1. Introduction
This Privacy Policy describes how iHUB Technologies Private Limited ("iHUB", "we", "us", or "our") collects, uses, stores, shares, and protects information when you use the Qurix EMR mobile application (the "App"), package name com.qurix.emr, and related services operated under the Qurix brand.
Qurix EMR is an electronic medical records (EMR) application intended for authorised healthcare professionals and hospital staff. By installing or using the App, you agree to the practices described in this policy. If you do not agree, please do not use the App.
2. Who This Policy Applies To
This policy applies to:
- Healthcare professionals, nurses, and hospital staff who log in to the App.
- Organisations (hospitals, clinics, or healthcare providers) that subscribe to Qurix services.
The App is not intended for use by patients as end users. Patient health information may be accessed and processed through the App by authorised clinical users on behalf of their healthcare organisation.
3. Information We Collect
Depending on how you use the App, we may collect the following categories of information:
3.1 Account and authentication information
- Username and login credentials submitted through our single sign-on (SSO) service.
- Access tokens, refresh tokens, and session identifiers used to keep you signed in securely.
- Organisation, location, role, and permission details associated with your account.
3.2 Professional user information
- Name, employee ID, designation, mobile number, and profile details of authorised users.
- Department, location, and role-based access configuration.
3.3 Patient and clinical health information
When you use EMR features, the App may access, display, or transmit patient-related health information, including but not limited to:
- Patient demographics and visit details.
- Vitals, prescriptions, medications, investigations, and treatment records.
- Medical history, physical examination notes, and discharge summaries.
- Nursing worklists, inpatient records, and appointment information.
- ABHA (Ayushman Bharat Health Account) related data when ABHA features are enabled.
This information is processed on behalf of your healthcare organisation and in accordance with applicable healthcare laws and your organisation's policies.
3.4 Technical and usage information
- Device type, operating system version, and app version.
- IP address, network connection status, and timestamps of access.
- Logs related to authentication, errors, and system performance for security and support.
- Temporary data stored locally on your device during an active session (for example, authentication helpers and selected workspace context).
4. How We Use Your Information
We use collected information to:
- Authenticate users and provide secure access to the App.
- Enable clinical workflows such as doctor visits, nursing tasks, inpatient management, and discharge documentation.
- Display, record, and synchronise patient health information within your organisation's EMR system.
- Support ABHA and ABDM integrations where enabled by your organisation.
- Maintain security, prevent unauthorised access, and investigate incidents.
- Provide technical support and improve reliability of the App and related services.
- Comply with legal, regulatory, and contractual obligations.
5. How Information Is Shared
We do not sell your personal information or patient health information.
We may share information only in the following circumstances:
- With your healthcare organisation: Clinical and user data is accessible to authorised personnel within your organisation according to role-based permissions.
- With service providers: We use trusted infrastructure and technology partners to host, secure, and operate Qurix services (including authentication, cloud hosting, and content delivery).
- With government health systems: When ABHA/ABDM features are used, relevant data may be exchanged with authorised government health infrastructure as required for those integrations.
- For legal reasons: When required by law, regulation, court order, or to protect rights, safety, and security.
- With your consent: Where additional sharing is requested and permitted by applicable law.
Key domains and services used by the App include:
- qurix.io – core application and API services
- sso.qurix.ai – authentication services
- bi.qurix.io – reporting and analytics (where enabled)
- ABDM/ABHA government gateway services (where enabled)
6. Data Storage and Security
We implement administrative, technical, and organisational safeguards designed to protect information against unauthorised access, alteration, disclosure, or destruction. These measures include encrypted communication over HTTPS, access controls, authentication mechanisms, and role-based permissions.
Some session-related data may be stored temporarily on your device while you are logged in. Primary clinical records are stored on secure servers operated or managed by iHUB and/or your healthcare organisation.
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security.
7. Data Retention
We retain information for as long as necessary to provide the App and related services, fulfil the purposes described in this policy, and comply with legal and regulatory requirements. Clinical records are retained according to your healthcare organisation's policies and applicable healthcare record-keeping laws.
Session and authentication data on your device is generally cleared when you log out or when the session expires.
8. Your Rights and Choices
Depending on applicable law (including India's Digital Personal Data Protection Act, 2023, where applicable), you may have rights to access, correct, update, or request deletion of certain personal information, or to withdraw consent where processing is consent-based.
Because Qurix EMR is typically provided through your employer or healthcare organisation, requests relating to your professional account or patient records may need to be submitted through your organisation's designated administrator, in addition to contacting us using the details below.
9. Permissions Used by the App
The Android version of Qurix EMR requests the following permission:
- Internet access – required to connect to Qurix servers, authenticate users, and synchronise clinical data.
The App does not request access to device contacts, camera, microphone, or location unless such permissions are added in a future version. If that changes, this policy will be updated accordingly.
10. Children's Privacy
The App is intended for use by authorised healthcare professionals and is not directed at children under the age of 18 for direct registration or use. Patient records relating to minors may be processed by authorised clinical users as part of legitimate healthcare services.
11. International Data Transfers
Your information may be processed and stored on servers located in India or other jurisdictions where our service providers operate. Where required, we take steps to ensure appropriate safeguards are in place for such processing.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. Continued use of the App after changes become effective constitutes acceptance of the revised policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Data Controller: iHUB Technologies Private Limited
- Product: Qurix EMR
- Email: contact@ihubtechnologies.co
- Phone: +91-9963553531
- Website: https://qurix.com
For account access issues, please also contact your hospital or clinic administrator.