Privacy Policy
This policy explains how Caresoft Systems Private Limited ("Caresoft", "we") handles personal data in the Caresoft VMS visitor management platform at vms.caresoft.co.in. It is written for three audiences: visitors who scan a QR code at a hospital gate, hospitals and clinics that deploy the platform, and staff who operate it.
If you are a visitor: the hospital you are visiting decides what is collected at its gate, why, and how long it is kept. The hospital's own privacy notice governs your visit. Caresoft supplies the software the hospital uses.
Questions about your visit record should go to the hospital first. Our contact details are in Section 17 if you cannot reach them.
1. Who is responsible for what
| Data | Hospital | Caresoft |
|---|---|---|
| Visitor details, gate passes, entry and exit records | Data Fiduciary / Controller | Data Processor |
| Patient, ward and doctor information drawn from the hospital system | Controller | Processor |
| Hospital staff accounts and audit logs | Controller | Processor |
| Hospital's contract, billing and support records | Counterparty | Controller |
| Our website and enquiry forms | — | Controller |
| System logs required by law | — | Controller |
Processing terms between Caresoft and each hospital are in the Data Processing Addendum, which prevails for hospital customers.
2. Why a visitor record is sensitive
A hospital visitor log is not an ordinary visitor log.
A record showing that a person visited a patient in a named ward reveals that the patient is admitted, and often what they are being treated for. A visit to an oncology, psychiatry, HIV, maternity or de-addiction ward can disclose a diagnosis to anyone who reads the log — without the patient ever having consented.
We treat visitor records accordingly, and hospitals deploying Caresoft VMS should too. What follows is built around that risk, not bolted on afterwards.
Practical consequences of that principle, applied throughout this policy: ward and department names are minimised on passes and screens; access to visitor records is restricted by role; retention is short by default; and the log is never used for marketing to anyone.
3. What we collect from visitors
When you scan the QR code at the gate and complete the signup screen:
- Name — as you enter it.
- Mobile number — verified by an OTP sent over WhatsApp (Section 5).
- Email address — optional. You may leave it blank and still receive a pass.
- Who you are visiting — the patient, ward or department, and in some configurations the doctor, depending on how the hospital has set the system up.
- Purpose of visit, where the hospital asks for it.
- Entry and exit times, recorded when your pass is scanned at the gate, and the duration of your visit.
- Technical data — device type, browser and IP address, used for security and to prevent misuse of passes.
Fields marked optional in the form are genuinely optional. Leaving one blank will not prevent a pass being issued.
4. What we do not collect
The platform does not capture, and in its current form has no capability to capture:
• Photographs of visitors — no camera capture at the gate
• Face recognition or biometrics of any kind
• Aadhaar, PAN or other government identity numbers
• Location tracking — we do not follow a visitor's movement inside or outside the premises
• Any clinical information about the patient — no diagnosis, no treatment, no test results
Hospitals must not attempt to collect identity documents, photographs or biometrics through free-text fields in this platform. If a hospital's own policy requires photo identification at the gate, that must be handled separately, with its own lawful basis, notice and security — not by uploading images into a visitor form.
If a future version introduces photo capture or ID scanning, it will be an opt-in feature, notified to hospitals in advance, and this section will be updated before it ships — not quietly afterwards.
5. Mobile verification by WhatsApp
- We send a one-time password to the mobile number you enter, over WhatsApp, to confirm the number is yours. This prevents passes being issued against numbers that do not belong to the visitor.
- Delivery is through a WhatsApp Business Solution Provider acting as our sub-processor. Your number and the OTP message are processed by them and by WhatsApp for delivery.
- We do not use your number for marketing. It is used to verify you, to deliver your pass where the hospital has enabled that, and for the hospital to contact you about your visit if it needs to.
- OTP records are kept only as long as needed to prevent replay and abuse — see Section 14.
- We will never ask you for an OTP over a phone call. Anyone calling to ask for your OTP is committing a fraud.
6. Information from the hospital system
Where the hospital has connected Caresoft VMS to its hospital information system, the platform receives a limited set of information to make the gate process work:
- Whether the patient you name is currently admitted, and in which ward or bed.
- The number of simultaneous visitors permitted for that patient — used to enforce rules such as one attendant in intensive care.
- Ward and consulting doctor lists, so the visitor form offers valid choices.
The platform sends back a record that a visit occurred, so the hospital's own systems reflect it.
No clinical data crosses this interface. The platform receives admission status and visitor limits, not diagnoses, treatment or results. Where the interface is unavailable, the gate falls back to manual entry rather than failing.
7. The gate pass and its QR code
- The pass carries a randomly generated token. It is not guessable and is tied to a single visit.
- Anyone holding your pass link or QR code can view that pass. Treat it like a ticket — do not share it, and do not post it publicly.
- Pass pages are served with instructions to search engines not to index them, and without referrer information, so the token cannot leak through links or be found by searching.
- A pass expires automatically at the end of its validity and cannot be reused after check-out.
- Passes are designed to show the minimum needed at a gate. Hospitals configuring what appears on the pass should keep ward and department detail off it wherever the gate process allows.
8. Content shown on the signup screen
The signup screen may display hospital notices, health education material and hospital promotional content, chosen by the hospital.
This is not advertising targeting. Content is shown to everyone who scans the code at that gate. It is not selected based on who you are, who you are visiting, or anything about the patient. We do not build a profile of you, do not track you across websites, and do not share your details with advertisers.
9. Hospital staff and user data
For each user of the platform — gate operators, client administrators, platform administrators — we process name, role, contact details, credentials (passwords stored only as salted and peppered one-way hashes), permissions, and a record of sign-ins and actions taken, including who issued, checked in or cancelled each pass.
Staff should be aware that their actions are logged and auditable by their hospital. This exists so that a disputed entry can be traced, not to monitor performance.
10. Why we process it
- To verify a visitor's mobile number and issue a gate pass.
- To record entry and exit, and to know who is inside the premises at any time.
- To enforce the hospital's visiting rules, including limits on simultaneous visitors per patient.
- To help the hospital respond in an emergency — evacuation, fire, or an incident requiring a headcount.
- To support the hospital's own security and any investigation of an incident on its premises.
- To produce management reports on footfall and visit patterns for the hospital.
- To provide support and investigate faults.
- To meet legal obligations, including mandatory log retention and incident reporting.
- To administer and bill the hospital's account.
We do not use visitor data for our own purposes. We do not sell it, share it between hospitals, provide it to advertisers or insurers, or use it to train artificial intelligence models. This is a contractual commitment in the Data Processing Addendum.
11. Lawful basis and consent
The hospital establishes the lawful basis. Typically this is the visitor's consent, given at the signup screen, together with the hospital's legitimate interest in controlling access to its premises and keeping patients, staff and visitors safe.
- The signup screen must carry a clear notice of what is collected, by whom and why, with a link to the hospital's privacy notice and to this policy. Caresoft provides the wording; the hospital is responsible for it being displayed and accurate.
- Where a visitor declines to provide details, entry is a matter for the hospital's own policy. Caresoft does not require that anyone be refused entry, and a hospital should have a manual process for visitors who cannot or will not use the digital form — including those without a smartphone.
- Where a visitor is a minor, the accompanying adult provides the details.
12. Who can see visitor data
- Hospital staff — limited by role. Gate users see what they need to admit and check out a visitor. Client administrators see records and reports for their own hospital only. No hospital can see another hospital's data.
- Caresoft personnel — only to run and support the platform, investigate a security incident, or comply with law. Access is individually authenticated, requires multi-factor authentication for administrative roles, and is logged with the person, time and reason. Production visitor data is never copied into development, test or demonstration environments.
- Sub-processors — hosting within India, and the WhatsApp Business Solution Provider used for OTP delivery. Listed in the DPA.
- Authorities — where compelled by valid legal process, or where a hospital lawfully provides records to police in connection with an incident on its premises. We assess each request made to us, disclose the minimum required, and notify the hospital unless prohibited.
- Nobody else.
13. Where data is held
Data is stored and processed within India, including backups. Caresoft support and engineering access is from India. Where the platform is installed on a hospital's own infrastructure, data remains there and Caresoft has no access except as the hospital grants for support. OTP messages transit the WhatsApp platform, which operates internationally; only the number and the OTP text are involved.
14. How long it is kept
Retention here is deliberately short. A visitor log's usefulness falls away within days; its sensitivity does not. Hospitals may configure longer periods where their own policy or accreditation requires, and should record why.
| Data | Default retention |
|---|---|
| Visitor name, mobile, visit record, entry and exit times | [90] days, then deleted or anonymised — configurable by the hospital |
| Gate pass tokens | Invalidated at check-out or expiry; purged within [7] days |
| OTP records | [24] hours — retained only to prevent replay and abuse |
| Aggregate footfall statistics (no personal data) | Retained for the hospital's reporting; contains no identifiable visitor |
| Hospital system sync log | [30] days |
| Staff accounts and audit logs | Life of the account plus [24] months |
| Records relating to a security or safety incident | Preserved until the matter is closed, then per the hospital's instruction |
| System logs required by law | Minimum 180 days, held in India |
| Backups | Rolling [35] days |
| Hospital account, contract and tax records | Up to 8 years as required by Indian tax law |
15. Security
Measures include: encryption in transit and at rest; passwords stored as salted and peppered one-way hashes; three-level role separation with administrative surfaces isolated from the visitor-facing form; unguessable pass tokens; pass pages served with no-index and no-referrer headers so tokens cannot leak or be indexed; tenant isolation so no hospital can reach another's data; rate limiting on OTP requests; audit logging of pass issue, check-in, check-out and cancellation; no production data in non-production environments; vulnerability scanning and periodic penetration testing; and a documented incident response plan.
Security is shared. The hospital is responsible for its network, the physical security of gate devices, and revoking staff access promptly when someone leaves.
16. If something goes wrong
- We notify the affected hospital of any personal data breach within [24] hours of becoming aware.
- We are required to report specified cyber incidents to CERT-In within 6 hours, and to retain system logs for a minimum of 180 days within India. These obligations override conflicting deletion requests to the extent the law requires.
- Evidence is preserved until the investigation closes.
- The hospital notifies visitors and regulators as data fiduciary. We provide the information and support required and do not contact visitors directly without the hospital's written instruction.
- We provide a written root cause analysis with corrective actions within [10] working days.
17. Rights and how to exercise them
17.1 Visitors
You may have the right to access your visit record, have it corrected, request erasure, obtain information about processing, nominate someone to act for you, and raise a grievance.
Exercise these with the hospital you visited. It holds the record and decides what happens to it, and it can verify your identity in a way we cannot. If you contact us directly, we will refer you to the hospital and tell them you have been in touch within [2] working days.
Some records cannot be erased on request — those relating to a security or safety incident under investigation, and system logs the law requires us to keep. The hospital can explain what applies to your record and why.
17.2 Hospital staff
Your account and activity data forms part of your hospital's record. Raise requests with your hospital administrator; we will assist them.
17.3 Hospitals and website visitors
Write to [[email protected]]. We verify identity and respond within 30 days.
18. Contact and Grievance Officer
Privacy: [email protected]
Support: [email protected]
Grievance Officer (Information Technology Act, 2000; Digital Personal Data Protection Act, 2023)
Name: Rajeev Pillai
Address: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107
Acknowledgement within 24 hours; resolution within 15 days.
You may complain to the Data Protection Board of India if you are dissatisfied with our response.
Caresoft Systems Private Limited, 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107, CIN U72900MH2022PTC387875.
19. Changes
We may update this policy. The version date will change. Hospitals are notified of material changes at least [30] days in advance; changes reducing protection require the hospital's agreement under the DPA. Any change to Section 4 will be notified prominently and in advance — what the platform does not collect is the substance of the promise.