1. Scope & applicability

This policy applies to authorized users of the pkhcare platform — including clinicians, administrative staff, and other personnel granted access by a healthcare organization (“Customer” or “Clinic”). It covers use of the web application, including OPD encounter management, patient records, AI copilot features, voice-assisted documentation, clinical summaries, and analytics modules.

Important: pkhcare is a business-to-business healthcare platform. Your Clinic is typically the data controller for patient health information entered into the system. pkhcare processes such data on behalf of the Clinic as a service provider, subject to applicable agreements and law.

2. Information we collect

Account & authentication data

When you sign in, we collect information necessary to authenticate and authorize your access, such as:

  • Email address and account identifiers
  • Authentication tokens and session credentials
  • Role and permission assignments within your organization
  • Login timestamps and security-related audit events

Clinical & patient information

Through authorized use of the Platform, the following types of health-related information may be processed:

  • Patient demographics and contact details
  • Medical history, allergies, and clinical notes
  • OPD encounter records, vitals, observations, diagnoses, and treatment plans
  • Medications, investigations, and follow-up instructions
  • Clinical summaries and structured documentation generated during care

AI copilot & conversation data

When you interact with the AI copilot agent, we may process:

  • Messages, prompts, and responses exchanged in copilot sessions
  • Structured proposals and actions suggested or accepted by users
  • Context derived from the active patient, encounter, or workspace

Voice data

If you use voice-assisted features, we may process:

  • Audio recordings captured with your consent and device permission
  • Transcripts produced from speech-to-text processing
  • Voice command metadata (intent, confidence scores, resolution status)

Usage & technical data

We automatically collect certain technical information to operate and improve the Platform:

  • Device type, browser, operating system, and IP address
  • Pages visited, features used, and interaction patterns
  • Error logs, performance metrics, and diagnostic data

3. How we use information

We use collected information for the following purposes:

  • Providing the service — enabling OPD workflows, patient management, documentation, and AI-assisted clinical support
  • Authentication & authorization — verifying identity and enforcing role-based access controls
  • Clinical documentation — storing, displaying, and generating structured records as directed by authorized users
  • Platform improvement — monitoring reliability, fixing errors, and enhancing usability
  • Security & compliance — detecting unauthorized access, maintaining audit trails, and meeting legal obligations
  • Analytics — aggregated reporting on clinic activity where enabled (e.g., OPD analytics dashboards)

We do not sell personal information or patient health data.

4. AI & automated processing

pkhcare uses artificial intelligence to assist with clinical documentation, conversation understanding, summarization, and workflow automation. AI features are designed to support — not replace — professional clinical judgment.

  • AI outputs are suggestions; authorized clinicians remain responsible for reviewing and approving clinical decisions
  • Patient and encounter context may be sent to AI processing services to generate relevant responses
  • We implement safeguards to limit AI access to data required for the requested task
  • Where applicable, AI providers are bound by contractual obligations regarding confidentiality and data use

Your Clinic may configure which modules and AI features are available to users based on permissions and organizational policy.

5. Health & clinical data

Health information processed through pkhcare may be subject to healthcare privacy regulations, including but not limited to HIPAA (where applicable), local medical record laws, and your Clinic’s internal policies.

  • Access to patient data is restricted by role-based permissions
  • Clinical records may require approval workflows before becoming finalized
  • Audit logging helps track access and modifications to sensitive records
  • Patients should direct privacy requests regarding their health records to their healthcare provider (the Clinic)

6. Sharing & disclosure

We may share information only in the following circumstances:

  • With your Clinic — data entered by users is available to authorized personnel within the organization
  • Service providers — cloud hosting, authentication, AI inference, and infrastructure partners who process data on our behalf under strict agreements
  • Legal requirements — when required by law, regulation, court order, or to protect rights, safety, and security
  • Business transfers — in connection with a merger, acquisition, or sale of assets, with appropriate notice where required

We require third-party processors to maintain appropriate security and confidentiality standards.

7. Data retention

We retain information for as long as necessary to provide the Platform, fulfill contractual obligations with your Clinic, and comply with applicable law. Retention periods may vary by data type:

  • Clinical records are retained according to your Clinic’s policies and regulatory requirements
  • Authentication logs and security audit data are retained for a defined period for security and compliance purposes
  • AI conversation logs may be retained to support session continuity, troubleshooting, and quality improvement
  • Voice recordings and transcripts are retained only as long as needed for transcription, documentation, or as directed by the Clinic

When data is no longer required, we take steps to securely delete or anonymize it.

8. Security measures

We implement technical and organizational measures designed to protect information, including:

  • Encryption in transit (TLS/HTTPS) for data transmitted between your browser and our servers
  • Role-based access control (RBAC) limiting features and data by user permissions
  • Secure authentication and session management
  • Monitoring for unauthorized access and anomalous activity
  • Regular review of security practices and infrastructure hardening

No method of transmission or storage is completely secure. If you believe your account has been compromised, contact your Clinic administrator and us immediately.

9. Your rights

Depending on your jurisdiction and your relationship with the Platform, you may have rights including:

  • Access to personal information we hold about you as an authorized user
  • Correction of inaccurate account information
  • Deletion or restriction of processing, subject to legal and contractual limits
  • Objection to certain processing activities
  • Data portability where technically feasible

For patient health data: patients should exercise their rights through their healthcare provider (the Clinic), which controls clinical records. We will assist Clinics in fulfilling applicable requests as required by our agreements and law.

Authorized users may contact their Clinic administrator for account-related requests, or reach us using the contact details below.

10. Cookies & session data

The Platform uses cookies and similar technologies to maintain authenticated sessions, remember preferences, and protect against unauthorized access. These may include:

  • Session cookies required for login and secure navigation
  • Authentication tokens stored according to our security configuration
  • Functional cookies that support language preferences and UI state

You can configure your browser to refuse cookies, but some features of the Platform may not function properly without them.

11. International transfers

Your information may be processed in countries other than where you or your Clinic are located. Where required, we implement appropriate safeguards — such as standard contractual clauses or equivalent mechanisms — to protect data transferred across borders.

12. Children’s privacy

pkhcare is intended for use by authorized healthcare professionals and clinic staff, not by children directly. Patient records for minors may be processed as part of clinical care under the direction of the Clinic and applicable law. We do not knowingly collect personal information from children for marketing purposes.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify your Clinic or display a notice within the application.

We encourage you to review this page periodically for the latest information.

14. Contact us

If you have questions about this Privacy Policy or our data practices, please contact:

pkhcare Privacy Team
Email: numanimran661@gmail.com
Website: pkhcare.health

For urgent security concerns, please include “Security” in your subject line. Clinic administrators may also contact us regarding data processing agreements and compliance documentation.