Skip to content

Privacy Policy

Last updated

AppZad ("we", "us") provides hospital management software (the "Service") to hospitals and clinics ("organizations"). This policy explains what information we handle when you use the Service or this website, why we handle it, and the choices you have.

Organizations use AppZad to keep their own records. For the patient and healthcare information an organization enters, the organization decides what is recorded and why, and we handle it on the organization's behalf. If you are a patient, your hospital or clinic is the right first contact for questions about your records.

1. Information we collect

Account information. When you are invited to AppZad and sign in, we hold your name, email address and, if you add it, your mobile number. Sign-in itself is handled by our authentication provider (see section 7).

Organization and user information. For each organization we hold the details its staff enter: the hospital's name, address, contact numbers, licence and business identification numbers, website, clinic hours, logo and letterhead image. We also hold the list of staff who have access to the organization, and the email addresses of people who have been invited.

Patient and healthcare information entered by users. Staff of an organization enter information about their patients and doctors, including:

  • patient details such as name, contact numbers, date of birth or age, gender, guardian, address, and identity and insurance details;
  • appointments, including the doctor, date, time slot and token number;
  • out-patient (OP) visits, including vitals and billing amounts;
  • prescriptions, including complaints, history, diagnosis, investigations, medicines, advice and the next visit date;
  • doctor details such as name, qualifications, registration number, fee, time slots and signature.

Support requests. When you send a support request from inside the Service, we receive its subject, description and any file you attach.

Technical information. Our hosting providers keep standard server logs, which can include your IP address, browser type and the time of each request. The Service uses cookies that are necessary to keep you signed in. This website does not use advertising or analytics cookies.

2. How we use information

We use the information described above to:

  • provide the Service to your organization, including showing records to its staff and producing prescription PDFs;
  • sign you in and check that you have access to an organization;
  • send service messages such as sign-in codes and invitations;
  • answer support requests;
  • keep the Service secure and find and fix problems.

We do not sell personal information. We do not use patient information for advertising.

3. Data storage

Records are stored in a hosted database operated by the service providers listed in section 7. At the time of writing, our database and application servers run in data centres in Singapore, which may be outside the country where your organization is located.

Prescription PDFs are created when a user downloads them and are not stored by us.

4. Security

We take reasonable steps to protect the information we hold:

  • every page of the Service, and every request to our servers, requires a signed-in account;
  • every request is checked against the organization the signed-in person has access to, so that one organization's records are not shown to another;
  • connections to the Service are made over HTTPS;
  • files uploaded to the Service are checked for type and size.

No method of storage or transmission over the internet is completely secure, and we cannot guarantee absolute security. If you believe an account or record has been accessed without permission, tell us straight away at the address in section 10.

5. Access control

Access to an organization is by invitation. An administrator of the organization invites staff by email and can remove a person's access at any time. Every person with active access to an organization can view and edit that organization's records in the Service, so organizations should invite only the staff who need that access.

A small number of AppZad staff can access an organization's information when that is needed to set up the organization, answer a support request or keep the Service working.

6. Sharing of information

We share information only:

  • with the service providers listed in section 7, who process it for us;
  • when the law requires it, or to respond to a valid legal request;
  • with your organization's consent or at its direction.

7. Service providers

We use the following providers to run the Service. Each handles information for us under its own terms and privacy policy.

  • Clerk: sign-in and account management, including sign-in and invitation emails.
  • Neon: database hosting.
  • Railway: hosting of our application servers.
  • Vercel: hosting of the web application and this website.

We will update this list when our providers change.

8. Data retention

We keep an organization's records for as long as the organization uses the Service. When a user deletes a record in the Service, it is removed from the live database. Removing a staff member's access does not delete their account or the records they created.

When an organization stops using the Service, it can ask us to delete its records by writing to the address in section 10. We may keep information for longer where the law requires us to.

9. Your rights

If you have an AppZad account, you can view and change your name and mobile number in My Account inside the Service.

You may ask us for access to, correction of or deletion of personal information we hold about you. If the information was entered by an organization, such as a patient record, we will normally refer your request to that organization, because it controls those records. We respond to requests as the law that applies to us requires.

10. Contact

For any question about this policy or about how your information is handled, email appzadhq@gmail.com.

11. Changes to this policy

We may update this policy as the Service changes. When we do, we will change the "Last updated" date at the top of this page.