Legal
Privacy statement
Effective 1 January 2026 · Wellnext Technologies Pvt Ltd
1. Introduction
This Privacy Statement ("Statement") explains how Wellnext ("Company," "we," "us," or "our")
collects, uses, discloses, and safeguards your information when you visit our website, web applications,
mobile applications (collectively, the "Platform"), and when you engage with our services ("Services").
Our Platform and Services are designed for doctors, healthcare professionals, medical assistants, clinics,
and healthcare organizations (each a "User" or "Customer"). We are committed to protecting your privacy
and ensuring transparency about our data practices. Please read this Statement carefully.
2. Information We Collect
We collect information in the following ways:
2.1 Information You Provide Directly
• Account Registration: Name, email address, phone number, professional credentials, clinic/organization details
• Profile Information: Professional background, specialization, qualifications, work experience
• Communication Data: Messages, feedback, support requests, and correspondence with our team
• Beta Program Data: Responses to forms, surveys, and participation in testing programs
• Payment Information: Billing address, payment method details (processed securely through third-party providers)
2.2 Information Collected Automatically
• Device Information: Device type, operating system, browser type, IP address, device identifiers
• Usage Data: Pages visited, time spent, features accessed, clickstream data, search queries
• Performance Data: Load times, error logs, API response times, diagnostic information
• Location Data: General geographic location (city/country level) based on IP address
• Cookies and Similar Technologies: Session identifiers, preferences, authentication tokens
2.3 Patient/Clinical Data (When Acting as Data Processor)
When Customers use our Platform to store, manage, or process patient information:
• We act as a Data Processor on your behalf
• We do not collect, use, or disclose patient data except as instructed by the Customer
• Patient data is subject to separate Data Processing Agreements (DPA)
• Customers retain full responsibility for patient consent and compliance
3. How We Use Your Information
We use collected information for the following purposes:
3.1 Core Service Delivery
• Providing, maintaining, and improving the Platform and Services
• Creating and managing your account
• Processing transactions and sending transaction confirmations
• Delivering customer support and responding to inquiries
3.2 Product Development and Analytics
• Analyzing usage patterns to improve functionality
• Conducting market research and generating aggregated analytics
• A/B testing and feature optimization
• Developing new features and services
3.3 Communication
• Sending service announcements and updates
• Notifying you about changes to the Platform or our policies
• Promotional communications (with your consent)
• Security alerts and account notifications
3.4 Compliance and Legal
• Complying with legal obligations
• Enforcing our Terms of Service
• Protecting against fraud, security, or technical issues
• Responding to lawful requests from authorities
3.5 Clinical Feedback and Improvement
• Gathering feedback from beta program participants
• Validating clinical workflows
• Improving product usability for healthcare professionals
• Anonymized data may be used for research and product validation
4. Data Sharing and Third Parties
We may share your information in the following circumstances:
4.1 Service Providers
• Cloud Infrastructure Providers (AWS, Azure) for hosting and storage
• Payment Processors for secure payment handling
• Email and Communication Services for notifications
• Analytics Providers for usage analysis
• Customer Support Platforms for support ticket management
4.2 Business Partners
• Integration partners enabling interoperability with your existing systems
• Marketing partners (only with your explicit consent)
4.3 Legal and Regulatory Requirements
• Law enforcement, government agencies, or regulatory bodies when legally required
• To protect against fraud, security threats, or illegal activities
• In response to valid subpoenas, court orders, or government requests
4.4 Business Transfers
• In the event of merger, acquisition, bankruptcy, or asset sale
• We will provide notice and applicable choices before transferring personal data
4.5 Public or Aggregated Information
• Testimonials and case studies (only with explicit written consent)
• Anonymized, aggregated data that cannot identify you
• General usage statistics and industry benchmarks
4.6 Sensitive Handling
• Patient data is never shared except as per your explicit instructions (Data Processing Agreement)
• We do not sell personal information to third parties for marketing purposes
5. Data Retention
5.1 Account and Service Data
• Active accounts: Information retained for the duration of your subscription
• After account deletion: Core data retained for 30 days (for account recovery), then permanently deleted
• Legal compliance: Certain data retained as required by law (e.g., tax records for 7 years)
5.2 Patient Clinical Data
• Retained as per your instructions and applicable healthcare regulations
• You can request deletion of patient records at any time
• We comply with data retention requirements under HIPAA, GDPR, and local regulations
5.3 Backup and Archive Data
• Backup copies may persist for up to 90 days for disaster recovery purposes
• Archived data may be retained longer as required by compliance frameworks
5.4 Usage Logs and Analytics
• Technical logs retained for 12 months for security and performance analysis
• Anonymized aggregates retained indefinitely for product improvement
6. Your Rights and Choices
6.1 Access and Portability
• You have the right to access your personal data
• You can request your data in a portable, machine-readable format
• Requests processed within 30 days at no cost
6.2 Correction and Updates
• You can update, correct, or modify your profile information at any time via account settings
• We will update records within a reasonable timeframe
6.3 Deletion (Right to Be Forgotten)
• You can request deletion of your account and associated personal data
• We will delete your data within 30 days, except where retention is legally required
• Note: Patient data deletion follows your instructions in the DPA
6.4 Opt-Out of Communications
• Opt out of promotional emails via account settings or unsubscribe links
• You cannot opt out of essential service notifications (e.g., security alerts)
6.5 Cookie and Tracking Preferences
• Control cookie preferences via your browser settings
• We honor "Do Not Track" signals where applicable
6.6 Exercising Your Rights
• Submit requests to privacy@wellnextek.com
• Include sufficient information to verify your identity
• We will respond to requests promptly and professionally
7. Data Security
7.1 Security Measures
• Encryption: All data transmitted over HTTPS/TLS 1.2 or higher
• At-Rest Encryption: Patient and sensitive data encrypted in databases
• Access Controls: Role-based access with multi-factor authentication options
• Monitoring: Continuous security monitoring and intrusion detection
7.2 Infrastructure Security
• Hosting on AWS in compliance with SOC 2 Type II standards
• Regular security audits and penetration testing
• Automated backup and disaster recovery procedures
• Firewalls and network segmentation
7.3 Employee and Contractor Security
• Background checks for employees with data access
• Confidentiality agreements and data handling training
• Limited access on a need-to-know basis
• Incident response procedures
7.4 Limitations
• While we implement industry-standard security, no method is 100% secure
• You are responsible for maintaining your account credentials
• Report any security concerns to security@wellnextek.com immediately
9. GDPR and International Data Protection
9.1 GDPR Compliance (EU/UK Users)
• Legal Basis: We process data based on contract performance, legitimate interests, compliance obligations, or your consent
• Data Processing Agreements: Available for B2B customers
• GDPR Rights: Access, correction, deletion, portability, and objection rights
• International Data Transfers: We use Standard Contractual Clauses (SCCs) for EU-US transfers
9.2 Data Protection Officer (DPO)
• Customers can contact our DPO for GDPR-related inquiries
• DPO email: dpo@wellnextek.com
9.3 Privacy by Design
• Data minimization: Collecting only necessary information
• Purpose limitation: Using data only for stated purposes
• Accountability: Maintaining records of data processing activities
9.4 Other International Regulations
• CCPA (California): Residents have rights to access, delete, and opt-out
• PIPEDA (Canada): Personal information handling complies with Canadian standards
• LGPD (Brazil): Compliance with Brazilian data protection requirements
• HIPAA Compliance: As applicable for healthcare data processors
10. Children's Privacy
10.1 Age Restrictions
• Our Platform and Services are not intended for individuals under 18 years of age
• We do not knowingly collect personal information from minors
• If we become aware of data from someone under 18, we will delete it promptly
10.2 Parental Consent
• If a minor's information is discovered, parents/guardians can request deletion
• Contact privacy@wellnextek.com to report any child safety concerns
11. Changes to This Privacy Statement
11.1 Updates and Amendments
• We may update this Statement to reflect changes in practices, technology, or regulations
• Material changes will be communicated via email or prominent notice on the Platform
• Continued use after changes indicates acceptance of the updated Statement
11.2 Notification
• We will provide at least 30 days' notice for significant policy changes
• Major changes may require explicit consent
12. Contact Us
For privacy-related inquiries, requests, or concerns, please contact us:
Email: privacy@wellnextek.com
Data Protection Officer: dpo@wellnextek.com
Mailing Address:
Wellnext
Kolkata, West Bengal, India (registered office address to be published)
[City, State/Country, Postal Code]
Response Time: We aim to respond to all privacy inquiries within 10 business days.
EU Users: You also have the right to lodge a complaint with your local data protection authority.