01Who we are and what this covers
Wellness Studio is a cloud-based hospital and diagnostic centre management system developed and operated by Oxitech Software Ltd., a company registered in Dhaka, Bangladesh. In this policy, “Oxitech”, “we”, “us” and “our” mean Oxitech Software Ltd.
This policy applies to:
- The Wellness Studio platform and all of its modules, including Lab and Pathology, Indoor and Outdoor Pharmacy, Reception, Hospital and Outdoor Billing, Doctor Serial, Nurse Station, Accounts, Human Resources, Inventory Management and Asset Management.
- The Online Report Delivery service, through which patients receive secure links to their diagnostic reports.
- Our marketing website at oxitechbd.com and any demo request or contact forms on it.
- Support channels operated by Oxitech, including phone, WhatsApp, email and in-app chat.
- Onboarding and data migration services we perform for a facility before go-live.
It does not apply to the independent privacy practices of a healthcare facility that licenses Wellness Studio, nor to third-party websites that may be linked from our site.
02Key terms
| Term | Meaning in this policy |
|---|---|
| Facility | The hospital, diagnostic centre, clinic, polyclinic or pharmacy that licenses Wellness Studio and enters into a service agreement with Oxitech. Also referred to as the Customer. |
| Patient Data | Any information relating to an identified or identifiable patient that is entered into, generated by or stored in Wellness Studio. This includes demographic, clinical, diagnostic, prescription and billing information. |
| Health Data | The subset of Patient Data that reveals physical or mental health status, including test results, diagnoses, treatment records, vital signs and medication history. Treated as a special category requiring heightened protection. |
| Authorised User | An individual granted login credentials by the Facility, such as a doctor, nurse, lab technician, pharmacist, receptionist, accountant or administrator. |
| Data Controller | The party that determines the purposes and means of processing personal data. For Patient Data this is the Facility. |
| Data Processor | The party that processes personal data on behalf of, and under the documented instructions of, the Controller. For Patient Data this is Oxitech. |
| Sub-processor | A third party engaged by Oxitech to assist in delivering the service, such as a cloud hosting provider or SMS gateway. |
| Processing | Any operation performed on data, including collection, recording, storage, retrieval, use, transmission, restriction, erasure or destruction. |
03Controller and processor roles
This distinction determines who is accountable for what, and it is the single most important part of this policy to understand.
The Facility is the Data Controller of Patient Data
The healthcare facility that licenses Wellness Studio decides which patients are registered, what clinical information is recorded, who on its staff may see it, and how long it is kept. The facility remains the custodian of its patient records and is responsible for obtaining any patient consent required under Bangladeshi law and professional practice standards.
Oxitech is the Data Processor of Patient Data
We store, transmit and process Patient Data solely to deliver the Wellness Studio service to the facility, and only in accordance with the facility’s documented instructions and our service agreement. We do not decide the purposes for which Patient Data is used, and we do not use it for our own commercial purposes.
Oxitech is a Data Controller for a narrow set of data
We act as Controller only for information that is genuinely ours to manage, namely:
- Facility account and contract records, including billing and subscription history.
- Business contact details of the facility’s administrative and commercial contacts.
- Support tickets and correspondence raised with our team.
- Demo requests and enquiries submitted through our website.
- System-level security logs and aggregated, non-identifying performance telemetry.
Your patient records belong to your facility, not to Oxitech. We hold them the way a bank holds money in a vault: we secure them, we maintain the vault, and we open it only when you instruct us to or when the law compels us.
04Information we process
4.1 Patient and health information
Entered by Authorised Users of the facility in the course of providing care. Depending on which modules the facility uses, this may include:
| Category | Examples |
|---|---|
| Identifiers | Name, patient ID, age, date of birth, sex, address, mobile number, guardian or next-of-kin details, National ID or passport number where the facility records it |
| Clinical records | Presenting complaints, diagnoses, doctor's notes and orders, treatment plans, procedure records, discharge summaries |
| Diagnostic data | Test requisitions, sample barcodes, laboratory and pathology results, reference ranges, quality control flags, turnaround times, generated PDF reports |
| Nursing records | Vital signs including blood pressure, temperature, oxygen saturation and pulse, medication administration logs, ward and bed assignment |
| Medication records | Prescriptions, dispensing records from indoor and outdoor pharmacy, batch and expiry data linked to a dispensing event |
| Admission data | Registration, admission, transfer and discharge records, bed occupancy, visitor logs |
| Appointment data | Doctor serial numbers, booking times, queue position, attendance and cancellation history |
| Financial data | Invoices, itemised charges, payments received, outstanding dues, payment method, insurance or third-party payer details where recorded |
4.2 Facility staff and workforce information
Processed through the Human Resources module and through user account management:
- Employee name, designation, department, contact details and employment contract records.
- Professional qualifications and registration or licence numbers where the facility records them.
- Recruitment records, including vacancies, applicant details and interview stages.
- Attendance logs, shift rosters, overtime and leave records and balances.
- Payroll data, including salary, deductions, bonuses and tax calculations.
- Login credentials in hashed form, assigned role and permission set, and activity logs.
4.3 Facility and account information
- Facility legal name, type, address, licence or registration references and departmental structure.
- Named administrative, billing and technical contacts.
- Subscription tier, module entitlements, user seat count, invoices and payment history.
- Configuration settings, price lists, test catalogues, chart of accounts and report templates.
4.4 Operational and inventory information
- Medicine, reagent and consumable stock levels, purchase requests and Goods Received Notes.
- Supplier and vendor records, purchase history and payables.
- Asset registers, unique asset identifiers, maintenance schedules, depreciation records and warranty or AMC data.
4.5 Technical and security information
Generated automatically when the platform is used:
- IP address, browser type and version, operating system and device type.
- Login timestamps, session duration, failed authentication attempts and source location of access.
- Audit trail entries recording which Authorised User viewed, created, modified or deleted which record and when.
- Application error logs and performance diagnostics.
4.6 Website visitor information
- Information you submit voluntarily through a demo request or contact form, namely name, designation, mobile number, email address, facility name and type, location and any message you write.
- Basic analytics about pages viewed and general geographic region, collected in aggregate.
05Why we process it
Every category of data we hold serves a defined operational purpose. We do not collect data speculatively.
| Purpose | What this involves |
|---|---|
| Delivering the service | Storing, retrieving and displaying records so that Authorised Users can register patients, run tests, dispense medication, raise invoices, manage stock and produce reports. |
| Automating clinical workflow | Generating lab reports, consolidating discharge bills, calculating payroll, triggering low-stock and expiry alerts and scheduling preventive maintenance. |
| Delivering reports to patients | Sending a secure report link to the mobile number the facility has recorded, and authenticating the patient when they open it. |
| Security and integrity | Authenticating users, enforcing role-based permissions, detecting suspicious access, maintaining audit trails and preventing data loss. |
| Backup and continuity | Maintaining encrypted backups so a facility can recover from accidental deletion, hardware failure or a disaster event. |
| Technical support | Diagnosing and resolving issues raised by the facility. Support staff access Patient Data only when necessary to resolve a specific reported issue, under logged and time-limited access. |
| Billing and administration | Managing the facility's subscription, issuing invoices and collecting payment. |
| Legal and regulatory | Complying with a lawful order, court direction or regulatory requirement, and defending or establishing legal claims. |
| Service improvement | Analysing aggregated, de-identified system performance to improve speed and reliability. This never involves reading clinical content. |
06Lawful basis and consent
Oxitech processes Patient Data on the documented instruction of the facility, under the service agreement between us. The facility is responsible for establishing the lawful basis for processing under applicable Bangladeshi law and professional practice obligations, which will typically be one or more of the following:
- Provision of medical care to the patient, which is the primary basis for clinical record keeping.
- Consent obtained from the patient or their legal guardian, particularly for optional services such as receiving reports by mobile link.
- Legal obligation, where a record must be created or retained under law or regulatory direction.
- Vital interests, in a medical emergency where the patient cannot give consent.
Consent is collected by the facility at the point of care, not by Oxitech. Wellness Studio provides fields to record that consent has been obtained, but the facility remains responsible for actually obtaining it and for honouring any withdrawal.
For data where Oxitech is the Controller, such as demo requests and support correspondence, our basis is your consent when you submit an enquiry and our legitimate interest in operating and supporting our business.
07What we never do
These are absolute commitments, not preferences. They apply for the full duration of the agreement and after it ends.
08Online Report Delivery
Because this feature transmits diagnostic results outside the facility’s premises, it carries specific privacy controls that we set out separately here.
How it works
When a report is finalised, reception or lab staff may send a secure link to the mobile number recorded for that patient. The patient opens the link and views the report online without visiting the facility.
Safeguards applied
- The link points to an access-controlled page, not to an openly readable file. The report itself is not sent in the body of the message.
- Links are single-patient scopedand cannot be modified to reveal another patient’s report.
- Links expire after a validity period configured by the facility, after which they stop working.
- Patient identity is verified before the report is displayed, using a verification step configured by the facility.
- Every send and every open is recorded in the audit trail, with timestamp.
- Report pages are served over encrypted connections only.
The facility must confirm the mobile number belongs to the patient or their authorised representative, obtain the patient’s agreement to receive reports this way, and offer an alternative collection method to any patient who declines. Oxitech transmits to the number provided and cannot independently verify its ownership.
Delivery of the notification message depends on a telecommunications operator or messaging gateway. Once a message leaves our systems it travels over networks we do not control, which is why the report content itself is never placed in the message.
09Disclosure and sub-processors
9.1 Within the facility
Patient Data is visible to Authorised Users according to the role assigned to them by the facility administrator. A lab technician, a pharmacist and an accountant each see a different slice of a patient’s record. Oxitech supplies the permission framework, and the facility decides who gets which role.
9.2 Sub-processors
We engage a limited number of service providers to operate the platform. Each is bound by a written agreement imposing confidentiality and security obligations at least as protective as those in this policy, and each is permitted to process data only as needed to deliver its specific function.
| Function | What they can access |
|---|---|
| Cloud hosting and storage | Encrypted application data and encrypted backups. The provider cannot read decrypted clinical content. |
| SMS and messaging gateway | Recipient mobile number and the notification text containing a secure link. No report content or clinical results. |
| Transactional email | Recipient email address and notification content for account and system messages. |
| Payment processing | Facility billing contact and subscription payment details. No Patient Data. |
| Error and performance monitoring | Technical diagnostics and system logs. Configured to exclude clinical content. |
A current list of named sub-processors is available to any facility on request from support@oxitechbd.com. We will give facilities advance notice before adding a sub-processor that will process Patient Data.
9.3 Legal disclosure
We will disclose data outside the facility only where we are compelled to, specifically:
- In response to a valid order of a court of competent jurisdiction in Bangladesh.
- In response to a lawful and properly authorised request from a regulatory or law enforcement authority.
- Where disclosure is necessary to protect against an imminent threat to a person’s life or safety.
Where we receive such a request, we will notify the affected facility before disclosing, unless we are legally prohibited from doing so, and we will disclose only the minimum data specified in the order.
9.4 Business transfers
If Oxitech is involved in a merger, acquisition or transfer of assets, facility data may transfer to the successor entity. That entity would remain bound by this policy, and affected facilities would be notified in advance and given the opportunity to export their data and terminate before the transfer takes effect.
10Data security
Security controls are applied at every layer of the platform.
Encryption
- All data in transit is protected with TLS encryption between the user’s browser and our servers.
- Data at rest, including database contents and backup archives, is encrypted on disk.
- Passwords are stored as salted cryptographic hashes and are never recoverable in readable form, including by our own staff.
Infrastructure and network
- Servers are hardened, patched on a defined schedule and protected by network firewalls.
- Administrative access to production infrastructure is restricted to a named, minimal group of engineers.
- Each facility’s data is logically segregated so that one client’s records cannot be reached from another client’s session.
Operational controls
- Automated daily backups, stored encrypted, with periodic restoration testing.
- Continuous monitoring for anomalous login patterns and unauthorised access attempts.
- Confidentiality obligations and background-appropriate vetting for staff with access to production systems.
- Documented change management and code review before releases reach production.
- A documented incident response plan, rehearsed and reviewed periodically.
We secure the platform. The facility secures its own use of it. That means issuing individual accounts rather than shared logins, revoking access promptly when staff leave, enforcing sensible password practice, keeping workstations locked and never sharing credentials. No platform control can compensate for a shared password.
11Access control and audit
Role-based access
Wellness Studio enforces the principle of least privilege. Each Authorised User is assigned a role that grants only the permissions required for their job. A receptionist can register a patient but cannot view a lab result or a payroll record. A lab technician can enter test results but cannot alter an invoice.
Audit trails
The system records an immutable log of activity on patient records, capturing who accessed the record, what action they performed, and when. Facility administrators can review these logs to investigate any concern about inappropriate access by their own staff.
Oxitech support access
When our support team needs to access a facility’s environment to resolve a reported issue:
- Access is granted only in connection with a specific support request.
- Access is time limited and revoked once the issue is resolved.
- Every action taken is recorded in the same audit trail the facility can review.
- Staff access the minimum data necessary to diagnose the reported problem.
12Data location and transfers
Wellness Studio is built for Bangladeshi healthcare facilities, and our default position is that Patient Data is hosted on infrastructure located in Bangladesh.
- Primary storage and backups for Patient Data are held in Bangladesh unless the facility agrees otherwise in writing.
- Where any processing must occur outside Bangladesh, for example through a messaging or monitoring provider, we limit it to the minimum data required and impose contractual protections on the recipient.
- Facilities with specific data residency requirements should raise them before contracting so that we can confirm what we can accommodate.
13Retention and deletion
While the facility is a client
Patient records are retained for as long as the facility requires them. Retention periods for medical records are set by the facility in line with applicable Bangladeshi medical record-keeping obligations and its own clinical governance policy. Oxitech does not delete clinical records on its own initiative.
When the agreement ends
- The facility may request a complete export of its data in a structured, machine-readable format.
- Data remains available for a defined post-termination window specified in the service agreement, so the facility can complete migration.
- After that window, production data is permanently deleted.
- Encrypted backup copies are purged on the normal backup rotation cycle, after which no copy remains.
- On request, we will provide written confirmation that deletion has been completed.
Other retention
- Account, contract and invoice records are retained as required for tax, accounting and statutory purposes.
- Security and audit logs are retained for a defined period to support investigation of security incidents.
- Demo requests and enquiries that do not lead to a contract are deleted once they are no longer needed.
We may be required to suspend deletion of specific records where they are subject to a legal hold, court order or active regulatory proceeding. In that case we retain only the records covered by the hold, and only for as long as required.
14Patient rights
Patients have rights over their health information. Because the facility is the Controller of that information, patients exercise these rights through the facility that treated them, not through Oxitech directly.
Right of access
To obtain a copy of the health records the facility holds about them.
Right of correction
To have factually inaccurate demographic or record information corrected.
Right to information
To be told what data is held, why, and who it has been shared with.
Right to withdraw consent
To stop receiving reports by mobile link, or to withdraw consent for any optional processing.
Right to restrict
To ask the facility to limit certain processing, subject to clinical and legal obligations.
Right to complain
To raise a concern with the facility, and to escalate to the relevant regulatory authority.
How this works in practice:
- The patient contacts the facility that treated them.
- The facility verifies the patient’s identity, which is essential to prevent disclosure to the wrong person.
- The facility retrieves, corrects or restricts the record within Wellness Studio using the tools we provide.
- If the facility needs technical assistance to fulfil the request, we support them promptly.
We will not disclose or amend clinical records on a direct request from a patient, because we cannot verify identity or clinical context. We will refer the patient to the treating facility and, where appropriate, notify the facility that a request has been made.
A correction right does not extend to altering a clinical opinion or a validated diagnostic result. Where a clinical entry is disputed, the facility records an amendment or annotation rather than overwriting the original, preserving the integrity of the medical record.
15Facility responsibilities
Privacy in a clinical system is a shared duty. By using Wellness Studio, the facility undertakes to:
- Obtain any patient consent required by law or professional standards before recording or transmitting data.
- Issue individual named accounts to every staff member and prohibit shared logins.
- Assign the minimum role each user needs, and review role assignments periodically.
- Revoke access immediately when a staff member leaves or changes duties.
- Ensure the accuracy of the data entered, including patient contact numbers used for report delivery.
- Set and apply retention periods consistent with its legal and clinical governance obligations.
- Review audit logs where inappropriate internal access is suspected.
- Maintain its own patient-facing privacy notice describing how it handles patient information.
- Notify Oxitech without undue delay if it becomes aware of a security incident affecting the platform.
16Minors and sensitive categories
Paediatric records
Wellness Studio is used in facilities that treat children. Records for a patient under 18 are created and accessed under the authority of a parent or legal guardian, in line with the facility’s clinical policy. Guardian details are recorded alongside the patient record. Where a report link is sent, it is sent to the guardian’s number as recorded by the facility.
Our marketing website is directed at healthcare businesses and is not intended for children. We do not knowingly collect information from children through it.
Particularly sensitive information
Some diagnostic results carry heightened sensitivity and elevated risk of stigma or discrimination if disclosed improperly. Facilities handling such results should consider restricting the roles that can view them, and should think carefully before enabling mobile report delivery for those specific test types. Wellness Studio provides role-level controls to support this, but the clinical judgement is the facility’s to make.
17Breach notification
If we become aware of a security incident that has compromised, or is reasonably likely to have compromised, Patient Data or facility data, we will act on the following basis.
- Contain and investigate. We isolate the affected systems and begin investigation immediately on detection.
- Notify the facility without undue delay. We will inform affected facilities promptly once we have confirmed an incident, and will not withhold notification pending a complete investigation.
- Explain what happened. Our notification will describe the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures we have taken or propose to take.
- Support the facility’s own obligations. As Controller, the facility may need to notify patients or a regulator. We will supply the information it needs to do so.
- Remediate. We close the vulnerability, and we review the incident to prevent recurrence.
If you believe there has been unauthorised access to your Wellness Studio environment, contact us immediately at support@oxitechbd.com or call 01318800830. Treat it as urgent even if you are unsure.
18Website and cookies
This section applies to our marketing website only, not to the Wellness Studio application.
| Type | Purpose |
|---|---|
| Strictly necessary | Enable core site function such as page navigation and form submission. The site cannot operate without these. |
| Analytics | Aggregated understanding of which pages are visited so we can improve the site. Not used to identify individuals. |
We do not run third-party advertising networks, behavioural retargeting or cross-site tracking on our website. You can block or delete cookies through your browser settings, though blocking strictly necessary cookies may prevent forms from working. Our Cookie Policy sets out the full detail.
Within the Wellness Studio application itself, we use only session cookies required to keep an Authorised User securely logged in. These are functional and are not used for tracking.
19Regulatory compliance
Wellness Studio is designed to help facilities meet their obligations under the Bangladeshi legal and regulatory framework applicable to healthcare providers, including:
- The Medical Practice and Private Clinics and Laboratories (Regulation) Ordinance and associated licensing requirements for private clinics, hospitals and diagnostic laboratories.
- Directorate General of Drug Administration (DGDA) requirements relevant to pharmacy operation, stock handling and medicine record keeping.
- Professional confidentiality duties applicable to registered medical and dental practitioners.
- Bangladeshi law governing digital systems, electronic records and information security.
- Applicable tax and financial record-keeping requirements relevant to billing and accounting records.
Bangladesh’s dedicated data protection legislation continues to develop. We monitor these developments and will update our practices and this policy as new obligations take effect. Facilities subject to additional requirements, for example through an international partner or funder, should raise this with us so we can confirm what we can support.
Our security practices are modelled on recognised information security principles for health information systems. Where a facility requires evidence of specific certification or a formal security assessment, contact us and we will tell you exactly what we currently hold.
20Changes to this policy
We may update this policy to reflect changes to the platform, our sub-processors or applicable law. When we do:
- We update the effective date and version number at the top of this page.
- For material changes affecting how Patient Data is processed, we notify facility administrators by email in advance of the change taking effect.
- We keep previous versions available on request so facilities can see what changed.
Continued use of Wellness Studio after a change takes effect constitutes acceptance of the updated policy. A facility that objects to a material change should contact us before the effective date.
21Contact us
For any question about this policy, to request our sub-processor list, to raise a data protection concern or to report a suspected security incident, contact us using the details below.
Privacy and Data Protection
Mark your message "Privacy Enquiry" for priority routingTelephone
Support is available 24 hours a day, 7 days a weekGeneral Enquiries
Sales, demos and commercial questionsRegistered Office
Oxitech Software Ltd.
Level-06, Holland Center, Badda, Dhaka, Bangladesh · www.oxitechbd.comWe aim to acknowledge every privacy enquiry within 2 business hours and to provide a substantive response within 7 business days. If your concern relates to a facility’s handling of your own health records, please contact that facility directly, as they are the custodian of your medical record.