Skip to privacy policy

HD MEDICAL GROUP

HDSteth – Privacy Policy

How we collect, use, and protect your information across the HDSteth application, device, website, and related services.

OUR COMMITMENT

Your privacy matters.

We respect your privacy and are committed to protecting the personal and health-related information collected through HDSteth.

Contact us about privacy
HDSTETH PRIVACY POLICY

HDMedical Services (India) Private Limited ("HDMedical", "we", "our", or "us") respects your privacy and is committed to protecting the personal and health-related information collected through the HDSteth application, device, website, and related services (collectively, the "Services").

This Privacy Policy explains how we collect, use, store, protect, and disclose information when you use HDSteth.

By using HDSteth, you acknowledge that you have read and understood this Privacy Policy.

1. About HDSteth

HDSteth is a digital medical device solution designed to work with the HDSteth hardware device and application to support the recording, processing, visualization, storage, and management of physiological data such as heart sounds and related measurements.

HDSteth may allow authorized users to:

  • Connect the application to an HDSteth device.
  • Record physiological/auscultation data.
  • View recorded data and measurements.
  • Generate and view reports.
  • Store and manage authorized patient records.
  • Transfer relevant information to authorized cloud services.
  • Access information through authorized accounts and systems.

2. Information We Collect

Depending on how you use HDSteth, we may collect the following categories of information.

2.1 Account Information

When an account is created or used, we may collect:

  • Name
  • Email address
  • Phone number
  • User ID
  • Login credentials or authentication information
  • Organization or professional information, where applicable

2.2 Patient Information

When HDSteth is used to record or manage patient information, authorized users may enter information such as:

  • Patient name
  • Patient ID
  • Age/date of birth
  • Gender, where required
  • Other information entered by the authorized user
  • Clinical or examination-related information

Users should only enter patient information when they have the appropriate authorization to do so.

2.3 Medical and Device Data

Depending on the features being used, HDSteth may process:

  • Heart sound/auscultation recordings
  • ECG or other physiological measurements, where applicable
  • Measurement results
  • Examination records
  • Generated reports
  • Device-generated data
  • Recording timestamps
  • Device status and diagnostic information

This information may constitute health or medical information and is handled with appropriate security controls.

2.4 Device and Technical Information

We may collect technical information required to operate and maintain the application, including:

  • Device model
  • Operating system and version
  • Application version
  • HDSteth device information
  • Bluetooth connection information
  • Connection status
  • Error and diagnostic information
  • Crash information
  • IP address and related technical information, where applicable

3. Bluetooth and Device Permissions

HDSteth may require Bluetooth/Bluetooth Low Energy (BLE) access to communicate with the HDSteth hardware device.

Depending on your operating system and application functionality, HDSteth may request permissions such as:

  • Bluetooth
  • Nearby devices
  • Storage/files, where required for reports
  • Notifications, where applicable
  • Camera or microphone, only where a specific feature requires it

We use these permissions only for the functionality described by the application.

HDSteth does not use device permissions for purposes unrelated to the application's functionality.

4. How We Use Your Information

We may use collected information to:

  • Provide and operate HDSteth.
  • Establish and manage user accounts.
  • Connect the application to the HDSteth device.
  • Record and process physiological data.
  • Generate reports and measurements.
  • Store and retrieve authorized patient records.
  • Provide authorized cloud-based services.
  • Maintain and improve application functionality.
  • Detect, investigating, and resolve technical problems.
  • Maintain application and device security.
  • Respond to customer support requests.
  • Comply with applicable laws, regulations, and legal requirements.
  • Prevent unauthorized access, misuse, fraud, or security incidents.

We will not use medical or patient information for unrelated purposes without an appropriate legal basis or authorization.

5. Cloud Storage and Data Processing

Depending on the HDSteth configuration and services used by your organization, information may be securely transmitted to our authorized cloud infrastructure for storage, processing, report management, or authorized access.

Cloud-based information may include:

  • User account information
  • Patient information
  • Medical/physiological recordings
  • Reports
  • Device-related information
  • Application and system information

Access to stored information is restricted through appropriate authentication and authorization controls.

Only authorized users or personnel with a legitimate business or service-related requirement should have access to protected information.

6. Data Security

We take reasonable technical and organizational measures to protect information from:

  • Unauthorized access
  • Unauthorized disclosure
  • Accidental loss
  • Alteration
  • Destruction
  • Misuse

Security measures may include:

  • Authentication and access controls
  • Role-based access where applicable
  • Secure communication protocols
  • Encryption where applicable
  • Cloud security controls
  • Monitoring and logging
  • Security testing and vulnerability management
  • Regular maintenance and security updates

However, no electronic transmission or storage system can be guaranteed to be completely secure.

7. Sharing and Disclosure of Information

We do not sell personal information or patient medical information.

We may disclose information only when reasonably necessary for purposes such as:

Authorized Users

Information may be made available to users authorized by the relevant organization, healthcare provider, administrator, or account owner.

Service Providers

We may use trusted third-party service providers for services such as:

  • Cloud hosting
  • Authentication
  • Infrastructure management
  • Application maintenance
  • Security services
  • Technical support

Such providers may process information only as necessary to provide the relevant services and subject to applicable contractual and security requirements.

Legal Requirements

We may disclose information where required or permitted by applicable law, regulation, court order, legal process, or governmental authority.

Security and Protection

We may disclose information when reasonably necessary to detect, prevent, or investigate fraud, security incidents, misuse, or threats to our services or users.

8. Third-Party Services

HDSteth may use third-party infrastructure or services to support application functionality, authentication, cloud storage, analytics, crash reporting, or other technical services.

Third-party services may process certain technical or account information according to their own privacy policies and applicable agreements.

We recommend reviewing the privacy practices of relevant third-party service providers where applicable.

Third-party services used by HDSteth:

[Add actual services here, e.g., Google Cloud, Firebase, analytics/crash-reporting services, etc.]

9. Data Retention

We retain information only for as long as reasonably necessary to:

  • Provide the Services;
  • Maintain user and patient records;
  • Meet contractual requirements;
  • Fulfill legitimate business purposes;
  • Comply with legal and regulatory obligations;
  • Resolve disputes; and
  • Enforce our agreements.

The retention period may vary depending on the type of information and the purpose for which it was collected.

Organizations using HDSteth may have their own data retention policies for patient information.

10. Data Deletion

Where applicable, users may request deletion of their personal information or account information.

Requests involving patient or medical information may be subject to applicable legal, regulatory, contractual, or medical-record retention requirements.

To request deletion or inquire about your information, please contact us using the details provided in the Contact Us section below.

11. Your Privacy Rights

Depending on your location and applicable law, you may have rights regarding your personal information, including:

  • Right to access your personal information
  • Right to request correction of inaccurate information
  • Right to request deletion, where legally permitted
  • Right to request information about how your data is processed
  • Right to withdraw consent where processing is based on consent
  • Right to raise a privacy complaint

Requests may be subject to identity verification and applicable legal requirements.

12. Children's Privacy

HDSteth is not intended for children to use independently without appropriate authorization and supervision.

We do not knowingly collect personal information from children in violation of applicable law.

If you believe that information belonging to a child has been collected improperly, please contact us so that we can investigate and take appropriate action.

13. International Data Transfers

Depending on the infrastructure and services used to operate HDSteth, information may be processed or stored in countries other than the country in which the user is located.

Where applicable, we take reasonable steps to ensure that such processing is conducted in accordance with applicable privacy and data protection requirements.

14. Cookies and Website Technologies

Our website may use cookies or similar technologies for purposes such as:

  • Website functionality
  • Security
  • Performance monitoring
  • Understanding website usage
  • Improving our services

You may be able to control cookies through your browser settings.

15. Medical Information Disclaimer

HDSteth is designed to support authorized healthcare and medical-device workflows.

Information generated or displayed by HDSteth should be used according to the intended use, instructions for use, and applicable documentation of the product.

HDSteth should not be used outside its intended purpose or as a substitute for professional medical judgment where professional evaluation is required.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in:

  • Our Services
  • Technology
  • Data-processing practices
  • Applicable laws and regulations
  • Security requirements

When we make material changes, we may update the "Last Updated" date at the top of this Privacy Policy.

We encourage users to periodically review this page.

17. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or the processing of your personal information, please contact us:

HDMedical Services (India) Private Limited

Address
[To be provided]
Phone
[To be provided]

18. Privacy Policy for HDSteth Mobile Application

This Privacy Policy applies to the HDSteth mobile application and related services provided by HDMedical Services (India) Private Limited.

By downloading, installing, accessing, or using HDSteth, you agree to the practices described in this Privacy Policy.

HDMedical Services (India) Private LimitedBack to top