required, and for recording the basis relied upon. Caresoft does not make that determination and cannot make it on the hospital's behalf.
Where a patient is a child, the hospital is responsible for verifiable consent from a parent or lawful guardian, and for the Act's restrictions on tracking and targeted advertising directed at children. The Platform performs no tracking or advertising of any kind.
For each user of the Platform we process: name, role, professional identifier where supplied, work email and phone, hospital and unit, account credentials (passwords stored only as salted and peppered one-way hashes), assigned permissions, and a full record of sign-ins, actions and data accessed.
Clinical users should be aware that their activity in the Platform is logged in detail and is auditable by their hospital. This is not surveillance of performance — it is a patient safety and medical-records requirement. Access to a patient's record without a care relationship is detectable and is a disciplinary matter for the hospital.
Organisation name and address, CIN or registration details, GSTIN, named clinical, technical and data protection contacts, licensed bed and user counts, subscription and billing records, and support correspondence. For this data Caresoft is the controller.
Enquiry form submissions, IP address, browser and device information, pages viewed and referrer. Strictly necessary cookies for session and security, and analytics cookies where you consent. Our marketing site sets no advertising cookies. The Platform itself uses only necessary and functional cookies — no analytics or advertising within the clinical portals.
We do not use patient data for our own purposes. We do not sell it, share it for advertising, use it for research or marketing, or use it to train artificial intelligence or machine learning models of any kind. This is a contractual commitment in the Data Processing Addendum §17, not a policy statement we can quietly change.
Only users the hospital has authorised, limited by their assigned role and unit. The hospital controls provisioning and revocation. The Platform enforces role-based permissions and separates the administrative, hospital-admin and clinical portals, with wrong-portal access attempts recorded.
Access is restricted to what is necessary to deliver the service, and occurs only where:
Every such access is individually authenticated, requires multi-factor authentication, and is logged with the person, the time, the record and the stated reason. That log is available to the hospital on request. Production patient data is never copied into development, test, training or demonstration environments.
The Platform can send alerts and reports by email, SMS and WhatsApp to hospital-designated recipients. These travel over third-party networks that we do not control.
Because of this, notification content is minimised and identifiers are masked. A notification is designed to tell a clinician that attention is needed and where, not to carry clinical detail through an insecure channel. Full information is available only after signing in to the Platform.
Hospitals configuring notification content and recipient lists are responsible for keeping those lists current and for ensuring recipients handle messages appropriately — including not forwarding them.
| Data | Retention |
|---|---|
| Patient clinical and physiological data | As instructed by the hospital, consistent with its medical-record obligations. We do not delete it on our own initiative |
| Audit trail of access and clinical entries | With the associated record; immutable, amendments recorded rather than overwritten |
| System logs required by law | Minimum 180 days, held in India (Section 13) |
| Data relating to an open safety or security investigation | Preserved until the investigation is formally closed, regardless of any deletion instruction |
| Backups | Rolling [35] days; deleted data ages out with them |
| Hospital account, contract and tax records | Up to 8 years as required by Indian tax law |
| Support correspondence | [24] months from closure |
| Website enquiries | [24] months, or until you ask us to remove them |
On termination of a hospital's agreement, data is exported to the hospital and then deleted on written confirmation, with certification. See DPA §16.
Measures include: encryption in transit and at rest; cryptographically signed device data with rejection of invalid signatures; role-based access with multi-factor authentication for administrative access; server-side portal separation; immutable audit logging; multi-tenant isolation; no production data in non-production environments; masked identifiers in notification channels; backup with tested restoration; vulnerability scanning and periodic penetration testing; and a documented incident response plan with a patient-safety severity ranked above critical.
The full measures are in DPA Annex II. Security is shared — the hospital is responsible for its network, its device segment, edge agent physical security, and user access hygiene, as set out in the Device Interfacing Policy.
You may have the right to access your data, have it corrected, obtain information about processing, nominate someone to act for you, and raise a grievance. Exercise these with your hospital — it holds your record and decides what happens to it. It has a grievance officer and a defined response time.
If you contact us directly, we will not disclose your records to you; we will refer you to your hospital and tell them you have been in touch within [2] working days. This is not obstruction — we are not permitted to release a hospital's medical records, and we cannot verify your identity as your treating hospital can.
Erasure of a clinical record is limited. Medical records must be retained for periods set by law and accreditation standards, and audit trails are immutable for patient safety and evidential reasons. Your hospital can explain what can and cannot be removed and why.
Your account and activity data belongs to your hospital's record. Raise access or correction requests with your hospital administrator. We will assist them.
Grievance Officer (Information Technology Act, 2000; Digital Personal Data Protection Act, 2023)
Name: Rajeev Pillai
Email:
[email protected]
Address: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107
Acknowledgement within 24 hours; resolution within 15 days.
You may complain to the Data Protection Board of India if you are dissatisfied with our response. If your complaint concerns your care or your medical record, your hospital and its accreditation body are the right route.
Caresoft Systems Private Limited, CIN : U72900MH2022PTC387875.
We may update this policy. The version date at the top will change. Hospitals are notified of material changes at least [30] days in advance; changes reducing protection require the hospital's agreement under the DPA. Where a change affects patients, hospitals are responsible for reflecting it in their own patient notices.