Privacy Policy

Product: Caresoft VMS  •  Version: 1.1  •  Effective: 01/04/2026

This policy explains how Caresoft Systems Private Limited ("Caresoft", "we") handles personal data in the Caresoft VMS visitor management platform at vms.caresoft.co.in. It is written for three audiences: visitors who scan a QR code at a hospital gate, hospitals and clinics that deploy the platform, and staff who operate it.

If you are a visitor: the hospital you are visiting decides what is collected at its gate, why, and how long it is kept. The hospital's own privacy notice governs your visit. Caresoft supplies the software the hospital uses.

Questions about your visit record should go to the hospital first. Our contact details are in Section 17 if you cannot reach them.

1. Who is responsible for what

DataHospitalCaresoft
Visitor details, gate passes, entry and exit recordsData Fiduciary / ControllerData Processor
Patient, ward and doctor information drawn from the hospital systemControllerProcessor
Hospital staff accounts and audit logsControllerProcessor
Hospital's contract, billing and support recordsCounterpartyController
Our website and enquiry forms—Controller
System logs required by law—Controller

Processing terms between Caresoft and each hospital are in the Data Processing Addendum, which prevails for hospital customers.

2. Why a visitor record is sensitive

A hospital visitor log is not an ordinary visitor log.

A record showing that a person visited a patient in a named ward reveals that the patient is admitted, and often what they are being treated for. A visit to an oncology, psychiatry, HIV, maternity or de-addiction ward can disclose a diagnosis to anyone who reads the log — without the patient ever having consented.

We treat visitor records accordingly, and hospitals deploying Caresoft VMS should too. What follows is built around that risk, not bolted on afterwards.

Practical consequences of that principle, applied throughout this policy: ward and department names are minimised on passes and screens; access to visitor records is restricted by role; retention is short by default; and the log is never used for marketing to anyone.

3. What we collect from visitors

When you scan the QR code at the gate and complete the signup screen:

Fields marked optional in the form are genuinely optional. Leaving one blank will not prevent a pass being issued.

4. What we do not collect

The platform does not capture, and in its current form has no capability to capture:

• Photographs of visitors — no camera capture at the gate
• Face recognition or biometrics of any kind
• Aadhaar, PAN or other government identity numbers
• Location tracking — we do not follow a visitor's movement inside or outside the premises
• Any clinical information about the patient — no diagnosis, no treatment, no test results

Hospitals must not attempt to collect identity documents, photographs or biometrics through free-text fields in this platform. If a hospital's own policy requires photo identification at the gate, that must be handled separately, with its own lawful basis, notice and security — not by uploading images into a visitor form.

If a future version introduces photo capture or ID scanning, it will be an opt-in feature, notified to hospitals in advance, and this section will be updated before it ships — not quietly afterwards.

5. Mobile verification by WhatsApp

6. Information from the hospital system

Where the hospital has connected Caresoft VMS to its hospital information system, the platform receives a limited set of information to make the gate process work:

The platform sends back a record that a visit occurred, so the hospital's own systems reflect it.

No clinical data crosses this interface. The platform receives admission status and visitor limits, not diagnoses, treatment or results. Where the interface is unavailable, the gate falls back to manual entry rather than failing.

7. The gate pass and its QR code

8. Content shown on the signup screen

The signup screen may display hospital notices, health education material and hospital promotional content, chosen by the hospital.

This is not advertising targeting. Content is shown to everyone who scans the code at that gate. It is not selected based on who you are, who you are visiting, or anything about the patient. We do not build a profile of you, do not track you across websites, and do not share your details with advertisers.

9. Hospital staff and user data

For each user of the platform — gate operators, client administrators, platform administrators — we process name, role, contact details, credentials (passwords stored only as salted and peppered one-way hashes), permissions, and a record of sign-ins and actions taken, including who issued, checked in or cancelled each pass.

Staff should be aware that their actions are logged and auditable by their hospital. This exists so that a disputed entry can be traced, not to monitor performance.

10. Why we process it

We do not use visitor data for our own purposes. We do not sell it, share it between hospitals, provide it to advertisers or insurers, or use it to train artificial intelligence models. This is a contractual commitment in the Data Processing Addendum.

11. Lawful basis and consent

The hospital establishes the lawful basis. Typically this is the visitor's consent, given at the signup screen, together with the hospital's legitimate interest in controlling access to its premises and keeping patients, staff and visitors safe.

12. Who can see visitor data

13. Where data is held

Data is stored and processed within India, including backups. Caresoft support and engineering access is from India. Where the platform is installed on a hospital's own infrastructure, data remains there and Caresoft has no access except as the hospital grants for support. OTP messages transit the WhatsApp platform, which operates internationally; only the number and the OTP text are involved.

14. How long it is kept

Retention here is deliberately short. A visitor log's usefulness falls away within days; its sensitivity does not. Hospitals may configure longer periods where their own policy or accreditation requires, and should record why.

DataDefault retention
Visitor name, mobile, visit record, entry and exit times[90] days, then deleted or anonymised — configurable by the hospital
Gate pass tokensInvalidated at check-out or expiry; purged within [7] days
OTP records[24] hours — retained only to prevent replay and abuse
Aggregate footfall statistics (no personal data)Retained for the hospital's reporting; contains no identifiable visitor
Hospital system sync log[30] days
Staff accounts and audit logsLife of the account plus [24] months
Records relating to a security or safety incidentPreserved until the matter is closed, then per the hospital's instruction
System logs required by lawMinimum 180 days, held in India
BackupsRolling [35] days
Hospital account, contract and tax recordsUp to 8 years as required by Indian tax law

15. Security

Measures include: encryption in transit and at rest; passwords stored as salted and peppered one-way hashes; three-level role separation with administrative surfaces isolated from the visitor-facing form; unguessable pass tokens; pass pages served with no-index and no-referrer headers so tokens cannot leak or be indexed; tenant isolation so no hospital can reach another's data; rate limiting on OTP requests; audit logging of pass issue, check-in, check-out and cancellation; no production data in non-production environments; vulnerability scanning and periodic penetration testing; and a documented incident response plan.

Security is shared. The hospital is responsible for its network, the physical security of gate devices, and revoking staff access promptly when someone leaves.

16. If something goes wrong

17. Rights and how to exercise them

17.1 Visitors

You may have the right to access your visit record, have it corrected, request erasure, obtain information about processing, nominate someone to act for you, and raise a grievance.

Exercise these with the hospital you visited. It holds the record and decides what happens to it, and it can verify your identity in a way we cannot. If you contact us directly, we will refer you to the hospital and tell them you have been in touch within [2] working days.

Some records cannot be erased on request — those relating to a security or safety incident under investigation, and system logs the law requires us to keep. The hospital can explain what applies to your record and why.

17.2 Hospital staff

Your account and activity data forms part of your hospital's record. Raise requests with your hospital administrator; we will assist them.

17.3 Hospitals and website visitors

Write to [[email protected]]. We verify identity and respond within 30 days.

18. Contact and Grievance Officer

Privacy: [email protected]
Support: [email protected]

Grievance Officer (Information Technology Act, 2000; Digital Personal Data Protection Act, 2023)
Name: Rajeev Pillai
Address: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107
Acknowledgement within 24 hours; resolution within 15 days.

You may complain to the Data Protection Board of India if you are dissatisfied with our response.

Caresoft Systems Private Limited, 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107, CIN U72900MH2022PTC387875.

19. Changes

We may update this policy. The version date will change. Hospitals are notified of material changes at least [30] days in advance; changes reducing protection require the hospital's agreement under the DPA. Any change to Section 4 will be notified prominently and in advance — what the platform does not collect is the substance of the promise.