Privacy Policy
1. Introduction
This Privacy Policy explains how Purple NICU EMR Software ("Software", "we", "our", or "us") collects, uses, stores, and protects information related to neonatal patients, parents/guardians, and authorized healthcare users.
This Software is intended strictly for use by authorized hospital staff for NICU clinical documentation, patient care, billing, consent management, and operational purposes.
By accessing or using this Software, users agree to this Privacy Policy.
2. Information We Collect
a. Patient (Neonatal) Information
We collect and store medical data including:
- Baby name/ID, date and time of birth
- Birth weight, gestational age
- Diagnosis, treatment, medications
- Vitals, progress notes
- Lab reports and investigations
- Admission and discharge details
- Referring doctor information
- NICU clinical summaries
b. Parent / Guardian Information
- Name, contact number, address, email
- Relationship to patient
- Consent records and digital signatures
c. User (Staff) Information
- Name, email, and role (Admin / Doctor / Nurse / Billing / Staff)
- Encrypted login credentials
- Access permissions and department details
d. Technical and Usage Information
- Login/logout time and session duration
- IP address, device and browser details
- System activity logs and audit logs
- Failed login attempts and security logs
3. Purpose of Data Usage
We use collected data strictly for:
- Patient care and NICU clinical documentation
- Consent management and legal documentation
- Billing and financial records
- Hospital operations and reporting
- Security monitoring, audit logs, and compliance
We may also use aggregated and anonymized data (non-identifiable) for:
- Clinical statistics (e.g., admissions, outcomes, survivability rates)
- Internal analysis and quality improvement
- Awareness, educational, and marketing purposes
We do not use or disclose personally identifiable patient data for marketing or advertising purposes.
4. Data Storage and Processing
All data is securely stored on Supabase cloud infrastructure. Appropriate safeguards are implemented to protect stored data.
Authorized technical service providers may have controlled access to data strictly for maintenance, support, and system improvement purposes. Such access is provided under confidentiality and data protection obligations.
5. Data Sharing and Disclosure
Data is shared only:
- With authorized hospital staff for patient care and operations
- With authorized technical service providers for system support
- When required by law or regulatory authorities
- For audit and compliance purposes
We do not sell, rent, or share personally identifiable data with unauthorized third parties.
Aggregated and anonymized data may be used for reporting or public communication.
6. App Permissions and Usage
The Software may request access to the following:
- Camera: For document capture or clinical workflows (if enabled)
- Microphone: For audio-related features (if applicable)
- File Storage: For saving and exporting reports/documents
- Notifications: For system alerts and operational updates
These permissions are used strictly for operational and clinical purposes within the Software.
7. Audit Logs and Monitoring
The Software maintains secure, non-editable audit logs of:
- Patient record creation and updates
- Medical and billing changes
- Consent form generation and signatures
- User activity and system access
These logs are used for traceability, compliance, and security monitoring.
8. Consent Forms and Digital Signatures
The Software supports NICU consent documentation, including:
- Admission, procedure, and high-risk consents
Digital signatures:
- Are securely stored and timestamped
- Are non-editable after submission
- Are linked to relevant records
- May be treated as legally valid acknowledgments
9. Data Security
We implement appropriate safeguards, including:
- Role-based access control
- Secure authentication and encrypted transmission (HTTPS)
- Session timeout and automatic logout
- Audit logging and monitoring
- Secure cloud infrastructure
Access is restricted to authorized personnel only.
10. Data Access Control
Access is restricted based on user roles:
- Admin - full access
- Doctor - clinical access
- Nurse - clinical updates
- Billing - billing access
Users can only access data necessary for their role.
11. Data Retention
Data is retained:
- As per hospital policy
- In accordance with medical and legal requirements
- For audit, compliance, and reporting purposes
12. Data Export and Responsibility
The Software allows export of data (e.g., PDF, reports, spreadsheets). Once exported, the handling and security of such data becomes the responsibility of the healthcare organization and authorized users.
13. User Responsibilities
Users must:
- Maintain confidentiality of login credentials
- Use the system only for authorized purposes
- Log out after use
- Report unauthorized access or security concerns immediately
14. Children's Privacy
This Software manages neonatal patient data strictly for medical purposes. All data is entered and handled by authorized healthcare professionals.
Parent or guardian consent is obtained and recorded where required.
15. User Rights
Healthcare organizations may request:
- Access to stored data
- Correction of inaccurate data
Requests may be processed in accordance with hospital policies and applicable regulations.
16. Limitation of Use
This Software is intended to support clinical documentation and hospital operations. It does not replace professional medical judgment or decision-making.
17. Updates to this Policy
We may update this Privacy Policy from time to time. Updated versions will be made available within the Software or on the official website.
Continued use of the Software constitutes acceptance of the updated policy.
18. Contact Information
For privacy-related queries:
Hospital / Organization Name:
Software Name: Purple NICU
Email:[email protected]
19. Consent
By using this Software, users confirm that they have read, understood, and agreed to this Privacy Policy.
