1. Overview & Core Philosophy
Ezycure ("we", "our", or "us") operates the website https://ezycure.com and associated healthcare software applications. Our platform is designed to provide precision medical matchmaking, artificial intelligence clinical assistance, appointment booking, electronic health record (EHR) management, and diagnostic synthesis.
Because healthcare involves the most sensitive form of human personal data, our system architecture is built on the principle of Zero Unconsented Exposure. We do not sell, license, or monetization-trade your personal health information to third-party advertisers, data brokers, or insurance companies under any circumstances.
Key Principle: Your health records, genomic profiles, wearable telemetry, and diagnostic results remain your property. You maintain total granular control over which doctors and clinics can view your medical file.
2. Information We Collect
To deliver AI-powered precision treatment matching and smooth clinic workflows, we collect the following categories of data:
A. Personal & Account Identifiers
- Patient Profile: Full name, age, gender, contact details (email address, phone number), residential address, and emergency contact details.
- Doctor Profile: Professional licensure numbers, medical registration credentials, specialization certifications, clinic affiliations, and consultation hours.
B. Precision Health & Clinical Records
- Medical Uploads: Digital Health Records, prescriptions, doctor consultation notes, surgical history, and discharge summaries.
- Diagnostics & Lab Reports: Comprehensive blood panel results, pathology files, imaging reports (DICOM/X-Rays/MRIs), and genomic/DNA sequencing files.
- Vitals & Symptoms: Patient-reported symptom logs, allergies, current medications, and medical history questionnaires.
C. Connected Devices & Wearable Telemetry
- Real-time or periodic heart rate, pulse oximetry (SpO2), sleep metrics, activity steps, ECG traces, and continuous glucose monitoring data from synced wearable devices (when authorized by you).
D. Technical & Usage Data
- IP address, browser type, device OS, system timestamps, and interaction logs required for audit trails and cybersecurity safeguards.
3. How We Use Your Information
We utilize collected information solely for legitimate clinical, operational, and security purposes:
- AI Matchmaking & Precision Diagnostics: Analyzing multi-modal health inputs (blood work, DNA, wearables, history) to match patients with specialized doctors and suggest personalized treatment options.
- Appointment & Care Coordination: Facilitating appointment scheduling, teleconsultations, e-prescriptions, and reminder notifications.
- Clinic Management: Supporting registered healthcare providers with scheduling tools, patient intake forms, scribe assistance, and inventory tracking.
- Security & Regulatory Fraud Audit: Verifying practitioner credentials, preventing unauthorized profile access, and ensuring audit compliance.
4. Data Sharing & Third-Party Disclosure
We restrict data access to strict necessity. We share information only in the following scenarios:
- Authorized Healthcare Providers: When you book an appointment or consent to share your medical history, your designated doctor, clinic staff, or diagnostic lab receives access to relevant portions of your file.
- Infrastructure & Service Partners: Trusted technology partners (such as cloud database providers and SMS/Email notification gateways) operating under strict HIPAA-compliant and DPDP-compliant Business Associate Agreements (BAA).
- Legal & Emergency Mandates: Where required by valid judicial order, court summons, or emergency life-threatening clinical intervention requirements.
5. Data Security & Encryption Standards
We employ military-grade administrative, physical, and technical safeguards to secure your sensitive health records:
- Encryption at Rest: All database storage and medical file repositories are encrypted using AES-256 standards.
- Encryption in Transit: All data transmissions between your browser/app and our servers are protected via Transport Layer Security (TLS 1.3).
- Role-Based Access Control (RBAC): Strict identity verification prevents staff or unauthorized accounts from accessing patient charts without valid credentials.
- Audit Logging: Every attempt to view, export, or edit a patient record generates an immutable access log.
6. Your Patient Data Rights
Under global data protection laws and Indian healthcare privacy norms, you possess full sovereignty over your data:
- Right to Access & Export: Request a complete digital copy of your medical history and uploaded records (Data Portability).
- Right to Rectification: Request correction of inaccurate personal or demographic profile details.
- Right to Erasure (Account Deletion): Request the permanent deletion of your account and personal identifiers via our Delete Account Page (subject to mandatory medical record retention laws).
- Right to Revoke Access: Withdraw doctor or clinic access permissions at any time from your patient dashboard.
7. Healthcare Regulatory Compliance
Ezycure operates in accordance with leading international and national health data regulations:
- Digital Personal Data Protection Act, 2023 (DPDP Act, India): Full compliance with consent manager requirements, data fiduciary responsibilities, and user rights.
- Digital Information Security in Healthcare Act (DISHA principles): Adherence to strict health data confidentiality guidelines.
- HIPAA Alignment: Implementation of administrative, physical, and technical safeguards modeled on U.S. Health Insurance Portability and Accountability Act guidelines.
8. Cookies & Local Storage Policy
We use essential session cookies and local storage tokens to keep you securely signed in, save your layout preferences, and manage authentication states across pages. We do not use intrusive third-party cross-site advertising cookies.
9. Data Retention Guidelines
We retain active patient data for as long as your account remains open. Medical consultation records and prescription histories are preserved in accordance with statutory medical council guidelines (typically 3 to 7 years depending on local jurisdiction requirements). Inactive or deleted account data is purged or permanently anonymized following legal hold expirations.
10. Contact Our Privacy Officer
If you have questions, privacy concerns, or wish to exercise your data subject rights, please reach out to our designated Data Protection Officer: