1. Introduction & Privacy Commitment
Kiara Health AI ("we", "us", "our") recognizes the vital importance of privacy, data protection, and confidentiality in healthcare environments. This Privacy Policy details our operational protocols regarding the collection, processing, storage, and protection of information when physicians, healthcare professionals, and users access our website and clinical decision support system.
Under the executive direction of Dr. Satyam Bhavsar, Kiara Health AI is engineered around a zero-trust, privacy-by-design framework. We prioritize absolute user data isolation, end-to-end encryption, and complete transparency.
2. Protected Health Information (PHI) & Zero-Storage Architecture
As a clinical decision support system designed for outpatient clinical consultation aid, Kiara Health AI handles data inputs with extreme stringency:
- Transient Query Memory Processing: Symptomatology inputs, vital sign entries, and diagnostic query strings submitted by physicians during active consultations are processed strictly in volatile, transient cloud memory. Once the diagnostic response or SOAP note is rendered to the user's browser, transient query data is automatically flushed from server RAM.
- No Permanent Storage of Patient Identifiers: Kiara Health AI does not store identifiable patient attributes such as full names, social security numbers, residential addresses, or government identification numbers. Clinicians are explicitly instructed to utilize anonymized patient age, biological sex, and clinical history parameters when querying the platform.
- Zero Sale of Health Data: We strictly pledge that no patient clinical data, physician consultation log, or user browsing history is ever sold, rented, leased, or transferred to third-party data aggregators, pharmaceutical companies, or marketing brokers.
3. Data Collection Matrix & Technical Processing Boundaries
| Information Category | Specific Data Elements Processed | Primary Purpose & Processing Boundary |
|---|---|---|
| Account & Auth Credentials | Physician name, medical council registration ID, email address, password hash. | User authentication, clinic letterhead personalization, and secure session validation. |
| Transient Consultation Inputs | Anonymized age, biological sex, vital signs, chief complaints, proposed drugs. | Real-time differential diagnosis ranking, DDI safety checks, and SOAP note generation. Flushed immediately from RAM. |
| Server Telemetry & Logs | IP address, user-agent string, timestamped latency, HTTP request header. | DDoS prevention, network threat detection, and server latency optimization. Retained for 30 days. |
| Local Web Storage | UI theme state (dark/light), custom clinic logo header format. | Browser client-side persistence for user preference convenience. |
4. Data Encryption & Security Standards
Kiara Health AI implements industry-leading cryptographic and technical safeguards to protect all data transmissions against unauthorized interception or access:
- Transport Layer Security (TLS 1.3): All data exchanged between the user's browser and our server infrastructure is encrypted using modern TLS 1.3 protocols with strict HTTP Strict Transport Security (HSTS) preloading.
- AES-256 Storage Encryption: Account configurations and saved clinic templates in database storage are encrypted at rest using Advanced Encryption Standard with 256-bit keys (AES-256).
- Role-Based Access Control (RBAC): Access to server infrastructure is restricted exclusively to authorized systems engineers under multi-factor authentication (MFA) and audit logging.
5. Statutory Compliance: HIPAA, GDPR, CCPA & DPDP Act
Kiara Health AI is structured to align with major international healthcare and data protection regulations:
- HIPAA Compliance Alignment (United States): By maintaining a non-PHI architecture that flushes transient clinical query data, Kiara Health AI supports covered entities in maintaining HIPAA security rule compliance.
- GDPR Compliance (European Union / UK): Users possess complete rights to access, rectify, export, or permanently erase their personal account information upon request.
- DPDP Act Compliance (India): We strictly adhere to data minimisation principles and explicit consent frameworks outlined in India's Digital Personal Data Protection legislation.
6. Privacy Contact & Data Protection Officer
Users exercising their statutory data protection rights or seeking clarification regarding our security protocols may contact our Data Protection Officer directly:
Email: privacy@kiarahealthai.com
Attn: Data Privacy Officer, Kiara Health AI Governance Board.