Vass Softwares and SolutionsClick to Customize

Legal

Privacy Policy

How personal information and health-related information may be collected, used, stored, disclosed and protected across Aspire HIMS websites, web applications, mobile applications and APIs.

Effective Date
14 September 2026
Last Updated
14 September 2026

01Introduction

Vass Softwares and Solutions Pvt. Ltd. (“VASS”, “we”, “us”, or “our”) provides Aspire HIMS, a configurable hospital information management platform used by hospitals, clinics, healthcare institutions, doctors, patients, administrators and other authorized users. Aspire HIMS supports clinical, administrative and patient-engagement workflows, including patient registration, appointments, electronic medical records, laboratory, pharmacy, billing, diagnostics, communications and mobile applications.

This Privacy Policy explains how personal information and health-related information may be collected, used, stored, disclosed and protected when you use Aspire HIMS websites, web applications, patient mobile applications, doctor mobile applications, APIs and related services (collectively, the “Services”).

02Important Role of the Hospital or Healthcare Institution

Aspire HIMS is a technology platform. A hospital, clinic or healthcare institution using Aspire HIMS (“Healthcare Customer”) may determine what patient information is collected, how it is used, who can access it, how long it is retained and how it is shared for healthcare and operational purposes.

Where a Healthcare Customer controls the purposes and means of processing patient or healthcare information, that Healthcare Customer may be the relevant data controller or equivalent responsible entity, while VASS may process information on the Healthcare Customer’s behalf as a technology/service provider, subject to the applicable agreement and law.

For questions about a particular patient record, treatment, medical service, correction of a hospital record, or the Healthcare Customer’s specific privacy practices, users may need to contact the relevant hospital or healthcare institution directly. A hospital may maintain additional privacy terms or notices that apply to its services.

03Information We May Collect

Depending on the Services enabled by a Healthcare Customer and the user's role, information may include:

  • Identity and contact information such as name, mobile number, email address, date of birth, gender and address.
  • Account and authentication information, including phone-number verification and OTP-related information.
  • Patient and healthcare information, including appointments, consultation details, case sheets, diagnoses, prescriptions, laboratory results, imaging-related information, discharge summaries, allergies, medications, vitals and other information entered or generated during healthcare workflows.
  • Doctor and professional information such as profile details, speciality, schedules, consultation channels and fees, where configured.
  • Images, documents and reports uploaded through the patient application using the camera, gallery or device files.
  • Payment, wallet and transaction-related information required to process appointments, consultations or other enabled services. Payment card, banking or other payment credentials may be processed by the applicable payment service provider rather than stored directly by VASS.
  • Device and technical information such as device type, operating system, application version, IP address, identifiers, logs and diagnostic information, where collected and permitted.
  • Communication information, including support requests, notifications and communications associated with enabled chat, video consultation or messaging features.
  • Information provided to us when requesting a product demo, support, partnership or other enquiry.

04How We Use Information

We may use information, as applicable, to:

  • Provide, operate, maintain and secure Aspire HIMS and its mobile and web applications.
  • Create and manage user accounts and authenticate users.
  • Enable appointment booking, consultation, video consultation, chat, notifications, medical records and other configured healthcare workflows.
  • Display and manage patient records for authorized users according to the permissions configured by the Healthcare Customer.
  • Process payments, wallet transactions and related reconciliation through applicable payment providers.
  • Provide customer support, troubleshooting, implementation and service communications.
  • Send transactional notifications such as appointment, consultation, report or service notifications.
  • Monitor performance, security, availability and reliability, and investigate suspected misuse or security incidents.
  • Generate operational, analytical or aggregated insights for authorized purposes, using appropriate safeguards.
  • Comply with legal, regulatory, contractual and security obligations.
  • Improve the Services, including workflow, reliability and usability, subject to applicable agreements, permissions and law.

05Health and Medical Information

Aspire HIMS can process sensitive healthcare information because it is designed for hospital and clinical workflows. Access to patient information is intended to be controlled through role-based permissions and other security measures configured for the Healthcare Customer.

VASS does not provide medical diagnosis or treatment merely by operating the platform. Any clinical decision, diagnosis, prescription or treatment remains the responsibility of the appropriately authorized healthcare professional and Healthcare Customer.

AI-enabled functions, where enabled, may support documentation, scheduling, analytics, alerts, clinical workflows or other operational purposes. AI outputs are intended to assist authorized users and should be reviewed by qualified healthcare professionals before being relied upon for clinical decisions.

06Mobile Applications

Aspire HIMS patient and doctor mobile applications may provide features such as OTP-based login, appointment booking, online payment and wallet functionality, report upload, access to doctor-updated records, notifications, chat and video consultation.

Depending on the feature being used, the application may request access to the camera, microphone, files/photos or other device capabilities. Permissions are requested for the relevant feature and may be controlled through the device settings. If a user does not provide a required permission, the corresponding feature may not function.

07Video Consultation and Communication

Where video consultation or communication features are enabled, the Services may use third-party communication infrastructure to establish secure communications between authorized participants. Depending on the configured service, information such as user identifiers, session information and technical connection data may be processed by the relevant service provider.

Users should not use an unsecured or unauthorized account to conduct healthcare communications. Recording of video or audio is not implied merely because a video consultation feature is available; any recording, storage or other processing will depend on the applicable configuration, Healthcare Customer instructions, consent requirements and law.

08Third-Party Service Providers

To provide the Services, VASS or a Healthcare Customer may use third-party providers for functions such as cloud infrastructure, authentication/OTP, push notifications, video or communication services, payment processing, analytics, security, email, SMS, WhatsApp or healthcare interoperability. These providers may process information only as necessary for their services and under their applicable terms, contracts and privacy practices.

The specific third-party services used may vary by Healthcare Customer, deployment model, country and enabled features. Examples may include Firebase/Google services, Twilio or payment gateway providers. VASS does not control the independent privacy practices of third-party providers.

09Data Sharing and Disclosure

We may disclose information:

  • To the Healthcare Customer and its authorized personnel as necessary to provide healthcare and administrative services.
  • To service providers and technology partners that support the Services.
  • To payment, communication, interoperability or other providers when a relevant feature is used.
  • When required by applicable law, regulation, court order or lawful governmental request.
  • To protect the rights, safety, security and property of VASS, users, Healthcare Customers or others, or to investigate fraud, abuse or security incidents.
  • In connection with a merger, acquisition, restructuring, financing or transfer of business assets, subject to applicable law and appropriate safeguards.

10Data Security

We use reasonable technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, loss or destruction. Depending on the deployment, these measures may include encryption, access controls, role-based permissions, audit logging, secure authentication, network and infrastructure controls, backups and monitoring.

No electronic system can be guaranteed to be completely secure. Users and Healthcare Customers are responsible for protecting credentials, devices, access tokens and other authentication information and for notifying the appropriate support or security contact of suspected unauthorized access.

11Cloud and On-Premises Deployment

Aspire HIMS may be deployed in cloud or on-premises environments. In cloud deployments, data may be hosted on infrastructure selected under the applicable service arrangement. In on-premises deployments, the Healthcare Customer may control the physical and network environment in which the system and data are hosted. Security responsibilities therefore vary according to the deployment model and contractual arrangement.

12Data Retention

Information is retained for as long as reasonably necessary to provide the Services, fulfil contractual and legal obligations, maintain healthcare and business records, resolve disputes, enforce agreements, maintain security and for other legitimate purposes. Healthcare records may be subject to retention requirements established by the Healthcare Customer and applicable law.

When VASS is acting as a service provider for a Healthcare Customer, deletion or return of healthcare information may be governed by the applicable agreement and the Healthcare Customer’s instructions.

13Data Transfers

Depending on the deployment, service providers and location of the Healthcare Customer, information may be processed or stored in India or other jurisdictions. Where cross-border processing occurs, VASS and relevant service providers will apply appropriate safeguards required by applicable law and contractual arrangements.

14Children's Privacy

Aspire HIMS may be used to manage healthcare information concerning children when a Healthcare Customer provides pediatric or other child healthcare services. Such information should be entered and accessed only by authorized users and in accordance with the Healthcare Customer’s procedures and applicable law. The Services are not intended to encourage children to create independent accounts without the required authorization.

15Your Rights and Choices

Depending on the applicable law and the user's relationship with the Healthcare Customer, users may have rights relating to access, correction, updating, deletion, restriction, objection, consent withdrawal, data portability or other rights. Because healthcare records are generally controlled by the relevant Healthcare Customer, requests concerning a patient record may need to be directed to that hospital or healthcare institution.

Users may also control certain device permissions, notifications and application access through their device settings. Withdrawal of a permission may limit the availability of the corresponding feature.

16Cookies and Website Technologies

The Aspire HIMS website may use cookies or similar technologies for essential website functionality, security, preferences, analytics and service improvement. The specific cookies and technologies used may change over time. Where required by law, applicable consent mechanisms will be provided.

17Marketing and Communications

We may use contact information provided through our website, demo forms or business enquiries to respond to requests, provide service information and communicate about Aspire HIMS. Where required, marketing communications will be subject to applicable consent and opt-out requirements. Transactional and service-related communications may still be sent when necessary to provide requested services.

18International and Regulatory Frameworks

Aspire HIMS is designed with security and healthcare interoperability considerations including ABDM/ABHA readiness and alignment-oriented capabilities for frameworks such as HIPAA, GDPR and SOC 2. Such statements describe platform design objectives or alignment and do not by themselves mean that every Healthcare Customer, deployment or processing activity is certified, registered or compliant with every framework. Compliance obligations depend on the applicable organization, configuration, contract and law.

19India and Applicable Privacy Law

For users and Healthcare Customers in India, processing of personal data may be subject to applicable Indian privacy and information-technology laws and regulations, including the Digital Personal Data Protection Act, 2023 and rules or regulations made under applicable law, as and when applicable. The respective responsibilities of VASS and the Healthcare Customer will depend on the nature of the processing and the applicable agreement.

20Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the Services, technology, legal requirements or business practices. The updated version will be published on the Aspire HIMS website with a revised “Last Updated” date. Material changes may be communicated through appropriate channels where required.

21Contact Us

Vass Softwares and Solutions Pvt. Ltd.
108, Sir Thyagaraya Rd,
T. Nagar, Chennai,
Tamil Nadu – 600017, India

For patient-record or healthcare-service requests, users should also contact the relevant hospital or healthcare institution providing the healthcare service.

22Hospital-Specific Privacy Notices

Aspire HIMS may be branded and configured for individual hospitals, clinics and healthcare networks. A Healthcare Customer may publish an additional or more specific privacy notice describing its own processing activities, legal basis, data-controller details, retention practices, contact information and patient rights. Where such a notice applies, users should read it together with this Privacy Policy.

This Privacy Policy should be read together with our Terms & Conditions.