Privacy & Data Protection

Privacy Policy

Your privacy and the security of your healthcare data are our top priorities

Last Updated: October 16, 2025Effective Date: January 1, 2025

Your Data, Your Control

This Privacy Policy explains how The Doctor Hub collects, uses, and protects your personal and healthcare information. We are committed to transparency and giving you control over your data.

For questions or to exercise your privacy rights, contact us at support@thedoctorhub.com

1. Introduction

The Doctor Hub ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal and healthcare information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Smart Hospital Management System.

1.1 Scope

This Privacy Policy applies to all users of our platform, including hospitals, healthcare providers, staff members, patients, and any other individuals whose information is processed through our Service.

1.2 Consent

By using The Doctor Hub, you consent to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

We collect several types of information from and about users of our Service:

2.1 Personal Information

Information that identifies you as an individual, including: name, email address, phone number, postal address, date of birth, government-issued ID numbers, professional license numbers (for healthcare providers), and login credentials.

2.2 Healthcare Information

Medical and health-related information, including: patient medical records, diagnoses and treatment information, prescriptions and medication history, laboratory test results, vital signs and health metrics, medical imaging and reports, insurance information, and billing records.

2.3 Professional Information

For healthcare providers and staff: medical licenses and certifications, specialization and qualifications, work schedules and availability, professional affiliations, and employment history.

2.4 Technical Information

Information collected automatically when you use our Service: IP addresses, browser type and version, device information, operating system, access times and dates, pages viewed and interactions, referring website addresses, and location data (with permission).

2.5 Communication Data

Information from communications through our platform: messages between users, prescription delivery confirmations, appointment notifications, customer support interactions, and feedback and surveys.

3. How We Collect Information

3.1 Direct Collection

Information you provide directly when registering for an account, completing your profile, scheduling appointments, entering patient information, communicating through our platform, and contacting customer support.

3.2 Automatic Collection

We automatically collect certain information using cookies, web beacons, log files, analytics tools, and device identifiers when you interact with our Service.

3.3 Third-Party Sources

We may receive information from: healthcare partners and laboratories, payment processors, identity verification services, and public databases (for verification purposes).

4. How We Use Your Information

We use the collected information for various purposes:

  • Provide, operate, and maintain our hospital management platform
  • Process registrations, appointments, and medical records
  • Generate and deliver digital prescriptions via SMS, WhatsApp, and email
  • Facilitate communication between healthcare providers and patients
  • Process payments and manage billing
  • Provide customer support and respond to inquiries
  • Analyze usage patterns to improve our Service
  • Develop AI-powered features and insights
  • Send service updates, security alerts, and administrative messages
  • Comply with legal obligations and prevent fraud
  • Protect the security and integrity of our platform
  • Conduct research and analytics (with anonymized data)

5. Information Sharing and Disclosure

5.1 Within Healthcare Institutions

Information is shared among authorized personnel within your healthcare institution as necessary for treatment, operations, and coordination of care.

5.2 Service Providers

We share information with trusted third-party service providers who assist us in: cloud hosting and storage, payment processing, SMS and WhatsApp messaging services, analytics and monitoring, customer support tools, and security services. These providers are contractually obligated to protect your information.

5.3 Healthcare Partners

With your consent, we may share information with: laboratories for test processing, pharmacies for prescription fulfillment, insurance companies for claims processing, and referring healthcare providers.

5.4 Legal Requirements

We may disclose information when required by law, court order, or governmental request, or when necessary to: protect our legal rights, prevent fraud or security threats, comply with healthcare regulations, or respond to emergencies involving health or safety.

5.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.

5.6 Aggregated Data

We may share anonymized, aggregated data that cannot identify individuals for research, analytics, or business purposes.

6. Data Security

6.1 Security Measures

We implement comprehensive security measures including: end-to-end encryption for data transmission, encrypted data storage, secure authentication and access controls, regular security audits and penetration testing, intrusion detection and prevention systems, secure backup and disaster recovery procedures, and staff training on data security.

6.2 Healthcare Compliance

Our security practices comply with HIPAA, GDPR, and other applicable healthcare data protection regulations.

6.3 Limitations

While we implement strong security measures, no system is completely secure. We cannot guarantee absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials.

7. Data Retention

7.1 Retention Period

We retain your information for as long as necessary to: provide our services, comply with legal obligations (medical records may be retained for 7-10 years as required by law), resolve disputes, and enforce our agreements.

7.2 Deletion

Upon account termination, we will delete or anonymize your personal information within 30 days, except where retention is required by law. Healthcare data may be retained longer to comply with medical record retention requirements.

8. Your Privacy Rights

Depending on your location, you may have the following rights:

8.1 Access and Portability

You have the right to access your personal information and request a copy in a portable format.

8.2 Correction

You can request correction of inaccurate or incomplete information.

8.3 Deletion

You may request deletion of your personal information, subject to legal retention requirements.

8.4 Restriction

You can request restriction of processing of your information in certain circumstances.

8.5 Objection

You may object to certain types of processing, including marketing communications.

8.6 Withdrawal of Consent

Where processing is based on consent, you may withdraw consent at any time.

8.7 Exercising Rights

To exercise any of these rights, please contact us at support@thedoctorhub.com. We will respond within 30 days.

9. Cookies and Tracking Technologies

9.1 What We Use

We use cookies, web beacons, and similar technologies to: maintain your session, remember your preferences, analyze usage patterns, and improve user experience.

9.2 Types of Cookies

Essential cookies (required for Service functionality), performance cookies (analytics), functional cookies (preferences and settings), and targeting cookies (with your consent).

9.3 Managing Cookies

You can control cookies through your browser settings. However, disabling certain cookies may limit Service functionality.

10. Communications and Consent

10.1 Service Communications

By using our Service, you consent to receive communications via email, SMS, WhatsApp, RCS, and other channels for: prescription delivery, appointment reminders, test results, service updates, and security alerts.

10.2 Marketing Communications

We may send promotional communications with your explicit consent. You can opt-out at any time by clicking unsubscribe or contacting us.

10.3 WhatsApp and SMS

When you provide your phone number, you consent to receive SMS and WhatsApp messages. Standard message and data rates may apply.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place, including: standard contractual clauses, adequacy decisions by regulatory authorities, and compliance with applicable data transfer regulations.

12. Children's Privacy

Our Service is not intended for children under 13 (or applicable age in your jurisdiction) without parental consent. When treating minor patients, healthcare providers must obtain appropriate parental or guardian consent. We do not knowingly collect information from children without proper authorization.

13. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt-out of sale of personal information (we do not sell personal information)
  • Right to deletion of personal information
  • Right to non-discrimination for exercising privacy rights
  • Right to designate an authorized agent

14. European Privacy Rights (GDPR)

If you are in the European Economic Area, you have rights under GDPR including:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure (right to be forgotten)
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing
  • Right to lodge a complaint with supervisory authority

15. AI and Automated Processing

15.1 AI Features

We use artificial intelligence and machine learning to: provide smart scheduling recommendations, analyze usage patterns, predict inventory needs, generate insights and analytics, and improve Service efficiency.

15.2 Automated Decisions

AI is used to assist, not replace, human decision-making. Critical healthcare decisions remain with licensed professionals. You have the right to human review of automated decisions.

15.3 Data Training

We may use anonymized data to train and improve our AI models. Personal identifiers are removed before any AI training.

16. Changes to Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes via: email notification, prominent notice on our platform, or in-app notification. Your continued use after changes constitutes acceptance of the updated policy. The "Last Updated" date at the top indicates when the policy was last revised.

17. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Officer: support@thedoctorhub.com

Download Your Data

Request a copy of all your personal information

Delete Your Data

Request deletion of your personal information

Contact Privacy Team

Have questions about your privacy?

Your Privacy Matters

We're committed to protecting your healthcare data with bank-level encryption and industry-leading security practices. Your trust is our responsibility.