Legal
Privacy Policy
Last updated: 25 August 2026
Who we are
Swasthyamanasa Healthcare Private Limited (“Swasthya”, “we”, “us”) provides healthcare software, including Swasthya EMR, patient portals, cloud provisioning, messaging and payment integrations. Contact us at contact@swasthyamanasahealthcare.com.
Whose data we process
This policy covers visitors, prospective customers, hospital administrators and users of our public services. Hospitals generally control the clinical and patient records stored in their tenant; Swasthya processes that information for the hospital under its instructions and applicable law. A hospital's own privacy notice governs its care relationship with a patient.
Information we collect
- Contact, account, organization and professional-role information.
- Subscription, invoice, payment status and transaction references.
- Support communications, consent choices and onboarding information.
- Security, audit, device, browser, IP-address and service-usage events.
- Clinical or patient information only when we provide services to a hospital.
Hosted payment forms are provided by our payment partner. Swasthya does not receive or store complete card credentials.
How we use information
- Provide, secure, support and improve the contracted services.
- Provision tenants, authenticate users and enforce permissions.
- Process subscriptions, messaging credits, payments, refunds and reconciliation.
- Send service communications requested or consented to by the recipient.
- Prevent abuse, investigate incidents and meet legal or regulatory duties.
Service providers and disclosures
We use vetted infrastructure, identity, communications, email and payment providers only for the services they supply. Razorpay processes hosted checkout and related payment data under its current Privacy Policy. Twilio or an approved WhatsApp provider may process opted-in messaging traffic. We may disclose information where required by law, to protect users or the service, or during a lawful corporate transaction. We do not sell clinical records.
Retention and security
We retain information for the contract, legal, medical-record, tax, audit and dispute periods that apply to it. Different records therefore have different retention periods. We use tenant isolation, role-based access, encryption, audit trails, backups and restricted production access. No internet service can guarantee absolute security.
Your choices and requests
You may ask for access, correction, erasure where legally available, consent withdrawal or grievance handling by contacting us. Patients should normally use their hospital's privacy contact or the privacy area in their patient portal so the hospital can identify the relevant medical record. Some records cannot be erased where retention is required by law or necessary for legal claims.
Updates
We may update this policy as our services or legal obligations change. The current version and its effective date will remain available on this page.