Beyond Care.HMS

Privacy Policy

Last updated: 26 August 2026

Beyond Care (Beyond Care Technologies Pvt Ltd) provides multi-tenant hospital and clinic management software ("the Service"). This policy explains what data we collect, why, how it is stored and protected, and what rights you have — written in plain terms, without claiming anything the Service doesn't actually do today.

Who we are

Beyond Care is operated by Beyond Care Technologies Pvt Ltd, registered at C2-1111, Pragati IT Park, opp. AR Mall, Mota Varachha, Surat, Gujarat 394105("we", "us"). We build and operate the Service — hospitals and clinics ("organisations") sign up, create staff accounts, and use it to run appointments, records, billing, and related front-desk and clinical workflows.

Scope — accounts, staff, and patients

This policy covers two kinds of people: (1) the organisation and its staff — the admins, doctors, and staff who create an account and log in directly, and (2) patients — whose records a subscribing organisation enters into the Service.

For patient data, the subscribing hospital or clinic is the data controller/fiduciary — they decide what patient information to record and who on their staff can access it. We act as the data processor: we run the software and infrastructure that stores and processes that data on the organisation's behalf, under the org's and staff accounts' own role-based permissions. If you are a patient with a question about your own medical records, please contact the hospital or clinic that treated you — they control that data, not us.

Data we collect

Account & staff data — name, email, phone number, role (e.g. doctor, receptionist, nurse, pharmacist, lab technician), and hospital/branch assignment, collected when an organisation is created or a staff member is added.

Organisation data — hospital/clinic name, branding (logo, colour, tagline) if configured, subdomain, and billing/plan details.

Patient data entered by the organisation — demographic details, appointment and visit history, consultation notes, prescriptions, lab orders/results, billing records, and — only where a hospital enables it — voice recordings of a consultation and their AI-generated transcription, used solely to help populate consultation notes.

Files & documents — uploads such as reports, prescriptions, or profile/branding images, attached to the relevant patient, staff, or organisation record.

Usage & log data — standard server logs (timestamps, IP address, requests made) generated by normal operation of the Service, used for security, debugging, and the audit trail described below. We do not run any analytics or advertising tracking on this website or inside the product today.

How we use data

  • To provide the core functionality an organisation has subscribed to (appointments, records, billing, etc.).
  • To authenticate users and enforce the role- and hospital-based access controls described below.
  • To maintain a record of who accessed or changed what, for security and accountability (our audit trail).
  • To send transactional communication — account, billing, and service notices — and, where a hospital configures it, optional patient reminders via SMS/WhatsApp or email.
  • To provide customer support when you contact us.
  • To maintain, secure, and improve the Service, including diagnosing and fixing faults.

We do not sell personal data, and we do not use patient data entered by an organisation for advertising, and we do not use it to train third-party AI models beyond the optional, per-organisation transcription feature described above (which uses a third-party transcription provider only to convert that organisation's own audio to text, and only when that organisation has turned the feature on).

Sharing and disclosure

We do not sell personal data. We share it only in these situations:

  • Within an organisation — staff can see the patient and records data their role and hospital membership entitle them to, and nothing outside that (see "Patient data & the hospital's role" below).
  • Service providers we use to run the Service — see "Sub-processors & integrations" below.
  • Legal requirements — if required to comply with a valid legal process, court order, or government request.
  • Business transfers — if Beyond Care is involved in a merger, acquisition, or asset sale, data may transfer as part of that deal, subject to this policy's protections continuing to apply.

Sub-processors & integrations

The following third parties may process data on our behalf, only where applicable:

  • Infrastructure & backups — our servers and encrypted off-site database backups run on third-party cloud hosting infrastructure.
  • Email delivery — an SMTP provider, used only if an organisation configures email notifications.
  • WhatsApp & SMS messaging — used only if an organisation enables patient messaging/reminders through that channel.
  • Voice transcription — a third-party speech-to-text provider, used only if an organisation enables voice-assisted consultation notes.

Every integration above is optional and only active for an organisation that has explicitly configured it — none of them run by default.

Storage, location & security

Application data, including patient records, is stored in a database on servers we operate on third-party cloud hosting infrastructure. Uploaded files (reports, images, documents) are currently stored on the application server's own disk, not a third-party file-hosting service. Encrypted database backups are additionally stored off-site in cloud object storage.

Access to data is restricted by a two-layer access-control model: a role determines what actions an account can take (e.g. only doctors can write consultation notes), and a separate tenant-membership check ensures a user can only ever reach data belonging to their own hospital/organisation — never another organisation's data, even though all organisations share the same database. Every access and change to a record is written to an audit trail that an organisation's admins can review.

We encrypt data in transit (HTTPS/TLS on every connection to the Service). Encryption of data at rest in the primary database is on our roadmap but is not yet implemented — we are stating this plainly rather than implying otherwise.

Data retention

We retain an organisation's data for as long as its subscription is active, so the organisation can keep using its own records. If an organisation's account is closed, contact support@beyondcarehms.in to request export or deletion of its data; we do not currently offer a fully self-service deletion/export workflow inside the product, so this is handled manually on request today.

Cookies & tracking

This marketing website (beyondcarehms.in) does not set any cookies and runs no analytics or advertising trackers.

The product application (app.beyondcarehms.in) uses a small number of strictly necessary cookies to keep you signed in and remember your active hospital context — for example an auth session token, your role, its expiry, and whether you have a hospital set up. These are essential to the Service working and are not used for advertising or cross-site tracking. We do not currently run Google Analytics or any other analytics/advertising tool inside the product.

Your rights

Depending on your relationship to the Service, you can:

  • Staff/organisation accounts — access and correct your own account details directly in the product, or by asking your organisation's admin. Ask us at support@beyondcarehms.in to export or delete your account data when you leave an organisation.
  • Patients — request access to, correction of, or deletion of your records from the hospital or clinic that holds them (they control that data). If they are unable to assist, you may write to us at support@beyondcarehms.in and we will coordinate with them.

We handle these requests manually today rather than through a self-service rights portal, and we aim to respond within a reasonable time, consistent with the DPDP Act.

Patient data & the hospital's role

Because Beyond Care is used by many independent hospitals and clinics on the same platform, our access-control design keeps every organisation's data separate: a staff member can only see patients and records belonging to a hospital they are actually part of, and different organisations can never see each other's data. The organisation you were treated at — not Beyond Care — decides who on their staff can see your records, how long they keep them, and how to respond to a request about them.

Children's data

The Service is intended for use by hospital/clinic staff, who are adults. Patient records may include information about minors where a hospital treats a child patient — that data is entered and controlled by the treating hospital as part of its own medical record-keeping, under its own consent and guardian-authorisation processes, not directly by the minor.

Breach notification

If we become aware of a data breach that is likely to affect an organisation's data, we will notify that organisation without undue delay, and will support them in meeting any notification obligations they may have to their own patients or regulators.

Changes to this policy

We may update this policy as the Service evolves. We will update the "Last updated" date above when we do, and for material changes we will make reasonable efforts to notify organisation admins directly.

Grievance officer & contact

In accordance with the Information Technology Rules, 2021, the Grievance Officer for Beyond Care is:

Parth P
Beyond Care Technologies Pvt Ltd
C2-1111, Pragati IT Park, opp. AR Mall, Mota Varachha, Surat, Gujarat 394105
Email: support@beyondcarehms.in

For any other question about this policy or your data, write to us at support@beyondcarehms.in. See also our Terms of Service.