Medical Disclaimer:MEDAX provides AI-generated guidance. This is not a substitute for professional medical advice, diagnosis, or treatment. If any medical issue or symptom occurs, you must consult a real doctor.

MEDAX

Privacy Policy

Our Privacy Commitment

As a provider of clinic management systems, Medax implements rigorous security practices to preserve patient health confidentiality. We do not sell data, we use enterprise-grade end-to-end transport layer security, and we implement rigorous data protection safeguards.

1. Introduction & Scope

Welcome to MEDAX, a premium clinical management and automated patient recovery platform. We are deeply committed to protecting the privacy and security of clinical providers, administrative staff, and the patient records entrusted to our platform. This Privacy Policy details how we gather, process, encrypt, and store personal and health-related data. By accessing or using MEDAX, you agree to the data management practices outlined in this policy.

1.1 Direct Application

This policy applies directly to all registered medical practitioners (doctors), clinic managers, supporting staff, and administrators who operate accounts on MEDAX.

1.2 Data Processor Relationship

In terms of health data storage, MEDAX acts primarily as a data processor, storing Protected Health Information (PHI) under strict contract-backed security terms on behalf of our licensed providers.

1.3 Medical Disclaimer & AI Guidance Limitation

All clinical suggestions, summaries, patient follow-up scripts, and reports generated by MEDAX are AI-generated guidance. MEDAX is not a medical professional, does not practice medicine, and does not provide clinical diagnoses. If a user or patient experiences any health-related issue or symptom, they must immediately consult a real, licensed doctor. In the event of any medical issue, the user must consult a doctor directly, as AI-generated guidance is not a substitute for professional medical advice, diagnosis, or treatment.

2. Information We Collect

To facilitate clinical operations, web dashboard utilities, and automated mobile patient follow-ups, MEDAX collects specific data sets. We only collect the minimal amount of information required to deliver secure, high-quality healthcare management, tracking, and recovery features across our web and mobile applications.

2.1 Provider Account & Administrative Details

For medical professionals and clinic managers, we collect full names, professional registration details, business email addresses, contact numbers, clinic locations, timezone, language, and system config preferences.

2.2 Patient Clinical & Protected Health Information (PHI)

For patients managed under our platform, we record full names, contact info, date of birth, gender, marital status, blood group, primary language, existing diagnoses, allergies, symptoms, condition severity, clinical notes, prescriptions, laboratory orders/reports, recovery plans, and daily check-ins.

2.3 Patient Lifestyle, Wellness & Mobile App Activity

For mobile app and tracking users, we collect height, weight, activity levels, sleep logs, exercise and activity session logs, daily goals, task completions, medication adherence logs, health coin balances, streak records, notification configurations, and push notification tokens.

2.4 Technical, Device & Session Metadata

We gather technical data to secure and optimize the platform, including IP addresses, browser agents, operating system settings, access timestamps, session logs, failed login counters, and details of actions taken within the system.

3. How We Use Information

We strictly process data to deliver, optimize, and secure MEDAX. We do not sell, rent, or lease clinical or personal information under any circumstances.

3.1 Clinical Automation & Support

Using patient contact information to automatically trigger follow-up reminders, recover health metrics, dispatch prescription copies, and update doctors regarding critical vitals.

3.2 Access Controls & Personalization

Authenticating accounts, enforcing role-based permissions (so nurses can only access assigned files), and adapting timestamps to the user's localized timezone.

3.3 Audit Trails & Performance Tuning

Analyzing log data to detect security anomalies, prevent unauthorized intrusion, run system diagnostics, and maintain internal compliance logging.

4. Data Security & Encryption Charter

Security is the core foundation of MEDAX. We employ enterprise-grade cryptographic standards and strict organizational protocols to safeguard medical records against data breaches or loss.

4.1 Encryption Standards

All data is encrypted in transit using Transport Layer Security (TLS 1.3) and at rest using Advanced Encryption Standard (AES-256) with key rotation schemas.

4.2 Logical Access Restrictions

We enforce strict multi-factor authentication (MFA) parameters and isolate clinic databases logical separation to prevent cross-tenant data leakage.

4.3 Infrastructure & Sub-processor Safeguards

We enter into standard confidentiality and data protection agreements with our infrastructure partners (e.g., cloud hosts, database providers) to guarantee equivalent security baselines.

5. Data Sharing & Disclosures

We do not disclose patient or provider data to third parties except as necessary to provide MEDAX features, fulfill compliance mandates, or with explicit consent.

5.1 Third-Party Sub-Processors

We work with trusted sub-processors for services like hosting, databases, SMS routing, and email notifications. These vendors are legally bound to protect your data and cannot use it for secondary purposes.

5.2 Legal Compliance

If legally required, we may disclose information to law enforcement agencies or regulatory authorities to satisfy subpoenas, court orders, or medical audit requests.

6. Data Retention & Deletion

We store data only for as long as your clinical account remains active or as required by applicable medical record retention laws.

6.1 Clinical Record Obligations

Depending on state or country legislation, clinical notes and patient records must be kept for a minimum duration. We help providers comply by preserving inactive records securely.

6.2 Account Closure

Upon account deletion request, personal identification data is removed or anonymized within 30 days, except where data must be retained for legal defense or auditing.

7. Your Rights & Choices

As a MEDAX user, you hold complete control over your account. Patients registered under your clinic can request records through you as the data controller.

7.1 Data Portability

Export your complete patient database, scheduling reports, and prescription histories in secure CSV or XLSX structures at any point.

7.2 Access & Rectification

Directly modify email addresses, profile configurations, and patient entries to ensure information remains accurate and updated.

8. AI-Generated Insights & Google Play Health Compliance

In compliance with Google Play Store Health App Policies and international data regulations, this section details how our mobile and web applications handle health data, automated AI-generated recommendations, and integration with health services.

8.1 Purpose and Operation of AI-Generated Insights

MEDAX uses artificial intelligence (AI) and machine learning models to analyze patient-logged health metrics (such as daily steps, activity sessions, sleep duration, and vital trends) to generate personalized recovery insights, lifestyle suggestions, and patient follow-up guidelines. These features are designed to help users track progress and assist healthcare providers in monitoring recovery. All AI analyses are conducted on secure, encrypted servers.

8.2 Play Store Health Disclosure & Non-Clinical Limitations

Any insights, tips, or automated summaries generated by the AI are strictly informational and advisory in nature. They do not constitute clinical diagnoses, medical devices, or medical treatment plans. The application does not replace professional medical judgment. Users and patients must consult a licensed physician or doctor before making clinical decisions or changing their medical/exercise routines based on AI insights.

8.3 User Control over Health Data & AI Processing

Users maintain complete control over their health information. You can choose to enable or disable mobile data syncing, opt-out of AI-based wellness summaries, and request the immediate deletion of all health history directly from the mobile app settings. If you delete your account or specific data logs, they are permanently removed from our active production systems within 30 days.

8.4 Strict Health Data Sharing Restriction

We strictly adhere to Google Play Developer policies regarding health and fitness apps. Your personal health data, vitals, and wellness metrics are never shared, sold, or rented to third-party advertisers, data brokers, or marketing platforms. Data is only accessible to your designated medical provider, authorized sub-processors performing infrastructure services under strict confidentiality agreements, or as legally required.

Data Security Safeguards

Interactive overview of the administrative, physical, and technical safeguards implemented by MEDAX.

AES-256 Encryption at Rest
TLS 1.3 Transmission Security
Granular Access Roles (Doctor/Manager/Nurse)
Automated Encrypted Data Backups
Encrypted Cloud Infrastructure
Audit Logs & Verification Trails

Frequently Asked Questions

Common inquiries regarding patient confidentiality and storage operations.