1. Data ownership
All clinic data, patient records, operational information, uploaded content, and communications generated through Simpld remain the property of the respective clinic or authorized account owner.
Simpld acts only as a software service provider and data processor for enabling platform functionality.
Simpld does not sell patient or clinic data to advertisers or external parties.
2. What we collect and how we use it
Simpld collects and processes limited operational and account-related information necessary for delivering software services.
This may include:
- Clinic information
- Staff details
- Patient records entered by clinics
- Billing information
- Appointment details
- Communication logs
- Usage logs and audit records
Simpld uses this data solely for:
- Service delivery
- Technical support
- Security monitoring
- Backup and recovery
- Communication functionality
- Product maintenance and improvements
Simpld does not publicly expose patient information and does not permit public patient access or appointment marketplace functionality.
Reasonable industry-standard safeguards are implemented to protect stored information, including:
- Infrastructure monitoring and operational security reviews
- Encryption of sensitive information during transmission
- Role-based permission management for authorized users
- Restricted administrative access to production systems
- Backup redundancy and recovery-oriented operational procedures
- Activity monitoring and audit logging for operational security
While reasonable efforts are made to maintain security, no online system can guarantee absolute security or uninterrupted availability.
3. Data hosting and security
Simpld infrastructure is hosted on Amazon Web Services (AWS) servers located in Mumbai, India.
The platform follows industry-standard operational security practices appropriate for healthcare-oriented software environments.
Simpld may periodically improve security architecture, infrastructure, authentication methods, backup systems, monitoring systems, and access management processes without prior notice.
Simpld follows healthcare-oriented operational and security practices suitable for cloud-based healthcare software environments. Formal compliance certifications, where applicable, may be introduced progressively based on operational, business, and regulatory requirements.
Simpld continuously improves infrastructure security, authentication methods, monitoring systems, operational controls, and backup architecture as part of ongoing platform improvements and operational risk management practices.
4. Future AI features
As of the current policy version, Simpld does not use identifiable clinic or patient data for AI model training.
If AI-powered features, automation systems, analytics modules, or machine learning services are introduced in the future, Simpld may update its policies accordingly and obtain necessary permissions or consents where applicable.
5. Communication and messaging
Simpld may facilitate appointment reminders, operational alerts, invoices, notifications, WhatsApp messages, SMS communications, and emails on behalf of clinics.
Communication services may utilize third-party providers including but not limited to:
- MSG91
- Interakt
- Email service providers
- SMS gateway providers
Clinics are solely responsible for:
- Obtaining patient consent for communications
- Ensuring compliance with applicable communication regulations
- Managing message content accuracy
- Maintaining lawful communication practices
Simpld acts only as a technology facilitator for such communications. Simpld encourages clinics to maintain transparent patient communication practices and obtain appropriate consent for reminders, follow-ups, treatment communications, invoices, and operational notifications.
6. Data retention and deletion
Upon subscription expiry:
- Account access may be paused or restricted
- Data may remain retained for up to 180 days
- Clinics may request backups or exports during the retention period
If no written or verbal renewal confirmation is received within the retention period, data may be permanently deleted from active systems and backups.
Simpld may retain limited records where required for taxation, compliance, fraud prevention, legal obligations, or dispute resolution.
7. Data export
Authorized clinics may request export of their operational data subject to:
- Identity verification
- Account ownership verification
- Pending dues clearance
- Technical feasibility
Simpld reserves the right to define export formats, timelines, and operational limitations. Simpld aims to support reasonable operational portability requests wherever technically feasible and operationally practical.
8. Regulatory alignment
Simpld aims to maintain operational practices aligned with applicable Indian data protection and digital privacy principles, including relevant provisions of the Digital Personal Data Protection Act, 2023 (DPDP Act), where applicable.
Policies may be updated periodically to reflect evolving legal, operational, security, or technology requirements.
Simpld aims to maintain operational practices aligned with evolving digital privacy, cybersecurity, and healthcare-oriented software standards applicable to its operational environment.
9. Updates to this policy
Simpld reserves the right to revise, modify, or update this Privacy Policy at any time. Updates may be published through website updates, in-platform notices, or email communications.
Continued usage of the platform after updates constitutes acceptance of the revised policy.
10. Contact
For privacy or data-handling questions, write to us at info@simpld.in. For billing or commercial questions, write to sales@simpld.in.