হ্যালোডক্টর

Privacy Policy

Applies to patients, caregivers, doctors, assistants and visitors using HelloDoctor's websites, PWA and authorised communication channels.

This Privacy Policy explains how HelloDoctor HealthTech Limited collects, uses, discloses, stores and protects personal information. By using the Platform or submitting information, you acknowledge this Policy. Where consent is required for teleconsultation, sensitive information, cookies or another activity, HelloDoctor will seek it through an appropriate notice or control.

Patient and caregiver information may include name, age, sex, phone, email, location, account details, guardian relationship, symptoms, medical history, medicines, allergies, pregnancy information where relevant, chats, audio/video-related records, reports, images, prescriptions, consultation and follow-up information, serial requests, booking status, consent, complaints and support records.

Doctor and assistant information may include name, photograph, phone, email, BMDC number and registration data, submitted documents, qualifications, specialty, training, experience, workplace, chamber, map location, schedule, fees, assistant/chamber contact, posts, responses, activity, subscription and payment information.

Payment and transaction information may include amount, method, status, transaction ID, payer identifier, time, refund information and confirmation evidence. HelloDoctor does not ask for or intentionally store mobile-banking PINs, card PINs, OTPs, passwords or full secret card credentials. Payment gateways and financial providers process their own secure payment data under their policies.

Technical and usage information may include IP address, browser/device type, operating system, cookie or device identifiers, page views, clicks, search filters, referral/campaign source, approximate or consented location, PWA token, security events and service logs.

A doctor's approved profile may publicly display name, photograph, BMDC verification status or partial/full number as configured, professional description, qualifications, specialty, experience, workplace, chamber address, schedule, fee, posts, views, follows, reactions and booking availability. Doctors should not submit private information for public fields.

A non-public assistant/chamber contact number provided for serial coordination will be available only to authorised HelloDoctor staff/systems and the relevant doctor/chamber, unless the provider separately authorises public display. Patient health records, phone numbers and booking details are not public.

We may use information to create and secure accounts; review and verify doctors; publish approved profiles; search and rank relevant doctors; route and confirm serial requests; conduct online consultations; identify participants; obtain consent; communicate with doctors, assistants and patients; process payment/refund; send service notices; moderate content; prevent fraud; investigate complaints; keep appropriate records; improve service; measure campaigns; maintain security; and comply with law.

HelloDoctor may compare submitted identity and BMDC information with available official records, keep verification evidence and dates, request corrections or further proof, and re-check or suspend a badge. Only information reasonably necessary for verification and safety should be collected.

Information may be shared, on a need-to-know basis, with the assigned or selected doctor; an authorised assistant/chamber for a serial request; HelloDoctor clinical, care, support, operations, finance, moderation and security personnel; and vendors supporting payments, SMS/telecom, hosting, backups, cybersecurity, email, maps, analytics or communications.

We may disclose information to regulators, courts, law-enforcement or other authorities when required or permitted by law, or where reasonably necessary to address safety, fraud, legal claims or professional misconduct. HelloDoctor does not sell personal or health information. Service providers may use it only for instructed services and lawful purposes, subject to appropriate safeguards.

Payments may be processed by SSLCOMMERZ and participating cards, banks or mobile financial services. HelloDoctor may receive transaction status and reference information needed for fulfilment, accounting, fraud control and refund. Users should review the payment provider's own privacy and security notices and never share a PIN or OTP with HelloDoctor personnel.

HelloDoctor may use necessary cookies and, where permitted, analytics or advertising measurement tools such as Meta Pixel to understand visits, clicks, referrals and campaign performance. Users can control non-essential cookies through available preferences or browser settings. Identifiable health

messages, reports or consultation content will not be used to build unrelated advertising audiences or shared for unrelated advertising without valid consent.

Automation or AI may assist doctor search, routing, chamber-information responses, support, moderation, transcription or summarisation. HelloDoctor will use reasonable controls, human review where appropriate and data minimisation. We will not intentionally provide identifiable health records to an unrelated third-party AI service for its independent model training. Automated output does not replace a doctor's final clinical judgment.

HelloDoctor intends to store and handle patient and medical information within Bangladesh where required by applicable health guidance or law. If an approved provider processes information outside Bangladesh, HelloDoctor will use an appropriate lawful basis, notice, contractual and technical safeguards, and any required authorisation. Users should be told when a chosen third-party messaging platform independently processes data under its own rules.

Information is kept only as long as reasonably necessary for consultation and booking continuity, professional or medical record obligations, verification, accounting, fraud prevention, complaints, audit, legal claims, security and applicable law. After the purpose ends, information may be securely deleted, anonymised, archived or access-restricted. Account deletion does not require removal of records that must lawfully or safely be retained.

HelloDoctor uses reasonable administrative, organisational and technical safeguards, including access controls, authentication, secure transmission where supported, logging, backup and vendor controls. No internet, cloud, phone or messaging system can be guaranteed completely secure. Users should protect devices and credentials, verify official channels and report suspicious activity promptly.

Subject to identity verification, applicable law and legitimate retention needs, a user may request access to, correction of or deletion of personal information; withdraw consent for future optional processing; restrict non-essential marketing; or raise a privacy complaint. A doctor may update public profile information and request review of inaccurate verification data. Withdrawal does not invalidate processing already lawfully completed and may make a requested service unavailable.

Where a patient is a child or cannot provide valid consent, a parent, legal guardian or responsible adult should participate as appropriate. HelloDoctor may verify age or authority and limit collection to what is necessary for safe service.

If HelloDoctor becomes aware of a material personal-data incident, it will take reasonable steps to contain, investigate and remediate the incident and provide notices to affected persons or authorities where required by applicable law.

This Policy may be updated as services, vendors or legal requirements change. Material changes will be published with a revised date and, where required, an additional notice or renewed consent.