Cureambit Privacy Policy

Version 1.4

21st April 2021

Please read the policy carefully before using Cureambit Private Limited Services. This Privacy Policy is drafted in simple English, is concise, and takes less time to read. It is meant to help you understand what information we collect, when we collect, why we collect it, and how we use it.

Cureambit Private Limited (“us”, “our”, “we”) respects the privacy of every individual and is committed to protecting the privacy and security of the information we gather through our product and services. It is vitally important to us that our users (“Customers”, “you”) feel secure when using the Services. 

Introduction

1

Cureambit is a healthcare technology company offering product and services to the stakeholders of healthcare industry to enhance the quality of the healthcare journey.

 

This Privacy Policy (the “Privacy Policy”) applies to all the Personal Information (“Sensitive Personal Information”) processed by Cureambit Private Limited, a company incorporated under the provisions of the (Indian) Companies Act, 2013 having its registered office at B/1703, Ekta Meadows, Magathane, Borivali East, Mumbai 400066, India.

 

When you use our product and services, you give us consent for the use of your personal information as outlined in this privacy policy. 

 

This Privacy Policy is in compliance with, Section 43A of the Information Technology Act, 2000, Regulation 3(1) (Intermediaries Guidelines) & 4 (Reasonable Security Practices & Procedures and Sensitive Personal Information) of the Information Technology Rules, 2011.

 

Suggestions, queries, and requests regarding this Privacy Policy shall be addressed to dp@cureambit.com

How and when do we collect you data?

2

The personal and non-personal information is collected when you use our mobile application(s) (“App”), when and where available, our web-based application (“Web-embed”) our tool(s) (“Tool”), or accessing our website cureambit.com (“Website”) or any service and/or product we may provide you for achieving one or more of below services; 

We collect the data and process it when you;

  • Use our services from our customers

  • Register online for our services

  • Participate in surveys or provide feedback

  • Subscribe to our newsletter

What information does Cureambit collect, why we collect it and how do we use it?

3

We do not sell your personal information to third parties nor do we use the information to personally identify you for our own purpose without your consent. We may use the data in aggregate or in anonymous form in developing new functionalities and services in your vital interest.

 

Note: It is not possible to use our services if the non-optional data are not provided.

Personal General Information

3.1

Processing of Personal General Information is required for creating a user account, providing access to the account, and using our services.

Type of data;

  1. First Name

  2. Last Name

  3. Middle Name (Optional). This information will be used in case of account conflict to further validate the individual identity

  4. Date of Birth

  5. Gender

  6. Photograph

  7. Address

  8. Mobile Number

  9. Email Address

  10. Passwords

  11. Cureambit Id

Auto Collected Information

3.2

Processing of Auto Collected Information is required in establishing an internet connection, to ensure easy and proper use, functioning maintenance, and improving our services, analyzing system security & stability and administrative purposes. 

Type of data;

  1. IP Address

  2. Mobile IMEI Number / Device Id

  3. User preferences and session activities

Physician Specific Personal Information

3.3

Processing of physician-specific personal information is essential to confirm the identity and verify the authenticity of physician qualifications and credentials. By providing your EPIC ID, you authorize Cureambit and the Educational Commission for Foreign Medical Graduates (ECFMG) to exchange your personal information in order to confirm your identity and verify the authenticity of your submitted qualifications. The information collected will be processed as per the privacy policy of Cureambit. The Privacy Policy of ECFMG can be accessed at https://www.ecfmg.org/annc/privacy.html

Type of data;

  1. Physician unique identifiers like medical registration number, EPIC ID, and similar which we may found appropriate to maintain the highest quality of physician and credential authentication

  2. Physician medical school transcripts, educational and qualification certificates

  3. Physician experiences, achievements, and awards (Optional)

  • This information will help enhance physician credentialing in the public domain

Patient Specific Personal Information

3.4

Processing of patient personal data is necessary for the purposes of preventive or occupational medicine, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services on the basis of defined law of India or pursuant to contract with a health professional keeping the vital interests of the patient.

Type of data;

  1. Patient Information (as outlined in Personal General Information)

  2. Medical and health records

  3. Allergies and habitats

  4. Tests and lab reports

  5. Other medical assessments as necessitated by healthcare professional

User Provided Optional Information

3.5

The information provided by you is optional and is used for your convenience; like directions to the clinic, adding, maintaining, and accessing the medical records with ease for self and family. The information provided will be processed as per this privacy policy

Type of data;

  1. Location

  2. Uploading medical and health records for self by the user

  3. Adding family members & their information (as outlined in Personal General Information)

  4. Uploading medical and health records for added family members

Note: Adding family members under your (user) identity is limited only to your (user) living family members and guardians and you (user) agree(s) to have obtained all required approvals oral, written, or as per the governing law of India or applicable law of the user or from the added living individuals whose data you provide to us prior their sharing of data with us.

Employee Provided Information

3.6

(Employee of Cureambit and employee of healthcare provider who use our services)

The information provided by you &/or by your employer will be held as proof of identity for security purposes. The data shall be accessed by relevant entities and authorized individuals only.     

  1. Photocopies of government authorized documents related to identity, residence proof, and nationality (Optional)

  2. Fitness certificate (Optional)

  3. Other relevant documents as necessitated by the employer &/or as applicable by law

Cookies and Similar Technologies

3.7

Cookies are small bits of data that are stored on the user device (computers, smartphones, or tablets). Cookies are necessary to enable basic features on our website. Most browsers allow you to control cookies, including whether or not to accept &/or remove them. You may set most browsers to notify you if you receive a cookie, or you may choose to block cookies with your browser. Please note that if you delete or choose not to accept cookies from us, you may not be able to use certain features of our Services. We may also use session cookies which are active and available only the time you are logged into the service.

Children

3.8

Cureambit services are not directed to children users, as defined by applicable law. We do not intend to collect personal information from children and the condition is applicable exclusively to the use of our platform by children. This condition is not applicable for children’s personal information, medical or health records generated or uploaded by the authorized users.  In cases where you find children as a user and underlying information is provided by children,  we request you to bring it to our attention by emailing us at dp@cureambit.com and we will try to destroy the information at the earliest possible time.

Where do we store personal information?

4

The personal information we collect is stored in India on cloud servers of Amazon Web Services India Limited or otherwise as specified by the law of the user country. The data may, however, be processed by sub-processors operating outside the defined location. 

 

Sensitive information from users of Cureambit services to Cureambit systems is transferred in encrypted form using standard industry processes. Also, we will handle your personal information in accordance with this Privacy Policy regardless of where your personal information is stored or processed.

Disclosures of personal information?

5

We use technical service providers to operate and maintain our services who act as processors based on data sharing agreements. A full list of 3rd party processors can be found here. We do not transfer your personal data to third parties; with the exception of the purpose mentioned here within.

  • If we sell or buy any business or assets, we may disclose your personal information to the prospective seller or buyer of such business or assets

  • If we, or substantially all our assets are acquired by a third party, personal information of our users will be one of the transferred assets

  • If we are required by the law of India (limited to residents of India) or governing law of the user country to disclose or share your personal information.

  • We may disclose certain information to organizations for research and clinical trial purposes, where you have explicitly authorized us to do so.

Information Security

6

We use a combination of process, technology, and physical security controls to help protect your information from unauthorized access, use, or disclosure, but remember that no method of transmission over the Internet, or method of storage, is 100% secure.

How long we retain personal information?

7

We will hold the personal information for as long as it is necessary in order to provide you with the services, deal with any specific issues that may arise, or otherwise as it is required by law or any relevant regulatory body.

 

Your data is deleted or irreversibly anonymized when you request deletion of your account. If your account is inactive for more than 36 months, we will contact you to check your wish in continuing the account. If you acknowledge continuing with your account, we will repeat the process in case the account is unused for straight 12 months. We will wait for 30 days for your reply and if unanswered our request, we will delete your account and anonymize your data. If by any chance the data could not be anonymized then it will be securely permanently destroyed.

 

Even after the deletion of the account or termination, we may hold patient records for the period of 7 years as required by the law of India or more as governed by the law of the participating countries.

 

We restrict access to your personal information to the individuals or entities who need to use it for relevant purposes as outlined in this Privacy Policy.

Data Protection Rights

8

Cureambit would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:

  • You have the right to request Cureambit for copies of your personal data. We may charge you a small fee for this service.

  • You have the right to request that Cureambit correct any information you believe is inaccurate or incomplete. 

  • You have the right to request that Cureambit deletes your personal data. In most cases, we irreversibly anonymized your data and if that is not applicable then we permanently destroy your data in a secured way. In some cases, if personal data is required to be held by law, then will abide by the law.

 

For any of the above-mentioned requests, please reach us at dp@cureambit.com. All requests are responded to in a timely manner not exceeding 30 days from the date of request. For processing such rights Cureambit will take reasonable efforts to validate your identity and in some cases, we may even request legal validation as appropriate.

Changes to this Policy

9

Any changes to our Privacy Policy in the future will be posted here and will be immediately in effect. Where appropriate, users will be notified via SMS or email or app, limited to the correct and updated communication information is provided by the user. We still encourage you to review the Privacy Policy at regular intervals.