Privacy Policy
Last updated: June 5, 2026
1. Introduction
At Eldovian Desk, we take the confidentiality, privacy, and security of health information with the utmost seriousness. This Privacy Policy describes how we collect, use, and protect clinical records, patient demographics, and operational data when healthcare facilities utilize our Electronic Health Record (EHR) and Hospital Information System (HIS).
Eldovian Desk operates as a "Business Associate" under the U.S. Health Insurance Portability and Accountability Act (HIPAA) and as a "Data Processor" under the Indian Digital Personal Data Protection (DPDP) Act 2023 on behalf of healthcare institutions acting as Covered Entities / Data Fiduciaries.
2. Information We Process
A. Healthcare Staff & Clinic Accounts
When a clinic workspace is deployed, we store administrator contact details, doctor/nurse credentials, role assignments, and billing information necessary for hospital operations.
B. Patient Demographic & Clinical Data
Our system stores patient names, dates of birth, MRN numbers, blood groups, contact details, diagnoses (ICD-10), clinical encounter notes, vital signs, prescription orders, and inpatient ward stay telemetry. Sensitive demographic fields are stored with dedicated AES-256 encryption.
C. Audit Trail & Telemetry Logs
To comply with ISO 27789 health informatics standards and Section 8(4) of the DPDP Act, all patient chart views, record exports, and safety overrides are cryptographically logged into aggregated audit ledgers.
3. How We Use Healthcare Data
We process clinical and organizational information strictly to:
- Provide seamless Outpatient (OPD) queue triage and Inpatient (IPD) ward bed tracking.
- Enable electronic prescription generation, drug interaction (DDI) safety checks, and billing invoicing.
- Bridge authorized audio captures to Simplify AI for transcription when clinicians explicitly launch the scribe.
- Ensure non-repudiable medico-legal compliance under National Medical Commission (NMC) regulations.
4. Data Security & Sovereign Hosting
All patient demographic fields and clinical notes are safeguarded through dual-layer encryption: transparent database encryption at rest (AES-256) combined with application-level field encryption. Primary database hosting is localized in AWS Asia Pacific (Mumbai - ap-south-1) to fulfill strict sovereign data localization requirements.
5. Contact & Grievance Redressal
For privacy inquiries, audit ledger requests, or grievance redressal under DPDP Act rules, contact our Data Protection Officer at:
Data Protection Officer • Eldovian Technologies