1.Who controls patient data
Micro Clinic is a tool used by clinics to manage their own operations. When a clinic uses Micro Clinic to store patient information, the clinic is the controller of that patient data — it decides what to collect and how it is used. We act as a data processor, handling that information on the clinic's behalf and according to their instructions, solely to provide the Service.
If you are a patient and wish to access, correct, or delete your information, please contact the clinic that treated you. The clinic can use Micro Clinic tools to fulfil your request.
2.Information we collect
a. Clinic & account information
Clinic name, address, and phone number; staff names, roles, and login credentials; and subscription and billing details.
b. Patient information entered by the clinic
- Patient name, phone number, age, gender, and address
- Visit records, diagnoses, prescriptions, and clinical notes
- Chronic-condition tags and any uploaded test reports or documents
- Billing and payment records
c. Payment information
When clinics pay for a subscription, payments are processed by third-party providers (e.g. bKash, Nagad). We receive transaction confirmations but do not store full payment-instrument details on our servers.
d. Device & usage information
Device model, operating-system version, app version, and basic diagnostic/crash data used to keep the app stable and secure. We collect only what is needed to operate the Service.
3.How we use information
We use the information to:
- Provide and operate the Service — patient queue, prescriptions, billing, history, and reminders
- Sync data between a clinic's devices and our secure servers
- Send clinic-authorised notifications to patients (e.g. appointment, follow-up, or report reminders via SMS/WhatsApp)
- Process subscription payments and provide customer support
- Maintain security, prevent fraud, fix bugs, and comply with legal obligations
We do not use patient health data for advertising, and we do not sell any personal or patient information to anyone.
4.How we share information
We share information only as follows:
- With the clinic that entered the data and its authorised staff.
- With patients, on the clinic's instruction (e.g. reminder messages, a shared prescription summary).
- With service providers who help us run the Service under confidentiality obligations — for example, secure cloud hosting, SMS/WhatsApp messaging providers, and payment processors (bKash, Nagad). They may access data only as needed to perform their service.
- For legal reasons, if required by law, regulation, or valid legal process, or to protect the rights, safety, and security of users and the public.
We never sell your data.
5.Data storage & security
We take the security of health data seriously. We use industry-standard measures including encryption of data in transit and at rest, access controls and role-based permissions, and secure managed hosting. The app is offline-first: data is stored on the clinic's device and synced to our servers when a connection is available.
No system is perfectly secure, but we work to protect your information and to limit access to authorised personnel only.
6.Data retention
We retain clinic and patient data for as long as the clinic maintains an active account, and as needed to provide the Service or comply with legal obligations. When a clinic closes its account, we delete or anonymise the associated data within a reasonable period, except where retention is required by law. Clinics may request export or deletion of their data at any time (see below).
7.Your rights & choices
Subject to applicable law, clinics (and patients, via their clinic) may:
- Access the information held about them.
- Correct inaccurate information.
- Export their data in a portable format.
- Delete their data, subject to legal retention requirements.
- Withdraw consent for optional processing such as notifications.
To exercise these rights, contact us at the address below (clinics) or contact your clinic (patients).
8.Children's privacy
The Micro Clinic application is intended for use by clinics and their staff, not by children. Patient records may include minors, but these are entered and controlled by the clinic as part of medical care. We do not knowingly allow children to create accounts or use the app directly.
9.Third-party services
The Service relies on trusted third parties, including secure cloud hosting, SMS/WhatsApp messaging providers, and payment processors (bKash, Nagad). Their use of information is governed by their own privacy policies. We encourage you to review them.
10.International data transfers
Your information may be stored or processed on servers located outside Bangladesh by our hosting providers. Where this happens, we take steps to ensure appropriate protection of your information consistent with this policy.
11.Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here with a new "Last updated" date and, where appropriate, notify clinics within the app. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12.Contact us
For any questions, requests, or concerns about this Privacy Policy or your data, contact: