1. Scope
This policy covers this Everchart website and the founding-network application form. The registered data controller — to be published before general availability
It does not cover a hospital's live Everchart deployment. In a deployment, the hospital is the controller of its clinical data and Everchart processes that data under a separate written agreement.
2. No patient data is requested here
We do not ask for, and you must not submit, patient records, clinical details or any personal health information through this website. Every clinical value shown in the preview is synthetic.
3. What we collect
- Application details: organisation name and type, country and city, facility and bed counts, modules of interest, rollout timeline, current system, an optional description of your priority problem, and your name, job title, work email and phone number.
- Messages you send us: whatever you choose to include when you contact us.
- Technical request data: our hosting provider processes standard server logs, such as IP address, timestamp, requested page, referrer and user agent, to deliver and protect the service.
4. Cookies and tracking
This site does not set advertising or analytics cookies, does not run third-party tracking pixels, and does not build advertising profiles. Photography is delivered by a third-party image network, which receives the network request needed to deliver each image.
5. Why we use it
- to evaluate your application and respond to you;
- to plan and scope a potential pilot with your organisation;
- to keep a governed, auditable record of onboarding decisions;
- to keep the service secure, available and free from abuse;
- to meet legal and record-keeping obligations.
We rely on your consent for the application you choose to submit, and on our legitimate interest in operating and securing the service. We do not sell your information.
6. Where it is stored
Application submissions are stored in an encrypted database hosted in an India region, with encryption in transit and at rest. The database has no public endpoint. If that private queue is unavailable when you submit, the site tells you that nothing was stored rather than accepting your details silently.
7. Who can access it
Access is limited to authorised reviewers on a least-privilege basis. Intake and review use separate database identities, reviewers cannot rewrite an application's identity or contact details, and status decisions are recorded with the reviewer, timestamp and reason.
8. Service providers
We use a small number of specialist providers to run Everchart. They are listed here by category and data location. We do not publish the specific platforms, products or infrastructure details, because a public inventory of our stack helps an attacker and helps no applicant.
The named provider list, the data-flow description and our security controls are shared with your team under a data-processing agreement before any pilot, so your procurement and information-security reviewers can assess them in full.
9. How long we keep it
We keep application records while your organisation is under consideration and afterwards only as long as needed for our legitimate business and legal record-keeping. When a record is no longer needed, it is deleted or anonymised. Governance evidence about a decision may be retained after the underlying contact details are removed.
10. Your rights
Subject to applicable law, including India's Digital Personal Data Protection Act 2023, you can ask us to confirm what we hold about you, correct it, delete it, or withdraw a consent you previously gave. You may also raise a grievance with us and, where available, with the relevant authority.
Send requests through our contact page. We will verify your identity before acting so that we do not disclose information to the wrong person.
11. Grievance officer
The named grievance officer — to be published before general availability
12. Security
We use encryption in transit and at rest, isolated database roles, forced row-level access rules, private network placement for the database, secret management outside the application, and audit records for privileged actions. No system is perfectly secure, so if you believe you have found a vulnerability, please report it through the contact page before disclosing it publicly.
13. Children
This site is intended for healthcare professionals and organisational representatives. It is not directed at children, and we do not knowingly collect their information here.
14. Changes
We will update this policy as the product and our infrastructure develop. The effective date at the top of this page shows the current version. Material changes will be reflected here before they take effect.