PreneurShip, a sole proprietorship operating under the brand name Medikunj, is located at 46 Nibedita Road, Kolkata – 700078, India. Medikunj operates medikunj.com and provides hospital management software and related services to hospitals, nursing homes, clinics, healthcare professionals, and authorised business partners.
This policy applies to the public website, demo and affiliate forms, customer support, and the Medikunj platform. A hospital or clinic may also give its own privacy notice for the patient and workforce information it manages through Medikunj.
Privacy at a glance
What we collect
Only information needed to run the website, serve healthcare customers, and operate configured hospital workflows.
How health data is handled
The healthcare provider controls its patient records; Medikunj processes them to provide the contracted service.
What we do not do
We do not sell personal information or use identifiable patient data for advertising.
How to reach us
supratik@medikunj.comScope and who this policy covers
This policy covers information relating to:
- Website visitors and business contacts who browse medikunj.com, request a demo, contact us, or communicate with our team.
- Customer users, including hospital owners, administrators, doctors, nurses, pharmacists, laboratory staff, billing teams, and other authorised personnel.
- Patients and their representatives whose information is entered into Medikunj by an authorised healthcare provider.
- Affiliates, vendors, and partners who apply to or participate in a Medikunj business programme.
If you provide information for another person, you must be authorised to do so and must ensure that any notice or consent required by law has been provided or obtained.
Our role and the hospital’s role
For website, sales, account, billing, and support information
Medikunj decides why and how this information is used for its own business operations and is responsible for the processing described in this policy.
For patient, clinical, and hospital workforce records
The hospital, nursing home, clinic, or healthcare professional using Medikunj generally decides why the information is collected, which records are created, who may access them, and how long they must be kept. Medikunj processes those records to provide the contracted software and support, subject to the customer’s documented instructions, the applicable agreement, and law.
Patients should ordinarily direct record-access, correction, or deletion requests to the healthcare provider that created or controls the record. Medikunj will assist the provider where required and appropriate.
Information we process
Contact, sales, and account information
- Name, work email, phone number, organisation, role, city, referral details, and meeting preferences.
- Username or account identifier, role, permissions, authentication and session events, and account status.
- Messages, support requests, feedback, training records, and communications with our team.
Patient and clinical information entered by a healthcare provider
- Identity and demographic details, contact information, emergency contacts, and identifiers assigned by the provider.
- Appointments, visits, admissions, bed and ward records, discharge information, referrals, and care-team details.
- Medical history, diagnoses, allergies, vitals, prescriptions, clinical notes, treatment plans, procedures, consent records, and uploaded documents.
- Laboratory and radiology orders and results, pharmacy records, insurance or TPA information, invoices, and payment status.
- ABHA or ABDM-related identifiers, links, and consent artefacts when an authorised customer enables those integrations.
Hospital operations and workforce information
- Staff profiles, schedules, attendance or duty data, professional details, digital signatures, and role assignments.
- Inventory, procurement, pharmacy, finance, billing, doctor-payable, audit, and reporting information.
AI-feature inputs and technical records
- Text, audio, images, or documents deliberately submitted to a configured AI-assisted feature.
- IP address, device and browser information, timestamps, audit trails, error reports, and security events generated when the service is used.
Affiliate and payment information
- Affiliate application details, operating area, professional-network information, referrals, payout records, and tax or banking details where required.
- Invoice, subscription, transaction reference, amount, status, and payment timestamps.
How we receive information
- Directly from you when you complete a form, create or use an account, contact support, book a meeting, or submit information through the platform.
- From the hospital, clinic, healthcare professional, or authorised user that creates and manages a record.
- From a configured integration, such as ABDM/ABHA, a laboratory, pharmacy, payment gateway, or communication provider, when authorised for the relevant workflow.
- Automatically from the service infrastructure through operational, audit, and security logs.
We do not seek to collect personal information from data brokers or social networks for patient profiling.
Why we process information
We process information only for identified operational purposes, including:
- Responding to enquiries, arranging demos, preparing proposals, onboarding customers, and managing the business relationship.
- Creating accounts, applying role-based permissions, authenticating users, and maintaining secure access.
- Providing configured clinical, administrative, pharmacy, laboratory, inventory, billing, reporting, and communication workflows.
- Maintaining patient-safety and accountability records, including audit trails and access logs.
- Processing invoices, subscriptions, affiliate payouts, and transaction reconciliation.
- Providing implementation, training, maintenance, incident response, and customer support.
- Preventing misuse, investigating security events, enforcing agreements, and meeting legal or regulatory obligations.
- Improving reliability and usability using aggregated or de-identified operational insights.
We do not sell personal information. We do not use identifiable patient or clinical information for targeted advertising.
Health records, ABDM, and AI features
Clinical responsibility
Medikunj is a technology platform and does not replace the independent clinical judgement of a qualified healthcare professional. The healthcare provider remains responsible for reviewing clinical records, prescriptions, results, and AI-assisted drafts before relying on or issuing them.
ABDM and ABHA workflows
Where a customer enables ABDM features, health-record linking or sharing is performed through the configured ABDM workflow and applicable consent mechanism. An ABHA number is not a condition for receiving care from a healthcare provider unless applicable law or a separate programme requires it.
AI-assisted features
Information deliberately submitted to an AI-assisted feature may be sent to an approved technology provider solely to generate the requested output, secure and operate the feature, and provide support. Customers must ensure that users and patients receive any notice and choice required for audio, document, image, or clinical-data processing before the feature is used. Access to AI outputs is limited by the same account and role controls that apply to the related workflow.
Payments and subscriptions
- Payment processors may receive the payer’s name, contact details, amount, invoice or order reference, and transaction metadata required to process and verify a payment.
- Complete card numbers, card security codes, and payment credentials are entered into and handled by the payment processor; Medikunj does not store complete card details on its servers.
- A payment processor may retain a token or payment mandate for an authorised recurring subscription.
- Invoices, tax records, settlement records, and transaction references are retained as required for accounting, audit, dispute, and legal obligations.
Retention and deletion
We retain each category only for as long as it serves its stated purpose:
- Demo, enquiry, and sales records: while the enquiry or business relationship remains active and for a reasonable follow-up period, unless deletion is requested or a legal need requires retention.
- Customer account and service records: for the subscription or contract term and the agreed post-termination export, backup, or deletion period.
- Patient, clinical, and hospital records: according to the customer’s instructions, contract, applicable medical-record obligations, and law. The healthcare provider determines the primary retention period.
- Security and audit logs: for the period reasonably needed to investigate events, maintain accountability, and meet contractual or legal duties.
- Financial and transaction records: generally for 5–7 years, or longer where tax, accounting, audit, or legal rules require it.
Deletion from active systems may not immediately remove information from encrypted, access-restricted backups. Backup copies are isolated from routine use and removed or overwritten under the applicable backup cycle. We may preserve information subject to a legal hold, dispute, fraud investigation, or other lawful retention requirement. Data that has been irreversibly de-identified may be retained because it no longer identifies an individual.
Security and incident response
We use safeguards proportionate to the sensitivity and volume of information processed. These include, as appropriate, encrypted network connections, authentication, role-based access, least-privilege administration, activity logging, backup controls, vulnerability management, and confidentiality obligations for personnel and service providers.
Customers are responsible for approving users, assigning appropriate roles, promptly removing access that is no longer required, protecting credentials, and using secure devices and networks. Suspected unauthorised access should be reported to us promptly.
If a personal-data incident occurs, we will investigate, contain, remediate, document, and provide notifications to affected customers, individuals, or authorities where required by applicable law or contract. No internet or storage system can be guaranteed completely secure.
Your rights and choices
Subject to applicable law and verification, you may request:
- A summary of personal information processed about you and relevant processing activities.
- Correction, completion, or updating of inaccurate or incomplete information.
- Erasure of information that is no longer required, unless lawful retention applies.
- Withdrawal of consent where processing depends on consent. Withdrawal does not affect processing already lawfully completed and may prevent the relevant optional feature from continuing.
- Opt-out from non-essential marketing communications.
- Grievance redressal concerning the handling of your information.
To protect confidentiality, we may verify identity and authority before acting on a request. If the request concerns a hospital-managed patient or workforce record, contact that hospital or clinic first; it is best placed to verify the request and determine the appropriate response. We will support the healthcare provider as required.
You are responsible for providing accurate information and for using the service lawfully. You may also nominate another individual to exercise rights on your behalf where applicable law permits.
Children and dependent patients
The Medikunj public website and business services are not offered directly to children. However, an authorised healthcare provider may create and manage a medical record for a child or dependent patient as part of lawful care. Responsibility for providing notices, obtaining verifiable parental or guardian consent where required, and managing access rests with the relevant healthcare provider. If information appears to have been submitted without proper authority, contact us and the healthcare provider promptly.
Data location and transfers
Information may be processed from locations where Medikunj, the customer, or an approved service provider operates. Before appointing a provider, we consider the nature of the service, the information involved, security measures, and applicable contractual and legal requirements. Where a transfer across jurisdictions is permitted and necessary, we use appropriate safeguards and follow applicable restrictions or government directions.
Third-party services and links
The website or platform may link to or integrate with services operated by hospitals, government programmes, laboratories, pharmacies, payment providers, communication providers, or other independent organisations. This policy governs Medikunj’s processing; it does not replace the privacy policy of an independent third party. Review that provider’s terms before submitting information directly to it.
Changes to this policy
We may update this policy when our services, processing practices, or legal obligations change. The effective date at the top will show the latest revision. If a change materially affects how existing personal information is used, we will provide a reasonable notice through the website, platform, customer administrator, or email, as appropriate. We will seek fresh consent where applicable law requires it.
Privacy and grievance contact
For a privacy question, rights request, security concern, or grievance, contact:
Privacy and Grievance Contact
Medikunj, operated by PreneurShip
46 Nibedita Road, Kolkata – 700078, India
Email: supratik@medikunj.com
Phone: +91 8910967001
Please describe the request, the organisation or hospital involved, and how we can contact you. Do not send medical records or identity documents by ordinary email unless we specifically request them through an appropriate secure channel. We will acknowledge and address grievances within the period required by applicable law.
This policy is intended to align with applicable Indian privacy and information-security requirements, including the Digital Personal Data Protection Act, 2023 and rules as they become applicable, the Information Technology Act, 2000 and applicable rules, and the ABDM Health Data Management Policy where an ABDM workflow is used.
This policy is governed by the laws of India. Subject to any mandatory statutory grievance or dispute mechanism, courts in Kolkata, West Bengal will have jurisdiction.