Back to home

Privacy Policy

This policy describes how we handle personal information in connection with Caresoft.ai. It is not a Business Associate Agreement (BAA) and not legal advice.

Last updated: September 7, 2026

Terms of ServiceTrust & security

1. Who we are and scope

Caresoft.ai is operated by DotBunch Healthcare Solutions LLP (KSUM Building, UL Cyberpark, Kozhikode, Kerala, India). This Privacy Policy applies to information processed through websites and applications operated as part of the Caresoft.ai Service. The data controller or processor role may depend on your contract and configuration (for example whether your organization hosts data or we process it as a service provider).

2. Information we collect

Depending on how you use Caresoft.ai, we may collect:

  • Account data: name, email, phone, professional credentials, organization details, and authentication identifiers.
  • Clinical and operational data: information you enter about care delivery, scheduling, assessments, notes, and communications sent through the Service.
  • Technical data: IP address, device and browser type, logs, cookies or similar technologies, and diagnostic information used for security and reliability.
  • Informed consent and audit: when you sign clinical consent forms in the product, we store the agreement text (including language), version you agreed to, a cryptographic integrity hash, and the time of signing. We may also record IP address and browser type for audit and dispute resolution. When authorized clinicians or administrators view stored consent records, we may log that access for accountability.
  • Integration data: information received from services you connect, as authorized by you — for example Google Sign-In (name, email, profile photo) and Google Calendar (calendar event details, attendees, and free/busy times) when you connect your calendar for scheduling.

3. How we use information

We use information to:

  • Provide, maintain, and improve the Service;
  • Authenticate users, enforce access controls, and prevent abuse;
  • Communicate about the Service, security, and policy updates;
  • Comply with law and respond to lawful requests;
  • Analyze usage in aggregate or de-identified form where permitted.

4. Legal bases (where applicable)

If laws such as the GDPR apply, we rely on appropriate bases including contract performance, legitimate interests (for example securing the Service), consent where required, and legal obligation.

5. Sharing and subprocessors

We share information with vendors that help us operate the Service (hosting, email, analytics, support), subject to confidentiality and security obligations. We may disclose information if required by law or to protect rights, safety, and integrity. A current list of subprocessors should be published or provided to customers as part of your procurement process.

6. Google user data

When you connect Google Calendar or sign in with Google, we access only the scopes needed for scheduling: your calendar's events and free/busy times, so we can create, update, and cancel appointments you book through the Service and avoid double-booking. We do not use this data for advertising, and we do not sell it or share it with third parties except the service providers needed to operate the feature (for example our hosting provider), under confidentiality obligations.

Caresoft.ai's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke Caresoft.ai's access to your Google account at any time from your Google Account permissions page, or by disconnecting Google Calendar from within the Service.

7. Retention

We retain information for as long as needed to provide the Service, meet legal and contractual obligations, resolve disputes, and enforce agreements. Retention periods may be configured with your organization where the product supports it.

8. Security

We implement technical and organizational measures designed to protect information. No method of transmission or storage is completely secure. See our Trust & security page for a high-level discussion of how we think about controls and compliance messaging.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. Many Caresoft.ai users exercise rights through their healthcare provider or employer as the primary account holder. You may also contact us as described below. You may lodge a complaint with a supervisory authority where applicable.

10. International transfers

If data is processed across borders, we use appropriate safeguards (such as standard contractual clauses) where required by law.

11. Children

The Service is not directed at children for independent sign-up. Patient accounts are typically created under a clinician’s direction. If you believe we have collected information improperly, contact us.

12. Changes to this policy

We may update this Privacy Policy. We will post the new version and revise the “Last updated” date. Material changes may require additional notice under applicable law.

13. Contact

For questions about these policies, contact DotBunch Healthcare Solutions LLP at +91 96334 47508.

DotBunch Healthcare Solutions LLP
KSUM Building, UL Cyberpark, Kozhikode, Kerala, India

Caresoft.aiSign in