Privacy Policy
Last updated: 14 August 2026
1. Who we are
EMRDoctor is an electronic medical records (EMR) and clinical workflow platform used by doctors, clinics, polyclinics and hospitals to manage patient records, consultations, prescriptions, billing, and related clinical workflows. In this policy, “we,” “our” and “EMRDoctor” refer to Team EMRDoctor.
2. What this policy covers
This policy explains what information EMRDoctor collects, how it is used, who can access it, and the choices available to doctors, clinic administrators, and patients whose data is processed by clinics that use EMRDoctor.
It applies to the EMRDoctor web application, mobile / iPad applications, marketing website, and any other services that link to this policy.
3. Information we collect
From doctors and clinic staff: name, email address, phone number, professional details (specialty, registration number, clinic affiliation), the account credentials you set up, and records of your activity within EMRDoctor (login times, feature usage, IP address, device information).
From patients (entered by clinic staff): demographic details, contact information, medical history, consultation notes, prescriptions, investigation reports, vitals, and other clinical records that the clinic chooses to record in EMRDoctor.
Billing and payments: when a clinic recharges its EMRDoctor wallet or pays for the service, the payment is processed by a third-party payment gateway. We store transaction identifiers and invoice records; we do not store card numbers or bank credentials.
Cookies and similar technologies: we use strictly necessary cookies for session management and security. We do not use advertising or cross-site tracking cookies.
4. How we use information
We use the information described above to:
- Provide, operate and maintain the EMRDoctor service for the clinics we serve.
- Authenticate users, secure accounts, and prevent unauthorized access.
- Process wallet recharges and generate GST-compliant tax invoices.
- Communicate with clinic administrators about service updates, billing and support.
- Diagnose technical problems, monitor uptime, and improve the software.
- Comply with applicable laws and legal process.
We do not sell your data. We do not use patient data for advertising or marketing. We do not cross-market to your patients on your behalf or otherwise.
5. Who can access what
EMRDoctor is a multi-tenant platform. Each clinic's data is isolated from every other clinic's data. Within a clinic, access is controlled by role — doctors, reception, nursing, billing and admin roles each see only what their role needs.
Clinic administrators control who at their clinic has access to what. They are responsible for provisioning and de-provisioning staff accounts.
Our team accesses clinic data only when explicitly requested for support, or when required to investigate a security incident. All such access is recorded in the audit log.
6. How data is secured
Patient data is encrypted at rest and in transit using industry-standard algorithms (AES-256). Each clinic's tenant is isolated at the database level; queries from one tenant cannot return another tenant's records. Every write action inside EMRDoctor is attributable to a user account and a timestamp via an append-only audit log.
No security control is perfect. Doctors and clinic administrators must also follow reasonable practices — use strong unique passwords, do not share accounts, revoke access promptly when a staff member leaves.
7. Data retention
We retain clinical records as long as the clinic maintains an active EMRDoctor account. If a clinic closes its account, we retain records for a further period consistent with applicable laws (typically related to medical record retention requirements) and then securely delete them.
Clinics can export their data at any time in standard formats (CSV, PDF).
8. Your rights
Depending on where you are based, you may have rights to access, correct, or delete the personal information EMRDoctor holds about you, and to object to or restrict certain processing. Patients whose data is stored in EMRDoctor should contact the clinic that captured their records to exercise these rights — the clinic is the data controller for their patients' medical information; EMRDoctor is the processor.
9. Third-party services
EMRDoctor uses a small number of third-party services to operate — hosting infrastructure, a payment gateway (for wallet recharges and invoices), and a communications service (for messaging clinic administrators). These providers process data only as necessary to perform their function and are contractually required to keep it confidential.
10. Changes to this policy
We may update this policy from time to time. Material changes will be communicated to active clinic administrators before they take effect. The date at the top of this page reflects the most recent update.
11. Contact
Questions about this policy or about how your data is handled? Write to us at hello@emrdoctor.com. We reply.