Privacy Policy
The short version. Your hospital owns the patient records it enters; we hold them on your behalf and never use them for anything but running the service for you. We do not sell data, we do not advertise, and we do not share records with another hospital under any circumstances.
Who controls what
True-Doctor is hospital management software sold to healthcare facilities. Two different relationships run through it, and they are worth separating because your rights differ between them.
- Your hospital is the controller of the patient and clinical data it enters. It decides what is collected, why, and for how long. We are its processor, acting on its instructions.
- We are the controller of the account itself — the hospital’s subscription, its staff logins and the billing relationship between us.
Data your hospital holds
Hospitals use True-Doctor to record patients, appointments, visits, vitals, diagnoses, prescriptions, lab and radiology results, dispensing, admissions, invoices and payments. That information belongs to the hospital that entered it and is kept strictly separate from every other hospital on the platform.
We do not read it, mine it, train anything on it, or use it to build features. Our staff access it only when your hospital asks us to help with a specific problem, and that access is logged like any other.
Staff accounts
For each member of staff we store the name, email address, role and activity needed to run the login and the audit trail. Accounts are invite-based with a forced password change on first sign-in. Passwords are stored only as a hash and cannot be recovered by us or by anybody else.
If a member of staff chooses “keep me signed in”, their browser is given a long-lived token that identifies that one session on that one device. Signing out invalidates it everywhere.
Visitors to this website
These public pages set no third-party advertising or analytics cookies, and load no tracking scripts. Three cookies of our own may be set:
- A session cookie, needed to protect forms against cross-site request forgery.
- A currency preference, if you use the switch in the footer, so the site remembers how you want prices shown.
- A visitor cookie, kept for 30 days, holding a random identifier. It lets us see which advertisement or link brought a visitor, which of our pages they opened, and whether they went on to start a trial — so we know which of our adverts are worth paying for.
With that identifier we record, on our own servers: the pages opened and when; the campaign details and click identifier in the link you followed (for example from a Google advert); the website that referred you; the type of device, browser and operating system; and the country your connection appears to be in. We do not store your IP address — only a one-way keyed fingerprint of it that cannot be turned back into the address. None of this is shared with anybody, except that when a visit leads to a sign-up or a payment, the advert’s click identifier is reported back to Google so it can tell which advert worked. Records of visits that did not lead to a sign-up are deleted after about thirteen months.
To decide which currency to quote in before you have chosen, the site looks at the country your network connection appears to be in — from a header your network provider or our content delivery network supplies, and otherwise from your browser’s language setting. You can override it with the switch in the footer.
Our servers keep ordinary web logs — IP address, page, time — for security and troubleshooting, and discard them on a rolling basis.
How data is protected
- Every record carries its hospital and is filtered at the database layer, not by a condition somebody has to remember to write.
- Sensitive fields — card numbers, bank details and protected clinical data — are encrypted at rest.
- Access is role-based: each role sees only the records and fields its job needs.
- Changes to patient and visit records are logged with who made them and when, and every workflow keeps an append-only status history. Read access is not currently logged.
- Credentials and third-party keys live only in server configuration, never in the code.
See the security page for the detail, including what we do not claim.
Who else touches it
Running the service needs a small number of suppliers: a hosting provider, an email delivery service for notifications, and a payment provider for subscriptions and for patient payments taken online. Each receives only what it needs to do its job — a payment provider sees an amount and a reference, not a clinical record. We do not share hospital data with anybody else.
Retention, export and erasure
Your hospital decides how long to keep its records, subject to whatever its own regulator requires. You can export your data at any time, including after a subscription lapses. If you close your account and ask us to erase what remains, we will — and we will tell you when it is done, including from backups as those rotate out.
If you are a patient
Your records belong to the hospital that treated you, not to us. To see, correct or ask about anything held about you, contact that hospital directly — they can act on it immediately, and we cannot act on it without them.
Changes and contact
If this policy changes in a way that affects how hospital data is handled, we will tell account administrators rather than quietly editing the page.
Questions about this policy? Email hello@true-doctor.online.