HealthEase now runs whole hospitals, not just the front desk. Read more →

Legal

Product Privacy Policy

Effective 25 July 2026 · Last updated 26 July 2026

1. Who we are and what this Policy covers

HealthEase is clinic and hospital management software provided by Vanta (Private) Limited ("Vanta", "we", "us"), a company incorporated in Pakistan.

This Policy explains how personal data — including patient health data — is handled inside the HealthEase product (the hosted service and the HealthEase Windows, Android, and iOS applications, together the "Service").

This Policy does not cover the HealthEase marketing website at healthease.app. Visitor and lead data collected on the marketing website is covered by the separate Website Privacy Policy, for which Vanta is the data controller.

Contact for general questions about this Policy: info@healthease.app. Questions about data protection — including any request you would direct to a data-protection officer — should be sent to wecare@healthease.app, and we will route them to the person responsible for privacy at Vanta.


2. The most important thing to understand: who controls your data

HealthEase is used by healthcare providers — clinics, hospitals, and their staff (each a "Customer"). Roles under data-protection law are split as follows:

Data Controller (decides why and how data is used) Processor (acts on the controller's instructions)
Patient and clinical data entered into the Service The Customer (your clinic or hospital) Vanta
Customer staff account data inside the Service The Customer Vanta
Customer account, billing, and subscription data Vanta (as controller)
Marketing website visitor/lead data Vanta (as controller, under the separate Website Privacy Policy)

If you are a patient: your healthcare provider — not Vanta — decides what data about you is collected and why. Vanta stores and processes that data only on your provider's instructions, under a binding Data Processing Agreement ("DPA"). Requests about your data should go to your healthcare provider first (see the explanation of your rights as a patient below); Vanta assists the provider in responding.


3. What data the Service processes

Acting as processor for the Customer, the Service processes:

  • Patient identity and demographic data — name, date of birth, gender, national identity number (e.g., CNIC), contact details, address, guardian/next-of-kin relation, medical record (MR) number.
  • Clinical data — visit records, diagnoses, prescriptions, vitals, nursing charts, lab notes, clinical documents, and linked pharmacy dispensing records where the Customer uses those modules.
  • Consent records — the patient consent captured by the Customer in the Service (see the description of consent captured in the Service below).
  • Operational data — appointment/queue tokens, room assignments, visit timestamps.
  • Billing records of the Customer's practice — receipts, invoices, payment records the Customer creates (the Service does not store patient payment-card or bank credentials).
  • Customer staff data — staff profiles, roles and permissions, attendance and roster records where the Customer uses those modules, and activity/audit logs of actions taken in the Service.

Acting as controller for its own purposes, Vanta processes: Customer administrator contact details, subscription and billing status, payment and transaction data relating to the Customer's subscription (see below), and aggregate service-usage metrics. Vanta bills Customers in Pakistani Rupees (PKR) unless the Customer's agreement states otherwise; payment may be made by invoice and bank transfer or online through the payment methods offered at checkout. The free trial requires no payment card.

Payment and transaction data. Where a Customer pays online by card (for example, debit or credit card), the payment is processed by United Bank Limited ("UBL"), a licensed commercial bank in Pakistan engaged by Vanta as its payment processor and acquiring bank. UBL collects the payment-card details directly through the UBL payment gateway and handles them under its own PCI-DSS-compliant terms and privacy policy; Vanta does not receive or store full payment-card numbers. Vanta receives and retains only limited billing and transaction data — such as the amount, currency, date, payment-method type, masked card digits, and the transaction status and reference — which it uses to record the payment, issue receipts, process any refund, and meet its accounting and tax obligations. Patient data is never used for Vanta's own marketing or advertising, and is never sold.


Processing Purpose Legal basis (typical)
Patient/clinical data in the Service Delivering the record-keeping, scheduling, queue, billing, and related functions the Customer has configured The Customer's instructions under the DPA; the Customer is responsible for its own lawful basis (typically provision of care, legal record-keeping duties, and/or patient consent under the law applicable to it)
Cross-border storage of patient data (explained below under international transfers) Hosting the Service in the selected hosting region Recorded patient consent captured by the Customer (the OFFSHORE_PROCESSING consent scope described below) plus contractual safeguards in the DPA
Optional AI features Only where separately agreed in advance in writing with the Customer and, where the feature touches identified patient data, only with recorded patient consent (AI_PROCESSING scope). AI features are not included in the free trial. Consent + contract
Security, audit logging, backups Protecting the Service and its data; meeting the DPA's security commitments Legitimate interests / legal and contractual obligations
Customer account and billing data (including the payment and transaction data described above) Operating the subscription, invoicing, processing online payments and refunds, support Contract with the Customer; legal obligations (accounting and tax record-keeping)

5. How the data is protected

Vanta takes technical and organisational measures that it considers reasonable and appropriate to protect personal data in the Service. No product, security control, or method of transmission or storage can be guaranteed to be completely secure, and Vanta does not warrant or guarantee that the Service will be uninterrupted, error-free, or immune from unauthorised access; see the disclaimers and limitation of liability set out later in this Policy. In plain terms, the measures we apply, and continue to roll out, include:

  • Encryption. Data is encrypted in transit (TLS) and at rest. Patient-identifying and clinical fields are designed to be additionally protected by field-level encryption using per-Customer encryption keys, so that one Customer's data is not readable with another Customer's keys.
  • Access control. Every user has a unique login. Access is role-based and deny-by-default: staff see only what their role in the Customer's organisation permits. Vanta personnel have no standing access to production patient data; emergency ("break-glass") access is designed to be exceptional, time-limited, and logged.
  • Tenant isolation. Each Customer's data is logically isolated; isolation is enforced server-side on every request.
  • Audit logging. The Service is designed to record actions in an audit log so that it is possible to establish who accessed or changed what, and when.
  • Backups and recovery. Encrypted backups are maintained with tested restore procedures.
  • Security program. We align our security program with recognised industry security practices. Vanta is not currently certified against any specific security standard; we can share our current certification status on request to info@healthease.app.

6. Where the data is hosted

  • Hosting is provided by a reputable third-party cloud hosting provider, engaged as a sub-processor under appropriate data-protection safeguards (see the description of our sub-processors below).
  • The primary data region is Asia-Pacific (Singapore).
  • The hosting region is Customer-selectable from the regions Vanta offers for the Service.
  • Patient data is not stored in India or the Middle East. This is a standing platform rule, not merely a default.
  • Disaster-recovery copies, where enabled, are encrypted and held only in regions consistent with the rule above; the Customer's DPA records the applicable regions.

7. International transfers

Because Customers and patients may be located in a different country from the hosting region, storing data in the Service is typically an international data transfer. Safeguards:

  1. Contractual — the DPA between the Customer and Vanta names the hosting region(s), restricts processing to the Customer's documented instructions, and imposes the security measures summarised above under how the data is protected. Where the law applicable to the Customer requires a specific transfer mechanism (e.g., EU/UK standard contractual clauses or an equivalent), the parties incorporate it via the DPA.
  2. Technical — encryption in transit and at rest, field-level encryption under keys controlled by Vanta in the hosting region.
  3. Recorded patient consent — where the Customer relies on consent for cross-border storage, the Service captures it as a distinct, recorded consent scope (OFFSHORE_PROCESSING), including the notice version shown, the recording method, and who recorded it. Consent can be refused or withdrawn; refusal does not prevent the patient from receiving care (the provider maintains alternative record-keeping arrangements).

The Service records patient consent as separate, purpose-specific scopes — consent to one purpose is never bundled into another:

Scope What it authorises
CARE_RECORD Creation and maintenance of the patient's care record in the Service
OFFSHORE_PROCESSING Storage/processing of the record in the hosting region outside the patient's country
AI_PROCESSING Use of optional AI features on the patient's identified record (only where the Customer has separately agreed AI in advance in writing with Vanta)
DATA_SHARING_RESEARCH Any de-identified research/benchmarking sharing (off by default; never a condition of care)
MR_HISTORY Cross-provider medical-record history access, where offered

Each consent record stores its status, notice version, method, and recording user. Withdrawal is recorded as a new entry — consent history is append-only.


9. How long data is kept

Retention is set by the Customer within the Service, subject to platform defaults and legal minimum floors that vary by record type and jurisdiction. Indicative platform defaults (the Customer's DPA records its chosen schedule; the Customer may extend, never shorten below legal floors):

Data Default retention
Clinical records (adult) 12 years from last visit/discharge
Clinical records (minor) Until age 21 plus 3 years
Patient demographics As long as any linked clinical record is retained
Financial records (receipts, sales) 7 years
Pharmacy dispensing/batch records 5 years (longer where controlled-substance rules require)
Audit logs 12 years (retained to evidence access to records over their retention life; extended where a longer clinical retention applies, such as minors' records)
Consent records Duration of the data they authorise, plus 3 years
Data of a Customer that terminates 60-day export window, then deletion with a deletion certificate

When retention ends, data is deleted by an automated disposal process; deletion extends into backups through destruction of the relevant encryption keys ("crypto-shredding").


10. Your rights as a patient (data subject)

Depending on the law that applies to you (for example the EU GDPR, UK GDPR, Singapore PDPA, or similar laws elsewhere), you may have rights to:

  • Access — obtain a copy of your record (the Service can produce a readable PDF and a machine-readable export);
  • Rectification / correction — have inaccurate data corrected (clinical records are corrected by append-and-supersede, preserving the medico-legal history);
  • Erasure / deletion — have data deleted where no legal retention duty requires keeping it (clinical records within a legally required retention period cannot be erased early; you will receive a documented explanation);
  • Portability — receive your record in a structured, machine-readable format;
  • Objection / restriction and withdrawal of consent — for processing based on consent (such as offshore storage or AI features), withdraw at any time without affecting your care;
  • An accounting of disclosures — where this capability is enabled, a list of exports and disclosures of your record, compiled from the audit log.

How to exercise them: contact your healthcare provider — they are the controller of your record and the Service gives them the tools to respond. Under the DPA, Vanta assists the provider (target: acknowledgement within 72 hours, fulfilment within 30 days). If you cannot reach your provider, or your request concerns Vanta itself, contact wecare@healthease.app and we will route the request to the correct controller and assist. You may also have the right to complain to the data-protection authority in your jurisdiction.


11. Sub-processors

Vanta uses a small set of sub-processors, each bound by contract to data-protection obligations no less protective than the Customer's DPA. They fall into the following categories:

  • Cloud hosting provider — hosting, storage, and compute for the Service; primary region Asia-Pacific (Singapore), operating under appropriate data-protection safeguards.
  • Email/SMS delivery provider — account and notification messages (message content is minimised; no clinical data in message bodies).
  • Error monitoring / analytics tooling — service reliability (no patient-identifying data).
  • Payment processor — United Bank Limited (UBL), Pakistan — where the Customer pays its subscription online, UBL handles the payment as payment processor and acquiring bank (online card payment processing / card acquiring), including the payment-card details, which it processes under its own PCI-DSS-compliant terms; Vanta shares with UBL only the data needed to take the payment or process a refund, as described above under payment and transaction data. No patient data is involved in subscription billing or payment processing.

The current, versioned sub-processor list — including the legal names and regions of each sub-processor — is available at healthease.app/legal and on request from info@healthease.app, and is recorded in the Customer's DPA. Customers receive advance notice of sub-processor changes with an objection window, per the DPA.


12. Data breach handling

Vanta operates a documented incident-response and breach-notification process. If a breach affecting personal data is confirmed, Vanta notifies affected Customer-controllers without undue delay and within 72 hours of confirmation, with the information they need to meet their own legal duties (what happened, data categories, affected individuals, measures taken, and recommended patient communication). Regulator notifications are made where the applicable law requires.


13. Children's data

The Service processes minors' health data only as patient records controlled by the Customer. Consent for minors is recorded via a guardian, with the guardian relationship recorded. The Service is not directed at children as users.


14. Customer responsibilities

Data protection in the Service is a shared responsibility. As controller of the patient, clinical, and staff data it enters into the Service, the Customer (the healthcare provider) is solely responsible for, and Vanta does not undertake or warrant, the following — each of which sits with the Customer under the DPA:

  • Lawful basis and consent. Establishing and maintaining a valid lawful basis for its processing (including provision of care, legal record-keeping duties, and/or patient consent as applicable), and obtaining, recording, and honouring any patient consent required — including consent for offshore storage (OFFSHORE_PROCESSING) and, where enabled, AI features (AI_PROCESSING).
  • Accuracy of data. The accuracy, quality, completeness, and legality of the data the Customer and its staff enter into the Service.
  • Clinical decisions. All clinical, diagnostic, prescribing, and treatment decisions. The Service is a record-keeping and workflow tool; it does not provide medical advice and is not a substitute for the professional judgement of a qualified healthcare professional (see the disclaimers and limitation of liability below).
  • User and credential management. Issuing unique logins per staff member, prohibiting credential sharing, applying appropriate device and screen-lock controls, and promptly deactivating departed or unauthorised users through the Service.
  • Configuration and legal compliance. Configuring the Service (including retention schedules, roles and permissions, and enabled modules) in line with the laws, professional obligations, and regulatory requirements that apply to the Customer, and using the Service in compliance with those laws.

Customer indemnity. To the maximum extent permitted by applicable law, the Customer shall indemnify and hold Vanta harmless against any claims, losses, liabilities, damages, fines, penalties, and reasonable costs (including legal fees) arising out of or in connection with the Customer's breach of these responsibilities, its breach of the DPA or the Subscription Agreement, its instructions to Vanta, or its (or its users') unlawful, negligent, or unauthorised use of the Service. The detailed indemnity terms are set out in the Subscription Agreement, which prevails in the event of any conflict.


15. Disclaimers and limitation of liability

No medical advice; not a medical device. The Service is clinic and hospital management and record-keeping software. It is not a medical device, does not perform diagnosis, and does not provide medical, clinical, or professional advice. Any optional AI feature (where separately agreed in advance in writing) produces assistive, non-authoritative output that must be independently reviewed by a qualified healthcare professional before any reliance. Vanta is not responsible for clinical decisions taken by the Customer or its staff.

"As is" / "as available". To the maximum extent permitted by applicable law, the Service is provided "as is" and "as available", and Vanta disclaims all warranties, conditions, and representations of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, satisfactory quality, fitness for a particular purpose, non-infringement, accuracy, and uninterrupted or error-free operation. Vanta does not warrant or guarantee any particular uptime, availability, or level of performance except as, and only to the extent, expressly stated in a written service-level commitment in the Subscription Agreement.

Third-party services and force majeure. The Service depends on third-party services (including the hosting, connectivity, messaging, and payment providers identified in the sub-processor list in this Policy). To the maximum extent permitted by applicable law, Vanta is not liable for any unavailability, delay, loss, or damage caused by such third parties or by events beyond its reasonable control, including internet or telecommunications failures, power outages, cyber-attacks, acts of government, or other events of force majeure.

Limitation of liability. To the maximum extent permitted by applicable law, the aggregate and per-claim liability caps and the exclusions of liability set out in the Subscription Agreement between Vanta and the Customer govern Vanta's liability in connection with the Service and this Policy. Where no such written agreement is in force, then to the maximum extent permitted by applicable law: (a) Vanta shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss of profits, revenue, business, goodwill, anticipated savings, or loss of or damage to data; and (b) Vanta's total aggregate liability arising out of or in connection with the Service and this Policy, from all causes and claims combined, shall not exceed the greater of (i) the fees actually paid by the Customer to Vanta for the Service in the twelve (12) months preceding the event giving rise to the claim, or (ii) the nominal fallback amount stated in the Subscription Agreement (which applies where no fees have been paid, including during a free trial).

Non-excludable liability preserved. Nothing in this Policy or the Subscription Agreement excludes or limits any liability that cannot lawfully be excluded or limited, including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, for gross negligence where it cannot lawfully be excluded, or under non-excludable data-protection or consumer-protection rights. Nothing here limits any right or remedy a data subject has under applicable data-protection law.


16. Changes to this Policy

We may update this Policy from time to time. Material changes are notified to Customers in advance, and where a change materially affects the patient notice, the Service prompts re-capture of consent against the new notice version. The "Last updated" date at the top of this Policy shows when it last changed.


17. Governing law

This Policy and any dispute arising from it are governed by the laws of Pakistan, and the courts of Islamabad have exclusive jurisdiction.


18. Contact

Vanta (Private) Limited — a company incorporated in Pakistan.

Ready when you are

See HealthEase running your clinic — before you decide.

Book a free demo. We'll walk you through the system on a real screen, answer every question, and never rush you.

Book a free demo