1. Scope & applicability
This policy applies to authorized users of the pkhcare platform — including clinicians, administrative staff, and other personnel granted access by a healthcare organization (“Customer” or “Clinic”). It covers use of the web application, including OPD encounter management, patient records, AI copilot features, voice-assisted documentation, clinical summaries, and analytics modules.
Important: pkhcare is a business-to-business healthcare platform. Your Clinic is typically the data controller for patient health information entered into the system. pkhcare processes such data on behalf of the Clinic as a service provider, subject to applicable agreements and law.
2. Information we collect
Account & authentication data
When you sign in, we collect information necessary to authenticate and authorize your access, such as:
- Email address and account identifiers
- Authentication tokens and session credentials
- Role and permission assignments within your organization
- Login timestamps and security-related audit events
Clinical & patient information
Through authorized use of the Platform, the following types of health-related information may be processed:
- Patient demographics and contact details
- Medical history, allergies, and clinical notes
- OPD encounter records, vitals, observations, diagnoses, and treatment plans
- Medications, investigations, and follow-up instructions
- Clinical summaries and structured documentation generated during care
AI copilot & conversation data
When you interact with the AI copilot agent, we may process:
- Messages, prompts, and responses exchanged in copilot sessions
- Structured proposals and actions suggested or accepted by users
- Context derived from the active patient, encounter, or workspace
Voice data
If you use voice-assisted features, we may process:
- Audio recordings captured with your consent and device permission
- Transcripts produced from speech-to-text processing
- Voice command metadata (intent, confidence scores, resolution status)
Usage & technical data
We automatically collect certain technical information to operate and improve the Platform:
- Device type, browser, operating system, and IP address
- Pages visited, features used, and interaction patterns
- Error logs, performance metrics, and diagnostic data
3. How we use information
We use collected information for the following purposes:
- Providing the service — enabling OPD workflows, patient management, documentation, and AI-assisted clinical support
- Authentication & authorization — verifying identity and enforcing role-based access controls
- Clinical documentation — storing, displaying, and generating structured records as directed by authorized users
- Platform improvement — monitoring reliability, fixing errors, and enhancing usability
- Security & compliance — detecting unauthorized access, maintaining audit trails, and meeting legal obligations
- Analytics — aggregated reporting on clinic activity where enabled (e.g., OPD analytics dashboards)
We do not sell personal information or patient health data.
4. AI & automated processing
pkhcare uses artificial intelligence to assist with clinical documentation, conversation understanding, summarization, and workflow automation. AI features are designed to support — not replace — professional clinical judgment.
- AI outputs are suggestions; authorized clinicians remain responsible for reviewing and approving clinical decisions
- Patient and encounter context may be sent to AI processing services to generate relevant responses
- We implement safeguards to limit AI access to data required for the requested task
- Where applicable, AI providers are bound by contractual obligations regarding confidentiality and data use
Your Clinic may configure which modules and AI features are available to users based on permissions and organizational policy.
5. Health & clinical data
Health information processed through pkhcare may be subject to healthcare privacy regulations, including but not limited to HIPAA (where applicable), local medical record laws, and your Clinic’s internal policies.
- Access to patient data is restricted by role-based permissions
- Clinical records may require approval workflows before becoming finalized
- Audit logging helps track access and modifications to sensitive records
- Patients should direct privacy requests regarding their health records to their healthcare provider (the Clinic)
7. Data retention
We retain information for as long as necessary to provide the Platform, fulfill contractual obligations with your Clinic, and comply with applicable law. Retention periods may vary by data type:
- Clinical records are retained according to your Clinic’s policies and regulatory requirements
- Authentication logs and security audit data are retained for a defined period for security and compliance purposes
- AI conversation logs may be retained to support session continuity, troubleshooting, and quality improvement
- Voice recordings and transcripts are retained only as long as needed for transcription, documentation, or as directed by the Clinic
When data is no longer required, we take steps to securely delete or anonymize it.
8. Security measures
We implement technical and organizational measures designed to protect information, including:
- Encryption in transit (TLS/HTTPS) for data transmitted between your browser and our servers
- Role-based access control (RBAC) limiting features and data by user permissions
- Secure authentication and session management
- Monitoring for unauthorized access and anomalous activity
- Regular review of security practices and infrastructure hardening
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact your Clinic administrator and us immediately.
9. Your rights
Depending on your jurisdiction and your relationship with the Platform, you may have rights including:
- Access to personal information we hold about you as an authorized user
- Correction of inaccurate account information
- Deletion or restriction of processing, subject to legal and contractual limits
- Objection to certain processing activities
- Data portability where technically feasible
For patient health data: patients should exercise their rights through their healthcare provider (the Clinic), which controls clinical records. We will assist Clinics in fulfilling applicable requests as required by our agreements and law.
Authorized users may contact their Clinic administrator for account-related requests, or reach us using the contact details below.
11. International transfers
Your information may be processed in countries other than where you or your Clinic are located. Where required, we implement appropriate safeguards — such as standard contractual clauses or equivalent mechanisms — to protect data transferred across borders.
12. Children’s privacy
pkhcare is intended for use by authorized healthcare professionals and clinic staff, not by children directly. Patient records for minors may be processed as part of clinical care under the direction of the Clinic and applicable law. We do not knowingly collect personal information from children for marketing purposes.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify your Clinic or display a notice within the application.
We encourage you to review this page periodically for the latest information.
14. Contact us
If you have questions about this Privacy Policy or our data practices, please contact:
pkhcare Privacy Team
Email: numanimran661@gmail.com
Website: pkhcare.health
For urgent security concerns, please include “Security” in your subject line. Clinic administrators may also contact us regarding data processing agreements and compliance documentation.