Legal
Privacy Policy
privacy policyThis policy describes how MedEazy collects, uses, stores, and protects information when you visit our public website, request a demo or contact us, authenticate to the platform, or use authorized clinical decision support services under your organization’s agreement.
Draft legal content for MedEazy. Independent legal review and sign-off required before production reliance (APR-043).
Who We Are and Scope
who we are and scopeMedEazy provides clinical decision support software and related services for hospital pharmacy, antimicrobial stewardship, and clinical governance teams. This policy applies to the MedEazy public website, marketing communications, authentication flows, and the authorized product workspace unless a separate written agreement with your organization specifies different terms.
MedEazy is positioned as an India-first platform. Where applicable, we aim to align with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other Indian privacy and health-information requirements, in addition to obligations under your organization’s contract.
Information We Collect
information we collectThe categories of information we process depend on how you interact with MedEazy:
- Public website and forms: name, organization, role, email address, phone number if provided, inquiry topic, and message content submitted through demo requests, contact forms, or partnership inquiries.
- Authentication and account data: credentials, email address, name, organization membership, role assignments, facility scope, session metadata, and security event logs.
- Clinical workspace data: patient-context information, medication orders, allergies, laboratory results, alerts, acknowledgements, overrides, stewardship cases, and audit events — processed only when your organization has authorized use and configured integrations or manual entry.
- Technical data: IP address, browser type, device identifiers, timestamps, cookies or similar technologies on the public site, and application logs with protected data redacted where feasible.
Public Website — Do Not Submit PHI
public website — do not submit phiPublic contact, demo, and marketing forms are intended for product evaluation, security review, integration planning, and partnership inquiries only.
Do not submit patient names, medical record numbers, diagnoses, prescriptions, clinical notes, images of patients, passwords, API keys, invitation tokens, or other protected health information through public channels. If you need to discuss a clinical scenario, use de-identified or synthetic examples only.
Information submitted through public forms is used to respond to your inquiry, route it to the appropriate team, maintain records of commercial communications, and improve our public materials. We do not use public-form submissions to deliver clinical decision support.
How We Use Information
how we use informationWe use collected information to provide, secure, and improve MedEazy, including:
- Delivering authorized clinical decision support, drug reference, alert workflows, stewardship tools, and monitoring features enabled for your tenant.
- Authenticating users, enforcing role-based access, maintaining tenant and facility isolation, and detecting abuse or unauthorized access.
- Recording acknowledgements, overrides, administrative actions, and other audit events required for clinical governance and security review.
- Responding to support requests, pilot onboarding, security questionnaires, and contractual obligations.
- Operating, maintaining, and improving the platform, including troubleshooting, capacity planning, and quality assurance using de-identified or synthetic data where possible.
- Complying with applicable law, regulatory requests, and contractual duties, including legal hold and incident response where required.
Legal Bases and Your Organization’s Role
legal bases and your organization’s roleFor authorized workspace use involving patient-related information, your hospital or health system is typically the data fiduciary or controller for clinical data, and MedEazy acts as a data processor or service provider under your agreement. The specific roles, lawful bases, and notices to data principals (including patients and workforce members) are defined in your organization’s privacy notices and the data processing terms in your contract.
For public website inquiries and account administration data where MedEazy determines purposes and means, we process information based on consent where required, legitimate interests in operating our business and responding to inquiries, and performance of a contract when you are an authorized user or customer representative.
DPDP Act and Data Principal Rights (India)
dpdp act and data principal rights (india)Where the DPDP Act applies, data principals may have rights to access, correction, erasure, grievance redressal, and nomination, subject to applicable exceptions for health, safety, legal compliance, and contractual performance.
Workforce members and clinicians should generally direct privacy requests relating to clinical workspace data to their organization’s privacy officer or administrator, who coordinates with MedEazy under the applicable agreement.
You may contact us through the public contact form for product privacy questions that do not include patient information. We will route verifiable requests in accordance with applicable law and your organization’s contract.
Sharing and Subprocessors
sharing and subprocessorsWe do not sell personal information. We share information only as necessary to operate MedEazy:
- With your organization’s authorized administrators and users according to role and facility permissions.
- With infrastructure, hosting, email, monitoring, and security vendors that process data on our behalf under contractual confidentiality and security obligations.
- With licensed content providers only to the extent required by content agreements and your organization’s authorized features.
- When required by law, regulation, court order, or to protect rights, safety, and security, subject to notice where permitted.
- In connection with a merger, acquisition, or asset transfer, with appropriate confidentiality safeguards.
A current subprocessor list and data residency commitments are provided to customers under NDA or in the data processing schedule attached to your agreement.
International Transfers
international transfersData residency, hosting region, and cross-border transfer mechanisms are defined per pilot or production agreement. We do not represent on this public page that all deployments store data exclusively in India unless contractually agreed for your organization.
Retention and Deletion
retention and deletionPublic inquiry records are retained for a period reasonable to manage commercial relationships and legal obligations, then deleted or anonymized unless a longer period is required by law.
Clinical workspace data retention, archival, legal hold, and tenant offboarding are governed by your organization’s agreement, configured retention policies, and applicable health-record requirements. MedEazy supports defined retention schedules and export boundaries where contractually enabled.
Security Measures
security measuresWe implement administrative, technical, and organizational measures appropriate to the sensitivity of the data, including tenant-scoped isolation, encryption in transit and at rest for production architectures, role-based access control, multi-factor authentication for privileged workflows, and append-only audit logging for defined sensitive events. See our Security and Data Processing pages for public summaries.
No system is perfectly secure. You are responsible for safeguarding your credentials, reporting suspected compromise promptly, and following your organization’s acceptable use and clinical governance policies.
Children’s Privacy
children’s privacyMedEazy is a professional healthcare platform not directed to children. We do not knowingly collect personal information from children through public marketing channels. Clinical use involving pediatric patients occurs only within authorized hospital workflows under organizational control.
Changes and Contact
changes and contactWe may update this policy when our practices or legal requirements change. Material changes will be posted on this page with an updated effective date after legal review.
For privacy questions about the public website or to reach our privacy contact, use the Contact page. Do not include patient information. Authorized customers should use contractual support channels for operational privacy matters.