📢 🚧 Website Testing চলছে — বর্তমানে সিস্টেমটি পরীক্ষামূলক পর্যায়ে রয়েছে। অনুগ্রহ করে এই সময়ে কোনও Appointment Book করবেন না। Testing সম্পূর্ণ হলে Booking Service চালু করা হবে। ধন্যবাদ। 🙏

Security Policy

📅 Effective Date: 15 August 2026 🔄 Last Updated: 01 August 2026

Welcome to VaidyaSathi. VaidyaSathi is committed to maintaining the confidentiality, integrity, and availability of its Platform and the information entrusted to us by patients, doctors, healthcare providers, employees, and other users.

This Security Policy outlines the measures we take to protect our Platform and the responsibilities of users in maintaining a secure environment.

1. Purpose

The purpose of this Policy is to:

  • Protect user information from unauthorized access, disclosure, alteration, or destruction.
  • Maintain the security and reliability of the Platform.
  • Reduce cybersecurity risks.
  • Promote secure use of the Platform by all users.
  • Support compliance with applicable Indian laws and regulations.

2. Scope

This Policy applies to:

  • Patients
  • Doctors
  • Clinics and Hospitals
  • Employees and Administrators
  • Vendors and Service Providers
  • Visitors using the VaidyaSathi website

3. Security Measures

VaidyaSathi implements reasonable administrative, technical, and organizational security controls, which may include:

  • Encrypted communication using HTTPS/TLS.
  • Role-based access controls (RBAC).
  • Secure authentication and password protection.
  • Session management and automatic logout where appropriate.
  • Firewall and network protection.
  • Server monitoring and logging.
  • Malware detection and prevention measures.
  • Regular software updates and security patches.
  • Periodic security reviews and vulnerability assessments.
  • Secure backup and disaster recovery procedures.

While we take reasonable measures to protect the Platform, no system connected to the internet can be guaranteed to be completely secure.

4. User Responsibilities

Users are responsible for:

  • Keeping login credentials confidential.
  • Using strong and unique passwords.
  • Not sharing account credentials with others.
  • Logging out after using shared or public devices.
  • Keeping their contact information up to date.
  • Promptly reporting any suspected unauthorized access or security incident.

Users must not attempt to bypass or interfere with the security of the Platform.

5. Prohibited Security Activities

The following activities are strictly prohibited:

  • Unauthorized access to accounts or systems.
  • Attempting to bypass authentication or authorization controls.
  • Uploading malware, ransomware, viruses, or malicious code.
  • Conducting denial-of-service (DoS/DDoS) attacks.
  • Exploiting security vulnerabilities without authorization.
  • Intercepting or monitoring communications unlawfully.
  • Using bots, scripts, or automated tools to disrupt Platform operations.
  • Attempting to gain access to databases, servers, or confidential information without permission.

Violations may result in suspension of access and may be reported to the appropriate authorities.

6. Data Protection

Personal information is protected in accordance with the VaidyaSathi Privacy Policy and Data Protection Policy. Access to personal data is limited to authorized personnel who require it for legitimate operational purposes.

7. Third-Party Services

VaidyaSathi may use trusted third-party service providers, including payment gateway providers, cloud hosting providers, SMS and email service providers, and analytics providers. While we select providers carefully, each provider is responsible for the security of its own systems and services.

8. Security Incident Reporting

If you discover or suspect a security issue affecting the Platform, please notify us as soon as possible. When reporting an issue, include, where possible:

  • A description of the issue.
  • The affected page or feature.
  • Date and time observed.
  • Any supporting screenshots or logs.

Please do not publicly disclose security vulnerabilities until VaidyaSathi has had a reasonable opportunity to investigate and address them.

9. Security Updates

To help maintain Platform security, VaidyaSathi may install software updates, apply security patches, upgrade infrastructure, or temporarily suspend services for maintenance when necessary. Such actions may occur without prior notice where immediate security measures are required.

10. Business Continuity

VaidyaSathi maintains reasonable backup and recovery procedures designed to help restore essential services in the event of system failures, cyber incidents, or other operational disruptions.

11. Limitation of Liability

While VaidyaSathi implements reasonable safeguards, users acknowledge that no online service can guarantee absolute security. To the maximum extent permitted by law, VaidyaSathi shall not be liable for losses arising from circumstances beyond its reasonable control, including sophisticated cyberattacks, internet outages, third-party service failures, or user negligence.

12. Changes to This Policy

VaidyaSathi may revise this Security Policy from time to time. The latest version will always be available on the Platform with the updated effective date. Continued use of the Platform after such changes constitutes acceptance of the revised Policy.

13. Contact Us

For security-related questions or to report a suspected security issue, please contact:

VaidyaSathi Security Team
📧 Security Email: security@vaidyasathi.in
📧 Support Email: support@vaidyasathi.in
🌐 Website: https://vaidyasathi.in

14. Governing Law

This Security Policy shall be governed by and interpreted in accordance with the laws of the Republic of India. Any disputes arising under this Policy shall be subject to the jurisdiction of the competent courts having jurisdiction over the registered office of VaidyaSathi.

By using the VaidyaSathi Platform, you acknowledge that you have read, understood, and agreed to this Security Policy.