Introduction
This Privacy Policy explains how AIMDek Technologies Pvt Ltd, operating the AIMCare platform ("AIMCare", "we", "us", or "our"), collects, uses, stores, shares and protects personal information when you visit aim-care.health, interact with us, or use AIMCare products and services.
AIMCare provides healthcare technology solutions for clinics, hospitals, healthcare groups and other healthcare organisations. Depending on how AIMCare is used, we may process information relating to healthcare professionals, administrative users, patients, prospective customers and website visitors.
This Privacy Policy should be read together with our Terms of Service, applicable customer agreements, order forms, data processing agreements and other contractual documents governing use of AIMCare.
1 Scope of this Privacy Policy
This Privacy Policy applies to personal information processed through:
- the AIMCare website;
- AIMCare cloud and software applications;
- patient-facing applications or portals made available through AIMCare, where applicable;
- integrations, APIs and connected services;
- demo, sales, support and customer-service interactions; and
other services provided by AIMCare.
Where a healthcare organisation uses AIMCare to process patient or healthcare information, the healthcare organisation will generally determine why and how that information is processed. AIMCare processes such information on its behalf in accordance with the applicable agreement, documented instructions and applicable law.
For information that AIMCare collects for its own purposes, such as website enquiries, account administration, billing or marketing communications, AIMCare may act as the relevant data controller or data fiduciary.
2 Information We May Collect
The information we collect depends on how you interact with AIMCare.
Information you provide directly
We may collect information such as:
- name;
- business email address;
- telephone number;
- organisation name;
- job title or professional role;
- account and profile information;
- login credentials;
- support requests and communications;
- billing and administrative information; and
information submitted through demo, contact or enquiry forms.
Information processed through the AIMCare platform
Where AIMCare is used by a healthcare organisation, the platform may process information including, depending on the modules and configuration being used:
- patient identification and demographic information;
- contact information;
- appointments and registration information;
- medical and clinical history;
- consultations and clinical documentation;
- diagnoses, prescriptions and medication information;
- laboratory and diagnostic information;
- radiology-related information;
- inpatient and outpatient records;
- nursing and care information;
- discharge records;
- insurance, payer or TPA information;
- billing and payment information;
- consent information;
- documents and healthcare records; and
audit, access and activity records.
The healthcare organisation using AIMCare is responsible for determining what patient and healthcare information is entered into or processed through the platform.
Information collected automatically
When you access our website or services, we may automatically collect certain technical information, including:
- IP address;
- browser type;
- operating system;
- device information;
- pages viewed;
- date and time of access;
- referring pages;
- session and usage information; and
diagnostic and performance information.
We may collect this information using cookies and similar technologies.
3 How We Use Information
We may process personal information to:
- provide, operate and maintain AIMCare;
- create and manage user accounts;
- authenticate users and control access;
- deliver healthcare workflows requested by our customers;
- provide customer support;
- respond to enquiries and demo requests;
- manage subscriptions, billing and customer relationships;
- maintain security and prevent misuse;
- identify and resolve technical problems;
- monitor system performance;
- maintain audit and activity records;
- improve product functionality and user experience;
- develop and test AIMCare features using information we are permitted to use for those purposes;
- communicate important product, operational or security information;
- meet contractual obligations;
- comply with applicable legal and regulatory requirements; and
establish, exercise or defend legal rights.
Where consent is required by applicable law, we will process information on the basis of appropriate consent.
4 Healthcare and Sensitive Personal Information
Healthcare information requires a higher level of protection.
Where AIMCare processes patient or health information on behalf of a hospital, clinic or other healthcare organisation, AIMCare processes that information in accordance with the healthcare organisation's instructions, the applicable agreement and applicable law.
AIMCare does not independently determine the clinical purpose for which healthcare organisations collect their patients' medical records.
Depending on the jurisdiction and circumstances, health information may be treated as sensitive personal information, special-category personal data, protected health information or another legally protected category.
For example, health data receives specific protection under the GDPR.
5 AIMCare as a Service Provider or Data Processor
Healthcare organisations may use AIMCare to store, manage or otherwise process information about their patients, employees and operations.
In these circumstances, the healthcare organisation remains responsible for matters including:
- determining the lawful basis for collecting and processing information;
- providing appropriate notices to patients or other individuals;
- obtaining consent where required;
- determining appropriate retention periods;
- responding to individuals exercising applicable privacy rights; and
configuring authorised access within its organisation.
AIMCare will support its customers in meeting applicable data-protection obligations as required under the applicable contract and law.
If you are a patient seeking access to, correction of or deletion of information held by your hospital or clinic through AIMCare, you should ordinarily contact that healthcare organisation first.
6 HIPAA and Protected Health Information
Where AIMCare provides services to a healthcare organisation subject to the United States Health Insurance Portability and Accountability Act ("HIPAA") and AIMCare qualifies as a Business Associate, the parties may enter into an applicable Business Associate Agreement ("BAA").
In those circumstances, Protected Health Information ("PHI") will be processed in accordance with the applicable BAA, customer agreement and HIPAA requirements.
HIPAA requires covered entities and applicable business associates to contractually define permitted uses and disclosures of PHI and appropriate safeguards.
Nothing in this Privacy Policy should be interpreted as a representation that HIPAA applies to every AIMCare deployment.
7 India Data Protection
For processing subject to Indian data-protection law, AIMCare will process personal data in accordance with applicable requirements of the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, and other applicable laws as they become operative and apply to the relevant processing activity.
Depending on the processing relationship, AIMCare may act as a Data Fiduciary or process personal data on behalf of another Data Fiduciary.
8 European and International Data Protection
Where the GDPR, UK GDPR or another applicable data-protection framework applies, AIMCare will process personal information according to the role and obligations applicable to the relevant processing activity.
Depending on the circumstances, processing may be based on:
- performance of a contract;
- compliance with legal obligations;
- legitimate interests;
- consent;
- healthcare-related legal grounds; or
another lawful basis permitted by applicable law.
11 We Do Not Treat Patient Data as Advertising Data
Patient and clinical information processed by AIMCare on behalf of healthcare organisations is intended for providing the contracted healthcare technology services.
It should not be used for unrelated advertising or marketing purposes unless such processing has been separately authorised and is permitted by applicable law.
12 Data Security
AIMCare uses appropriate administrative, technical and organisational measures designed to protect information against unauthorised access, disclosure, alteration, loss or misuse.
Depending on the service and deployment, these safeguards may include:
- role-based access controls;
- authentication controls;
- audit logging;
- encryption for supported data transmission and storage;
- backup and recovery processes;
- monitoring;
- access-management procedures; and
security controls applied to infrastructure and service providers.
No online service or storage system can guarantee absolute security. Users and customers are also responsible for protecting account credentials and configuring access appropriately.
13 Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including contractual, operational, security and legal requirements.
Customer-controlled healthcare data may be retained according to:
- the healthcare organisation's instructions;
- the applicable customer agreement;
- regulatory or medical-record retention requirements; and
applicable law.
Following termination of a customer relationship, customer data will be handled according to the applicable agreement, data-processing terms and legal requirements.
14 International Data Transfers
AIMCare and its service providers may process information in countries other than the country in which it was originally collected.
Where applicable law imposes requirements on international transfers of personal information, AIMCare will use appropriate contractual, organisational or other recognised safeguards.
Deployment-specific hosting or data-residency commitments, where applicable, will be governed by the relevant customer agreement.
15 Your Privacy Rights
Depending on your location and applicable law, you may have rights relating to your personal information, including rights to:
- request access;
- request correction;
- request deletion or erasure;
- withdraw consent where processing relies on consent;
- object to certain processing;
- request restriction of processing;
- request portability where applicable;
- obtain information regarding processing;
- raise a grievance or complaint; and
approach an applicable supervisory or regulatory authority.
These rights are subject to applicable legal limitations.
Where AIMCare processes information on behalf of a hospital, clinic or other customer, requests concerning that information may need to be submitted directly to the relevant customer. AIMCare will assist the customer where required.
16 Children's Information
AIMCare is primarily provided to healthcare organisations and their authorised users.
Healthcare organisations may use AIMCare to maintain health records relating to minors where permitted by applicable law and appropriate to the delivery of healthcare services.
Where consent from a parent or lawful guardian is required, responsibility for obtaining that consent generally rests with the healthcare organisation collecting the information unless otherwise agreed.
AIMCare does not knowingly use children's personal information collected through its public website for independent marketing purposes where prohibited by applicable law.
17 Third-Party Links
Our website may contain links to external websites or services.
AIMCare is not responsible for the privacy practices or content of third-party websites that operate independently from AIMCare. We encourage users to review the privacy policies of those services.
18 Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect changes to our services, technology, business practices or legal obligations.
The updated version will be published on this page with a revised "Last Updated" date.
Where required by law or where changes are material, we may provide additional notice.
19 Contact Us
Questions, concerns or requests concerning this Privacy Policy may be directed to: