1. Scope and Controller
This Privacy Policy applies to the ActiveEMR Android application and related services. ActiveEMR is a healthcare practice-management and electronic medical-record tool for authorized healthcare professionals, clinics, and clinic staff in India.
Aether Enterprise Applications LLP is the service provider and, where it determines the purposes and means of processing, the data fiduciary/controller. A clinic or healthcare organization may separately be the controller/data fiduciary for patient information it enters into ActiveEMR. The Terms & Conditions are available separately at terms.html.
2. Information We Collect
We collect only information needed to provide, secure, maintain, and improve ActiveEMR. The exact fields depend on features enabled by the healthcare organization.
Health Information
Authorized users may enter patient names, contact details, demographic information, appointment details, consultation notes, symptoms, diagnoses, prescriptions, medicines, allergies, medical history, and other health information. This is sensitive personal data. We process it to provide the requested clinical and practice-management functions on behalf of the relevant healthcare organization and its authorized users.
Personal Information
We may collect a user's name, email address, phone number, clinic or organization, professional role, and account identifiers. We may also receive information included in support requests.
Device and Technical Information
We may collect app version, operating-system version, device model, language, time zone, IP address, identifiers needed for authentication or security, log data, and the Firebase Cloud Messaging (FCM) device registration token. We do not use this information to build advertising profiles.
Where Information Is Stored
Patient and account information is stored in the ActiveEMR application service and infrastructure configured by the relevant healthcare organization. FCM may process a device registration token for notification delivery, but no patient medical records are stored in Firebase Cloud Messaging. ActiveEMR is intended for use by healthcare organizations and authorized users in India. We process and store information in accordance with applicable Indian laws and regulations.
Authentication Information
We collect account credentials or authentication tokens needed to sign in and keep an account secure. Passwords, if used, are stored in a protected form and not as readable text. ActiveEMR does not use Firebase Authentication. If a future version enables Google Sign-In, this Policy will be updated before that processing begins.
Information We Do Not Collect
ActiveEMR does not sell personal or health information. ActiveEMR currently does not collect precise location, contacts, photos, microphone, storage contents, or advertising identifiers.
3. Permissions Used
ActiveEMR requests only the permissions necessary to provide its features. Where notification permission is required by the operating system, it is requested solely to deliver appointment reminders, service updates, and security or account notifications. Users may grant, deny, or revoke this permission through their device settings. ActiveEMR does not request camera, microphone, contacts, location, or storage permissions.
4. How We Use Information
- Provide appointment, consultation, prescription, patient-record, and account functions.
- Authenticate users, enforce clinic roles, prevent fraud and unauthorized access, and investigate security incidents.
- Send appointment reminders, service updates, and security or account notifications through FCM.
- Provide support, maintain service reliability, and investigate security events using applicable service logs.
- Comply with legal obligations, respond to lawful requests, and protect rights and safety.
We do not use health information for advertising, sell it, or use it for unrelated profiling.
5. Legal Basis
Where GDPR applies, processing may be based on performance of a contract, compliance with legal obligations, legitimate interests in securing and operating the service, or consent where required. Health information is processed only with an appropriate legal basis and applicable special-category condition, normally under the direction of the healthcare organization. Where India's Digital Personal Data Protection Act, 2023 applies, processing is based on consent or a permitted legitimate use, as applicable, and in accordance with applicable rules and notifications.
6. Sharing and Third Parties
We share information only as described below and only to the extent necessary:
- Healthcare organization and authorized users: Patient records are available to the clinic, care team, and users whose role-based access permits it.
- Service providers: Hosting, application infrastructure, support, security, and notification providers may process information under confidentiality and contractual safeguards.
- Firebase Cloud Messaging: ActiveEMR uses FCM solely to deliver push notifications such as appointment reminders, updates, and service-related notifications. We share an FCM device registration token and the technical information needed for delivery with Google as the FCM service provider. FCM may process that token for notification delivery. No patient medical records are stored in FCM. ActiveEMR currently does not use Firebase Authentication, Cloud Firestore, Cloud Storage, Firebase Analytics, or Firebase Crashlytics. If a future release enables additional Firebase services, this Policy will be updated before that processing begins.
- Legal and safety disclosures: We may disclose information when required by law, court order, or competent authority, or when necessary to prevent fraud, security threats, or harm.
- Business changes: Information may transfer in a merger, acquisition, or restructuring subject to applicable law and continued protection.
We do not sell, rent, or share personal or health information for targeted advertising. We do not permit third-party advertising SDKs to access patient records.
7. Security Measures
We use reasonable technical and organizational safeguards appropriate to the sensitivity of healthcare information, including HTTPS/TLS encryption in transit, authenticated access, least-privilege access, role-based access controls, protected password storage, security logging, and security monitoring. No system is completely secure, so users must protect devices, credentials, and access tokens and report suspected incidents promptly.
Role-Based Access
Clinic administrators assign roles and permissions. Users should receive only the access needed for their duties. Healthcare organizations remain responsible for approving users, reviewing permissions, and removing access when a user leaves or changes role.
8. Retention and Deletion
We retain account, security, support, service, and FCM registration-token information for as long as needed to provide ActiveEMR, deliver requested notifications, meet legal, accounting, dispute-resolution, and security obligations, or until the relevant organization requests deletion, subject to lawful retention requirements. Patient records are retained according to the healthcare organization's instructions and applicable medical-record laws. FCM registration tokens are deleted or refreshed when they are no longer needed for notification delivery or when deletion is requested, subject to technical and legal limits.
Data Deletion Process
To request account or data deletion, contact activeemr@aetherti.com from an authorized account or ask the clinic administrator. We may verify identity and authority before acting. We will delete or anonymize information we control within a reasonable period, unless retention is required by law, needed to resolve disputes or security incidents, or requested by the healthcare organization as controller/data fiduciary. The organization remains responsible for deletion requests concerning patient records it controls.
9. Your Rights
Depending on location and role, you may have rights to access, correction, portability, restriction, objection, withdrawal of consent, and deletion, and the right to complain to a data-protection authority. Patients should first contact the healthcare organization that controls their records. Users may contact us for requests concerning information we control; withdrawal does not affect processing already lawfully completed. We will respond within the period required by applicable law.
10. Children's Privacy
ActiveEMR is intended for healthcare professionals and clinic staff, not children. We do not knowingly allow children to create provider accounts. A child may be a patient whose information is entered by an authorized healthcare professional; the responsible healthcare organization must obtain any consent required by law.
11. Changes to This Privacy Policy
We may update this Policy to reflect changes in ActiveEMR, law, or our processing. We will post the revised version with a new “Last updated” date and, where required, provide additional notice or obtain consent. Continued use after an effective update is subject to applicable law and the revised Policy.
12. Contact Information
For privacy questions, rights requests, complaints, or security concerns, contact:
Aether Enterprise Applications LLP
Email: activeemr@aetherti.com
Unit No. 5, S. No. 22, Plot 18,20
Near Metropolis
Off Balewadi High Street
Balewadi
Pune 411045, India