Back to home

Privacy Policy

Last updated: 26 June 2026

This Privacy Policy explains how Codagam Software Labs Private Limited ("Welbuk", "we", "us", or "our") collects, uses, discloses, and protects personal information when you use Welbuk Practice and related websites, mobile applications, and services (collectively, the "Services").

Welbuk provides software that healthcare facilities (clinics, hospitals, and diagnostic centres) use to manage care. For most health records you create or access through the Services, the healthcare facility is the controller/data fiduciary and Welbuk acts as a processor/data processor (and, where applicable, a business associate) handling that data on the facility's instructions. For your account and the operation of the Services, Welbuk acts as a controller/data fiduciary.

We are committed to handling health information in line with applicable laws, including the U.S. Health Insurance Portability and Accountability Act (HIPAA) safeguards, the EU/UK General Data Protection Regulation (GDPR), and India's Digital Personal Data Protection Act, 2023 (DPDP Act). By using the Services, you acknowledge the practices described here.

1. Information We Collect

We collect the following categories of information:

  • Account & identity data: name, email address, phone number, role, profile photo, employee/staff identifiers, and login credentials.
  • Health & medical data (sensitive personal data): patient demographics, appointments, consultation and clinical notes, diagnoses, prescriptions, lab referrals and reports, pharmacy and dispensing records, and, where enabled, national health identifiers such as ABHA/ABDM IDs.
  • Billing & payment data: invoices, charges, and payment status. Card and bank details are processed by our payment processor and are not stored by us.
  • Biometric data: where face-recognition attendance is enabled, facial templates of staff who opt in, used solely for attendance verification.
  • Device & usage data: IP address, device and browser type, log and diagnostic data, and actions taken within the Services.
  • Communications: messages, support requests, and feedback you send us.

2. How We Use Information

We use information to:

  • Provide, operate, secure, and improve the Services;
  • Enable healthcare facilities to deliver and document patient care;
  • Process appointments, prescriptions, lab referrals, billing, and payments;
  • Authenticate users and prevent fraud, abuse, and unauthorised access;
  • Send service-related notifications and respond to your requests;
  • Comply with legal, regulatory, and audit obligations.

We do not sell personal information, and we do not use health information for advertising.

3. Legal Bases and Consent

Where the GDPR applies, we process personal data on one or more of these legal bases: performance of a contract, your consent, compliance with a legal obligation, protection of vital interests, and our legitimate interests (such as securing the Services). Health data is processed for the provision of healthcare and related purposes permitted under Article 9 GDPR.

Where the DPDP Act applies, we process personal data based on your consent or for legitimate uses permitted under the Act. You may withdraw consent at any time (see 'Your Rights'); withdrawal does not affect processing already carried out.

4. How We Share Information

We share information only as needed to run the Services:

  • With the healthcare facility you belong to or are a patient of, and its authorised staff, according to their access permissions;
  • With service providers/processors who support us (cloud hosting, storage, messaging, analytics, and payment processing) under contractual confidentiality and security obligations;
  • With national digital health systems (e.g. ABDM) where you choose to link or use such services;
  • When required by law, regulation, court order, or to protect rights, safety, and the integrity of the Services;
  • In connection with a merger, acquisition, or asset transfer, subject to this Policy.

5. Protection of Health Information (HIPAA-aligned)

Where we handle protected health information on behalf of a covered entity, we apply administrative, physical, and technical safeguards consistent with HIPAA principles, including access controls, audit logging, encryption in transit, and use-and-disclosure limitations. We will enter into a Business Associate Agreement with covered entities where required.

6. Data Security

We use reasonable technical and organisational measures to protect information, including encryption in transit, role-based access controls, granular permissions, audit trails, and tenant data isolation. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Data Retention

We retain personal and health information for as long as needed to provide the Services, and thereafter as required to meet legal, regulatory, accounting, or medical-records retention obligations. Records are typically soft-deleted before permanent removal. When a healthcare facility is the controller, retention follows that facility's instructions and applicable law.

8. International Data Transfers

Your information may be processed or stored in countries other than your own. Where we transfer data internationally, we use appropriate safeguards (such as standard contractual clauses) as required by applicable law.

9. Your Rights

Subject to applicable law, you may have the right to: access your personal data; request correction or erasure; restrict or object to processing; request data portability; withdraw consent; nominate another person to exercise your rights (DPDP); and obtain a copy of your health records. Under HIPAA, you may also request access to and amendment of your medical records held by the relevant facility.

For health records held by a healthcare facility, please direct requests to that facility. For other requests, or to exercise the above rights, contact us at privacy@welbuk.com. You also have the right to lodge a complaint with your data-protection authority, and Indian residents may complain to the Data Protection Board of India.

10. Children's Privacy

The Services are intended for use by healthcare providers and adult users. Where a child's health information is processed, it is done on behalf of, and under the responsibility of, the treating healthcare facility and the child's parent or lawful guardian, with consent obtained as required by law.

11. Cookies and Tracking

We use cookies and similar technologies that are necessary to authenticate users, maintain sessions, and operate the Services, along with limited analytics to understand and improve performance. You can control cookies through your browser settings, though some features may not function without them.

12. Grievance / Data Protection Officer

If you have questions, concerns, or complaints about how we handle your information, you may contact our Grievance Officer / Data Protection contact at grievance@welbuk.com. We will acknowledge and address grievances within the timelines required by applicable law, including India's DPDP Act.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new 'Last updated' date and, where required, provide additional notice. Continued use of the Services after changes take effect constitutes acceptance of the updated Policy.

14. Contact Us

Codagam Software Labs Private Limited, Codagam Software Labs Private Limited, DOOR NO 3 Rukmani Illam, Ramnagar 3rd Cross St, Gobichettipalayam - 638452. General: support@welbuk.com · Privacy: privacy@welbuk.com · Grievance Officer: grievance@welbuk.com.