Privacy Policy
Our role
Under the Digital Personal Data Protection Act 2023, the doctor using Medveda EMR is the Data Fiduciary for their patients’ records. We are a Data Processor: we hold and process that data on the doctor’s instructions, and we do not decide the purposes it is used for.
For a doctor’s own account information — their name, registration details, contact and billing — we are the Data Fiduciary.
What we process on a doctor’s behalf
Patient identity: name, phonetic name, date of birth and how precisely it is known, and gender. Exactly one identifier — an ABHA number, a mobile number, or a clinic-issued UHID.
The clinical record: consultations, visits, vital signs, examination findings, diagnoses, clinical notes, recorded allergies, laboratory reports and results, prescriptions and the medicines on them, and documents issued such as prescriptions and certificates.
Also: consent records, family links between patients, corrections to records, and merges of duplicate records.
What we process for ourselves
The doctor’s name, contact details and professional registration; sign-in sessions; counts of prescriptions issued, for billing; and payments.
Consent
Consent is recorded per purpose, not as a single blanket grant. The exact wording shown to the patient is stored alongside the record, so what they agreed to can be read later rather than inferred.
Consent can be withdrawn at any time. The record of it is kept, because it is the evidence that processing was lawful up to the moment it was withdrawn.
Where the data is kept
In India, in the Mumbai region. This is enforced technically rather than merely intended: an organisation-wide rule denies our systems the ability to operate in any other region.
Who we share it with
Nobody. Medveda EMR sends no patient data to any third party. There is no messaging vendor, no email vendor and no artificial-intelligence service in the path. If this changes, this page will be updated before it changes, not after.
Our infrastructure is provided by Amazon Web Services, who host the data in India under a data-processing agreement.
Cookies
One cookie, which keeps you signed in. No analytics, no advertising, and no third-party trackers of any kind.
How long we keep it
For as long as the doctor’s account is active. When an account ends, records remain available for export for 90 days and are then permanently deleted.
Access transparency
Every read of a patient record is logged. A doctor can see who accessed a record and when.
Your rights
Because the doctor is the Data Fiduciary for patient records, a patient exercises their rights — access, correction and erasure — through their doctor. We assist the doctor in answering those requests.
Grievances
Amit Kumar Tiwari, Grievance Officer — support@medvedaemr.com
Changes to this policy
Changes are posted to this page with an effective date. Material changes take effect no sooner than 30 days after posting. Continued use of the service after the effective date constitutes acceptance.