Comprehensive Privacy & Data Management Policy

Last updated: July 26, 2026

1. Preamble & Scope of Policy

Health Align (referred to herein as "Health Align", "we", "us", or "our") operates a high-integrity clinical operating network, providing digital prescription writer platforms, electronic medical records (EMR) portals, and clinic chamber organization systems. Data safety, digital trust, and confidentiality represent the core principles of our technology systems. This Privacy Policy details the exact specifications, procedures, and legal guidelines under which we handle personal, professional, and patient health datasets.

This policy binds all registered medical practitioners, clinic staffs, agents, and system operators using the platform. Health Align acts as a Data Processor concerning patient clinical records and health logs entered by practitioners, who remain the primary Data Controllers. We act as a Data Controller for registration credentials and logging histories of our registered practitioners.

2. Categories of Information Collected

2.1 Practitioner Registration & Profile Details

To construct a verified clinical workspace, we collect the following practitioner details during registration and onboarding processes:

  • Full Name, professional degrees, specialization details, and medical registration council numbers.
  • Active mobile phone numbers, email addresses, and communication logs.
  • Chamber addresses, visiting hours, fees structures, and signature files used in digital prescription branding.

2.2 Patient Health Records & Clinical Logs

Under the direct guidance and inputs of authorized practitioners, the platform stores:

  • Patient identifiers including names, gender, age, contact telephone numbers, and weight indices.
  • Medical complaints, clinical findings, chronic illnesses, vital signs, and past surgical histories.
  • Prescribed medicines, diagnostic test requests, follow-up timelines, and clinical guidance instructions.

3. Operational Usage of Data

We process practitioner and clinical datasets exclusively to provide the software services requested. Specifically, data usage covers:

  • Validation of clinical credentials to prevent fraudulent account registration on the doctor network.
  • Generation, formatting, and secure storage of digital prescriptions in accordance with clinical standards.
  • Facilitation of queue organization and appointment logging systems across different clinic chambers.
  • Delivery of transaction records, payouts logs, and system analytics reports for practice monitoring.

4. Data Encryption & Security Safeguards

We employ strict, multi-tiered defensive configurations to protect databases from unauthorized access:

  • In-Transit Security: All API requests and clinical data exchange are routed via HTTPS using TLS 1.3 encryption keys.
  • At-Rest Security: All core databases are protected with AES-256 block encryption. Backup storage objects are fully encrypted.
  • Zero-Trust Access: Network configurations utilize secure database connections. Database root access is strictly restricted to isolated DevOps security units.

5. Retaining and Scrubbing Datasets

Practitioner profile credentials and transaction records are stored as long as the account remains active. Upon account deletion requests, our database system executes a global cascade:

All associated doctor profiles, chamber mappings, patient appointment tables, and active login sessions are permanently deleted and purged from our production databases. Stored browser artifacts like local storage structures are automatically cleared via automatic security checks.

6. Privacy Compliance & Contact Channels

For formal data requests, data correction demands, or general questions regarding our privacy rules, please contact our data safety division:

Health Align Compliance & Security Desk
Email: privacy@healthalign.in
Helpline: +91 95316 54447