Privacy Policy
This Privacy Policy explains how Dynamic System (“we”, “us”, “our” or “Company”) collects, uses, stores, protects and processes information through Dynamed (“Software”, “Application” or “Platform”).
Dynamed is a healthcare management platform intended for use by pharmacies.
The Software may provide functionality relating to pharmacy management, patient records, prescriptions, billing, ABHA identification, including integration with the Ayushman Bharat Digital Mission (ABDM) where enabled.
By using our Software, you acknowledge that you have read and understood this Privacy Policy.
1. Who We Are
The Software is operated by:
Dynamic SystemRegistered Address: Dighalbank, Dharmanagar, North Tripura
Website: https://dynamed.in/
Email: info@dynamed.in
Telephone: 8837306464
For privacy-related queries, complaints or requests, you may contact us using the details above.
2. Scope of This Privacy Policy
This Privacy Policy applies to information processed through:
- Our pharmacy management software;
- Patient registration and appointment modules;
- Electronic health/medical records;
- Prescription and medication records;
- Billing and transaction records;
- ABHA-related functionality;
- ABDM integrations;
- Our website and related services;
- Other services specifically identified as being covered by this Privacy Policy.
This Privacy Policy applies to information relating to patients, pharmacy staff, administrators and other authorised users.
3. Information We May Process
Depending upon the functionality used by a pharmacy, the Software may process the following categories of information.
3.1 Patient Information
This may include:
- Name;
- Date of birth/age;
- Gender;
- Address;
- Mobile number;
- Email address;
- Emergency contact details;
- Patient identification information;
- ABHA number/ABHA address, where applicable;
- Other information necessary for patient identification.
3.2 Health Information
The Software may process:
- Prescription information;
- Medicine details;
- Batch numbers;
- Expiry dates;
- Quantity and dosage information;
- Dispensing information;
- Purchase and sale information;
- Patient/customer information;
- Doctor/prescriber information.
3.3 Hospital and Clinical Information
The Software may process:
3.4 User Account Information
For authorised users, we may process:
- Username;
- Password credentials in protected form;
- Mobile number;
- Email address;
- User role;
- Professional/facility information;
- Login and security information.
4. ABHA and ABDM Integration
Where ABDM functionality is enabled, the Software may interact with ABDM services in accordance with applicable ABDM standards, policies and technical requirements.
The Software may support functionality such as:
- ABHA creation or verification;
- ABHA/ABHA address linking;
- Health record discovery;
- Health information exchange;
- Health information retrieval;
- Health information sharing;
- Consent-related workflows;
The exact ABDM functionality available will depend upon the modules enabled for the healthcare establishment.
ABDM health-information exchange is designed around consent and controlled access to health information. ABDM's public information states that health records may be accessed through appropriate/informed consent and that individuals can manage consents.
We do not represent that merely creating or linking an ABHA automatically gives us unrestricted access to a person's health records.
5. Consent for Health Information Exchange
Where health information is exchanged through ABDM or another consent-based mechanism, the Software will use the applicable consent workflow.
Depending on the particular ABDM transaction, consent may specify matters such as:
- The health information requested;
- The purpose of access;
- The requesting entity;
- The period or duration of access;
- The relevant patient;
- The applicable health facility or healthcare provider.
Health information will not be accessed through an ABDM consent-based mechanism merely because an individual has an ABHA.
Where required, the patient or authorised person must provide appropriate consent before health information is accessed or shared.
The consent mechanism used by the Software may be subject to ABDM technical specifications and may change when ABDM updates its standards or workflows.
6. How We Use Information
We may process information for purposes including:
- Providing healthcare-management functionality;
- Creating and maintaining patient records;
- Managing prescriptions and medicines;
- Managing pharmacy transactions;
- Managing appointments;
- Generating bills and invoices;
- Identifying patients;
- Supporting ABHA-related functionality;
- Facilitating authorised ABDM transactions;
- Facilitating health-information exchange based on applicable consent;
- Providing technical support;
- Maintaining system security;
- Preventing fraud, misuse and unauthorised access;
- Maintaining audit logs;
- Improving the Software;
- Complying with applicable laws and regulations;
- Responding to lawful requests from competent authorities;
- Performing other purposes disclosed to the relevant user at the time of collection.
We will not intentionally use health information for unrelated purposes without an appropriate lawful basis or consent where required.
7. Purpose Limitation
Information collected through the Software will be used for specified and legitimate purposes.
We will seek to avoid collecting information that is unnecessary for the intended service.
Health information obtained through an ABDM consent-based transaction will be handled in accordance with the applicable purpose and consent parameters.
8. Information Sharing
We may share information only where reasonably necessary and permitted under applicable law or where appropriate consent/authorisation exists.
Information may be shared with:
- Authorised pharmacy personnel;
- Authorised hospital personnel;
- Patients or their authorised representatives;
- ABDM services and network participants as applicable;
- Service providers supporting hosting, infrastructure, security or maintenance;
- Government authorities where legally required;
- Other entities where the patient/user has provided appropriate consent or where otherwise permitted by applicable law.
We do not sell patient health information as a commercial product.
9. ABDM and Third-Party Services
Our Software may communicate with external systems, including ABDM services, in order to provide enabled functionality.
The processing of information by such external systems may also be governed by the privacy policies, terms and technical rules applicable to those systems.
ABDM is operated under the National Health Authority (NHA), and ABDM maintains its own policies, including its Health Data Management Policy and Data Privacy Policy.
10. Security Measures
We take reasonable technical and organisational measures designed to protect information against:
- Unauthorised access;
- Unauthorised disclosure;
- Loss;
- Destruction;
- Alteration;
- Misuse;
- Other reasonably foreseeable security risks.
Depending upon the deployment and services used, security measures may include:
- Access controls;
- User authentication;
- Role-based permissions;
- Password protection;
- Encryption where appropriate;
- Secure communication protocols;
- Backup procedures;
- Audit logging;
- Monitoring;
- Security updates;
- Restricted administrative access.
No electronic system can be guaranteed to be completely secure. Therefore, while we take reasonable security measures, we cannot guarantee absolute security.
11. Role-Based Access
Access to patient and health information should be limited according to the role and responsibilities of authorised users.
For example, pharmacy personnel may have access to pharmacy-related information, while clinical personnel may have access to information required for providing healthcare services.
Healthcare establishments are responsible for appropriately configuring user accounts, permissions and access rights within their deployment.
12. Audit Logs
The Software may maintain logs relating to activities such as:
- User login;
- Patient record access;
- Record creation or modification;
- Health-information access;
- ABDM transactions;
- Consent-related transactions;
- Administrative activities;
- Security events.
Audit information may be retained for security, operational, regulatory and dispute-resolution purposes, subject to applicable retention requirements.
13. Data Retention
We retain information for as long as reasonably necessary to:
- Provide the services;
- Maintain healthcare records;
- Meet contractual obligations;
- Meet legal and regulatory requirements;
- Resolve disputes;
- Maintain security and audit records;
- Protect legitimate business interests.
Different categories of information may have different retention periods.
Where the healthcare establishment is the primary controller/data fiduciary of patient information, retention may also be determined by that healthcare establishment's legal and professional obligations.
14. Data Accuracy
Users and healthcare establishments should ensure that information entered into the Software is accurate and up to date.
Patients may request correction of inaccurate information through the relevant healthcare establishment or through the mechanism provided by us, as applicable.
15. Patient Requests
Subject to applicable law and the particular role of the healthcare establishment, a patient may request information concerning:
- Personal information held about them;
- Correction of inaccurate information;
- Applicable consent or sharing information;
- Deletion where legally permissible;
- Other rights available under applicable law.
Some records may need to be retained because of legal, medical, accounting, regulatory or other legitimate requirements.
16. Withdrawal of Consent
Where processing is based on consent, the individual may withdraw consent through the applicable mechanism where such withdrawal is legally and technically available.
Withdrawal of consent will not affect processing that was lawfully carried out before withdrawal.
For ABDM health-information transactions, consent withdrawal/revocation may also be handled through the applicable ABDM consent mechanism.
17. Children's Information
Where information relating to a child is processed, the healthcare establishment and other relevant parties must ensure that the required parental/guardian authorisation and other safeguards are followed as required under applicable law.
We do not knowingly encourage children to independently create accounts or provide health information without appropriate authorisation where such authorisation is required.
19. Data Breach and Security Incidents
If we become aware of a security incident involving personal information, we will take reasonable steps to:
- Investigate the incident;
- Contain and mitigate the impact;
- Restore affected services where appropriate;
- Maintain appropriate records;
- Notify affected parties or authorities where required by applicable law or regulatory requirements.
20. Third-Party Service Providers
We may use trusted third-party providers for services such as:
- Cloud hosting;
- Data storage;
- Backup;
- SMS;
- Email;
- Authentication;
- Security;
- Technical support;
- Infrastructure management.
Such providers will be permitted to process information only to the extent necessary for providing their services and subject to appropriate contractual or other safeguards, where applicable.
21. Data Transfers
Where information is stored or processed through third-party infrastructure, appropriate safeguards will be applied in accordance with applicable law.
Where applicable law imposes restrictions on cross-border transfer or processing of personal data, we will comply with those requirements.
22. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in our Software;
- Changes in ABDM requirements;
- Changes in applicable laws;
- Changes in security practices;
- Changes in our services.
The updated version will be published on this page with a revised “Last Updated” date.
23. Governing Law
This Privacy Policy shall be governed by the laws applicable in India.
Any dispute shall be subject to the jurisdiction of the competent courts at [Dharmanagar, Tripura, India], subject to applicable law.
24. Important Notice
This Software is a technology platform. It does not itself provide medical diagnosis or treatment unless a specific service is expressly identified as being provided by a licensed healthcare professional or healthcare establishment.
Healthcare decisions remain the responsibility of the relevant qualified healthcare professional.