Home About
HealNTrack VaidSetu Bizcare All Products
Healthcare Solutions Software Development Manufacturing ERP IT Consulting
Contact
Mode
Color theme
Contact Us WhatsApp

Healthcare Product Privacy Notice

How Galant processes personal data through HealNTrack, VaidSetu and related healthcare modules when acting as a processor for customer organisations.

Effective date: July 28, 2026  |  Last updated: July 28, 2026

1. Read this notice with your organisation’s notice

HealNTrack and VaidSetu are generally provided to hospitals, clinics, healthcare professionals and other organisations. The customer organisation normally decides why patient, staff and operational information is processed and therefore acts as the Data Fiduciary or Controller. Galant normally processes that information on the customer’s documented instructions as its Data Processor or Processor.

The customer’s privacy notice, consent process, medical-record policy and professional obligations apply to its use of the product. This notice explains Galant’s product role and baseline practices. Where Galant provides a direct-to-individual feature and determines the purpose of processing, Galant will provide an additional feature-specific notice.

See also the Corporate Website Privacy Policy for galantit.com inquiries and recruitment.

2. Information that may be processed

Depending on product configuration and authorised use, the product may process:

  • patient identifiers, contact details, age, sex and demographic information;
  • appointments, encounters, complaints, symptoms and histories;
  • clinical notes, observations, allergies, diagnoses, procedures and care plans;
  • prescriptions, medication details, investigation orders and results;
  • imaging or uploaded clinical documents;
  • billing, insurance and payment-related records;
  • healthcare-professional, staff and role information;
  • user credentials, authentication events, permissions and audit trails;
  • device, IP, security, error, performance and diagnostic logs;
  • voice input, audio segments, transcripts and extracted structured information where voice features are enabled; and
  • AI prompts, context, generated drafts, safety flags and user corrections where AI features are enabled.

The exact data set is defined in the customer order form, implementation record or processing schedule.

3. Purposes

Galant may process customer-controlled information only to:

  • provide, host, configure and support the contracted product;
  • authenticate users and enforce permissions;
  • transmit and display records to authorised users;
  • perform customer-enabled transcription, summarisation, structuring or workflow-support functions;
  • investigate errors, security incidents and misuse;
  • maintain backups, audit trails and service continuity;
  • comply with documented customer instructions and applicable law; and
  • perform other activities expressly described in the customer agreement.

Galant will not repurpose customer-controlled clinical data for unrelated advertising.

4. AI, model improvement and training

Unless a separate written agreement expressly states otherwise and the processing is legally permitted:

  • Galant will not use identifiable patient data or customer clinical data to train or fine-tune a shared or general-purpose model;
  • Galant will not permit a model or infrastructure provider to use customer content for its own model training;
  • prompts, transcripts and outputs will be retained only for the approved operational, audit, security or customer-support period; and
  • production data access for support or testing will require authorisation, logging and least-privilege controls.

5. Voice and transcription

Where voice features are enabled, the user interface and deployment documentation must state whether audio is processed locally, in Galant infrastructure or by a subprocessor; when recording begins; retention periods; hosting region; and how users review or correct transcripts. Transcription errors can occur. No product page should state that audio is deleted immediately unless deletion has been verified across temporary files, queues, logs, provider systems and backups.

6. Clinical responsibility and human review

AI-generated or automatically extracted content is a draft or support output. Authorised healthcare professionals remain responsible for reviewing patient identity, clinical accuracy, medication details, contraindications, dosage, allergies, investigations, diagnosis, treatment and follow-up before use.

The product must not be used as the sole basis for emergency, diagnosis, prescribing, treatment or discharge decisions unless that use has been specifically validated, approved and licensed where required.

See also the AI & Medical Use Disclaimer for short-form notices, academic and evaluation use on this website, and safety reporting.

7. Disclosure and subprocessors

Galant may use approved subprocessors for cloud hosting, processing, speech recognition, model inference, communications, support, monitoring, backup and security under appropriate confidentiality, security and data-processing terms. A current subprocessor list is provided to customers under contract. No production vendor may receive patient or clinical data merely because it is convenient for development.

8. Security

Depending on the deployment, measures may include encryption in transit and at rest, role-based access, administrative MFA, tenant separation, audit logs, monitoring, backups, vulnerability management and incident-response procedures. Security is a shared responsibility. Customers must configure users, roles, endpoints, integrations and local procedures appropriately.

9. Data location and international transfers

The hosting region and subprocessors for each deployment are identified in the order form or deployment documentation. Cross-border processing occurs only as authorised by contract and applicable law. Where HIPAA applies, an executed Business Associate Agreement is required before Galant handles PHI as a business associate.

10. Retention, export and deletion

Customer-controlled information is retained according to the customer agreement, documented instructions and applicable healthcare-record requirements. Galant does not promise immediate deletion where backups, incident evidence or law require controlled retention.

11. Individual rights

Patients and product users should normally submit access, correction, deletion, consent or grievance requests to the hospital, clinic, employer or organisation controlling the account. Galant will assist the customer as required by the agreement and law.

12. Children

Healthcare customers may process children’s information for lawful healthcare purposes with the involvement of parents, guardians or other authorised persons as required by applicable law and the customer’s policies.

13. Incidents

Galant maintains an incident-response process. Customers must promptly report suspected unauthorised access or disclosure. Galant will notify customers and authorities according to the contract and applicable law.

14. Deployment documentation

Hosting provider, region, subprocessors, voice/AI retention, export formats and deletion timelines for each production environment are documented in the customer order form, deployment facts sheet and Data Processing Addendum — not on this public summary page.

15. Contact

Privacy email: privacy@galantit.com
Support: info@galantit.com