Privacy Policy — BeatX Doctor
App: BeatX Doctor Developer: RhythmRX Private Limited Effective Date: 10 May 2025 Last Updated: 4 June 2026 Contact: support@rhythmrx.ai
RhythmRX Private Limited ("RhythmRX", "we", "us", or "our") operates the BeatX Doctor mobile application (the "App"). The App is a clinician-facing tool that lets physicians, physician assistants, distributors, and authorised hospital staff review cardiac monitoring data captured from patients' BeatX devices, communicate securely with those patients, approve or reject diagnostic reports, manage device configurations, and handle related billing.
This Privacy Policy describes the information we collect when you use the App, how we use it, who we share it with, how long we keep it, and how you can have it deleted. By creating an account or otherwise using the App, you confirm that you have read and accepted this Policy.
1. Information We Collect
1.1 Information you provide to us
When you register and use the App, we collect:
- Account information: full name, role (Physician, Physician Assistant, Distributor, Hospital Administrator, Super Admin), email address, mobile number, professional credentials, hospital / practice affiliation, and login credentials.
- Profile information: profile photograph and digital signature image (used to sign approved reports).
- Patient roster: identifying details of patients under your care that you create or are assigned to — name, date of birth, gender, contact number, address, and the cardiac study you have ordered for them.
- Clinical context: patient complaints, prior medical history, prescribed medications, and notes you enter while creating a study or reviewing a report.
- Communications: the text, voice notes, images, and report files you send through the in-App chat with patients or other clinicians.
1.2 Information generated through your clinical use of the App
- Diagnostic reports (Final, Interim, PT and similar) that you approve or reject, including your decision, rejection notes, and signature stamp.
- Cardiac data surfaced for review: electrocardiogram (ECG) traces, heart-rate metrics, rhythm classifications, MDN (Medical Device Notification) events, and Live-ECG sessions associated with patients under your care. This data is captured on the patient's BeatX device and surfaced in the App so you can review it; the App is the viewer, not the recorder.
- Device telemetry: serial numbers, firmware versions, battery and signal status of the BeatX devices linked to your patients.
1.3 Information collected automatically
- Usage data: screens you visit, actions you take (approve, reject, send message, raise invoice), and timestamps.
- Device & technical data: device model, operating system version, mobile network operator, IP address, language, time-zone, app version, and crash diagnostics.
- Push-notification tokens (FCM / APNs) so we can deliver alerts about new reports, pending approvals, chat messages, and live ECG events.
1.4 Information we do not collect
We do not collect biometric authentication data (fingerprint / Face ID — that stays on your device), precise GPS location, advertising identifiers, or contacts from your phone's address book.
2. How We Use Your Information
We use the information described above only for the purposes listed below:
- Providing the clinical workflow. Surfacing ECG / Holter / MCT studies for review, letting you approve or reject reports, applying your signature to approved reports, and synchronising the decision back to the patient and the technician.
- Communications between you and your patients or care team. Routing the chat, voice notes, PDF reports, and rejection notes you send through the App's secure messaging channel.
- Account and access control. Creating, authenticating, and securing your account; verifying your role and the patients you are entitled to access.
- Notifications. Sending push notifications and in-App badges for new pending approvals, MDN events, chat messages, and billing reminders.
- Billing and distribution management. For distributor and administrator accounts, generating invoices, processing Razorpay / UPI payments, and managing the hospitals and physicians attached to a distributor.
- Service operation and quality. Diagnosing crashes, monitoring performance, preventing abuse, and improving the App. Aggregated, non-identifying usage analytics may be used to understand which features clinicians rely on most.
- Legal and regulatory compliance. Meeting our obligations under applicable medical-device, data-protection, and information-technology laws, and responding to lawful requests from authorities.
We do not sell, rent, or trade your personal or patient information, and we do not use it for advertising.
3. Legal Basis for Processing
Where data-protection law requires a legal basis, we rely on:
- Performance of a contract with you (delivering the App's clinical functionality you have signed up for).
- Legitimate interest in operating, securing, and improving the App, where that interest is not overridden by your rights.
- Consent, which you may withdraw at any time, for optional features such as marketing communications (when offered).
- Compliance with a legal obligation when required by law.
4. How We Share Information
We share information only as follows:
- Within your care network. Information you enter or generate (reports, decisions, messages) is shared with the patient it concerns and, where applicable, the technician, attending physician, hospital, and distributor that the patient belongs to. This is the core purpose of the App.
- With service providers acting on our instructions and bound by confidentiality:
- AWS (Amazon Web Services, Mumbai region) for secure storage of reports, images, and audio. - Firebase Cloud Messaging and Apple Push Notification Service for push notifications. - Razorpay for online payment processing (for distributor billing only). - Google Analytics for Firebase / Crashlytics for crash and performance diagnostics (no personally-identifying clinical data is sent here).
- For legal reasons when required by court order, subpoena, regulator, or to protect the rights, safety, or property of RhythmRX, our users, or the public.
- In connection with a corporate transaction (merger, acquisition, restructuring); in such case we will require the recipient to honour this Policy.
We do not transfer personal data outside India except as required to operate the integrated services listed above, and only with appropriate safeguards.
5. Data Security
We apply the following safeguards to protect your information:
- TLS 1.2+ encryption for all data in transit between the App and our servers.
- Encryption at rest for stored reports, images, and audio in Amazon S3.
- Token-based authentication with short-lived session tokens and signed S3 URLs.
- Role-based access control: a physician sees only the patients and reports they are entitled to; distributors see only their own hospitals and physicians.
- Audit logging of report approvals, rejections, and signature uploads.
No method of transmission or storage is 100% secure. While we work hard to protect your information, we cannot guarantee absolute security. If we become aware of a security breach that affects your information, we will notify you and the relevant authorities as required by law.
6. Data Retention
We retain information only for as long as it is needed for the purpose it was collected, or as required by applicable law.
| Data category | Retention period |
| Account profile (name, email, role, signature) | For the lifetime of your account, plus up to 90 days after deletion to complete the wind-down. |
| Patient records and diagnostic reports you reviewed | Up to 7 years from the date of the report, in line with Indian medical-record retention norms (Indian Medical Council regulations). |
| Chat messages, voice notes, and attached images | Up to 3 years from the message date. |
| Invoice and payment records | Up to 8 years from the financial year end (Companies Act / GST archival requirements). |
| Push-notification tokens | Until the token is invalidated by the device or you log out. |
| Crash and usage analytics (de-identified) | Up to 2 years. |
| Server access and audit logs | Up to 1 year. |
When the retention period expires, the data is securely deleted or fully anonymised so that it can no longer be linked to you.
7. Your Rights and How to Delete Your Data
You have the following rights with respect to your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct information that is inaccurate or incomplete.
- Deletion — ask us to delete your account and the personal information associated with it (subject to the legal retention requirements in Section 6, e.g. invoice and medical-record archival).
- Restriction / objection — ask us to stop or limit certain processing.
- Portability — request your information in a structured, machine-readable format.
- Withdrawal of consent — withdraw consent for any processing that relies on consent.
7.1 In-App account deletion
- Open the App, go to Settings → Account → Delete My Account.
- Confirm the prompt. We will queue your account for deletion and send a confirmation email.
- Your account is deactivated immediately. All personal information not subject to a statutory retention requirement (Section 6) is deleted within 30 days. Information that must be retained for medical-record, accounting, or legal-defence reasons is locked down, restricted from active use, and deleted automatically when its retention period expires.
7.2 Email request (alternative)
If you cannot use the in-App option, email support@rhythmrx.ai from the address registered to your account with the subject line "Account Deletion Request — BeatX Doctor". We will verify your identity and complete the deletion within 30 days of verification, subject to the same retention carve-outs.
7.3 What gets deleted
- Your name, contact details, login credentials, profile photo, and digital signature.
- The push-notification tokens linked to your device.
- Your in-App chat content, except for messages that form part of a patient's medical record (which are retained per Section 6).
- Your usage analytics records.
7.4 What is retained after deletion (and why)
- Reports you approved or rejected — retained as part of the patient's medical record per Indian medical-record regulations.
- Invoice / payment records — retained for tax and accounting compliance.
- De-identified, aggregated metrics that no longer link to you.
We will respond to all rights requests within 30 days. If you are not satisfied with our response, you may complain to the relevant data protection authority in your jurisdiction.
8. Children
The App is intended for licensed healthcare professionals, distributors, and authorised hospital staff. It is not directed at children, and we do not knowingly collect information from anyone under 18 as an App user. The patient records reviewed inside the App may include minors; that data is collected from the treating physician or institution, not the minor directly.
9. Third-Party Links and Services
The App may surface links to third-party websites (for example, payment gateways or hospital portals). Once you leave the App, this Policy no longer applies — please review the privacy policy of the destination service.
10. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or in law. When we make material changes, we will:
- Update the Last Updated date at the top of this document.
- Notify you in-App and, where appropriate, by email at least 7 days before the change takes effect.
Your continued use of the App after the change takes effect means you accept the revised Policy. If you do not agree, please stop using the App and request account deletion as described in Section 7.
11. Contact Us
RhythmRX Private Limited Email: support@rhythmrx.ai
For data-protection or deletion requests, please use the subject line "Privacy Request — BeatX Doctor" and email us from the address registered to your account so we can verify your identity.
This Privacy Policy applies exclusively to the BeatX Doctor mobile application published by RhythmRX Private Limited on the Google Play Store and the Apple App Store.