Legal

Privacy Policy

Last updated: July 4, 2026

Overview

Introduction

MediBridgeX ("we," "us," or "our") is a healthcare data interoperability platform registered in India. This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website, use our platform, or interact with our APIs.

This policy applies to website visitors, registered users, and API consumers.

Important: This policy does not govern Protected Health Information (PHI) processed through the MediBridgeX engine on behalf of our clients — that data is governed exclusively by the Business Associate Agreement (BAA) or Data Processing Agreement (DPA) signed with the respective client.
Collection

Data We Collect

Account Information

When you create a MediBridgeX account, we collect your full name, email address, organisation name, job title, and contact information.

Usage & Telemetry Data

We automatically collect IP addresses, browser type, device information, pages visited, timestamps, and API request metadata (endpoint, status codes, latency). This data is used solely for platform performance monitoring and security.

Health Data (PHI / Sensitive Personal Data)

MediBridgeX processes health data exclusively as a data processor on behalf of our clients (Covered Entities or Data Fiduciaries). We do not independently collect, access, sell, or monetise any patient health information.

Usage

How We Use Your Data

  • Provide, maintain, and improve the MediBridgeX platform
  • Send transactional emails (account verification, security alerts, API notifications)
  • Monitor platform security and prevent fraud
  • Generate aggregated, anonymised analytics to improve our services
  • Comply with legal obligations under applicable law
Third Parties

Data Sharing & Third Parties

We never sell, rent, or trade your personal data to third parties for marketing or any other purpose.

We share personal data only with the following categories of service providers, all of whom are bound by contractual confidentiality obligations:

Cloud Infrastructure

Cloudflare (CDN, DNS, edge security), managed database providers

Email

Transactional email delivery services only

Analytics

Aggregated and anonymised usage data only — never raw personal data

Transfers

Cross-Border Data Transfers

MediBridgeX is headquartered in India. Depending on your region, data may be processed in India or other jurisdictions where our infrastructure providers operate.

🇮🇳

Indian Clients

Data is stored and processed in India unless the client explicitly opts for global processing.

🇪🇺

EU/UK Clients

Cross-border transfers are governed by Standard Contractual Clauses (SCCs) as approved by the European Commission.

🇺🇸

US Clients

Data handling is governed by the signed BAA in compliance with HIPAA.

Retention

Data Retention

Active + 90 days

Account Data

Retained while your account is active, plus 90 days after account deletion to support recovery requests.

Per BAA/DPA

Health Data (PHI)

Retained strictly as per the terms of the BAA/DPA with the client, then permanently and irrecoverably purged.

12 months

System Logs

Rolling 12-month retention, then automatically and irrecoverably deleted.

Rights

Your Rights

Depending on your jurisdiction, you have the following rights over your personal data:

🇮🇳

India (DPDPA 2023)

Right to access, correction, erasure, and grievance redressal with the Data Fiduciary.

🇪🇺

EU/UK (GDPR)

Right to access, rectification, erasure, data portability, restriction of processing, and objection.

🇺🇸

USA (HIPAA)

Right to access PHI, request amendments, and receive an accounting of disclosures (exercised through your healthcare provider).

To exercise any of these rights, contact our Data Protection Officer at privacy@medibridgex.com.

Contact

Data Protection Officer / Grievance Officer

In accordance with the DPDPA 2023 and GDPR, MediBridgeX has appointed a Data Protection Officer (DPO) who also serves as the Grievance Officer under Indian law.

Response Time

Acknowledged in 72 hrs, resolved in 30 days

Age Policy

Children's Privacy

MediBridgeX is a B2B enterprise platform and is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately.

Updates

Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify registered users via email at least 30 days before the changes take effect. Your continued use of the platform after the effective date constitutes acceptance of the updated policy.

Questions about this Privacy Policy? privacy@medibridgex.com or write to us at our registered office in India.