Sooprapps HMS Logo

Sooprapps HMS

Privacy Policy

Your Privacy Matters to Us

At Sooprapps HMS, we are committed to protecting the privacy of healthcare providers, their staff, and their patients. This policy outlines how we handle B2B data securely.

Last updated: May 18, 2026

1. Information We Collect

As a Hospital Management Software (SaaS) provider, Sooprapps HMS collects information necessary to provide services to our hospital clients (B2B).

Account & Hospital Information

  • Hospital name, registration details, and administrative contact information.
  • Admin names, emails, and phone numbers.
  • Billing and subscription payment information.

Patient Data (Processed on Behalf of Hospitals)

  • Medical records, appointments, prescriptions, and billing info entered by the hospital staff.
  • We act solely as a data processor for patient information. The hospital remains the data controller.

2. How We Use Your Information

  • To provision and manage your SaaS workspace and multi-tenant environment.
  • To process subscription billing and issue invoices.
  • To provide technical support, maintenance, and platform updates.
  • To monitor infrastructure performance and prevent fraud.
  • We never use patient health data for marketing or analytics purposes.

3. How We Share Your Information

We strictly limit data sharing. We only share information with:

  • Cloud Infrastructure Partners: E.g., AWS, for secure hosting of the SaaS platform.
  • Payment Gateways: To process your SaaS subscription payments securely.
  • Legal Requirements: When compelled by law, regulation, or legal process.

4. Data Security & HIPAA Compliance

Security is our top priority. We implement enterprise-grade protections for all healthcare data.

  • End-to-end AES-256 encryption for data at rest and TLS for data in transit.
  • Strict role-based access control (RBAC) and data isolation between hospital tenants.
  • Regular third-party security audits and penetration testing.
  • Execution of Business Associate Agreements (BAAs) with eligible healthcare entities to ensure HIPAA compliance.

5. Data Retention

  • Hospital account data is retained as long as the subscription is active.
  • If a subscription is canceled, patient data can be exported by the hospital. All data is then securely permanently deleted within 90 days.

6. Contact Us

If you have questions about this policy or need to execute a BAA, please contact our privacy officer:

  • Email: privacy@sooprapps.com
  • Address: 3/Alampat Business Centre, Near Cycle Circle, Krushi Nagar, Nashik 422001