PRACTICE121 PVT LTD
12. Purpose and Scope
12.1 PRACTICE121 PVT LTD (Practice121, we, us, our) is committed to protecting the privacy, confidentiality, and security of Personal Data and Health Data entrusted to us.
12.2 This Privacy Policy governs the collection, processing, storage, disclosure, and protection of data acquired through our software platform, mobile applications, websites, and clinical workflow tools (including AI ambient scribing, Electronic Patient Records, telehealth, e-prescriptions, and community networks).
12.3 This Policy applies to healthcare practitioners, clinic administrators, locum professionals, and patients accessing our portal or services. It forms an integral, legally binding part of our Terms and Conditions.
13. Legislative Framework
13.1 We process personal and health data in strict compliance with applicable laws of Sri Lanka, including:
- Personal Data Protection Act, No. 9 of 2022 (and the Personal Data Protection (Amendment) Act, No. 22 of 2025);
- Directives and guidelines issued by the Data Protection Authority of Sri Lanka (DPA);
- Applicable Sri Lanka Medical Council (SLMC) and Private Health Services Regulatory Council (PHSRC) guidelines regarding medical records and professional secrecy.
13.2 Where mandatory statutory provisions conflict with this Policy, applicable Sri Lankan statutory requirements prevail.
14. Definitions
- Personal Data: Any information that can directly or indirectly identify a natural person, as defined under the Personal Data Protection Act.
- Special Categories of Personal Data / Health Data: Personal data relating to physical or mental health, medical history, diagnosis, treatment, prescriptions, genetic/biometric data, or health status.
- Data Subject: An identified or identifiable natural person (patient or practitioner) to whom the personal data relates.
- Controller: The healthcare practitioner or medical center that determines the purpose and means of processing patient health records.
- Processor: Practice121 PVT LTD, processing data on behalf of the Controller.
15. Information We Collect
15.1 Practitioner & Account Data: Full name, date of birth, NIC number, SLMC registration details, qualifications, practice addresses, telephone number, email address, e-signature, and MFA credentials.
15.2 Patient Data & Clinical Records: Demographic details, contact info, clinical consultation transcripts, EPR notes, medical history, e-prescriptions, lab orders, and referral letters uploaded or generated on the platform.
15.3 Ambient Audio Data: Consultation audio captured live via the AI scribe strictly for transcription.
15.4 Technical & Usage Information: Device identifiers, IP addresses, application logs, geolocation mapping for practice locations, and audit trails.
15.5 Billing & Financial Information: Bank details and payment transaction data processed via secure payment gateways.
16. Purpose of Data Collection and Processing
We process data strictly for explicit, lawful, and specified clinical and administrative purposes:
- Delivering ambient AI scribing, EPR, e-prescription, and telehealth functionalities;
- Verifying doctor credentials, SLMC status, and awarding Verification Badges;
- Establishing unique Practice IDs and federated Location IDs linked with PHSRC registrations;
- Facilitating the doctor community, locum bookings, umbrella referral systems, and pharmacy/lab links;
- Generating aggregate, non-identifiable statistical analytics for medical education and epidemiological tracking of disease outbreaks;
- Meeting legal, regulatory, and audit obligations under Sri Lankan law.
17. AI Model Governance & Data Minimization
17.1 NO Model Training on Patient Data: Patient Health Data, clinical transcripts, consultation audio, and EPR notes are NEVER used to train, retrain, fine-tune, or validate public, global, or commercial artificial intelligence models.
17.2 All audio streams are pseudonymized and encrypted in transit. Audio data is processed in temporary memory solely to yield structured text notes and is automatically purged upon completion.
18. Legal Basis for Processing
We process data on the following bases under Schedule I and II of the Personal Data Protection Act:
- Explicit consent from the data subject (or parent/guardian in the case of a minor);
- Performance of a service contract with the practitioner or practice;
- Medical diagnosis, care, treatment, and management of healthcare services by licensed professionals;
- Compliance with legal and statutory duties imposed by Sri Lankan law.
19. Data Disclosure and Third Parties
19.1 We do not sell, rent, or trade Personal Data or Health Data.
19.2 Information may be shared strictly under secure, confidential parameters with:
- Preferred laboratories and pharmacies selected by the practitioner ("My Labs" / "My Pharmacy") for order/prescription fulfillment;
- Authorized locum network practices where a shift booking is accepted;
- Cloud infrastructure providers bound by statutory processor contracts pursuant to Section 21 of the PDPA;
- Law enforcement, regulatory bodies, or courts when required by written Sri Lankan law.
20. Rights of Data Subjects
In accordance with Part II of the Personal Data Protection Act, No. 9 of 2022 (as amended):
- Right of Access: You may request access to and confirmation of personal data held about you.
- Right to Rectification: You may request correction of inaccurate or incomplete personal data.
- Right to Erasure / Deletion: You may request erasure of your data, subject to medical record retention laws and statutory legal requirements.
- Right to Withdraw Consent: You may withdraw consent at any time without affecting prior lawful processing.
- Response Timeline: We will respond to requests within one (1) month of receipt, extendable by up to two (2) additional months for complex cases with prior notice. Requests are processed free of charge except where permitted by DPA rules.
- Appeals: You have the right to appeal any decision to the Data Protection Authority of Sri Lanka.
21. Data Breach Response & Security Safeguards
21.1 We implement robust administrative, technical, and physical safeguards, including AES-256 encryption at rest, TLS 1.3 encryption in transit, strict Role-Based Access Controls (RBAC), and immutable audit logs.
21.2 In the event of a confirmed or suspected personal data breach, Practice121 will execute its Data Breach Incident Response Plan and notify the Data Protection Authority of Sri Lanka and affected data subjects as required under Section 23 of the PDPA.
22. Direct Marketing & Communication
22.1 We may send administrative notifications, security alerts, and system update messages.
22.2 Marketing communications regarding new feature releases or educational offerings require opt-in consent. You may opt out at any time using the opt-out mechanism provided. Health Information is never used for commercial marketing.
23. App Store & Platform Disclosures (Google Play Store & Apple App Store)
- Permissions Required: Microphone access (for real-time ambient scribe), Location access (for practice mapping/geo-location), and Storage access (for uploading credential documents/e-signatures).
- Account & Data Deletion: Users may request full account and personal data deletion via the in-app settings or by contacting info@practice121.com, subject to health record retention mandates.
24. Contact Information
For privacy queries, exercising data rights, or contacting our Data Protection Officer (DPO):
Data Protection Officer
PRACTICE121 PVT LTD
Email: info@practice121.com
Website: www.practice121.com