Legal
Acceptable Use Policy
This Acceptable Use Policy ("AUP") describes what you may not do with HealthEase, the clinic and hospital management software provided by Vanta (Private) Limited, a company incorporated in Pakistan ("Vanta", "we", "us"). It forms part of, and uses the defined terms of, the HealthEase Subscription Agreement, available at healthease.app/legal. It applies to the Customer and every Authorised User, on every surface of the Service — web, Windows, Android, and iOS.
The point of this policy is simple: HealthEase holds sensitive patient information. Everyone who uses it shares responsibility for keeping that information safe, lawful, and accurate.
1. Lawful Use of Patient Data
Because the Service processes patient health information, you must:
- Have a lawful basis. Only enter, access, or use patient data where you (as the healthcare provider and data controller) have a lawful basis to do so, including any patient or guardian consent required by the laws that apply to you.
- Use data for care and administration only. Access patient records only for legitimate treatment, care-coordination, billing, and administrative purposes connected to your role. Looking up records out of curiosity — including records of family members, colleagues, friends, or public figures — is prohibited ("snooping"), even if your role technically permits access. Access is logged and auditable.
- Respect confidentiality. Do not disclose patient information except as permitted by law and your professional duties. Handle printed outputs (tokens, receipts, prescriptions, reports) with the same care as the digital record.
- Keep records honest. Do not enter data you know to be false, backdate or manipulate records to misrepresent what happened, or attempt to alter or delete audit trails. Corrections must be made through the Service's normal correction features, which preserve history.
- Do not export data beyond need. Use export features only for lawful purposes (patient requests, regulatory inspections, internal operations, migration). Mass extraction of patient data for unrelated purposes — including sale, marketing, or model training — is prohibited.
2. Account and Credential Security
- One person, one login. Every user must have their own account. Sharing logins, passwords, or authentication tokens is prohibited, including "counter" or "shift" accounts used by multiple staff.
- Protect credentials. Keep passwords confidential, use any required multi-factor authentication, and do not write credentials where others can see them.
- Deactivate leavers promptly. The Customer must remove or deactivate access for staff who leave or change roles, promptly and in any event within the period stated in the Data Processing Agreement.
- Secure your devices. Use screen lock, keep operating systems updated, and do not use the Service on devices you know to be compromised. Report lost or stolen devices that held an active session to us without delay.
- Report incidents. If you suspect unauthorised access, credential compromise, or a data leak, notify us immediately at wecare@healthease.app.
3. Prohibited Uses
You may not, and may not permit or help anyone else to:
- use the Service for any purpose that violates applicable law or regulation, or in support of any unlawful activity (including unlicensed medical or pharmacy practice, or unlawful sale of controlled substances);
- upload or transmit content that is unlawful, defamatory, harassing, or that infringes any person's rights (including privacy, publicity, and intellectual-property rights);
- use the Service to store or process data of individuals without a lawful basis, or enter another organisation's data without authority;
- transmit malware, or any code or content designed to disrupt, damage, or gain unauthorised access to any system or data;
- probe, scan, or test the vulnerability of the Service, or breach or circumvent any security or authentication measure, except under a written security-testing authorisation from Vanta;
- access or attempt to access data of another customer (tenant), or any account or record you are not authorised to access — even if a misconfiguration makes it technically possible (report it instead);
- interfere with the integrity or performance of the Service, including flooding, denial-of-service, or abusive automated traffic;
- use scrapers, bots, or automated scripts against the Service except through interfaces and methods we document and approve in writing;
- circumvent module entitlements, usage limits, trial limits, or billing mechanisms — including the free-trial limits set out in the Trial Offer Terms (one trial per organisation; the 100-patients-per-calendar-month trial cap; and the exclusion of AI features unless separately agreed in advance in writing);
- resell, sublicense, rent, lease, or provide the Service to third parties as a service bureau or on a timeshare basis, except as expressly agreed with Vanta in writing;
- use the Service to build, train, or improve a competing product, or perform benchmarking intended for public comparison without our written consent;
- misrepresent your identity or affiliation, or impersonate any person or organisation when using the Service.
4. No Reverse Engineering
Except to the extent a restriction is prohibited by applicable law (and then only to that extent), you may not:
- reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, underlying structure, or algorithms of the Service or its applications;
- copy, modify, translate, or create derivative works of the Service or its applications;
- remove, obscure, or alter any proprietary notices; or
- extract or reuse the Service's software components, schemas, or documentation outside the Service.
5. Security-Research Disclosure
We welcome responsible disclosure of security issues. If you discover a vulnerability, report it to wecare@healthease.app with "Security disclosure" in the subject line, and do not access, modify, or retain data beyond the minimum needed to demonstrate the issue. Do not publicly disclose an issue before we have had a reasonable opportunity to remediate it.
6. Consequences of Violation
- Suspension and termination. Material or repeated breach of this AUP is a material breach of the Subscription Agreement. We may suspend affected accounts or the Customer's Service (in whole or part) under the suspension terms of the Subscription Agreement, and may terminate for uncured material breach under its termination terms. Where practicable we will notify the Customer and work with it to remedy the issue first; where there is risk to patient data, other customers, or the platform, we may suspend immediately.
- Patient-safety posture. Suspension mechanisms are designed so that read access to existing patient records is not hard-locked, except where required by law or security necessity, as described in the Subscription Agreement.
- Individual accounts. We may disable individual Authorised User accounts implicated in a violation, and will inform the Customer's administrator.
- Cooperation with authorities. Unlawful activity may be reported to relevant authorities where we are required or lawfully permitted to do so. Unauthorised access to information systems and data may be a criminal offence in Pakistan (including under the Prevention of Electronic Crimes Act 2016) and in other jurisdictions.
- No fee relief. Suspension for AUP violation does not relieve the Customer of fee obligations, and the Customer remains responsible for its users' violations under the Subscription Agreement's indemnity.
7. No Warranty; Limitation of Liability
- Part of the Subscription Agreement. This AUP forms part of, and is subject to, the Subscription Agreement. It defines restrictions on your use of the Service; it does not expand, and must not be read as expanding, any warranty, service level, or obligation of Vanta beyond what the Subscription Agreement expressly states.
- No warranty. To the maximum extent permitted by applicable law, the Service is provided "as is" and "as available" without warranties, conditions, or representations of any kind, whether express, implied, or statutory (including any implied warranty of merchantability, satisfactory quality, fitness for a particular purpose, non-infringement, uninterrupted or error-free operation, or that the Service is secure or free from vulnerabilities), except only for those warranties, if any, expressly set out in the Subscription Agreement. Vanta takes reasonable technical and organisational measures to protect data but does not warrant or guarantee any particular security outcome, availability level, or result.
- Limitation of liability. To the maximum extent permitted by applicable law, Vanta's liability arising out of or in connection with this AUP, the Service, or your (or your Authorised Users') use or misuse of it is governed by and subject to the limitations and exclusions of liability set out in the Subscription Agreement — including the aggregate and per-claim liability caps and the exclusion of indirect, incidental, special, consequential, and punitive damages and any loss of profit, revenue, data, business, or goodwill. Vanta is not liable for any loss, harm, or regulatory consequence arising from a Customer's or Authorised User's breach of this AUP.
- Customer responsibility and indemnity. The Customer is responsible for its own and its Authorised Users' compliance with this AUP, for its lawful basis and any required consents, for the accuracy of the data it enters, for all clinical decisions, and for its user and credential management. The Customer's indemnity obligations under the Subscription Agreement extend to claims, losses, and liabilities arising from any breach of this AUP by the Customer or its Authorised Users.
- Not a medical device; clinical responsibility. HealthEase is clinic and hospital management software. It is not a medical device, and it does not provide medical, diagnostic, or clinical advice. All clinical judgement, diagnosis, treatment, and patient-care decisions remain the sole responsibility of the Customer and its licensed healthcare professionals.
- Force majeure and third-party services. To the maximum extent permitted by applicable law, Vanta is not liable for any failure or delay caused by events beyond its reasonable control, or for the acts, omissions, availability, or security of third-party services (including cloud hosting infrastructure, connectivity, and communications providers), as further addressed in the Subscription Agreement.
- Non-excludable liability preserved. Nothing in this AUP excludes or limits any liability that cannot lawfully be excluded or limited — including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, for gross negligence where it may not lawfully be excluded, or under any non-excludable statutory data-protection or consumer-protection rights. Where any limitation or exclusion in this AUP or the Subscription Agreement is held unenforceable, it applies to the maximum extent permitted by applicable law.
8. Changes and Contact
We may update this AUP from time to time following the change process described in the Subscription Agreement. The current version, together with the rest of the HealthEase legal terms, is always available at healthease.app/legal.
Questions about this policy: info@healthease.app · Security or privacy reports and support requests: wecare@healthease.app · Website: healthease.app