Privacy Policy

Last updated: 2026

1. Introduction

StethoSuite ("we", "us", "our") is committed to protecting the privacy of healthcare providers and their patients. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service. Please read this policy carefully.

2. Information We Collect

Account Information

When you register, we collect your name, email address, organization name, and contact details to create and manage your account.

Patient Data

Through the Service, you may input patient identifiers such as Medical Record Numbers (MRN), accession numbers, dates of birth, and phone numbers. This data is used solely to generate and manage secure viewing links. We do not store DICOM imaging files — these remain on your own infrastructure.

Usage Data

We automatically collect information about how the Service is used, including link creation timestamps, view counts, IP addresses of viewers, and API call logs. This data is used for security monitoring and service improvement.

3. How We Use Information

  • To provide, operate, and maintain the Service
  • To authenticate patients accessing viewing links
  • To send WhatsApp notifications on your behalf (when configured)
  • To monitor for security threats and unauthorized access
  • To generate usage reports and analytics for your account
  • To communicate with you about your account and the Service
  • To comply with legal obligations

4. Data Sharing and Disclosure

We do not sell patient data or account data to third parties. We may share information in the following limited circumstances:

  • Service Providers: We use trusted third-party providers (database hosting, cloud infrastructure) who process data only on our behalf under strict confidentiality agreements.
  • WhatsApp / Meta: When you send viewing links via WhatsApp, the patient's phone number and message content are transmitted to Meta's WhatsApp Business API.
  • Legal Requirements: We may disclose information if required by law, court order, or government authority.

5. Data Security

We implement industry-standard security measures including TLS encryption for all data in transit, encrypted storage, access controls, and regular security audits. Viewing links require patient identity verification (date of birth). Links automatically expire and can be revoked at any time. However, no method of transmission over the internet is 100% secure.

6. Data Retention

We retain account data for as long as your account is active. Viewing link records are retained for audit purposes for up to 12 months after expiry. You may request deletion of your data by contacting us. We will delete data within 30 days of a valid request, subject to legal retention requirements.

7. Your Responsibilities

As a healthcare provider using the Service, you are responsible for obtaining appropriate patient consent before sharing their data through StethoSuite, complying with all applicable data protection laws in your jurisdiction (including PDPA, HIPAA, GDPR, or other relevant regulations), and ensuring your use of patient data is lawful and authorized.

8. Cookies and Tracking

We use essential session cookies to authenticate users and maintain secure sessions. We do not use advertising cookies or third-party tracking technologies. Patient viewing sessions use minimal session storage for verification purposes only.

9. Data Transfers

Your data may be stored and processed in servers located outside your country. We ensure appropriate safeguards are in place for any cross-border data transfers in accordance with applicable data protection laws.

10. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Data portability

To exercise these rights, contact us at [email protected].

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice in the Service. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at [email protected].