MedPrax Report + MedPrax Capture
Privacy Notice
Effective 4 September 2026
Clinicians and clinics decide what patient information to place in MedPrax and must have a lawful basis and any required consent or authority. MedPrax processes that information to provide the requested workflow.
1. Information we handle
- Account and professional information: Firebase account identifier, name, email, email-verification state, phone, qualifications, clinic or organisation, address and verification information you provide.
- Clinical workflow information: patient reference or identifier, initials or name, age, gender, contact, procedure, findings, diagnosis or impression, follow-up details, clinical images or videos, annotations, report versions, signatures and sharing state.
- Billing information: plan, expiry, currency, amount and Razorpay order or payment identifiers. MedPrax does not receive or store your full card details.
- Technical and security information: session, device/browser, request, error and security-event information needed to authenticate, operate and protect the Services. Capture also keeps selected captures and a retry queue on your device.
2. Why we process it
We use information to authenticate a common MedPrax Account; bind captures to the intended case; synchronise, display and export clinical media; create, sign, amend, share and retrieve reports; manage usage limits and payments; verify professional profiles; provide support; prevent abuse; maintain backups; diagnose failures; and comply with applicable obligations.
3. Where information comes from
Information comes from you, authorised people using your workspace, the device used for Capture, authentication and payment providers, and actions performed within the Services. MedPrax does not purchase patient data.
4. When information is shared
We disclose information only as needed to operate the Services, on your instruction, or when lawfully required. Current service categories include Firebase authentication and cloud storage, Google Cloud hosting, MongoDB database hosting, Razorpay payment processing and email delivery. A report is disclosed to a recipient only when an authorised user exports it or creates a sharing link. We do not sell personal or clinical information or use it for advertising.
5. International processing
MedPrax's primary Google Cloud application hosting and clinical-media storage are currently configured in India, and support personnel may access information from India when authorised and necessary. Database and other service-provider locations depend on the configured deployment and must be confirmed for each customer before clinical use. Providers may also process limited information in countries identified in their current subprocessor notices. Before entering information subject to Australian or institutional residency restrictions, the clinic must confirm and approve the configured locations and contractual safeguards. MedPrax will provide available deployment, subprocessor and security information for that review.
6. Browser drafts, retention and backups
Report stores an unfinished draft—including entered clinical fields and locally selected report images—in that browser's local storage (draft metadata in localStorage and image bytes in IndexedDB) until successful report creation, the eight-hour draft expiry, or the browser storage is cleared. Capture stores selected captures locally first and may retain retry metadata on the device. We retain account, clinical, security and billing records while needed to provide the Services, meet legal or clinical-record obligations, resolve disputes and prevent fraud. Backups and audit records may persist for a limited period after the primary record changes. Ask support about the retention applicable to your workspace. Do not treat MedPrax as your only legally required clinical archive.
7. Security
We use authenticated access, case and workspace ownership checks, private object paths, limited-duration handoffs and sharing controls, and operational backups. No system is risk-free. Protect signed-in devices, sign out of shared equipment, use strong authentication and report a suspected incident promptly.
8. Your choices and rights
Depending on applicable law and your role, you may ask to access, correct or erase account information, withdraw consent for optional processing, obtain information about processing, or raise a grievance. Patient requests may need to be handled through the clinician or clinic that created the record. Send requests to support@medprax.in; we may verify identity and authority before acting. Some information may be retained where law, patient safety, billing, security or record-integrity duties require it.
9. Children and patient records
The account service is not offered directly to children. Clinicians are responsible for the lawful handling of a child’s clinical information and for obtaining verifiable parental or guardian authorisation where required.
10. Changes and contact
We will update the effective date when this notice materially changes. For privacy questions, rights requests or grievances, email support@medprax.in with “Privacy” in the subject.
11. Australian clinical use
Australian health information is sensitive information. The clinician or clinic must provide any required collection notice, establish an appropriate authority for collection, use and disclosure, and comply with applicable Commonwealth and state or territory health-record laws. Australian individuals may request access or correction and make a privacy complaint using the contact above; they may also contact the Office of the Australian Information Commissioner. MedPrax does not currently connect to My Health Record and is not currently listed on the Australian Register of Conformity. A portable FHIR export is not a My Health Record integration or conformance claim.