⚠️ Draft — please have this reviewed by a professional before launch.
Privacy Policy
Last updated: [effective date — set before launch]
This policy explains what information DPRS ("the Service") holds, why, and how it is protected. The Service is used to record a dialysis patient's care on behalf of their family and carers, so some of the information is health information and is treated with care.
1. What we collect
- Account details — your name and email address, and your password stored only as a secure bcrypt hash (never in plain text).
- Patient records you enter — patient profile, doctors, prescriptions and medicine schedules, dialysis sessions and readings, illness history, blood-report values, and any files (PDFs or photos) you upload.
- Technical records — an audit log of actions (who did what and when) with the network address of the request, used for security and integrity. We do not put health details in server logs.
2. Why we hold it
Solely to provide the Service: to store, display and chart the records you choose to enter, and to keep your account secure. We do not use your data for advertising, and we do not sell it.
3. How it is kept separate and secure
Each account's data is strictly isolated — you can only ever see the patients and records belonging to your own account. Connections are encrypted over HTTPS. Passwords are hashed with bcrypt. Records are append-only: a correction adds a new entry rather than erasing the original, giving a tamper-evident history.
4. Where it is stored and backed up
The Service runs on a private server (Oracle Cloud) and stores data in a local database. A nightly backup of the database and uploaded files is copied to cloud storage (Google Drive) via an encrypted transfer and kept for about 30 days, so data can be restored after a failure.
5. Administrator access
A system administrator operating the Service may access accounts and records when needed to run the Service, provide support, or fix problems. Every administrator action is written to a tamper-evident audit log (who, what, when). Administrators do not use your health information for any purpose beyond operating and supporting the Service.
6. Sharing
We do not share your data with third parties except the infrastructure providers needed to run and back up the Service (hosting and backup storage named above), or where we are required to by law. It is never sold.
7. How long we keep it
We keep your records while your account is active. Because records are append-only, superseded entries remain as history rather than being deleted. You can ask us to export or delete your account and its data (see Contact) — automated self-service deletion is planned but not yet available.
8. Your choices
You can view and correct records at any time within the Service, change your account details, and request a copy or deletion of your data by contacting us.
9. Contact
Privacy questions or requests: [contact email — set before launch].
This is a plain-language draft that reflects how the Service currently works. It is not legal advice; have it reviewed by a qualified professional and adapted to your jurisdiction (and to any health-data laws that apply) before you rely on it.