MediConnect
Legal

Privacy Policy

Last updated: February 2026

1. Who we are

MediConnect ("we", "our", "us") is a digital healthcare platform headquartered in Bengaluru, Karnataka, India. We connect patients, doctors and hospitals on a secure, unified medical vault. This policy explains what personal data we collect, how we use it, and the rights you have over it.

2. Data we collect

We collect account information (name, email, phone, role), medical records you choose to upload (bills, prescriptions, lab reports, discharge summaries), appointment metadata, device information, and technical logs required for security and reliability.

3. How we use your data

To provide the platform (record storage, sharing, appointments, prescriptions), to send transactional notifications, to protect against fraud/abuse, to improve the product with aggregated anonymised analytics, and to comply with legal obligations.

4. Your rights and controls

You own your medical records. You can view every access log, revoke sharing at any time, download your data, and request permanent deletion. Doctors and hospitals see only what you explicitly share — nothing more.

5. Security

All records are encrypted in transit (TLS) and at rest. Access is role-based, OTP-verified, protected against brute force, and every read is auditable. Employees do not access your data except in support requests initiated by you.

6. Sharing with third parties

We share data only (a) with doctors and hospitals you have chosen, (b) with regulated infrastructure providers (cloud storage, communications) bound by data-processing agreements, and (c) when compelled by law.

7. Data retention

Medical records are retained for the life of your account. On deletion, all records are permanently removed within 30 days, subject to legal retention requirements.

8. Contact

Questions? Email support.mediconnect@gmail.com.