Legal
Privacy Policy
Effective 23 July 2026
1. Scope
This policy explains how Healaxy AI handles personal data: account data of clinicians and staff, and patient data processed on behalf of healthcare organizations using the platform. Healthcare organizations are the data fiduciaries for their patients’ data; Healaxy processes it under their instructions.
2. What we process
Account data: name, work email, phone, role, and usage/audit records of staff actions.
Patient data (on behalf of your healthcare provider): registration details, intake interview responses (typed or transcribed audio), uploaded clinical documents, and the summaries, codes and reports generated from them. Where ABHA features are used, ABHA identifiers are stored on the patient record; Aadhaar numbers and OTPs are transmitted encrypted to government ABDM systems and are never stored by Healaxy.
3. Why we process it
Solely to provide the service to your healthcare organization: conducting AI-guided intake, generating clinical documentation for clinician review, maintaining access-audit trails required for accountability, securing the service, and support. We do not sell personal data or use patient data for advertising, and we do not use patient data to train foundation models.
4. AI processing and sub-processors
AI features are powered by hosted model providers accessed through Vercel AI Gateway, with Indian-language transcription by Sarvam AI. Infrastructure runs on Vercel (hosting) and Supabase (database and file storage); transactional email is sent via Resend. These providers process data only to deliver the service. Some processing occurs on servers outside India; a current sub-processor list is available on request.
5. Security
Data is encrypted in transit, access is role-based and organization-scoped, clinical documents are stored in private buckets with short-lived access links, and reads and changes to patient records are recorded in an append-only audit log.
6. Retention
Patient records are retained as directed by your healthcare organization and deleted or returned at the end of the engagement, subject to legal retention duties. Audit logs are retained for at least one year. Account data is removed within a reasonable period after account closure.
7. Your rights
Under the Digital Personal Data Protection Act, 2023, individuals may request access to, correction, or erasure of their personal data, and may raise grievances. Patients should contact their healthcare provider (the data fiduciary); we support providers in fulfilling these requests. Staff account holders may contact us directly.
8. Grievances
Grievance contact: support@healaxy.com. We acknowledge grievances promptly and aim to resolve them within the timelines prescribed by law.
9. Changes
We will post updates to this policy here with a new effective date, and notify organizations of material changes.
© 2026 Healaxy · Terms of Service