Privacy Policy
Ambit Minds runs OPD queues, ward beds and billing for hospitals. That means we handle sensitive information on behalf of the hospitals that use us. This page explains what we collect, how we use it, who we share it with, and the choices you have.
1. Introduction
Ambit Minds ("we", "us", "our") operates a hospital and clinic management platform made available at ambitminds.com, apps.ambitminds.com and through our mobile applications (together, the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
By signing in to or using the Service you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
2. Information we collect
The Service is used by hospitals, clinics, doctors and their staff to manage care. Depending on how you use it, we may collect the following categories of information:
- Account information: your name, email address, mobile number, role (for example hospital administrator, doctor, nurse or receptionist), specialisation and the hospital or clinic you belong to.
- Patient and clinical information entered by authorised users: patient demographics, appointments, admissions, vitals, prescriptions, medication administration records, lab orders and results, case files, discharge summaries and similar health records.
- Billing information: invoices, payment method and payment status for services rendered. We do not store full card numbers.
- Usage and device information: log data such as IP address, browser type, device identifiers, pages visited, actions performed and timestamps, collected automatically to keep the Service secure and reliable.
- Communications: messages you send to our support team, through the demo request form, or through the in-app help assistant.
3. How we use information
We use the information we collect to:
- Provide, operate and maintain the Service, including scheduling, patient records, ward and ICU monitoring, pharmacy, laboratory and billing workflows.
- Authenticate users and enforce role-based access so that clinical data is only visible to authorised staff of the relevant hospital.
- Send service notifications such as appointment reminders, critical alerts and account or security notices.
- Respond to demo requests and support enquiries.
- Monitor, troubleshoot and improve performance, reliability and security of the Service.
- Comply with legal obligations, including record-keeping requirements that apply to healthcare providers.
4. Health data and the hospital as data controller
Patient health records are entered into the Service by the hospital or clinic that treats the patient. That hospital or clinic determines why and how patient data is processed and is the data controller for it. Ambit Minds processes this data on the hospital's behalf and on its instructions, as a data processor.
If you are a patient and have questions about how your health information is handled, please contact the hospital or clinic that provides your care. We will assist them in responding to your request.
6. Data security
We use industry-standard safeguards to protect information, including encryption in transit (HTTPS), single sign-on with token-based authentication, role-based access control, audit logging of clinical actions and regular backups. Access to production systems is restricted to authorised personnel.
No method of transmission or storage is completely secure. You are responsible for keeping your credentials confidential and for signing out on shared devices.
7. Data retention
Account information is retained for as long as your account is active and for a reasonable period afterwards to comply with legal obligations and resolve disputes. Patient and clinical records are retained for the period required by applicable healthcare record-keeping laws or as instructed by the hospital or clinic that controls them. Usage logs are kept for a limited period for security and troubleshooting.
8. Your rights and choices
Subject to applicable law, you may:
- Access, correct or update the account information we hold about you.
- Request deletion of your account. Some information may be retained where required by law or where it forms part of a patient's clinical record.
- Opt out of non-essential notifications from your profile settings. Critical clinical and security alerts cannot be disabled.
- Object to or request restriction of certain processing, and lodge a complaint with your local data protection authority.
10. Children
The Service is intended for use by healthcare professionals and administrative staff and is not directed at children. Records about minors (for example in paediatric or neonatal wards) are entered and managed by the treating hospital or clinic, which is responsible for obtaining any consent required from a parent or guardian.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page and, for material changes, notify users through the Service. Continued use of the Service after a change takes effect means you accept the updated policy.
12. Contact us
If you have questions about this Privacy Policy or how your information is handled, write to us and we will respond as soon as we can.