⚡ New: PM-JAY hospitals must switch to ABDM-compliant HMIS before March 2026. Book a free demo
LevelsHMS

Privacy Policy

Last updated: January 1, 2026

LevelsHMS (“we”, “our”, “us”) is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information when you use our hospital management software and website.

1. Information we collect

We collect information you provide directly to us, including name, email address, phone number, and hospital details when you register for a demo or contact us. We also collect usage data such as pages visited, features used, and session duration to improve our product.

2. How we use your information

We use the information we collect to provide, maintain, and improve our services; respond to your enquiries; send product updates and marketing communications (with your consent); and comply with legal obligations. We do not sell your personal data to third parties.

3. Patient data

LevelsHMS processes patient health data on behalf of hospitals (our customers) as a data processor under the Digital Personal Data Protection (DPDP) Act, 2023. Hospitals are the data fiduciaries and are responsible for obtaining patient consent. We process data only as instructed by the hospital.

4. ABDM data handling

Health data exchanged via the ABDM ecosystem is handled in strict accordance with ABDM data privacy guidelines, NHA policies, and the DPDP Act. All health information exchange requires explicit patient consent via the ABDM Consent Manager. We do not retain ABDM-fetched health records beyond the session.

5. Data security

We use industry-standard security measures including AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, and regular security audits. Our infrastructure is hosted on AWS India region (ap-south-1) to ensure data residency within India.

6. Data retention

We retain your personal data for as long as your account is active or as needed to provide services. Hospital patient data is retained as per applicable Indian healthcare regulations. You may request deletion of your personal data by contacting us at privacy@levelshms.in.

7. Cookies

We use essential cookies for authentication and session management, and analytics cookies (with consent) to understand how our website is used. You can control cookie preferences through your browser settings.

8. Your rights

Under the DPDP Act and applicable laws, you have the right to access, correct, and erase your personal data. To exercise these rights, contact us at privacy@levelshms.in. We will respond within 30 days.

9. Changes to this policy

We may update this privacy policy from time to time. We will notify you of significant changes via email or a notice on our website. Continued use of our services after changes constitutes acceptance of the updated policy.

10. Contact us

For privacy-related queries, contact our Data Protection Officer at privacy@levelshms.in or write to LevelsHMS, Bengaluru, Karnataka, India.