Privacy Policy

Last updated:

This Privacy Policy explains how MedImages ("MedImages", "we", "us", or "our") handles information in connection with our website (medimages.org) and our hospital management software platform (the "Service"). By visiting our website or using the Service, you agree to the practices described here.

1. Who This Policy Covers

MedImages is a software-as-a-service platform licensed to hospitals, clinics, and healthcare practices ("Customers"). This policy applies to two distinct categories of data, and it is important to understand the difference:

  • Website & account data — information about visitors to our public website and about the Customer accounts and staff users who register to use the Service. MedImages determines how this data is used, and we act as the data controller for it.
  • Patient data entered into the Service — records, images, and other health-related information that a Customer (a hospital, clinic, or their staff) inputs into the platform in the course of treating their own patients. For this data, the Customer is the data controller, and MedImages acts only as a data processor / service provider that stores and processes it on the Customer's behalf and instructions.

If you are a patient and have questions about how your medical records are used, please contact the hospital or clinic that treated you directly — they control that data, not MedImages.

2. Information We Collect

Depending on how you interact with us, we may collect:

  • Account information: name, email, phone number, hospital/clinic name, and role, provided when a Customer registers for or uses the Service.
  • Billing information: subscription plan, payment status, and transaction records processed via our payment provider(s). We do not store full card numbers.
  • Usage data: log data, device/browser type, IP address, pages visited, and general interaction data collected automatically when you use our website or Service.
  • Communications: messages you send us via the contact form, email, or WhatsApp support channel.
  • Cookies and similar technologies: used for authentication, session management, site functionality, analytics, and (on our public marketing pages only) advertising, as described in Section 5.
  • Patient/clinical data: entered by Customers into the Service (e.g. patient records, lab results, images, prescriptions, billing). This is processed strictly under the Customer's direction, as described in Section 1.

3. How We Use Information

We use the information described above to:

  • Provide, operate, maintain, and secure the Service;
  • Create and manage Customer accounts and subscriptions, and process payments;
  • Respond to support requests and communicate service-related updates;
  • Monitor, troubleshoot, and improve platform performance and reliability;
  • Detect, prevent, and address fraud, abuse, or security incidents;
  • Comply with applicable legal obligations; and
  • On our public marketing pages only, display advertising as described in Section 5.

We do not use patient/clinical data entered by Customers for advertising, marketing, or any purpose other than operating the Service on the Customer's behalf.

4. How We Share Information

We do not sell personal data or patient data. We may share information with:

  • Service providers who help us operate the platform — e.g. cloud hosting/storage, payment processing, and email delivery — bound by confidentiality and data-processing obligations.
  • Legal or safety purposes — where required to comply with a legal obligation, enforce our terms, or protect the rights, property, or safety of MedImages, our Customers, or others.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy continuing to apply to previously collected data.

Each Customer's data (including any patient data they enter) is logically separated from other Customers' data and is not shared with other Customers.

5. Cookies & Advertising

Our authenticated dashboards (used by hospital staff to manage patients and operations) do not display third-party advertising. Advertising, where present, is limited to our public, logged-out marketing pages.

We use Google AdSense on those public pages, which may use cookies (including the DoubleClick cookie) to serve ads based on a visitor's prior visits to this and other websites. Google's use of advertising cookies enables it and its partners to serve ads based on visits to our site and/or other sites on the internet. You may opt out of personalized advertising by visiting Google Ads Settings, or generally at aboutads.info.

We also use essential and functional cookies (e.g. session/authentication cookies) required for the Service to work; these cannot be disabled without affecting core functionality.

6. Data Security

We use commercially reasonable technical and organizational measures — including encrypted connections (SSL/TLS), access controls, and role-based permissions within the Service — designed to protect information against unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

Customers are responsible for maintaining the confidentiality of their account credentials, configuring appropriate staff access levels within the Service, and complying with applicable healthcare data protection laws (such as HIPAA, GDPR, or local equivalents) in their jurisdiction, including obtaining any patient consents required to process data through the Service.

7. Data Retention

We retain account and patient data for as long as a Customer's subscription is active, and for a reasonable period afterward to allow account recovery, meet legal/accounting obligations, and resolve disputes, after which it may be deleted or anonymized in accordance with our standard retention practices.

8. Your Rights

Depending on your location and applicable law, you may have rights to access, correct, or request deletion of personal information we hold about you as a website visitor or account holder. To exercise these rights, contact us using the details in Section 11. If your request concerns patient/clinical data, we will direct you to the relevant hospital or clinic (the data controller for that data), or assist them in responding to you where required.

9. Children's Privacy

Our website and account registration are not directed at, and are not knowingly used by, individuals under 18. This does not restrict Customers from entering pediatric patient records into the Service in the normal course of providing healthcare.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. We will update the "Last updated" date above when we do. Continued use of our website or the Service after changes take effect constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy, contact us at support@medimages.org.