1. Who we are
ProVaidya is a FHIR-native, ABDM-aligned EHR prototype operated by the ProVaidya team ("ProVaidya", "we", "us"). This policy explains how we handle information when practitioners use the ProVaidya application at ehr.provaidya.com and its subdomains (the "Service"). ProVaidya is currently released to a limited set of testers for evaluation purposes.
2. Scope
This policy covers information we collect from practitioner accounts and information entered into the Service. Clinical data (patients, encounters, vitals, prescriptions, documents, etc.) is stored on the FHIR server the practitioner connects to (for example, a HAPI or Medblocks server). ProVaidya acts as a thin, secure interface over that record — we do not operate the FHIR server itself unless explicitly stated.
3. Information we collect
Account information. When you sign in (including via Google OAuth), we receive your email address, name, and a unique account identifier. We do not receive your Google password.
Practitioner settings. Preferences you set inside the app — active FHIR server, vitals template, Ayurveda mode, and cached practitioner FHIR identifiers.
Clinical content you enter. Data you create about patients (demographics, encounters, observations, diagnoses, prescriptions, notes, uploaded documents, appointments). This is written to the FHIR server you selected, through our secure proxy.
Operational logs. Standard request logs, error traces, and audit records (who did what, when) used to keep the Service secure and reliable.
4. Google user data
If you sign in with Google, we use your Google profile only to authenticate you and create your ProVaidya account. We do not use Google user data for advertising, resell it, or share it with third parties for their own purposes. We do not read your Gmail, Drive, Calendar, or Contacts. Access can be revoked at any time from your Google Account settings.
5. How we use information
- Authenticate you and keep your session secure.
- Route your requests to the FHIR server you selected.
- Attribute clinical writes to you (Provenance) for audit and safety.
- Enable AI-assisted features (e.g., clinical summaries, SOAP drafting).
- Diagnose bugs, prevent abuse, and improve the Service.
6. AI features
Selected features send de-identified or minimally identified clinical context to an AI model (currently via the Lovable AI Gateway) to generate summaries or drafts. Outputs are advisory only, must be reviewed by a qualified clinician before use, and are not a substitute for professional judgment.
7. Sharing
We share information only with: (a) the FHIR server you have connected to, at your direction; (b) infrastructure providers (hosting, database, AI gateway) that process data on our behalf under confidentiality obligations; and (c) as required by law. We do not sell personal information.
8. Security
FHIR bearer tokens live only in server-side secrets — never in the browser. All client-to-FHIR traffic passes through a JWT-validated edge function with a strict per-path whitelist. Data in transit is encrypted with TLS. Access to our backend is role-based and audited. No system is perfectly secure; you are responsible for keeping your account credentials safe.
9. Data retention
Account and settings data is retained while your account is active. Clinical data lives on your chosen FHIR server and is governed by that server's retention rules. You may request deletion of your ProVaidya account at any time (see Contact below).
10. Your rights
Depending on your jurisdiction (including under India's DPDP Act, GDPR, and similar laws), you may have the right to access, correct, export, or delete your personal information, and to withdraw consent. Contact us to exercise these rights.
11. Children
The Service is intended for use by healthcare practitioners and is not directed to children. Clinical records about minors may be entered by an authorized practitioner in the course of care.
12. Changes
We may update this policy as the Service evolves. Material changes will be communicated in-app or by email. The "Last updated" date above reflects the current version.
13. Contact
Questions or requests? Email privacy@provaidya.com.