Privacy Policy

We are committed to protecting data, privacy, and trust across every interaction

1. Introduction

mCURA Mobile Health Pvt Ltd (“mCURA”, “we”, “our”) respects the privacy of hospitals, clinicians, and users who interact with our platforms. This Privacy Policy explains how information is collected, used, stored, and protected.

2. Information We Collect

We may collect limited and relevant information including:

  • Contact information such as name, phone number, and email address
  • Hospital or clinic details shared through enquiry forms
  • Non-identifiable usage and interaction data
  • Website analytics and technical information

3. Patient Data & Clinical Information

mCURA follows a privacy-first, on-premise architecture. Identifiable patient data never leaves the hospital environment. All processing is designed to align with NABH principles and healthcare privacy best practices.

4. Use of Information

  • To respond to enquiries and demo requests
  • To deliver and improve OPD workflow solutions
  • To ensure regulatory and operational compliance
  • For internal analytics and performance optimisation

5. Data Security

We implement appropriate technical and organisational safeguards, including access controls, encryption, audit logs, and secure infrastructure practices. Security is continuously reviewed and strengthened.

6. Cookies & Analytics

Our website may use cookies to improve experience and measure usage. Cookies do not collect or store sensitive medical or patient-identifiable data.

7. Third-Party Services

We may engage trusted third-party services strictly for operational support. All partners are required to follow confidentiality and data protection standards.

8. Legal Disclosure

Information may be disclosed where required by law, regulation, or legal process, or to protect the rights and safety of mCURA and its stakeholders.

9. Policy Updates

This Privacy Policy may be updated periodically. Continued use of our services constitutes acceptance of the updated policy.

10. Data Retention

We retain personal information only for as long as necessary to provide our services, comply with applicable legal obligations, resolve disputes, and enforce our agreements.

mCURA follows a privacy-first, on-premise architecture. Clinical patient records remain within the hospital-controlled environment and are managed by the respective healthcare provider. We do not retain identifiable patient records on our servers.

Certain operational information, such as authentication logs, notifications, crash reports, diagnostics, and non-personal analytics, may be processed securely by mCURA or trusted service providers solely for operating, maintaining, securing, and improving our services.

11. Data Deletion

Users may request deletion of their personal information by contacting us through our official support channels.

Upon receiving a verified request, we will delete or anonymize personal information within 30 days unless we are legally required to retain certain information for regulatory, contractual, or legal purposes.

Where patient records are managed by a hospital or healthcare provider using the mCURA platform, requests for deletion or modification of clinical records should be directed to the respective healthcare provider, which acts as the data controller for such information.

**Clinical patient records remain within the hospital-controlled environment. Certain operational information (such as authentication, notifications, crash reports, diagnostics, or analytics) may be processed securely by mCURA or trusted service providers solely for operating and improving the application.**