Privacy Policy
What we store, where it lives, who can read it, and how to get it back or have it deleted.
Last updated: 5 October 2026
1. Who is responsible
AQcredix (proprietor: Dr S. G. Santhoshkumar) is the data fiduciary for account data, and a data processor acting on your hospital's instructions for the compliance records you enter. Contact: support.aqcredix@gmail.com.
2. What we hold
| Category | What it is | Why |
|---|---|---|
| Account | Name, email, hospital, role, department | To sign you in and attribute records to a person |
| Compliance records | Committees and minutes, recurring obligations, equipment and licences, calibration records, rounds and scores, audits, incidents, findings, documents | The purpose of the platform |
| Uploaded files | Certificates, photographs, scanned documents | Evidence attached to the record it proves |
| Activity | Which features you used and when | To show your own progress, and to know which parts of the product are used |
| Preferences | Pinned page, chosen department, notification settings | So the platform opens where you left it |
| Payment | Plan, amount, date, your UPI reference number | To grant and verify access |
| Class interest | Your email address and your yes/no answer to the question on the home page | To count each person once, and to tell you if we run the classes you said you wanted. Nothing else — see below |
The class-interest question
The one-question poll on the home page stores your email address and your answer, and nothing else. We use it for two things only: to make sure one person is counted once, and to write to you if those classes actually happen. It is never used for other marketing, never published, never sold, and no visitor can see the results — only we can.
Ask us at support.aqcredix@gmail.com and we will delete your answer. You do not have to give a reason.
What we deliberately do not hold
Patient identifiers. The incident reporting module has no field for a patient name, number or identifier, in the form or in the database. The printed form has ruled blanks completed in pen and kept by the hospital. The care-bundle audit asks for a bed number only, and tells the nurse not to enter a name or UHID. This is a deliberate design decision and we will not reverse it.
Card details. We never see or store card or bank credentials. Payment is made through UPI and Razorpay; we hold only the reference number you give us.
3. Where it lives
Data is held in Supabase (PostgreSQL and object storage) in the ap-south-1 (Mumbai) region, and the site is served by Vercel. Email, when enabled, is sent through Resend.
Your data is stored in India. Supabase hosts this project in its Mumbai region
(ap-south-1), so hospital records do not leave the country. Vercel serves the
site from a global network, which caches static page files worldwide, but no hospital data
passes through it — the workspace reads and writes directly to the Indian database.
Email is the one exception, and we would rather say so than let you find out. Resend does not operate an Indian region, so we have chosen Ireland (eu-west-1) — the strongest data-protection regime of the options available to us. When we send you a weekly summary or a renewal notice, that message is processed in the European Union before it reaches your inbox.
What that email contains is the whole of what leaves the country: your name and address, your hospital's name, and counts of what is outstanding — for example "4 overdue, 2 due soon, 1 open finding in Biomedical". It never carries a patient identifier, because we do not hold one. Your records themselves stay in the Mumbai database; only the summary travels. If you would rather nothing at all left India, open the notifications bell and clear "Email me a weekly summary" — we then send you nothing, and none of this applies to you.
4. Who can read it
- Your colleagues, within your hospital only. Every table is scoped to your organisation by database-level row security, not by what the screen chooses to show. Another hospital cannot read your records.
- Uploaded files are private. They sit in a private bucket under a folder named for your organisation, and the storage layer itself checks that folder. Links are signed and expire two minutes after being requested.
- Your learning history is yours alone. Quiz results, certificates and activity are readable only by you — not by a colleague, and not by a hospital administrator.
- We can access your data as operators of the platform, for support and maintenance. We do so only when necessary, and we do not read hospital records out of curiosity.
- We do not sell data, and we do not advertise.
5. How long we keep it
| Data | Kept for |
|---|---|
| Compliance records | As long as the account is active, and at least 90 days after a subscription ends |
| Account details | Until you ask us to delete them |
| Payment records | As long as tax law requires (8 years) |
6. Your rights
Under the Digital Personal Data Protection Act 2023 you may:
- Get a copy. Export everything from the workspace, any time, without asking us — Excel and JSON. After a subscription has lapsed, write to us and we send the export instead.
- Correct it. Most records are editable in the app; write to us for anything that is not.
- Have it deleted. Ask, and we will delete your account and your hospital's records, other than what tax law requires us to retain.
- Complain. To us first, and then to the Data Protection Board of India if we have not resolved it.
We will respond within 90 days.
7. Security
- All traffic is encrypted in transit (HTTPS).
- Access is enforced at the database, not only in the browser, so it cannot be bypassed by manipulating a page.
- Uploaded files are private and reachable only through short-lived signed links.
- Passwords are hashed by our authentication provider; we never see them.
Honestly stated: no system is perfectly secure. If a breach affects your data we will tell you and the Data Protection Board without undue delay, and tell you what we know rather than waiting until we know everything.
8. Cookies
We use browser storage to keep you signed in and to remember your theme, pinned page and chosen department. We do not use advertising or third-party tracking cookies.
9. Children
AQcredix is for healthcare professionals and is not intended for anyone under 18.
10. Changes
We will post changes here and update the date above. Material changes will be notified in the workspace or by email.
11. Contact
support.aqcredix@gmail.com · Thoraipakkam, Chennai, Tamil Nadu, India