Privacy

Privacy Policy

Last updated: 7 August 2026

Introduction

Prescriply is a cloud-based prescription and chamber-management service for doctors in Bangladesh, operated by Prescriply — a registered Bangladeshi business based in Dhaka, Bangladesh. This policy explains what information we collect, why we collect it, how we store and protect it, and what rights you have.

Two kinds of people are involved in this service: (1) doctors and team members — who open an account and act as the data controller when entering patient information, and (2) patients — whose clinical information is entered by the doctor. For patient clinical data, Prescriply acts mainly as a data processor on behalf of the responsible doctor, who is the controller.

What data we collect

  • Doctor account: full name, mobile number, registration type (MBBS/BDS, medical assistant or portable card) and registration number, email (if provided), qualifications/designation, an optional logo and signature image, and your password (hashed with bcrypt — never stored in plain text).
  • Patient clinical information (entered by the doctor): patient name, age/sex, mobile, visit type, chief complaints, diagnosis (including ICD-10 codes), medicines and dosing, investigations, advice and follow-up details.
  • OTP and verification: one-time codes sent to mobile numbers for registration, password reset and patient-portal access, and BM&DC registration details used for the Verified badge.
  • Financial / settlement information: chamber-wise fees, settlement model (FULL / SPLIT / RENT) and accounting. We do not store card or wallet numbers ourselves — subscription payments are processed by EPS (the Electronic Payment Switch, supporting bKash, Nagad and cards).
  • Usage information: login times, device/browser information, IP address and technical logs needed to keep the service secure and to improve it.

We collect only what the service needs, we do not use patient information for advertising, and we never sell your data.

Why we collect it & legal basis

We design Prescriply around recognised data-protection principles — consent, data minimisation, purpose limitation, security and accountability. Our processing rests on the following bases:

  • Consent for sensitive (health) data: patient clinical information is processed for medical purposes, on the basis of the patient’s consent obtained by the responsible doctor and the legitimate provision of care by a healthcare professional.
  • Consent: for OTP verification and for SMS sent during registration, password reset and through the patient portal.
  • Performance of a contract: to operate your account, create prescriptions, and provide chamber-wise revenue and settlement accounting.
  • Legal obligation: to respond to applicable law or a valid request from a competent authority.

Security monitoring and fraud prevention are carried out, as far as possible, on the basis of consent or legal obligation and in our capacity as service operator.

Who we share data with (sub-processors)

We do not sell your data. To run the service we share only the information necessary with the following trusted sub-processors:

  • Amazon Web Services (AWS): application hosting, file storage and outbound email.
  • Amazon RDS for PostgreSQL (AWS): managed PostgreSQL database hosting.
  • Amazon Bedrock: model inference for the optional AI-assist features.
  • GenNet: OTP and notification SMS delivery.
  • EPS (Electronic Payment Switch): subscription and credit-pack payment processing (bKash, Nagad and cards).
  • Meta Platforms (Facebook / Instagram): advertising measurement (Meta Pixel & Conversions API) on our public marketing pages and the account pages only — never any patient or clinical data.
  • Google (Analytics): anonymous usage analytics on our public website.
  • Microsoft (Clarity): heatmaps and session replay on our public marketing pages and the account pages (sign-up, sign-in, password reset and first-run setup) only — it records the pages you visit, your clicks, scrolling and mouse movement, and a replay of those pages as they appeared to you. It is never loaded inside the app, the patient portal, or any prescription view.

Each sub-processor receives only the information needed for its specific task. For our security measures, see Data Protection.

Advertising & analytics

To reach doctors who may benefit from Prescriply, we advertise on Meta (Facebook and Instagram) and measure how those ads perform using the Meta Pixel and Conversions API, alongside Google Analytics. We also use Microsoft Clarity to see how those pages are actually used. These tools tell us which ads led to a doctor signing up and where a page confuses people, so we do not waste spend — they run only on our public marketing pages and the account pages (sign-up, sign-in, password reset and first-run setup).

  • No patient or clinical data is ever shared with these tools. They are never loaded inside the app, the patient portal, or any prescription view — only on public marketing pages and the account pages.
  • For measurement, only a doctor’s own sign-up contact detail (mobile or email) may be sent in irreversibly hashed form so Meta can match a sign-up to an ad. We never send a patient’s details, a diagnosis, a medicine, or a prescription link.
  • Microsoft Clarity is a session-replay tool. It runs on our public marketing pages and on every account page — creating an account, signing in, resetting a password, and the first-run setup wizard where you enter your registration number, chamber details and fees. On those pages it records the page address, your clicks, scrolling, mouse movement and a reconstruction of the page as it appeared to you, together with the usual technical details (approximate location from your IP address, device, browser and referrer). We use it to find broken and confusing pages. It is never loaded on the authenticated app, the patient portal, a prescription view, or the public doctor profile pages that carry a patient booking form.
  • You can limit this measurement through your browser or device ad-privacy settings and your Facebook ad preferences.

Where your data is stored & cross-border transfer

The application, database and file storage are currently hosted in AWS Asia Pacific (Singapore) — region ap-southeast-1, with our PostgreSQL database on Amazon RDS in that same region and AI inference performed by Amazon Bedrock in ap-southeast-1. This means your and your patients’ data is processed outside Bangladesh.

We rely on the consent of the people concerned and on contractual data-protection commitments with our sub-processors for this cross-border processing. We monitor Bangladesh’s evolving data-protection requirements and, for sensitive health data, we are planning an in-country synchronised copy within Bangladesh — see the Data Protection page for the technical detail.

How long we keep it (retention)

We keep your data for as long as your account is active. Closing your account deactivates it — all logins stop, your public profile and online booking are taken down, and any paid plan is cancelled — but it is not by itself an erasure:

  • Clinical records are retained for at least 6 years, and longer where the law or a medico-legal requirement applies. We do not delete them on a schedule; past that period they are erased or anonymised on request, or when we no longer need them.
  • Account and identity data is retained after closure, because a retained prescription is signed with the prescriber’s name and registration number and has to stay attributable. It is also what lets you reactivate a self-closed account within 30 days.
  • Security and audit logs are kept for fraud prevention and to meet legal obligations. They are not on an automatic deletion schedule either, and the audit trail of an account closure is deliberately kept after the account is closed.

If you want your identity data erased or anonymised rather than only deactivated, ask us — see Your rights below. We will do it for everything we are not legally or medico-legally required to keep, and we will tell you plainly what we had to retain and why. Nothing above runs on an automatic timer — we have no scheduled job that erases data on a fixed date, so we do not promise one anywhere in this policy.

Your rights & patient rights

  • View and correct the information held about you.
  • Request deletion of your account and data where there is no legal obligation to retain it. We handle each request individually rather than on an automatic schedule, and we tell you what we were required to keep.
  • Withdraw consent from consent-based processing (such as SMS).
  • Patients may request to view or correct their own records through the responsible doctor, who is the controller of that data.

To exercise any of these rights, or for any privacy question, contact us at info@publicpulse.com.bd or call +880 1717-714676. We aim to respond within a reasonable time.

Security measures

  • Encryption in transit (HTTPS/TLS) and at rest at the infrastructure-provider level.
  • Passwords hashed with bcrypt — never stored in plain text.
  • Mobile OTP verification and role-based access (doctor / assistant / admin).
  • Each account’s data is isolated through tenant-based, doctorId-scoped row-level access — one practice can never see another’s data.
  • Optional two-factor authentication (2FA) via an authenticator app (TOTP) with one-time backup codes.

Children

Prescriply is built for healthcare professionals and is not intended for self-registration by anyone under 18. A minor’s clinical information may be entered lawfully by a doctor as part of their care.

Changes & contact

We may update this policy from time to time and will give appropriate notice of significant changes. For any question or complaint, contact info@publicpulse.com.bd or +880 1717-714676.

Related: Terms · Data Protection · FAQ

30 free prescriptions

Start free — the full service included

Write your first 30 prescriptions at ৳0, with chamber-wise revenue and settlement built in. No card, cancel anytime.

Start free — 30 Rx included

Free plan includes the full revenue & settlement engine