1. Introduction
This Privacy Policy explains how Healers Tab (“Healers Tab”, “we”, “us” or “our”), operated by FALCON EBIZ PRIVATE LIMITED, Office No.01, Ground Floor, Building No.18B, Vrindavan Society, Thane, Maharashtra, India, 400601, collects, uses, shares and protects information in connection with our clinic management and electronic medical records platform available at healerstab.com, emr.healerstab.com and related clinic subdomains (the “Service”).
We take the privacy of clinics, practitioners and their patients seriously. Please read this policy together with our Terms of Service.
2. Our role: data fiduciary & data processor
Our platform is used by clinics and healthcare practices (“Clinics”) to manage their own operations and patient records. It is important to understand the two different roles we play:
- For information a Clinic enters about its patients — medical records, prescriptions, appointments, billing and similar — the Clinic is the data fiduciary (controller) and decides how that data is used. We act as a data processor, handling that data only on the Clinic’s instructions and to provide the Service.
- For information about the Clinic account itself — the people who sign up, billing details, and how the account uses the Service — we act as the data fiduciary (controller).
If you are a patient, your records are controlled by your Clinic. Please direct requests about your medical records to the Clinic that treats you (see “Patient data”).
3. Information we collect
Account & contact information
Clinic name and address, the names, email addresses and mobile numbers of the account owner and users, login credentials (passwords are stored only as secure hashes), and any logo or branding you upload.
Billing & payment information
Your plan, billing period, GSTIN (if provided), invoices, and transaction references. Card and UPI payments are processed by our payment partners — we do not store full card numbers or UPI PINs on our servers.
Clinical & patient data (processed for Clinics)
Records a Clinic enters, such as patient demographics and contact details, vitals, allergies, diagnoses, prescriptions, lab tests, vaccination records, appointments, uploaded files and inventory data. We process this only to provide the Service to the Clinic.
Usage, device & log data
IP address, browser and device type, the pages and features used, timestamps, and security and audit logs.
Communications
Messages you send us (for example, support requests) and records of SMS and email notifications sent through the Service.
Cookies
We use strictly necessary cookies to keep you signed in and to secure the Service, and limited functional cookies to remember preferences. You can control cookies through your browser, though some features may not work without them.
4. How we use information
- To provide, operate, maintain and secure the Service;
- To create and manage accounts, authenticate users and enforce access controls;
- To process subscriptions and payments and generate GST-compliant invoices;
- To send service communications, one-time passwords, reminders and notifications (by SMS and email) that you or your Clinic configure;
- To provide support and respond to your requests;
- To monitor, prevent and investigate fraud, abuse and security incidents;
- To improve and develop the Service, using aggregated or de-identified data where possible;
- To comply with our legal obligations.
5. Legal bases for processing
Where the Digital Personal Data Protection Act, 2023 and other applicable Indian laws apply, we process personal data on the basis of: performance of our contract with you; your consent (including consent that Clinics obtain from their patients); our lawful and legitimate business interests, such as security and service improvement; and compliance with law. Clinics are responsible for obtaining any consents required from their patients before entering patient data into the Service.
6. Sharing & sub-processors
We share information only as needed to run the Service:
- Service providers / sub-processors who help us operate — such as cloud and hosting providers, our SMS provider (for OTPs and reminders), email delivery, and payment gateways (for example, Razorpay and Cashfree). These parties may use the data only to provide services to us.
- Within your Clinic, according to the roles and permissions your Clinic configures.
- Legal and safety reasons, where required by law, court order, or to protect rights, safety and security.
- Business transfers, in connection with a merger, acquisition or sale of assets, subject to this policy.
We do not share patient clinical data with third parties except as instructed by the Clinic or as required by law.
7. Data security
Each Clinic’s data is kept in a logically isolated, per-practice database. We use measures including encryption of data in transit (HTTPS/TLS), hashed passwords, role-based access controls, audit logging, signup and login rate-limiting, optional two-factor authentication, and regular backups. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Data retention
We retain account and clinical data for as long as the Clinic’s account is active and as needed to provide the Service. After an account is closed, we may retain data for a limited period to allow export and to meet legal, tax and accounting obligations, after which it is deleted or de-identified. Clinics can request export or deletion as described below.
9. Where data is stored
The Service is operated from, and data is primarily stored on, servers located in India. Where any processing or storage occurs outside India, we take steps to ensure appropriate protection consistent with applicable law.
10. Your rights & choices
Subject to applicable law, you may have the right to access, correct, update or delete your personal data, withdraw consent, and raise a grievance. Account owners can manage most information directly within the Service. To exercise other rights, contact us using the details below. Patients should contact their Clinic regarding their medical records.
11. Patient data
If you are a patient of a Clinic that uses Healers Tab, your Clinic controls your records. Requests to access, correct or delete your medical information should be made to your Clinic. We will assist Clinics in responding to such requests in our role as their processor.
12. Children
The Service is intended for use by healthcare businesses and their staff, not by children. Clinics may store records of patients who are minors; such records are entered and controlled by the Clinic, which is responsible for obtaining any necessary consent from a parent or guardian.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where appropriate, notify you. Continued use of the Service after changes take effect constitutes acceptance.
14. Grievance officer & contact
If you have questions, requests or complaints about this policy or your data, please contact our Grievance Officer:
Grievance Officer
Healers Tab — FALCON EBIZ PRIVATE LIMITED
Email: hello@healerstab.com
Office No.01, Ground Floor, Building No.18B,
Vrindavan Society, Thane, Maharashtra, India, 400601
We will acknowledge and address grievances within the timelines required by applicable law.
