Privacy Policy
What we store, where it lives, who can read it, and how to get it back or have it deleted.
Last updated: 19 August 2026
1. Who is responsible
AQcredix (proprietor: Dr S. G. Santhoshkumar) is the data fiduciary for account data, and a data processor acting on your hospital's instructions for the compliance records you enter. Contact: s.g.santhoshkumar18@gmail.com.
2. What we hold
| Category | What it is | Why |
|---|---|---|
| Account | Name, email, hospital, role, department | To sign you in and attribute records to a person |
| Compliance records | Committees and minutes, recurring obligations, equipment and licences, calibration records, rounds and scores, audits, incidents, findings, documents | The purpose of the platform |
| Uploaded files | Certificates, photographs, scanned documents | Evidence attached to the record it proves |
| Activity | Which features you used and when | To show your own progress, and to know which parts of the product are used |
| Preferences | Pinned page, chosen department, notification settings | So the platform opens where you left it |
| Payment | Plan, amount, date, your UPI reference number | To grant and verify access |
What we deliberately do not hold
Patient identifiers. The incident reporting module has no field for a patient name, number or identifier, in the form or in the database. The printed form has ruled blanks completed in pen and kept by the hospital. This is a deliberate design decision and we will not reverse it.
Card details. We never see or store card or bank credentials. Payment is made through UPI and Razorpay; we hold only the reference number you give us.
3. Where it lives
Data is held in Supabase (PostgreSQL and object storage) in the ap-northeast-1 (Tokyo) region, and the site is served by Vercel. Email, when enabled, is sent through Resend.
If any of these are outside India, that means your data is transferred and stored outside India. At present your data is stored outside India, in Supabase's Tokyo region, so this is a cross-border transfer and we state it plainly rather than leaving you to discover it. We are migrating to Supabase's Mumbai region so that hospital records stay within India; this page will be updated on the day that happens, not before. Vercel serves the site from a global network, which caches static page files worldwide, but no hospital data passes through it — the workspace reads and writes directly to the database.
4. Who can read it
- Your colleagues, within your hospital only. Every table is scoped to your organisation by database-level row security, not by what the screen chooses to show. Another hospital cannot read your records.
- Uploaded files are private. They sit in a private bucket under a folder named for your organisation, and the storage layer itself checks that folder. Links are signed and expire two minutes after being requested.
- Your learning history is yours alone. Quiz results, certificates and activity are readable only by you — not by a colleague, and not by a hospital administrator.
- We can access your data as operators of the platform, for support and maintenance. We do so only when necessary, and we do not read hospital records out of curiosity.
- We do not sell data, and we do not advertise.
5. How long we keep it
| Data | Kept for |
|---|---|
| Compliance records | As long as the account is active, and at least 90 days after a subscription ends |
| Account details | Until you ask us to delete them |
| Payment records | As long as tax law requires (8 years) |
6. Your rights
Under the Digital Personal Data Protection Act 2023 you may:
- Get a copy. Export everything from the workspace, any time, without asking us — Excel and JSON.
- Correct it. Most records are editable in the app; write to us for anything that is not.
- Have it deleted. Ask, and we will delete your account and your hospital's records, other than what tax law requires us to retain.
- Complain. To us first, and then to the Data Protection Board of India if we have not resolved it.
We will respond within 90 days.
7. Security
- All traffic is encrypted in transit (HTTPS).
- Access is enforced at the database, not only in the browser, so it cannot be bypassed by manipulating a page.
- Uploaded files are private and reachable only through short-lived signed links.
- Passwords are hashed by our authentication provider; we never see them.
Honestly stated: no system is perfectly secure. If a breach affects your data we will tell you and the Data Protection Board without undue delay, and tell you what we know rather than waiting until we know everything.
8. Cookies
We use browser storage to keep you signed in and to remember your theme, pinned page and chosen department. We do not use advertising or third-party tracking cookies.
9. Children
AQcredix is for healthcare professionals and is not intended for anyone under 18.
10. Changes
We will post changes here and update the date above. Material changes will be notified in the workspace or by email.
11. Contact
s.g.santhoshkumar18@gmail.com \u00b7 Thoraipakkam, Chennai, Tamil Nadu, India