Legal

Privacy Policy

Aviral Medcare is an EMR and hospital management platform for eye hospitals and ophthalmology clinics. Health information asks for more care than most software handles, and this page sets out how we handle it.

1. What we may collect

What we hold depends entirely on how you deal with us — a visitor filling in a demo form leaves us far less than a hospital running its whole outpatient department on the platform.

Contact details

  • Name
  • Email address
  • Phone number
  • Hospital or organisation name
  • Job title or professional role
  • Anything else you type into an enquiry or demo form

Account details

Where an account has been issued, we hold what is needed to run it: login credentials, the role assigned to the user, the branch they belong to, and a record of account activity.

Hospital and operational information

Once the platform is deployed at a hospital or clinic, it processes whatever authorised staff enter in the course of an ordinary working day. In practice that can include patient records, appointments, prescriptions, investigations, billing, inventory, surgery records, and anything else the hospital has configured.

Technical information

Some information reaches us simply because the software runs over a network:

  • IP address
  • Browser and device information
  • Operating system
  • Login and session information
  • Pages or services accessed
  • Security and audit events

2. How we use it

Information is used to:

  • Run and support the Aviral Medcare services.
  • Answer enquiries and arrange demonstrations.
  • Create and manage authorised accounts.
  • Keep hospital and clinic workflows moving.
  • Provide technical support.
  • Keep the platform secure and unauthorised users out of it.
  • Watch system performance and reliability.
  • Maintain audit records.
  • Improve the product.
  • Send service messages that matter — outages, changes, security notices.
  • Meet our legal and contractual obligations.

Patient information is never used for advertising or for marketing anything unrelated. It exists to run the hospital that entered it.

3. Patient information

Aviral Medcare exists to help a hospital or clinic run its own operations, and that shapes who is answerable for what.

Where a hospital uses the platform to hold patient records, the hospital decides what is collected, why, and how it is used in the course of patient care. That decision is theirs to make and theirs to justify.

We process that information to deliver the services the organisation has contracted for, following their instructions, the agreement between us, and the law that applies.

4. Sharing

We do not sell personal information. Not to anyone, in any form.

Information may be shared with service providers or technology partners where that is genuinely needed to run, secure, maintain or support the platform.

We may also disclose information where the law, a regulator, a court order, or a lawful government request requires it.

5. Security

We apply technical and organisational safeguards intended to keep information from being accessed, altered, disclosed or destroyed by anyone who should not be doing so.

Depending on how a deployment is configured, those measures include authentication controls, role-based permissions, branch-level access restrictions, audit trails, secure sessions, and the rest of the access-management machinery described in our Data Security & Data Protection Policy.

No system connected to the internet can promise absolute security, and we will not pretend otherwise. What we can commit to is reducing the risk and improving the safeguards, continuously.

6. Role-based access

Permissions in Aviral Medcare are assigned per role, so an organisation controls which of its people can see or change which parts of the system.

Assigning those roles sensibly, and keeping credentials confidential, is the hospital's responsibility. The software gives you the controls; it cannot decide who should have theatre access.

7. How long we keep it

Information is kept for as long as it is reasonably needed to deliver the service, meet contractual and legal obligations, resolve disputes, preserve security records, or satisfy legitimate business requirements.

Retention periods differ by the type of information and by what the customer's agreement says.

8. Your data

Where we process information for a hospital or clinic, that organisation holds rights and duties over it under the agreement between us and under the law.

Customers can come to us about access, export, correction, retention or deletion. We will act on those requests within what our legal and contractual obligations allow.

9. Cookies

This website may use cookies and similar technologies for functionality, security, analytics and general usability. Our Cookie Policy covers this in full, including how to turn analytics off.

10. Third-party services

Some features depend on outside services or integrations. Where information passes to one of them, it is handled according to that service's configuration, the contract governing it, and the privacy requirements that apply.

11. Children's information

The platform is built for healthcare organisations, their staff and business users. We do not knowingly collect a child's personal information directly, and never for marketing.

Where a hospital enters information about a child, it is handled as part of that hospital's clinical operations, under this policy and the agreement with them.

12. Changes to this policy

This policy will be updated when our services, technology, legal obligations or business practices change. The revised version replaces this one on this page, and the version published here is always the one that applies.

Contact

For anything to do with privacy — a question, a request, a concern — write to us:

Ebslon Infotech — info@aviralmedcare.com

Please include enough detail for us to understand what you are asking, so the answer comes back useful the first time.

Write to usinfo@aviralmedcare.com