Clinvora
PRIVACY NOTICE AND TERMS OF USE
Clinvora, pilot version. Plain-language draft, to be reviewed by a lawyer before general release.
PART 1. PRIVACY: WHERE YOUR PATIENTS' RECORDS GO
1. The clinic owns the records
Patient records entered in Clinvora belong to the clinic. The clinic
decides what is recorded and who may see it, and is responsible for it
under the law (in India, the Digital Personal Data Protection Act, 2023,
and the rules for medical records). The Clinvora supplier makes the
software. The supplier does not receive, store or see patient records.
2. On the clinic's PC
Records live on the clinic's own PC. The database and photos are
encrypted, and the key is protected by Windows for this PC. Copying the
files to another PC does not make them readable. Each user signs in with
their own password. The screen locks after 10 minutes without use.
3. Backups
Backups are encrypted with a backup password chosen by the clinic. They
are saved to folders the clinic chooses: this PC, a USB drive, or a
folder synchronised with the clinic's own Google Drive. Anyone who has a
backup file AND its password can restore it, so keep the password safe.
Help if the backup password is forgotten (on unless the clinic turns it
off, at setup or in Settings > Backups): each backup also carries a copy
of its database key locked with the supplier's public key. Only the
supplier's private key, which only the supplier holds, can unlock it, and
the supplier never receives the backup files. If the clinic forgets the
password, it sends the supplier a request code from the restore screen;
after checking who is asking, the supplier sends back a recovery code
that opens that clinic's backups. Each recovery is logged. With the
option off, a forgotten backup password cannot be recovered by anyone.
Google Drive backup (optional, off unless the clinic connects it):
the clinic signs in to its own Google account and allows Clinvora to
upload the encrypted backup files to a "Clinvora Backups" folder in that
account's Google Drive. Clinvora asks only for the "drive.file"
permission: it can see and manage only the files it created itself, and
nothing else in the Drive. The sign-in is kept on the clinic's PC,
protected by Windows; it is not sent to the supplier. Backups are
encrypted before upload, so Google cannot read the patient records.
Disconnecting in Settings stops the uploads; the clinic can also remove
the access at myaccount.google.com/permissions. Clinvora's use of
information received from Google APIs adheres to the Google API Services
User Data Policy, including the Limited Use requirements.
4. Phone view (optional, off unless the clinic sets it up)
If the clinic turns on the phone view, text records (not photos) are
copied to the clinic's own Firebase project. Firebase is a Google Cloud
service, and the project is set up in Mumbai (asia-south1). Only phones
that a doctor has linked from the clinic's PC can read them. Google
handles this data under the terms of the Google account that owns the
project. Turning the phone view off in Settings stops the copying.
5. What Clinvora itself sends over the internet
- Licence check, about once a day: the licence number is sent to the
supplier's licensing service to pick up renewals or cancellations.
- Update check, about once a day: the app downloads a small file that
says what the latest version is.
Both checks reveal only the PC's internet address and the app version.
No patient data is sent. Without internet, both are skipped.
- Problem reports are sent only when a user copies one and sends it
personally. A report contains the app and Windows versions, the licence
status and recent error messages. It contains no patient records.
6. Exports and printouts
"Export everything" (admins only) and printed or PDF prescriptions are
NOT encrypted, because they are meant to be read. The clinic is
responsible for keeping them safe and for deleting them when they are no
longer needed.
7. Patients' requests
Patients may ask the clinic to see or correct their records. Records can
be viewed, printed and edited in Clinvora. This version cannot delete
a patient; the rules for medical records may in any case require the
clinic to keep them for some years. Ask the supplier if a record must be
removed.
PART 2. TERMS OF USE
1. Licence
Clinvora is licensed per clinic for the period and number of doctors
on the licence. It is not sold. New installations include a 30-day
trial. When a licence ends, and after 7 days of grace, the app becomes
read-only unless the licence says otherwise. Records can still be
viewed, printed, exported and backed up. Do not copy, share, resell or
modify the software, and do not try to get around the licence.
2. The clinic's responsibilities
- Keep the PC's Windows account and Clinvora passwords private.
- Make sure backups run, and keep one copy away from the PC (a USB drive
kept elsewhere, or Google Drive).
- Check each prescription before giving it to a patient. Clinvora
records and prints what is entered; it does not give medical advice.
- Get patients' consent where the law requires it, and follow the rules
for keeping medical records.
3. Pilot version
This is a pilot version. It has been tested, but it may still contain
mistakes. Keep backups. To the extent the law allows, the supplier is
not liable for loss of data or for indirect losses. The supplier's total
liability is limited to the licence fee paid for the current period.
4. Support and updates
Updates are offered inside the app and do not change the records.
Problems can be reported with Settings > Updates & help > "Copy problem
report".
5. Changes
These terms may be updated with a new version of the app. The version
shown in the app is the one that applies.