The most important point first: the patient records you keep in Adhrit HMS stay on your computer and in your own Google Drive. They are never sent to us, and we cannot see them. This policy covers the much smaller set of information we do receive: details you give us when you contact us or buy a licence, what the software sends when it is activated, and how visitors use this website.
1. Who we are and what this policy covers
Adhrit Business Solutions (“we”, “us”), Station Road, Dalauda, Dist. Mandsaur, Madhya Pradesh - 458667, India, is responsible for the personal data described in this policy. Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) we act as the “data fiduciary” for that data.
This policy applies to adhritbusinesssolutions.com, to our licence and update services, to the contact and checkout forms, and to our dealings with customers and people who enquire. It does not apply to patient data that customers store in the Software, for the reasons in section 3.
2. At a glance
| What | Why | How long we keep it |
|---|---|---|
| Name, phone, email, hospital and city from the contact form | To reply, arrange a demo, prepare a quote | Up to 2 years after our last contact, unless you become a customer |
| Account email, name, hospital, phone, city | To sell, activate and support your licence | For as long as you are a customer, and 8 years after for tax and accounting |
| A key derived from your password (not the password) | To confirm it is you when you activate | Until you close your account |
| Order and payment records | Billing, tax, refunds, fraud prevention | 8 years, as tax laws require |
| Device identifiers for activated computers | To enforce the device limit of your licence | While the licence is active, and 1 year after |
| Website usage through Google Analytics | To understand which pages help visitors | 14 months, in Google Analytics |
| Patient records in the Software | Not collected by us. They stay with you. | |
3. Patient records in Adhrit HMS
Adhrit HMS is installed on your computer. Everything you enter, including patients’ names, contact details, visits, admissions, tests and bills, is stored on that computer. If you switch on backup, compressed copies travel over an encrypted connection directly from your computer to your own Google Drive, using a permission that lets the Software see only the files it creates there.
These records are not sent to us at any point: not during activation, not with updates, and not when you use the in-app feedback form, which is stored on your own computer. We therefore do not process that data, and for it you, the hospital or clinic, are the data fiduciary under the DPDP Act and responsible for obtaining any consent and meeting any obligations towards your patients.
The only exception is if you choose to show or send us patient information, for example on a screen-sharing support call. We then look only at what is needed to solve the problem, do not copy or keep it, and treat it as confidential.
4. Information we collect
Information you give us
- Enquiries: your name, mobile number, and optionally your email, hospital name, city, budget and message, when you use the contact form or write to us.
- Purchases: your name, hospital name, mobile number, city and email address when you buy.
- Your password: your browser and the Software turn your password into a one-way key before sending it. We store only a further salted hash of that key. We never receive or store your password itself.
- Support: what you tell us when you ask for help, and our notes of the conversation.
Information from payments
Payments are handled by Razorpay. We receive the payment ID, amount, status, date and the kind of payment method used. We do not receive or store card numbers, UPI PINs, CVVs or net-banking passwords.
Information the Software sends
- When you activate, list devices or move a licence: your account email, the password-derived key described above, and an identifier the Software generates for that computer.
- When it checks for updates: it downloads a small file from our website. Like any web request, this reveals your computer’s IP address to our hosting provider. Nothing else is sent.
Information collected automatically on the website
- Google Analytics records pages viewed, how you arrived, approximate location (city level), device and browser type, using cookies. See our Cookie Policy.
- Security and server logs kept by our hosting provider, Cloudflare, including IP addresses, for a short period to protect the website from abuse.
- For the contact form, we store a one-way hash of your IP address, never the address itself, to limit repeated submissions.
5. How we use it
- To reply to enquiries, give demos and prepare quotes.
- To create your account, take payment, issue and activate your licence, and enforce its device limit.
- To provide support, handle refunds and resolve complaints.
- To send you messages about your licence, such as payment receipts, renewal information, important updates and security notices.
- To tell you about new products or offers, only if you have not asked us to stop. Every such message says how to opt out.
- To understand how the website is used and improve it.
- To prevent fraud, piracy and misuse, and to meet our legal, tax and accounting obligations.
We do not sell your personal data, rent it, or use it for advertising profiles. We do not make decisions about you by automated means that have legal or similarly significant effects.
6. Our legal basis
We process personal data on the basis of your consent, which you give when you submit a form or place an order, and for the legitimate uses the DPDP Act allows, including where you have voluntarily provided data for a specific purpose, and to comply with the law. You may withdraw consent at any time as described in section 10; this does not affect processing already carried out, or data we must keep by law.
7. Who we share it with
We share personal data only with the service providers who help us run the business, only to the extent they need it, and under terms that require them to protect it:
| Provider | What they do for us |
|---|---|
| Cloudflare, Inc. | Hosts the website and our licence service and database |
| Razorpay Software Private Limited | Processes payments |
| Google LLC | Website analytics; our business email |
We may also disclose personal data if the law requires it, to a court or authority acting lawfully, to protect our rights or prevent fraud, or to a buyer of our business, who would be bound by this policy.
8. Where your data is stored
Our service providers may store and process data on servers outside India. Where they do, we use providers that apply recognised safeguards, and we will follow any restrictions the Government of India notifies under section 16 of the DPDP Act.
9. How long we keep it
We keep personal data only as long as it is needed for the purposes in this policy, as shown in the table in section 2. Records of orders, payments and invoices are kept for 8 years because tax and accounting laws require it. When data is no longer needed, we delete it or make it anonymous.
10. Your rights
Under the DPDP Act you have the right to:
- access a summary of the personal data we hold about you and how we use it;
- correct, complete or update it;
- erase it, where we no longer need it and the law does not require us to keep it;
- withdraw consent you have given;
- nominate another person to exercise these rights if you die or become unable to; and
- have a grievance addressed by us, and if you are not satisfied, to complain to the Data Protection Board of India.
To use any of these rights, write to adhritbusinesssolutions@gmail.com from the email address we know you by. We may need to verify your identity. We respond within 30 days.
Closing your account ends your ability to activate the Software. It does not affect the records stored on your own computer.
11. How we protect it
- All traffic to the website and our services is encrypted in transit (HTTPS).
- Passwords are never stored; only a salted hash of a key derived from them.
- Access to our customer records is limited to the owner of the business and protected by sign-in with a one-time code.
- Licences and updates are digitally signed, so the Software can tell a genuine one from a forged one.
No system is perfectly secure. If a breach affecting your personal data occurs, we will inform you and the Data Protection Board of India as the law requires.
12. Children
Our website and services are meant for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this policy
We will update this policy when our practices or the law change. The date at the top shows the latest version. If a change significantly affects how we use your personal data, we will tell customers by email or inside the Software before it takes effect.
14. Contact and grievance officer
For questions about this policy or your personal data, and for grievances under the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the DPDP Act:
Grievance Officer: Harshad Kumar Sharma, Proprietor, Adhrit Business Solutions
Address: Station Road, Dalauda, Dist. Mandsaur, Madhya Pradesh - 458667, India
Email: adhritbusinesssolutions@gmail.com (please write “Grievance” in the subject line)
Phone: +91 62600 34689, Monday to Saturday, 10:00 am to 7:00 pm IST (closed on public holidays)
We acknowledge every grievance within 48 hours and aim to resolve it within 30 days of receiving it.