This Privacy Policy describes how Experts InfoTech (Pvt) Ltd., doing business as xMedEMR ("we," "us," or "our"), collects, uses, and protects your personal information when you visit our website at xmedemr.com or use our software products and services.

1. Information we collect

Information you give us

Information we collect automatically

Customer data (when you use xMedEMR products)

If you are a customer using our xMedEMR software, you may process personal data of your patients, doctors, and staff within our platform. We process that data only on your documented instructions, as a data processor, in line with our Data Processing Addendum. This Privacy Policy does not apply to that customer data — see our Master Service Agreement and DPA for the terms that govern it.

2. How we use your information

3. Legal bases for processing (EEA / UK)

If you are in the European Economic Area or the United Kingdom, our legal bases for processing your personal data are:

4. How we share your information

We do not sell your personal information. We share it only with:

5. International data transfers

We are headquartered in Pakistan and use service providers across multiple regions. When we transfer your personal data outside your home country, we rely on appropriate safeguards, including Standard Contractual Clauses for transfers from the EEA/UK, and equivalent mechanisms elsewhere.

6. Data retention

We retain your personal data only as long as necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law. Marketing contacts are retained until you opt out. Customer account data is retained for the life of the account plus a defined archival period per our DPA.

7. Your rights

Depending on your location, you may have the right to:

To exercise any of these rights, contact us at privacy@xmedemr.com. We respond within 30 days.

8. Security

We use industry-standard technical and organizational measures to protect your personal data, including encryption in transit (TLS 1.3) and at rest (AES-256), role-based access control, two-factor authentication for our staff, append-only audit logs, regular penetration testing, and an incident response process with 72-hour breach notification.

9. Cookies

We use cookies and similar technologies for:

You can manage cookie preferences via your browser settings or our cookie banner.

10. Children's privacy

Our website and products are not directed to children under 16, and we do not knowingly collect personal data from them. If you believe we have collected data from a child, please contact us so we can delete it.

11. Third-party links

Our website may link to third-party sites (e.g., partner labs, regulatory bodies). We are not responsible for the privacy practices of those sites. Read their privacy policies before providing any personal data.

12. Changes to this policy

We may update this policy from time to time. The "last updated" date at the top reflects the latest revision. Material changes will be notified via email or a prominent notice on our website at least 30 days before they take effect.

13. Contact us

For any questions about this policy or our data practices, contact our Data Protection Officer at: