This policy covers the public CareDiumX website and its administration system. It does not by itself govern patient or hospital data processed within a deployed CareDiumX HMIS. That processing must be covered by the applicable hospital agreement, deployment terms and data-processing documentation.
1. Who we are
CareDiumX Healthtech LLP (“CareDiumX”, “we”, “us” or “our”) is the entity responsible for personal data collected directly through this website.
Corporate Office:
201, Adited House, Near Medicare Hospital, 1 Ravindra Nagar, Old Palasia Road, Indore, Madhya Pradesh 452018, India
Registered Office:
076 Gaduli, Police Station Rambhapur, Meghnagar, Jhabua, Madhya Pradesh 457779, India
Email: info@carediumx.in
Phone and WhatsApp: +91 70896 07044
2. Personal data we collect
Depending on how you use the website, we may collect:
- Contact and identity information: name, work email address, phone number and organization or hospital name.
- Hospital context: operational bed range, areas of interest and information you voluntarily include in an enquiry.
- Communications: correspondence, meeting requests, feedback and follow-up notes relating to your enquiry.
- Technical information: IP address, browser and device information, requested pages, timestamps, referral information, security events and essential cookie or session identifiers.
- Administration information: authorized CMS user account identifiers, roles, login and audit records.
Do not submit patient records, medical details, government identifiers, payment-card data or other sensitive hospital information through public website forms. The public website is not a patient portal or emergency service.
3. How we obtain personal data
We collect data directly when you complete a form, use the Zoho SalesIQ live chat, email, call, message us on WhatsApp, request a demo or interact with our team. Limited technical and visitor-session data may be generated automatically by the website, live-chat, hosting, analytics, security and authentication systems. We may also receive professional contact details from your organization or a legitimate business introduction.
4. Why we use personal data
We use personal data only for identified business and website purposes, including to:
- respond to enquiries and arrange product demonstrations;
- understand whether CareDiumX may be relevant to a hospital’s requirements;
- communicate about requested products, Add-on Services, implementation or support;
- manage business relationships and maintain appropriate enquiry records;
- operate, secure, troubleshoot and improve the website and CMS;
- prevent spam, fraud, unauthorized access and misuse;
- meet legal, regulatory, accounting and dispute-resolution obligations; and
- send optional updates where you have requested them or where otherwise permitted, with a way to opt out.
5. Consent and other permitted processing
Where consent is required, we will seek a clear affirmative action and explain the purpose of collection. You may withdraw consent by contacting us, although withdrawal does not invalidate processing already carried out and may prevent us from completing a requested service. We may also process data where permitted for responding to voluntarily submitted enquiries, fulfilling agreements, protecting systems, complying with law or establishing and defending legal claims.
6. Cookies and analytics
Essential cookies are used for security, session management and administrator authentication. The public website also uses Google Analytics to understand aggregate website usage. Google may receive technical information such as requested pages, browser or device details, approximate location derived from IP address and referral information. The website configuration requests IP anonymization. See the Cookie Policy for available choices.
7. How we share personal data
We do not sell personal data. We may disclose the minimum necessary data to:
- authorized CareDiumX personnel who need it for their work;
- hosting, database, authentication, communication, security and professional-service providers acting for us;
- business advisers, auditors or insurers subject to appropriate confidentiality duties;
- government, regulatory, judicial or law-enforcement authorities where legally required; or
- a successor organization during a lawful restructuring or transaction, subject to appropriate safeguards.
We use service providers for specific website functions: Netlify hosts and serves the website; Supabase supports CMS authentication, website content, media and enquiry storage; Brevo sends transactional enquiry notifications; Google Analytics helps us understand website usage; and Zoho SalesIQ provides live chat and related visitor-session functionality. WhatsApp, LinkedIn and Instagram process information when you choose to use their links or platforms. Each provider operates under its own terms and privacy practices.
8. International processing
Some service providers may process or store data outside India. Where cross-border processing occurs, we will use approved providers, contractual controls and other measures considered appropriate for the data and applicable law. We will also observe any transfer restrictions notified by the Government of India.
9. Retention
We retain personal data only as long as reasonably needed for the stated purpose, an active business relationship, security, legal obligations or dispute handling. Enquiries that do not lead to an active commercial relationship are reviewed periodically and should be deleted or anonymized when no longer reasonably required. CMS security and audit records may be retained separately to preserve system accountability. Specific contractual, tax or legal records may require longer retention.
10. Security
We use organizational and technical measures appropriate to the website’s risks, including controlled administrative access, role-based permissions, server-side handling of sensitive credentials, database access policies and auditability. No online service can promise absolute security. If a personal-data breach requires notification under applicable law, we will follow the required reporting and communication process.
11. Your choices and rights
Subject to applicable law and its commencement schedule, you may ask us to:
- provide information about personal data being processed and the parties with whom it has been shared;
- correct inaccurate or misleading personal data;
- complete or update incomplete personal data;
- erase personal data that is no longer required, unless retention is legally permitted or necessary;
- withdraw consent for consent-based processing;
- stop optional promotional communications; or
- address a grievance about our handling of personal data.
To protect you, we may request reasonable information to verify identity and authority before acting. If you submit a request for another person, we may ask for proof that you are authorized to do so.
12. Children
This business website is intended for hospital owners, administrators, professionals and other adults. It is not directed to children, and we do not knowingly seek personal data from a child through public website forms. If you believe a child has submitted data, contact us so we can review and take appropriate action.
13. External websites and communication platforms
The website links to services such as LinkedIn, Instagram and WhatsApp. Those organizations control their own platforms and privacy practices. Opening an external link may allow that provider to collect data under its own policy. CareDiumX is not responsible for an external platform’s independent processing.
14. Grievances and privacy requests
Send a privacy request or grievance to info@carediumx.in with the subject “Privacy Request”. Include enough information to identify the relevant interaction, but do not email patient records or passwords. You may also write to our registered office shown above.
We will acknowledge and assess the request, seek verification where appropriate and respond according to the applicable legal requirements. If a grievance is not resolved through our process, you may use any escalation or complaint mechanism available under applicable Indian law.
15. Changes to this policy
We may update this policy when our website, vendors, processing activities or legal obligations change. The revised version will be posted here with a new “Last updated” date. Material changes may also be communicated through an additional website notice or direct communication where appropriate.
16. Legal framework
This policy is designed with reference to India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, including their phased commencement. It is a public description of our website practices and does not replace customer contracts or professional legal advice.
