Last updated: 19 July, 2026
This Privacy Policy explains how Uposham (“we”, “us”, “our”) collects, uses, shares, and protects personal and health information when you use the Uposham telehealth service — the website, the patient and doctor dashboards at app.uposham.com, the in-chat assistant (including Facebook Messenger), and the WordPress plugin that powers them (collectively, the “Service”).
Because the Service handles health information, we treat it as sensitive personal data and apply stricter safeguards to it than to ordinary contact details. Please read this policy carefully. If you do not agree with it, do not use the Service.
Contact / Data Controller
Uposham
Mirpur DOHS, Dhaka
Email: privacy@uposham.com
Data Protection contact: dpo@uposham.com
1. Who this policy covers
- Patients who book appointments, chat with the assistant, or receive prescriptions.
- Doctors and clinic staff who hold accounts and treat patients.
- Visitors to the public website and doctor directory.
2. Information we collect
2.1 Information you provide
| Category | Examples |
|---|---|
| Patient identity & contact | Full name, phone number, email address, postal address |
| Health information (PHI) | Symptoms, diagnosis, on-examination findings and vitals (e.g. age, sex, blood pressure), prescribed medicines and dosages, advice, follow-up dates, and prescription history |
| Appointment data | Requested doctor, date, time, status, consultation fee, and payment status |
| Doctor profile | Specialty, qualifications, consultation fee, bio, phone, BMDC registration number, and signature image |
| Communications | Messages you send to the chat assistant or to us for support |
2.2 Information collected automatically
- Technical/log data — IP address, browser/user-agent, timestamps, and request metadata generated by our servers and hosting provider.
- Access audit logs — when a doctor opens a patient’s cross-visit history, we record the acting doctor’s ID, the patient’s ID, and the time (identifiers only — never names or phone numbers in the audit trail) to protect against unauthorized access.
- Cookies/session — WordPress authentication cookies for logged-in doctors and staff. See Section 9.
2.3 Information from third parties
- Facebook / Meta (Messenger) — if you contact us via Messenger, we receive your message content and the page-scoped sender ID that Meta provides.
- Payment provider — payment confirmation and reference for your booking (we do not receive or store your full card details).
3. How we use your information
We use the information to:
- Create and manage patient and doctor accounts.
- Schedule, confirm, reschedule, and cancel appointments.
- Enable doctor–patient consultations, including video visits.
- Let doctors write, sign, and deliver prescriptions, and view a patient’s relevant clinical history.
- Power the chat assistant that helps patients book and get information.
- Send you transactional notifications (booking, payment, prescription, and video-visit reminders) by chat, email, or SMS.
- Process payments for consultations.
- Maintain security, prevent abuse, debug, and audit access to health data.
- Comply with legal, regulatory, and medical record-keeping obligations.
4. Legal bases for processing
Where applicable law requires a legal basis, we rely on:
- Provision of a service / contract — to deliver the telehealth care you request.
- Consent — for optional communications and for processing health information through the chat assistant and AI features. You may withdraw consent at any time (Section 8).
- Legitimate interests — security, fraud prevention, and service improvement, balanced against your rights.
- Legal obligation — retaining medical records where the law requires.
5. How we share information
We share information only as needed to run the Service:
- Your treating doctor and authorized clinic staff. A doctor can access a patient’s clinical history only where they share at least one appointment with that patient. Doctors cannot browse patients they have not treated, and a doctor’s uploaded media (e.g. signature) is scoped to their own account.
- Service providers / sub-processors, strictly to operate the Service:
- Video conferencing — Jitsi / 8×8 (JaaS) for video visits.
- AI/LLM provider — the configured assistant backend (e.g. OpenAI, DeepSeek, or a self-hosted OpenAI-compatible endpoint) to generate chat replies. Conversation content needed to answer may be sent to this provider.
- Messaging — Facebook / Meta (Messenger), and our SMS and email providers, to deliver messages and notifications.
- Payment provider — to process consultation payments.
- Hosting/infrastructure — our server and hosting vendor.
- Chatbot backend — our own notification endpoint that receives booking/prescription events (transmitted over signed, authenticated webhooks).
- Legal and safety — to comply with law, enforce our terms, or protect the rights, safety, and health of patients, staff, or the public.
- Business transfers — in a merger, acquisition, or asset sale, subject to this policy.
We do not sell your personal or health information.
International transfers
Some providers listed above may process data outside your country. Where we transfer data internationally, we take steps to ensure an appropriate level of protection consistent with applicable law.
6. AI-assisted chat
The Service includes a chat assistant that can help with booking and general information. Please note:
- Messages you send to the assistant may be processed by a third-party AI provider to generate a response.
- The assistant is not a substitute for professional medical judgment and does not provide diagnosis or emergency care. In an emergency, contact local emergency services.
- Do not share more sensitive information with the assistant than necessary.
7. Data retention
- Medical records (prescriptions, clinical notes, vitals) are retained for the period required by applicable medical record-keeping laws, then deleted or anonymized.
- Account and contact data are retained while your account is active and for a reasonable period afterward.
- Logs and audit trails are kept for a limited period for security and compliance.
- If the site operator uninstalls the plugin with the “delete all data” option enabled, telehealth tables — including medical records — are permanently removed. This is an administrator action and is irreversible.
8. Your rights and choices
Subject to applicable law, you may:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your information (subject to medical record-keeping obligations).
- Object to or restrict certain processing.
- Withdraw consent for optional communications or AI processing.
- Port your data where required by law.
To exercise these rights, contact us at privacy@uposham.com. We may need to verify your identity before acting. We aim to respond within the timeframe required by law.
9. Cookies and sessions
We use strictly necessary cookies for authenticated doctor and staff sessions (standard WordPress login/session cookies). We do not use these for advertising. Public pages may use minimal cookies required for security and basic function.
10. Security
We apply technical and organizational safeguards, including:
- Role- and capability-based access control for doctors, staff, and patients.
- The “shared-appointment” access gate for patient health records, with an audit log of history access.
- Signed, authenticated webhooks (HMAC signatures) for event and payment notifications.
- Nonce/CSRF protection and input sanitization/output escaping across the application.
- Secrets (API keys, signing secrets, video and payment credentials) kept server-side and never exposed to browsers.
No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you and the relevant authorities as required by law.
11. Children’s privacy
The Service is intended to be used by adults. Where a patient is a minor, a parent or legal guardian is responsible for providing information and consent on the minor’s behalf, consistent with applicable law and clinical practice.
12. Third-party links and services
The Service may link to or rely on third-party services (e.g. video, messaging, payment). Their use of your information is governed by their own privacy policies. We encourage you to review them.
13. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new “Last updated” date and, where required, communicated to you. Your continued use of the Service after an update constitutes acceptance of the revised policy.
14. How to contact us
Questions, requests, or complaints about privacy:
Uposham
Mirpur DOHS, Dhaka
Email: privacy@uposham.com
If you are not satisfied with our response, you may have the right to lodge a complaint with the data protection authority in your jurisdiction.