1.Who controls patient data
rxIndex Assistant is a tool used by a doctor and the assistant that doctor invites, to run the doctor's own chamber. When patient information is entered into the app, the doctor is the controller of that data — they decide what is collected, who may see it, and how long it is kept. We act as a data processor, handling that information on the doctor's behalf and only to provide the Service.
An assistant can only ever reach a chamber's data because a doctor invited them. The doctor sets which chamber an assistant is assigned to, and whether that assistant may collect fees. The doctor can withdraw that access at any time from the rxIndex app.
If you are a patient and wish to access, correct or delete your information, please contact the doctor or chamber that treated you. They can use rxIndex Assistant and rxIndex to act on your request.
2.Information we collect
a. Assistant account information
The assistant's name and mobile number, the one-time passcode (OTP) used to sign in, the doctor and chamber they are linked to, and whether the doctor has permitted them to collect fees.
b. Patient information entered at the front desk
- Patient name and mobile number
- Age (recorded in years or months) and sex
- Visit type — new, follow-up or report review
- The assigned serial/token number and its status, and whether the visit was flagged urgent
c. Intake vitals
Weight, height, blood pressure, pulse, temperature, chest findings, and any free-text note the assistant adds for the doctor.
d. Fee records
Where the doctor has enabled fee collection: the consultation fee amount for the visit and the method it was taken by (cash, bKash, Nagad or card). This is a record of how a patient paid, not a payment. No transaction is processed through rxIndex Assistant, and we never receive or store card numbers, wallet PINs, account numbers or any other payment credentials.
e. Device and diagnostic information
Device model, operating-system version, app version and basic crash/diagnostic data, used to keep the app stable and secure.
What we do not collect. rxIndex Assistant does not store prescriptions, diagnoses, clinical notes or uploaded test reports — those belong to the doctor's rxIndex app and are outside this Service. We collect only what the front desk needs to run the day.
3.How we use information
We use the information to:
- Run the serial and token board for the doctor's session
- Record patient intake and vitals so the doctor has them at the consultation
- Show the doctor the same live queue inside the rxIndex app
- Record and total the day's consultation fees, where the doctor has enabled that
- Sync data between the assistant's device and our secure servers
- Send the OTP and invitation SMS needed to sign an assistant in
- Provide customer support
- Maintain security, prevent misuse and fix bugs
- Comply with legal obligations
We do not use patient health data for advertising, we do not profile patients, and we do not sell any personal or patient information to anyone.
4.How we share information
We share information only as follows:
- With the doctor who controls the data, and with the assistants that doctor has invited and scoped.
- With service providers who help us run the Service under confidentiality obligations — secure cloud hosting, and an SMS gateway used solely to deliver invitation and OTP messages. They may access data only as needed to perform that service.
- For legal reasons, where required by law, regulation or valid legal process, or to protect the rights, safety and security of users and the public.
We never sell your data, and we do not share patient data with advertisers or data brokers.
5.Data storage & security
We take the security of health data seriously. We use industry-standard measures including encryption of data in transit and at rest, access controls, and secure managed hosting.
Access is scoped rather than shared: an assistant sees only the doctor who invited them, and — where the doctor has assigned them to a specific chamber — only that chamber's queue. An assistant assigned to one chamber cannot add to or read another chamber's serial.
The app is offline-first: data is written to the assistant's device first so the desk keeps working during load-shedding or on a weak network, then synced to our servers when a connection is available.
No system is perfectly secure, but we work to protect your information and to limit access to authorised personnel only.
6.Data retention
We retain data for as long as the doctor maintains an active account and as needed to provide the Service or comply with legal obligations. When a doctor closes their account, we delete or anonymise the associated data within a reasonable period, except where retention is required by law. When a doctor revokes an assistant's access, that assistant immediately loses access to all patient data; the doctor's own records are unaffected.
Doctors may request an export or deletion of their data at any time (see section 7).
7.Your rights & choices
Subject to applicable law, doctors (and patients, via their doctor) may:
- Access the information held about them.
- Correct inaccurate information.
- Export their data in a portable format.
- Delete their data, subject to legal retention requirements.
- Withdraw consent for optional processing.
To exercise these rights, contact us at the address in section 11 (doctors and assistants), or contact your doctor or chamber (patients).
8.Children's privacy
rxIndex Assistant is intended for use by doctors and their assistants, not by children. Patient records may include minors — the app records age in months precisely so infants are recorded correctly — but these records are entered and controlled by the doctor as part of medical care. We do not knowingly allow children to create accounts or use the app directly.
9.Third-party services
The Service relies on trusted third parties: secure cloud hosting and an SMS gateway for invitations and login codes. Their use of information is governed by their own privacy policies, and we encourage you to review them.
The app is distributed through Google Play, whose own terms and privacy policy apply to the download and to any diagnostics Google collects.
bKash, Nagad and card networks are not integrated with rxIndex Assistant. Recording that a patient paid by bKash is a note in your own records; it sends nothing to bKash, and bKash sends nothing to us.
10.International data transfers
Your information may be stored or processed on servers located outside Bangladesh by our hosting providers. Where this happens, we take steps to ensure your information receives protection consistent with this policy.
11.Contact us
For any question, request or concern about this Privacy Policy or your data, contact:
12.Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here with a new "Last updated" date and, where appropriate, notify users within the app. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.