This policy explains how Akeera Pte Ltd (“Akeera”, “we”) handles information in the MedQR Healthcare Suite — TeleMedQR, CareMedQR, IPDMedQR, BillMedQR and MedQrx (together, the “Services”).
1. Who controls your data
MedQR is sold to healthcare organisations, not to patients directly. This distinction decides who is answerable for what:
| Data | Controller / Data Fiduciary | Our role |
|---|---|---|
| Patient health records, clinical notes, prescriptions, invoices | The hospital or clinic that subscribes | Processor, acting on that organisation’s instructions |
| Staff account details, sign-in activity, audit logs | Akeera | Controller |
If you are a patient, your care provider decides what is recorded about you and how long it is kept. Requests to see, correct or erase your health record should go to them first; we act on their instruction.
2. What we collect
- Account data — name, email, phone, role, organisation, and the modules you may use.
- Health and billing data — entered by clinical and administrative staff in the course of care.
- Technical data — device, browser, IP address, and timestamps, kept for security and audit.
We do not sell personal data, and we do not use patient health data to advertise to anyone.
3. Where your data is stored
The Services run on Google Cloud Platform and Firebase. Application data and backend functions for Indian deployments are hosted in the asia-south1 (Mumbai)region. Akeera is incorporated in Singapore, so a limited set of administrative and support data may be accessed from outside India under appropriate contractual safeguards.
4. Single sign-on across modules
One MedQR identity signs you in to every module your organisation subscribes to. To do this we create a linked account for you in each module and pass a short-lived token between them. That token carries your identifier, organisation and role — never a password, and never clinical content.
5. Security
- Encryption in transit (TLS) and at rest.
- Role-based access, enforced on the server, so staff reach only what their role permits.
- Access to a patient record is limited to the organisation that created it.
- Administrative actions are logged.
No system is perfectly secure. If a breach affects your data we will notify the affected organisation and the relevant authority as the law requires.
6. Retention
Health records are retained for as long as the subscribing organisation requires, and for any minimum period imposed on them by medical-records law. Account and audit data is kept for the life of the account plus the period needed to meet legal and accounting duties.
7. Your rights
Depending on where you live, you may have rights to access, correct, erase or port your personal data, to withdraw consent, and to complain to a data-protection authority. Staff users may exercise these against Akeera directly. Patients should approach their care provider, who instructs us.
8. Sub-processors
We use a small number of vendors to run the Services, principally Google Cloud Platform and Firebase for hosting, storage and authentication, and an email provider for transactional messages such as invitations and password resets.
9. Changes
We will update the effective date above when this policy changes, and will tell subscribing organisations in advance of material changes.
10. Contact
Akeera Pte Ltd — write to us at the address given in your subscription agreement, or through your organisation’s MedQR administrator.