Legal · Privacy & Terms

Privacy Policy & Terms

Wellness Studio processes some of the most sensitive information that exists: patient health records, diagnostic results, prescriptions and financial data. This policy explains exactly what we collect, why we collect it, who can see it, how long we keep it, and the controls that protect it.

Effective:7 August 2026Last updated:7 August 2026Version:1.0Applies to:Wellness Studio platform and oxitechbd.com

The short version

  • Your facility owns its data. Oxitech processes patient data only on your written instruction.
  • We never sell patient data. Not to advertisers, insurers, pharmaceutical companies or data brokers.
  • Encrypted end to end. In transit and at rest, with role-based access and full audit trails.
  • Hosted for Bangladesh. Primary data residency is Bangladesh unless you agree otherwise in writing.
  • No secondary use. We do not mine patient records to build products or train models.
  • You can export and delete. Full data export on request, and deletion on contract termination.

01Who we are and what this covers

Wellness Studio is a cloud-based hospital and diagnostic centre management system developed and operated by Oxitech Software Ltd., a company registered in Dhaka, Bangladesh. In this policy, “Oxitech”, “we”, “us” and “our” mean Oxitech Software Ltd.

This policy applies to:

  • The Wellness Studio platform and all of its modules, including Lab and Pathology, Indoor and Outdoor Pharmacy, Reception, Hospital and Outdoor Billing, Doctor Serial, Nurse Station, Accounts, Human Resources, Inventory Management and Asset Management.
  • The Online Report Delivery service, through which patients receive secure links to their diagnostic reports.
  • Our marketing website at oxitechbd.com and any demo request or contact forms on it.
  • Support channels operated by Oxitech, including phone, WhatsApp, email and in-app chat.
  • Onboarding and data migration services we perform for a facility before go-live.

It does not apply to the independent privacy practices of a healthcare facility that licenses Wellness Studio, nor to third-party websites that may be linked from our site.

02Key terms

TermMeaning in this policy
FacilityThe hospital, diagnostic centre, clinic, polyclinic or pharmacy that licenses Wellness Studio and enters into a service agreement with Oxitech. Also referred to as the Customer.
Patient DataAny information relating to an identified or identifiable patient that is entered into, generated by or stored in Wellness Studio. This includes demographic, clinical, diagnostic, prescription and billing information.
Health DataThe subset of Patient Data that reveals physical or mental health status, including test results, diagnoses, treatment records, vital signs and medication history. Treated as a special category requiring heightened protection.
Authorised UserAn individual granted login credentials by the Facility, such as a doctor, nurse, lab technician, pharmacist, receptionist, accountant or administrator.
Data ControllerThe party that determines the purposes and means of processing personal data. For Patient Data this is the Facility.
Data ProcessorThe party that processes personal data on behalf of, and under the documented instructions of, the Controller. For Patient Data this is Oxitech.
Sub-processorA third party engaged by Oxitech to assist in delivering the service, such as a cloud hosting provider or SMS gateway.
ProcessingAny operation performed on data, including collection, recording, storage, retrieval, use, transmission, restriction, erasure or destruction.

03Controller and processor roles

This distinction determines who is accountable for what, and it is the single most important part of this policy to understand.

The Facility is the Data Controller of Patient Data

The healthcare facility that licenses Wellness Studio decides which patients are registered, what clinical information is recorded, who on its staff may see it, and how long it is kept. The facility remains the custodian of its patient records and is responsible for obtaining any patient consent required under Bangladeshi law and professional practice standards.

Oxitech is the Data Processor of Patient Data

We store, transmit and process Patient Data solely to deliver the Wellness Studio service to the facility, and only in accordance with the facility’s documented instructions and our service agreement. We do not decide the purposes for which Patient Data is used, and we do not use it for our own commercial purposes.

Oxitech is a Data Controller for a narrow set of data

We act as Controller only for information that is genuinely ours to manage, namely:

  • Facility account and contract records, including billing and subscription history.
  • Business contact details of the facility’s administrative and commercial contacts.
  • Support tickets and correspondence raised with our team.
  • Demo requests and enquiries submitted through our website.
  • System-level security logs and aggregated, non-identifying performance telemetry.
In plain terms

Your patient records belong to your facility, not to Oxitech. We hold them the way a bank holds money in a vault: we secure them, we maintain the vault, and we open it only when you instruct us to or when the law compels us.

04Information we process

4.1 Patient and health information

Entered by Authorised Users of the facility in the course of providing care. Depending on which modules the facility uses, this may include:

CategoryExamples
IdentifiersName, patient ID, age, date of birth, sex, address, mobile number, guardian or next-of-kin details, National ID or passport number where the facility records it
Clinical recordsPresenting complaints, diagnoses, doctor's notes and orders, treatment plans, procedure records, discharge summaries
Diagnostic dataTest requisitions, sample barcodes, laboratory and pathology results, reference ranges, quality control flags, turnaround times, generated PDF reports
Nursing recordsVital signs including blood pressure, temperature, oxygen saturation and pulse, medication administration logs, ward and bed assignment
Medication recordsPrescriptions, dispensing records from indoor and outdoor pharmacy, batch and expiry data linked to a dispensing event
Admission dataRegistration, admission, transfer and discharge records, bed occupancy, visitor logs
Appointment dataDoctor serial numbers, booking times, queue position, attendance and cancellation history
Financial dataInvoices, itemised charges, payments received, outstanding dues, payment method, insurance or third-party payer details where recorded

4.2 Facility staff and workforce information

Processed through the Human Resources module and through user account management:

  • Employee name, designation, department, contact details and employment contract records.
  • Professional qualifications and registration or licence numbers where the facility records them.
  • Recruitment records, including vacancies, applicant details and interview stages.
  • Attendance logs, shift rosters, overtime and leave records and balances.
  • Payroll data, including salary, deductions, bonuses and tax calculations.
  • Login credentials in hashed form, assigned role and permission set, and activity logs.

4.3 Facility and account information

  • Facility legal name, type, address, licence or registration references and departmental structure.
  • Named administrative, billing and technical contacts.
  • Subscription tier, module entitlements, user seat count, invoices and payment history.
  • Configuration settings, price lists, test catalogues, chart of accounts and report templates.

4.4 Operational and inventory information

  • Medicine, reagent and consumable stock levels, purchase requests and Goods Received Notes.
  • Supplier and vendor records, purchase history and payables.
  • Asset registers, unique asset identifiers, maintenance schedules, depreciation records and warranty or AMC data.

4.5 Technical and security information

Generated automatically when the platform is used:

  • IP address, browser type and version, operating system and device type.
  • Login timestamps, session duration, failed authentication attempts and source location of access.
  • Audit trail entries recording which Authorised User viewed, created, modified or deleted which record and when.
  • Application error logs and performance diagnostics.

4.6 Website visitor information

  • Information you submit voluntarily through a demo request or contact form, namely name, designation, mobile number, email address, facility name and type, location and any message you write.
  • Basic analytics about pages viewed and general geographic region, collected in aggregate.

05Why we process it

Every category of data we hold serves a defined operational purpose. We do not collect data speculatively.

PurposeWhat this involves
Delivering the serviceStoring, retrieving and displaying records so that Authorised Users can register patients, run tests, dispense medication, raise invoices, manage stock and produce reports.
Automating clinical workflowGenerating lab reports, consolidating discharge bills, calculating payroll, triggering low-stock and expiry alerts and scheduling preventive maintenance.
Delivering reports to patientsSending a secure report link to the mobile number the facility has recorded, and authenticating the patient when they open it.
Security and integrityAuthenticating users, enforcing role-based permissions, detecting suspicious access, maintaining audit trails and preventing data loss.
Backup and continuityMaintaining encrypted backups so a facility can recover from accidental deletion, hardware failure or a disaster event.
Technical supportDiagnosing and resolving issues raised by the facility. Support staff access Patient Data only when necessary to resolve a specific reported issue, under logged and time-limited access.
Billing and administrationManaging the facility's subscription, issuing invoices and collecting payment.
Legal and regulatoryComplying with a lawful order, court direction or regulatory requirement, and defending or establishing legal claims.
Service improvementAnalysing aggregated, de-identified system performance to improve speed and reliability. This never involves reading clinical content.

06Lawful basis and consent

Oxitech processes Patient Data on the documented instruction of the facility, under the service agreement between us. The facility is responsible for establishing the lawful basis for processing under applicable Bangladeshi law and professional practice obligations, which will typically be one or more of the following:

  • Provision of medical care to the patient, which is the primary basis for clinical record keeping.
  • Consent obtained from the patient or their legal guardian, particularly for optional services such as receiving reports by mobile link.
  • Legal obligation, where a record must be created or retained under law or regulatory direction.
  • Vital interests, in a medical emergency where the patient cannot give consent.
Where consent is collected

Consent is collected by the facility at the point of care, not by Oxitech. Wellness Studio provides fields to record that consent has been obtained, but the facility remains responsible for actually obtaining it and for honouring any withdrawal.

For data where Oxitech is the Controller, such as demo requests and support correspondence, our basis is your consent when you submit an enquiry and our legitimate interest in operating and supporting our business.

07What we never do

These are absolute commitments, not preferences. They apply for the full duration of the agreement and after it ends.

We never sell patient dataTo advertisers, insurers, pharmaceutical companies, marketers or data brokers, under any circumstance or price.
We never use clinical records for advertisingNo profiling, targeting, retargeting or audience building from health information.
We never train AI models on your patient dataClinical records are not used as training data for machine learning models, ours or anyone else's.
We never share data between facilitiesEach facility's data is logically isolated. One client can never see another client's records.
We never disclose records to third parties for commercial gainIncluding research organisations, unless the facility has separately instructed and authorised it in writing.
We never access records out of curiositySupport access requires a logged reason, is time limited, and is visible in the facility's audit trail.

08Online Report Delivery

Because this feature transmits diagnostic results outside the facility’s premises, it carries specific privacy controls that we set out separately here.

How it works

When a report is finalised, reception or lab staff may send a secure link to the mobile number recorded for that patient. The patient opens the link and views the report online without visiting the facility.

Safeguards applied

  • The link points to an access-controlled page, not to an openly readable file. The report itself is not sent in the body of the message.
  • Links are single-patient scopedand cannot be modified to reveal another patient’s report.
  • Links expire after a validity period configured by the facility, after which they stop working.
  • Patient identity is verified before the report is displayed, using a verification step configured by the facility.
  • Every send and every open is recorded in the audit trail, with timestamp.
  • Report pages are served over encrypted connections only.
Facility responsibilities for this feature

The facility must confirm the mobile number belongs to the patient or their authorised representative, obtain the patient’s agreement to receive reports this way, and offer an alternative collection method to any patient who declines. Oxitech transmits to the number provided and cannot independently verify its ownership.

A note on SMS

Delivery of the notification message depends on a telecommunications operator or messaging gateway. Once a message leaves our systems it travels over networks we do not control, which is why the report content itself is never placed in the message.

09Disclosure and sub-processors

9.1 Within the facility

Patient Data is visible to Authorised Users according to the role assigned to them by the facility administrator. A lab technician, a pharmacist and an accountant each see a different slice of a patient’s record. Oxitech supplies the permission framework, and the facility decides who gets which role.

9.2 Sub-processors

We engage a limited number of service providers to operate the platform. Each is bound by a written agreement imposing confidentiality and security obligations at least as protective as those in this policy, and each is permitted to process data only as needed to deliver its specific function.

FunctionWhat they can access
Cloud hosting and storageEncrypted application data and encrypted backups. The provider cannot read decrypted clinical content.
SMS and messaging gatewayRecipient mobile number and the notification text containing a secure link. No report content or clinical results.
Transactional emailRecipient email address and notification content for account and system messages.
Payment processingFacility billing contact and subscription payment details. No Patient Data.
Error and performance monitoringTechnical diagnostics and system logs. Configured to exclude clinical content.

A current list of named sub-processors is available to any facility on request from support@oxitechbd.com. We will give facilities advance notice before adding a sub-processor that will process Patient Data.

9.3 Legal disclosure

We will disclose data outside the facility only where we are compelled to, specifically:

  • In response to a valid order of a court of competent jurisdiction in Bangladesh.
  • In response to a lawful and properly authorised request from a regulatory or law enforcement authority.
  • Where disclosure is necessary to protect against an imminent threat to a person’s life or safety.

Where we receive such a request, we will notify the affected facility before disclosing, unless we are legally prohibited from doing so, and we will disclose only the minimum data specified in the order.

9.4 Business transfers

If Oxitech is involved in a merger, acquisition or transfer of assets, facility data may transfer to the successor entity. That entity would remain bound by this policy, and affected facilities would be notified in advance and given the opportunity to export their data and terminate before the transfer takes effect.

10Data security

Security controls are applied at every layer of the platform.

Encryption

  • All data in transit is protected with TLS encryption between the user’s browser and our servers.
  • Data at rest, including database contents and backup archives, is encrypted on disk.
  • Passwords are stored as salted cryptographic hashes and are never recoverable in readable form, including by our own staff.

Infrastructure and network

  • Servers are hardened, patched on a defined schedule and protected by network firewalls.
  • Administrative access to production infrastructure is restricted to a named, minimal group of engineers.
  • Each facility’s data is logically segregated so that one client’s records cannot be reached from another client’s session.

Operational controls

  • Automated daily backups, stored encrypted, with periodic restoration testing.
  • Continuous monitoring for anomalous login patterns and unauthorised access attempts.
  • Confidentiality obligations and background-appropriate vetting for staff with access to production systems.
  • Documented change management and code review before releases reach production.
  • A documented incident response plan, rehearsed and reviewed periodically.
Shared responsibility

We secure the platform. The facility secures its own use of it. That means issuing individual accounts rather than shared logins, revoking access promptly when staff leave, enforcing sensible password practice, keeping workstations locked and never sharing credentials. No platform control can compensate for a shared password.

11Access control and audit

Role-based access

Wellness Studio enforces the principle of least privilege. Each Authorised User is assigned a role that grants only the permissions required for their job. A receptionist can register a patient but cannot view a lab result or a payroll record. A lab technician can enter test results but cannot alter an invoice.

Audit trails

The system records an immutable log of activity on patient records, capturing who accessed the record, what action they performed, and when. Facility administrators can review these logs to investigate any concern about inappropriate access by their own staff.

Oxitech support access

When our support team needs to access a facility’s environment to resolve a reported issue:

  • Access is granted only in connection with a specific support request.
  • Access is time limited and revoked once the issue is resolved.
  • Every action taken is recorded in the same audit trail the facility can review.
  • Staff access the minimum data necessary to diagnose the reported problem.

12Data location and transfers

Wellness Studio is built for Bangladeshi healthcare facilities, and our default position is that Patient Data is hosted on infrastructure located in Bangladesh.

  • Primary storage and backups for Patient Data are held in Bangladesh unless the facility agrees otherwise in writing.
  • Where any processing must occur outside Bangladesh, for example through a messaging or monitoring provider, we limit it to the minimum data required and impose contractual protections on the recipient.
  • Facilities with specific data residency requirements should raise them before contracting so that we can confirm what we can accommodate.

13Retention and deletion

While the facility is a client

Patient records are retained for as long as the facility requires them. Retention periods for medical records are set by the facility in line with applicable Bangladeshi medical record-keeping obligations and its own clinical governance policy. Oxitech does not delete clinical records on its own initiative.

When the agreement ends

  1. The facility may request a complete export of its data in a structured, machine-readable format.
  2. Data remains available for a defined post-termination window specified in the service agreement, so the facility can complete migration.
  3. After that window, production data is permanently deleted.
  4. Encrypted backup copies are purged on the normal backup rotation cycle, after which no copy remains.
  5. On request, we will provide written confirmation that deletion has been completed.

Other retention

  • Account, contract and invoice records are retained as required for tax, accounting and statutory purposes.
  • Security and audit logs are retained for a defined period to support investigation of security incidents.
  • Demo requests and enquiries that do not lead to a contract are deleted once they are no longer needed.
Legal holds

We may be required to suspend deletion of specific records where they are subject to a legal hold, court order or active regulatory proceeding. In that case we retain only the records covered by the hold, and only for as long as required.

14Patient rights

Patients have rights over their health information. Because the facility is the Controller of that information, patients exercise these rights through the facility that treated them, not through Oxitech directly.

Right of access

To obtain a copy of the health records the facility holds about them.

Right of correction

To have factually inaccurate demographic or record information corrected.

Right to information

To be told what data is held, why, and who it has been shared with.

Right to withdraw consent

To stop receiving reports by mobile link, or to withdraw consent for any optional processing.

Right to restrict

To ask the facility to limit certain processing, subject to clinical and legal obligations.

Right to complain

To raise a concern with the facility, and to escalate to the relevant regulatory authority.

How this works in practice:

  1. The patient contacts the facility that treated them.
  2. The facility verifies the patient’s identity, which is essential to prevent disclosure to the wrong person.
  3. The facility retrieves, corrects or restricts the record within Wellness Studio using the tools we provide.
  4. If the facility needs technical assistance to fulfil the request, we support them promptly.
If a patient contacts Oxitech directly

We will not disclose or amend clinical records on a direct request from a patient, because we cannot verify identity or clinical context. We will refer the patient to the treating facility and, where appropriate, notify the facility that a request has been made.

A correction right does not extend to altering a clinical opinion or a validated diagnostic result. Where a clinical entry is disputed, the facility records an amendment or annotation rather than overwriting the original, preserving the integrity of the medical record.

15Facility responsibilities

Privacy in a clinical system is a shared duty. By using Wellness Studio, the facility undertakes to:

  • Obtain any patient consent required by law or professional standards before recording or transmitting data.
  • Issue individual named accounts to every staff member and prohibit shared logins.
  • Assign the minimum role each user needs, and review role assignments periodically.
  • Revoke access immediately when a staff member leaves or changes duties.
  • Ensure the accuracy of the data entered, including patient contact numbers used for report delivery.
  • Set and apply retention periods consistent with its legal and clinical governance obligations.
  • Review audit logs where inappropriate internal access is suspected.
  • Maintain its own patient-facing privacy notice describing how it handles patient information.
  • Notify Oxitech without undue delay if it becomes aware of a security incident affecting the platform.

16Minors and sensitive categories

Paediatric records

Wellness Studio is used in facilities that treat children. Records for a patient under 18 are created and accessed under the authority of a parent or legal guardian, in line with the facility’s clinical policy. Guardian details are recorded alongside the patient record. Where a report link is sent, it is sent to the guardian’s number as recorded by the facility.

Our marketing website is directed at healthcare businesses and is not intended for children. We do not knowingly collect information from children through it.

Particularly sensitive information

Some diagnostic results carry heightened sensitivity and elevated risk of stigma or discrimination if disclosed improperly. Facilities handling such results should consider restricting the roles that can view them, and should think carefully before enabling mobile report delivery for those specific test types. Wellness Studio provides role-level controls to support this, but the clinical judgement is the facility’s to make.

17Breach notification

If we become aware of a security incident that has compromised, or is reasonably likely to have compromised, Patient Data or facility data, we will act on the following basis.

  1. Contain and investigate. We isolate the affected systems and begin investigation immediately on detection.
  2. Notify the facility without undue delay. We will inform affected facilities promptly once we have confirmed an incident, and will not withhold notification pending a complete investigation.
  3. Explain what happened. Our notification will describe the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures we have taken or propose to take.
  4. Support the facility’s own obligations. As Controller, the facility may need to notify patients or a regulator. We will supply the information it needs to do so.
  5. Remediate. We close the vulnerability, and we review the incident to prevent recurrence.
Report a suspected incident

If you believe there has been unauthorised access to your Wellness Studio environment, contact us immediately at support@oxitechbd.com or call 01318800830. Treat it as urgent even if you are unsure.

18Website and cookies

This section applies to our marketing website only, not to the Wellness Studio application.

TypePurpose
Strictly necessaryEnable core site function such as page navigation and form submission. The site cannot operate without these.
AnalyticsAggregated understanding of which pages are visited so we can improve the site. Not used to identify individuals.

We do not run third-party advertising networks, behavioural retargeting or cross-site tracking on our website. You can block or delete cookies through your browser settings, though blocking strictly necessary cookies may prevent forms from working. Our Cookie Policy sets out the full detail.

Within the Wellness Studio application itself, we use only session cookies required to keep an Authorised User securely logged in. These are functional and are not used for tracking.

19Regulatory compliance

Wellness Studio is designed to help facilities meet their obligations under the Bangladeshi legal and regulatory framework applicable to healthcare providers, including:

  • The Medical Practice and Private Clinics and Laboratories (Regulation) Ordinance and associated licensing requirements for private clinics, hospitals and diagnostic laboratories.
  • Directorate General of Drug Administration (DGDA) requirements relevant to pharmacy operation, stock handling and medicine record keeping.
  • Professional confidentiality duties applicable to registered medical and dental practitioners.
  • Bangladeshi law governing digital systems, electronic records and information security.
  • Applicable tax and financial record-keeping requirements relevant to billing and accounting records.
Evolving data protection law

Bangladesh’s dedicated data protection legislation continues to develop. We monitor these developments and will update our practices and this policy as new obligations take effect. Facilities subject to additional requirements, for example through an international partner or funder, should raise this with us so we can confirm what we can support.

Our security practices are modelled on recognised information security principles for health information systems. Where a facility requires evidence of specific certification or a formal security assessment, contact us and we will tell you exactly what we currently hold.

20Changes to this policy

We may update this policy to reflect changes to the platform, our sub-processors or applicable law. When we do:

  • We update the effective date and version number at the top of this page.
  • For material changes affecting how Patient Data is processed, we notify facility administrators by email in advance of the change taking effect.
  • We keep previous versions available on request so facilities can see what changed.

Continued use of Wellness Studio after a change takes effect constitutes acceptance of the updated policy. A facility that objects to a material change should contact us before the effective date.

21Contact us

For any question about this policy, to request our sub-processor list, to raise a data protection concern or to report a suspected security incident, contact us using the details below.

Privacy and Data Protection

support@oxitechbd.com

Mark your message "Privacy Enquiry" for priority routing

Telephone

01318800830

Support is available 24 hours a day, 7 days a week

General Enquiries

info@oxitechbd.com

Sales, demos and commercial questions

Registered Office

Oxitech Software Ltd.

Level-06, Holland Center, Badda, Dhaka, Bangladesh · www.oxitechbd.com

We aim to acknowledge every privacy enquiry within 2 business hours and to provide a substantive response within 7 business days. If your concern relates to a facility’s handling of your own health records, please contact that facility directly, as they are the custodian of your medical record.