Privacy Policy

SoftClinic GenX HIMS · JVS Technologies Private Limited · Version 1.1 · 17 July 2026

Who this policy is for. This policy is for the healthcare facilities (our tenants) that operate SoftClinic GenX HIMS and for the authorised staff who sign in to it. Patients do not sign in to this software. A patient's rights over their own health data are exercised through their own ABHA/PHR application and through the facility that treated them — see §7. Everything stated below is accurate as to how the software actually works.

1. Who we are, and the roles

SoftClinic GenX HIMS is operated by your healthcare facility and supplied by JVS Technologies Private Limited. Under the Digital Personal Data Protection Act, 2023:

2. What the software processes, and why

Two kinds of personal data pass through the software, and nothing else — there is no advertising, profiling, analytics or telemetry in this system.

(a) Your staff account data. So authorised users can sign in with least-privilege access and be attributed in the audit trail:

CategoryHandling
Staff name, email/login, assigned role, and (for a clinician) the linked HPR / doctor identityStored to operate the account and the audit trail
Account passwordStored only as a salted one-way hash — never in plain text, never recoverable

(b) Patient data the facility handles via ABDM. Only what ABDM functions require — creating and verifying a patient's ABHA, sharing their health records with their consent, and retrieving records the patient has consented to share:

CategoryHandling
Patient name, mobile, email, address, photo, ABHA number and address, health records and their attachmentsEncrypted at rest (AES-256-GCM)
Gender, date of birth, PIN/district/state, hospital record numberStored unencrypted — held as administrative data
Aadhaar number and OTPNever stored. Encrypted in transit to ABDM only, and never written to any database or log

3. Consent

The facility is responsible for obtaining the patient's informed consent. An ABHA is created only after the patient accepts the ABDM enrolment declarations, and health records are shared only under a consent the patient grants in their own ABHA/PHR application — this software never assumes or creates consent on a patient's behalf. No record is released without an active, unexpired consent covering that exact record type and date range, and a consent that has been revoked, denied or expired cannot be reactivated. The consent controls in the software record that decision; they do not make it.

4. How the software protects data

5. Where it is stored, and for how long

All data is stored in India, in a private-network Microsoft Azure database. Records fetched from other hospitals are held in memory only and become inaccessible after 60 minutes — they are never written to disk. Records a facility created are kept under that facility's own clinical retention obligations. Staff account records are kept while the account is active. Erasure is possible on request (see §7).

6. Who else receives it

RecipientWhat they receive
ABDM / National Health AuthorityThe data ABDM requires — this is the purpose of the ABDM features
Microsoft Azure (India)Hosting and storage
SMS provider (MSG91)Mobile number and OTP only. No ABHA, no health data. India only

We do not sell data, and no personal data is transferred outside India.

7. Rights

Your facility and its staff may, through JVS:

Patients exercise their rights over their own health data directly — access, correction, nomination and consent management through their own ABHA/PHR application (a hospital cannot change a patient's ABHA mobile or KYC-locked fields), and requests to the facility that treated them, which holds the primary obligation to them as Data Fiduciary.

8. Grievance Officer

Mr. Kirtan Valani, Grievance Officer
Email: operations@jvsgroup.com
Telephone: +91 90999 03150

For a complaint about a patient's personal data, the patient should normally contact the healthcare facility that treated them — it is the Data Fiduciary and holds the primary obligation. Facilities and their staff may contact our Grievance Officer at any time.

9. Breach notification

We will notify the Data Protection Board of India and affected parties of a personal data breach as required by §8(6) of the DPDP Act.

10. Changes

The version and date appear at the top of this page. Material changes will be notified to operating facilities.