Privacy Policy

How we protect your healthcare and communication data

Last updated: January 15, 2025

Our Commitment to Your Privacy

At Cure Clock, safeguarding healthcare-related information is a core responsibility. This Privacy Policy outlines how we collect, process, store, and protect information across our healthcare communication infrastructure. We follow strict security standards designed for medical environments, ensuring trust, transparency, and data protection.

1. Information We Collect

1.1 Account Information

  • Name, email address, and contact number
  • Healthcare organization details (clinic, hospital, pharmacy, distributor)
  • Professional credentials and compliance documents
  • Billing and subscription details
  • Dashboard preferences and notification settings

1.2 Patient Communication Data

  • Patient names and mobile numbers shared by providers
  • Medication reminders, appointment data, and refill cycles
  • Message content, timestamps, and delivery analytics
  • Opt-in/opt-out preferences

1.3 Usage & Technical Information

  • IP address, device identifiers, browser metadata
  • Platform performance logs and diagnostic events
  • Error logs and system monitoring data
  • Aggregate analytics for product improvement

2. How We Use Your Information

2.1 Core Healthcare Communication Services

  • Sending medication reminders and refill alerts
  • Automating appointment notifications and confirmations
  • Supporting clinic–patient and pharmacy–patient communication
  • Enhancing treatment adherence and continuity of care

2.2 Platform Operations

  • User authentication and account maintenance
  • Billing, invoicing, and payment management
  • User support, verification, and compliance checks
  • Fraud prevention and platform security

2.3 Improving Platform Quality

  • Product analytics and feature enhancement
  • Performance optimization
  • Quality assurance and debugging
  • Legal audit readiness and reporting

3. Data Protection & Security

Enterprise-Grade Security

Our infrastructure is built on global data-security frameworks suitable for healthcare environments, featuring encrypted communication channels, hardened cloud infrastructure, and multi-layer threat protection.

3.1 Technical Safeguards

  • AES-256 encryption for all stored data
  • End-to-end encryption for data in transit
  • Multi-factor authentication
  • Continuous vulnerability scanning
  • Disaster recovery & business continuity systems

3.2 Administrative Safeguards

  • Role-based access control with audit logs
  • Quarterly employee cybersecurity training
  • Compliance-driven data governance policies
  • Incident response protocols

3.3 Physical Safeguards

  • Enterprise-grade cloud data centers
  • Biometric and surveillance-controlled facilities
  • Environmental monitoring systems
  • Secure destruction of storage hardware

4. Healthcare Compliance

4.1 HIPAA (United States)

Cure Clock does not store Protected Health Information (PHI) on behalf of providers. Healthcare organizations remain responsible for HIPAA applicability in their workflows.

4.2 Digital Personal Data Protection Act (India)

We follow DPDPA 2023 principles for:

  • User consent management
  • Purpose limitation & lawful processing
  • Data minimization
  • Secure processing and breach reporting

4.3 GDPR (European Union)

  • Right to access, rectification, and erasure
  • Data portability
  • Lawful basis for processing
  • Data transfer safeguards (SCCs)

5. Data Sharing & Disclosure

Limited & Controlled Data Sharing

Data is never sold. Information is shared only when necessary to operate the platform or meet legal obligations.

5.1 Trusted Service Providers

  • WhatsApp Business API providers
  • AWS & Google Cloud hosting
  • Payment processors
  • Analytics tools for feature optimization

5.2 Legal Compliance

We may disclose information for:

  • Court orders and regulatory investigations
  • National security or law enforcement requests
  • Public health emergencies

5.3 Business Transfers

In case of mergers or acquisitions, your data remains protected under the same privacy commitments.

6. Your Rights & Choices

6.1 User Rights

  • Access your stored information
  • Request corrections or updates
  • Download your data
  • Request account and data deletion

6.2 Communication Control

  • Manage notification frequency
  • Opt-out of promotional messages
  • Control data sharing settings
  • Update consent preferences anytime

6.3 Patient Rights

  • Request communication restrictions
  • Set preferred communication methods
  • Submit privacy complaints
  • Request policy copies

7. Data Retention

7.1 Standard Retention Durations

  • Account Info: Duration of account + 7 years
  • Communication Logs: 3 years
  • Billing Data: 7 years
  • Analytics: Aggregated indefinitely

7.2 Secure Disposal

Upon expiry, data is permanently deleted using cryptographic wiping and secure destruction procedures.

8. International Data Transfers

Cure Clock operates globally and may process data outside your home country. We use:

  • Standard Contractual Clauses (EU)
  • Regional data residency when required
  • Cross-border transfer agreements
  • Compliance-proven cloud infrastructure

9. Children's Privacy

We do not knowingly collect data from children under 13 without verified parental consent. Pediatric healthcare providers using the platform must:

  • Obtain parental authorization
  • Ensure lawful processing of child data
  • Provide parents full access to information
  • Request deletion of a child's data anytime

10. Policy Updates

We update this policy when laws evolve or new capabilities are added. You will receive:

  • Email notifications
  • Dashboard alerts
  • 30-day review periods for major changes
  • Version logs for transparency

11. Contact Us

For questions or privacy-related requests, contact:

Privacy Officer

[email protected]

Response within 48 hours

Mailing Address

Cure Clock Privacy Team
Meethuu India LLP
Warje, Pune
Maharashtra 411058, India

This Privacy Policy is effective as of January 15, 2025

Version 2.1 — Updated for healthcare data protection