AiHospitalERP

Privacy Policy

Your Privacy Matters to Us

At AiHospitalERP, we are committed to protecting the privacy of healthcare providers, their staff, and their patients. This policy outlines how we handle B2B data securely.

Last updated: May 18, 2026
A product of Brightwave Digital Products LLP.

1. Information We Collect

As a Hospital Management Software (SaaS) provider, AiHospitalERP collects information necessary to provide services to our hospital clients (B2B).

Account & Hospital Information

  • Hospital name, registration details, and administrative contact information.
  • Admin names, emails, and phone numbers.
  • Billing and subscription payment information.

Patient Data (Processed on Behalf of Hospitals)

  • Medical records, appointments, prescriptions, and billing info entered by the hospital staff.
  • We act solely as a data processor for patient information. The hospital remains the data controller.

2. How We Use Your Information

  • To provision and manage your SaaS workspace and multi-tenant environment.
  • To process subscription billing and issue invoices.
  • To provide technical support, maintenance, and platform updates.
  • To monitor infrastructure performance and prevent fraud.
  • We never use patient health data for marketing or analytics purposes.

3. How We Share Your Information

We strictly limit data sharing. We only share information with:

  • Hosting & Infrastructure Providers: Our platform uses cloud hosting and CDN services (e.g., Vercel, Cloudinary) to securely deliver the application.
  • Communication Services: We use third-party email (Gmail SMTP) and SMS (Twilio) services to send appointment reminders and notifications.
  • Legal Requirements: When compelled by law, regulation, or legal process.

4. Data Security

Security is our top priority. We implement robust protections for all healthcare data.

  • All data transmitted between your browser and our servers is encrypted using TLS (HTTPS).
  • Strict role-based access control (RBAC) and data isolation between hospital tenants.
  • Passwords are securely hashed and never stored in plain text.
  • We follow applicable Indian data protection regulations (IT Act, 2000 and its rules) and industry best practices.

5. Data Retention

  • Hospital account data is retained as long as the subscription is active.
  • If a subscription is canceled, patient data can be exported by the hospital. All data is then securely permanently deleted within 90 days.

6. Contact Us

If you have questions about this policy, please contact us:

Important Disclaimer

The content on this page is provided for general informational purposes only and does not constitute legal advice. AiHospitalERP makes no representations or warranties regarding the completeness, accuracy, or applicability of this information to your specific circumstances. Please consult a qualified legal professional before making decisions based on this policy.