NUREV TECH LLP operates NADIS, a cloud healthcare technology platform used by hospitals, clinics, pharmacies, diagnostic centres, laboratories and other healthcare organizations.
We recognize that healthcare information requires a particularly high level of confidentiality, integrity and accountability. This Privacy Policy explains how NADIS collects, uses, stores, protects and discloses personal information.
1. Scope
This Privacy Policy applies to information processed through NADIS, including information relating to:
- patients and their representatives;
- doctors and healthcare professionals;
- Facility owners and administrators;
- pharmacists, nurses, diagnostic personnel and other staff;
- suppliers and business contacts; and
- visitors and authorised users of NADIS.
Where a Facility uses NADIS to provide healthcare services, that Facility generally determines the healthcare purpose for which patient information is collected and used. NADIS provides the technology used to securely process that information.
2. Information We Process
Depending on the services used, NADIS may process:
Identity and demographic information
Name, age, date of birth, sex, address, phone number, email, patient identifiers and similar information.
Health and clinical information
Consultation notes, medical history, diagnoses, prescriptions, allergies, medications, test orders, diagnostic results, audiometry information, medical documents, images, reports and related healthcare records.
Facility and professional information
Facility details, staff accounts, professional roles, registration information, permissions and employment-related information necessary to operate the platform.
Appointment and operational information
Appointments, queues, check-ins, follow-ups, communications and operational activity.
Billing and transaction information
Invoices, receipts, payment amounts, payment methods, refunds and transaction references.
NADIS does not currently intend to store raw payment-card credentials.
Consent and signature information
Consent records, acknowledgements, timestamps, user actions and electronic signatures where such features are used.
Technical and security information
Login events, IP addresses, device or browser information, audit trails, access logs, security events and system activity.
3. Why We Process Information
Information may be processed to:
- provide healthcare-management and EHR functionality;
- maintain patient records;
- schedule and manage appointments;
- support prescriptions and clinical workflows;
- operate pharmacy and inventory services;
- perform and record diagnostics;
- generate invoices, receipts and reports;
- enable authorized communications;
- authenticate users and manage permissions;
- maintain security and investigate misuse;
- provide technical support;
- maintain backups, audit trails and service reliability;
- comply with applicable law and lawful governmental requirements; and
- improve the reliability and functionality of NADIS.
We seek to limit collection and processing to information reasonably necessary for these purposes.
4. Healthcare Data and Consent
Healthcare information is processed only for legitimate healthcare, operational, contractual, security or legal purposes and, where required, on the basis of appropriate patient or representative consent.
Facilities using NADIS are responsible for obtaining the consents or other lawful authority required for the healthcare services they provide.
Separate or specific consent may be required for certain activities, including sharing records outside the treating Facility, ABDM/ABHA exchanges, certain communications, research or other secondary uses.
A Facility administrator accepting the NADIS Terms cannot provide consent on behalf of every patient whose information may later be processed.
5. How We Share Information
NADIS does not sell, rent or broker patient health information, and does not use identifiable patient health information for third-party advertising.
Information may be disclosed only where reasonably necessary:
- to authorized users within the relevant Facility;
- to another healthcare provider when lawfully authorized;
- at the direction or with the consent of the patient or Facility, as applicable;
- to infrastructure and service providers acting on our behalf;
- to payment providers where electronic payments are used;
- to government, regulatory, judicial or law-enforcement authorities where legally required; or
- during an emergency or other circumstance where disclosure is permitted or required by applicable law.
Service providers receive only the information reasonably necessary for their function and are subject to appropriate contractual and security controls.
6. AI and Automated Systems
NADIS may provide AI-assisted healthcare or operational functionality such as summaries, workflow assistance, clinical support, interaction checks or other decision-support capabilities.
AI outputs are designed to support human users and should not independently replace qualified clinical judgment.
NADIS does not currently sell patient data or provide identifiable patient health records to third parties for unrelated AI training.
Identifiable clinical information will not be used to train a general-purpose third-party AI model unless the processing is separately assessed, appropriately authorised and permitted under applicable law.
7. Security
NADIS uses security measures appropriate to the sensitivity of healthcare information, which may include:
- encryption in transit and at rest;
- role-based and permission-based access;
- authentication controls;
- tenant and Facility access boundaries;
- system and data-access logging;
- monitoring and security review;
- secure backups and recovery controls;
- restricted administrative access; and
- audit trails for sensitive healthcare actions.
We continually review security controls as the platform and regulatory environment evolve.
8. Storage in India
NADIS is architected so that production patient health records are stored on infrastructure located in India.
Where third-party services are used for ancillary functions, NUREV TECH evaluates the information processed by those providers and applicable restrictions before enabling such processing.
Any future transfer or processing outside India will be handled in accordance with applicable Indian law and contractual safeguards.
9. Retention, Correction and Deletion
Healthcare records may need to be preserved for clinical continuity, auditability, regulatory requirements, dispute resolution and other lawful purposes.
For this reason, NADIS uses record versioning, restricted archival and logical or "safe" deletion for certain clinical information rather than silently overwriting or immediately destroying historical records.
Personal information will not, however, be retained indefinitely merely because it can be stored.
Where information is no longer necessary and no legal, clinical, regulatory, security or contractual requirement requires continued retention, it may be securely erased or irreversibly anonymized in accordance with applicable law and NADIS retention schedules.
Where a correction is made to a clinical record, NADIS may preserve the previous version and audit trail where necessary to maintain record integrity.
10. Individual Rights
Subject to applicable law and healthcare-record requirements, individuals may request:
- information about how their personal information is processed;
- access to their personal information;
- correction or updating of inaccurate information;
- erasure where legally available;
- withdrawal of consent where processing is based upon consent; and
- resolution of a grievance relating to personal-data processing.
Some requests concerning clinical records may need to be handled by the healthcare Facility responsible for those records. NADIS will reasonably assist Facilities in responding to applicable requests.
Withdrawal of consent does not necessarily require deletion of information that must lawfully be retained.
11. Children and Persons Requiring a Lawful Representative
Healthcare services frequently involve children and individuals acting through parents, guardians or authorised representatives.
Facilities are responsible for ensuring that appropriate parental, guardian or representative authority is obtained where required. NADIS may provide functionality for recording and verifying such relationships and consents.
12. Security Incidents
If we become aware of a personal-data or security incident, we will investigate the event, take reasonable containment and remediation measures and provide notifications required under applicable law.
Facilities must promptly notify NADIS if they become aware of compromised credentials, unauthorised access or another security incident involving the platform.
13. Payment Information
Electronic payments may be processed by authorised payment providers.
NADIS does not intend to retain raw card numbers, CVV values or other card credentials prohibited from merchant storage. Transaction references and limited payment information may be retained for billing, reconciliation, refunds and accounting.
14. Government Health Infrastructure
Where NADIS integrates with systems such as the Ayushman Bharat Digital Mission, ABHA or other government healthcare infrastructure, information will be exchanged only through applicable authorised workflows and subject to the consent, security and interoperability requirements governing those systems.
15. Changes to This Policy
We may update this Privacy Policy when NADIS services, technologies or legal requirements change.
Material changes will be communicated through the website, application, email or another appropriate mechanism.
16. Privacy Contact and Grievances
Questions, requests or concerns concerning personal information may be directed to:
Privacy / Grievance Contact
NUREV TECH LLP – NADIS
Website: https://nadishealth.com
Email: [security@nurevtech.com]
Registered Office: [Noida, UP, India]
We will review privacy requests and grievances within the period required under applicable law.