← Back to home

Privacy Policy

Last updated: 23 June 2026

This Privacy Policy explains how Eco Biznfc Solutions Pvt. Ltd.(GSTIN 27AAJCE4400E1Z1, "we", "us", "Heartern") collects, uses and protects personal data when you use Heartern. It is published in accordance with the Digital Personal Data Protection Act, 2023 (India) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

1. Who is the data controller?

For data uploaded by a hospital or clinic ("Customer") into their Heartern tenant (such as patient records, appointments, payments), the Customer is the data controller. Heartern operates as a data processor on their behalf, storing and processing that data strictly under the Customer's instructions and these Terms.

For data we collect directly from website visitors and signed-up users (such as email, phone, login activity), Heartern is the data controller.

2. What data do we collect?

From hospitals / clinics (Customer-uploaded data)

  • Patient name, mobile number, age, gender, address
  • Visit history, diagnosis, treatment notes, follow-up dates
  • Uploaded prescriptions, lab reports and other documents
  • Payment amounts, modes and reference numbers
  • Doctor profiles and schedules

From you directly (as a Heartern customer or visitor)

  • Name, email, hospital name, phone number (via the lead form)
  • Login email, hashed password, role, last-login time
  • IP address, user-agent and request logs for security and abuse prevention
  • Cookies strictly necessary for authentication (httpOnly session cookie)

3. Why we process it

  • To provide the Heartern service to your hospital / clinic
  • To deliver WhatsApp templated messages you initiate, via our BSP
  • To respond to your enquiries from the marketing site
  • To prevent abuse, fraud, and unauthorised access
  • To comply with legal obligations (tax, regulatory, court orders)

4. With whom we share data

  • Infrastructure providers: Hostinger (VPS hosting), Cloudflare (DNS), Backblaze (encrypted offsite backups), Let's Encrypt (SSL certificates). All providers are bound by their own contractual data-protection terms.
  • WhatsApp BSP: Fast2SMS (Cellulant Cell Pvt. Ltd. or successor) for WhatsApp Business API delivery. Only the data required to deliver a template message (recipient mobile, template variables, media URL) is shared.
  • Email provider: Zoho Mail for transactional and lead-notification emails.
  • We do not sell personal data to third parties. We do not use patient data for advertising, analytics or model training.

5. Where data is stored

All Customer data is stored on infrastructure located in India (Hostinger data centre) with encrypted offsite backups to Backblaze B2 (USA region with end-to-end encryption at rest). Transport is over TLS 1.2+. Backups are retained for up to ninety (90) days unless a Customer instructs otherwise.

6. Security

  • Passwords are hashed using bcrypt (never stored in plain text).
  • Sessions use httpOnly + SameSite + Secure cookies.
  • All public endpoints serve over HTTPS only.
  • SSH access is key-only with fail2ban brute-force protection.
  • Database access is restricted to the Heartern application user; no public exposure.
  • Daily encrypted backups; quarterly restore drills.

7. Retention

We retain Customer-uploaded data for as long as the Customer subscription is active, plus a 30-day grace period after termination. Direct-collected data (lead enquiries, login activity) is retained for up to 24 months. Records required by law (invoices, tax records) are retained for the period mandated by Indian law (typically 8 years).

8. Your rights under the DPDP Act, 2023

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request erasure (subject to legal retention obligations)
  • Withdraw consent at any time (may affect ability to use the Service)
  • File a grievance with our Grievance Officer (below)

Patients of a Customer hospital should contact that hospital directly for data-subject requests, as the hospital is the controller of patient data.

9. Cookies

We use only strictly necessary cookies for authentication. We do not use third-party tracking cookies, advertising pixels, or analytics scripts that identify individual users.

10. Grievance Officer

In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, grievances may be addressed to:

Mr. Rahul Hrishikesh, Grievance Officer
Eco Biznfc Solutions Pvt. Ltd.
Airoli, Navi Mumbai 400708, India
Email: contact@ecobiznfc.com
Phone: +91 99871 81901

We will acknowledge your grievance within 24 hours and provide resolution within 15 days, as required by law.

11. Updates to this policy

We may update this Privacy Policy from time to time. Material changes will be notified to active Customers via email and posted on this page with a new "Last updated" date.