Privacy Policy.
We process data with extreme care, ensuring full transparency, user control, and compliance with healthcare guidelines.
NexEagle ("we," "our," or "us") is dedicated to protecting your privacy. This Privacy Policy details the policies, pipelines, and practices we use to secure personal profile datasets and clinical records processed across our primary healthcare systems (1HMS, 1Rad) and product engineering collaborations.
Information We Collect.
Information You Provide
When you use our services, contact us, or create an account, we collect personal information such as your name, email address, phone number, company name, professional credentials, and any other details you choose to provide.
Automatically Collected Information
We automatically collect certain information about your device and browser, including IP addresses, operating system types, browser configurations, referring URLs, and telemetry regarding your interaction with our services via cookies and web beacons.
Healthcare Data & PHI
For our core clinical products (such as 1HMS and 1Rad PACS), we process protected health information (PHI) strictly as a business associate in full alignment with HIPAA regulations, NABH guidelines, and local healthcare privacy legislation. This data is segregated and shielded with enterprise-grade encryption.
How We Use Information.
Service Provision
We process your information to deliver, support, and optimize our medical management systems, process transactions, and handle customer service tickets.
Administrative Communication
We use your contact coordinates to transmit technical alerts, security warnings, deployment schedules, and administrative notifications related to your active workspaces.
Aggregated Analytics
We analyze system metrics to diagnose bottlenecks, design updates, and measure overall usability. All performance analytics are processed using strictly anonymized and aggregated datasets.
Regulatory Compliance
We process personal data where required to satisfy tax laws, cooperate with statutory authorities, enforce agreements, or protect the safety and security of patients and clinicians.
Data Security.
Encryption & Hardening
We enforce end-to-end data encryption using TLS 1.3 for data in transit and AES-256 for data at rest. Access to production environments is limited via role-based access control (RBAC), multi-factor authentication, and strict virtual private cloud (VPC) segregation.
Industry Standards
Our software infrastructure is engineered to adhere to HIPAA, GDPR, ISO 27001, and SOC 2 Type II controls. We conduct external vulnerability assessments and code audits on a regular annual schedule.
Incident Management
In the event of a verified security incident or potential breach of data integrity, we will notify affected administrators and regulatory bodies within 72 hours, taking immediate remediation steps to isolate the vector.
Data Sharing & Disclosure.
Sub-processors & Vendors
We share necessary information only with vetted third-party vendors (such as AWS cloud hosting services). All vendors are subject to rigorous Business Associate Agreements (BAAs) and confidentiality constraints.
Corporate Transactions
If NexEagle is involved in a corporate restructuring, merger, or asset sale, clinical and user information may be transferred. We will provide prominent notice on this page before data transfers occur.
No Commercial Selling
We do not sell, lease, rent, or trade your personal information or patient databases to third parties for marketing or profiling purposes.
Your Rights.
Access & Portability
You hold the right to request a structured export of the personal information we process. Healthcare data can be extracted in standard HL7 and FHIR structures to prevent vendor lock-in.
Correction & Deletion
You can request corrections to inaccurate personal records or request deletion of data files, subject to statutory records-retention requirements imposed by medical councils or tax authorities.
Access
Request a copy of the personal profile information we store.
Correction
Request changes to outdated or inaccurate information.
Deletion
Request erasure of accounts, subject to records retention laws.
FHIR Export
Extract clinical data in standard interoperable formats.
Data Retention.
Retention Timeline
We retain account profile details for as long as your organization maintains an active contract. Patient clinical histories are preserved in accordance with institutional guidelines and statutory medical storage laws.
International Data Transfers.
Cross-Border Protocols
Your information is primarily stored on secured servers located within India. In cases where cross-border transfers are necessary, we implement standard contractual clauses to guarantee equal protection.
Children's Privacy.
Age Thresholds
Our enterprise services are not intended for individuals under 18. If a parent or guardian discovers that a minor has submitted personal profile details, contact us and we will delete the data immediately.
Changes to This Policy.
Amendments
We may revise this policy to reflect regulatory changes. We will notify you of modifications by publishing the new terms on this page and updating the modification date above.
Contact Us.
If you have questions about this Privacy Policy, want to report a vulnerability, or wish to exercise data rights, reach our compliance team:
HIPAA & NABH Notice: For regulatory audits, business associate agreement (BAA) coordination, or reporting privacy concerns under clinical compliance directives, contact our designated Data Protection Officer at privacy@nexeagle.com.