SOMIRAA. Calm operations for better care.
← Back to SOMIRAA home

Legal

Privacy Policy

This Privacy Policy explains how Positron, operator of SOMIRAA (“Positron”, “SOMIRAA”, “we”, “us”, or “our”), handles personal data when you visit somiraa.com, use the SOMIRAA clinic platform, or use Somiraa Desktop.

1. Operator and contact

Positron’s legal contact address is:

B-17, Vrujvardhan Coop H Soc Ltd,
Vatva Road Isanpur,
Ahmedabad - 382415, India

Our privacy and grievance contact is admin@somiraa.com. Do not email passwords, tokens, recovery phrases, encryption keys, or clinical records.

2. Scope and roles

Clinics generally determine why and how patient and clinical data is processed and are responsible for notices, lawful grounds or consent, professional duties, retention, and patient requests. Positron provides the platform and generally processes clinic-managed data on the Clinic’s instructions. Positron is a controller for website visitors, prospects, business contacts, account administrators, security records, and its direct customer relationship.

3. Data we process

4. Purposes and legal grounds

We use data to provide and administer SOMIRAA; authenticate and licence users; perform Clinic-requested workflows; provide support; secure, troubleshoot, and improve reliability and accessibility; communicate about the Service; prevent misuse; and meet legal obligations. Depending on the context, processing is based on a contract, consent, legal obligation, legitimate use or other ground permitted by applicable law. We do not sell patient data or use it for advertising.

5. Website storage and service providers

The website and web app may use essential browser local storage or session storage for authentication state, session continuity, security, and user preferences. Clearing browser data or signing out may remove that local state. We do not use patient data for behavioural advertising.

We may use vetted providers for hosting and infrastructure, identity and authentication, security, support, payment or communications functions, and professional advice. They receive only data reasonably necessary for their work and are subject to contractual or legal duties. Customer-selected Google and Microsoft services receive data only when a Clinic enables the relevant feature. We may also disclose data where law requires it, to protect rights or safety, or in a corporate transaction with appropriate safeguards.

6. Local-first desktop backups

Somiraa Desktop stores normal Clinic operations locally. If a Clinic enables customer backup, the app creates an encrypted Clinic snapshot and uploads it directly to the Clinic’s selected Google Drive or OneDrive account. Backup content is not routed through SOMIRAA cloud infrastructure. Positron does not receive provider tokens, backup contents, recovery phrases, or encryption keys through this feature.

Automatic backups retain the latest 30 automatic bundles; older automatic bundles are deleted from the provider account by the app. Manual backups are not automatically pruned and remain until the Clinic deletes them from its provider account.

7. Google API data and Limited Use

Somiraa Desktop’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only to provide or improve the user-facing feature the Clinic enables, and not for advertising, creditworthiness, sale, or unrelated profiling.

OAuth credentials are protected locally using operating-system safe storage and the encrypted lifecycle database and are not sent to Positron.

8. Microsoft and transactional email

When a Clinic authorises Microsoft backup or email delivery, the corresponding encrypted backup files or transactional email data are sent directly to Microsoft under the Clinic’s instruction. Email data can include recipients, subject and message body, appointment/calendar, invoice and dispatch information, and required attachments. The provider controls delivery and its own account records under its terms and privacy policy.

9. Disconnecting, disabling, revoking, and deleting

Disconnecting backup or disabling email inside Somiraa Desktop removes the locally protected provider credential and stops future access from that installation. It does not revoke the OAuth grant at Google or Microsoft, delete provider-side account records, or delete backup files already stored remotely. To revoke the grant, use the provider’s account-security settings. To remove retained backup files, delete them in the provider account.

Disabling email removes the locally protected email credential, but safe delivery/outbox metadata—such as event type, status, attempts, timestamps, provider message identifier, and error category—may remain for operational continuity, security, dispute handling, and legal compliance. Message bodies and recipient content are not retained in that outbox metadata.

10. Security and retention

We use reasonable technical, organisational, and administrative safeguards, including access controls, authentication, encryption where appropriate, least privilege, and security logging. No system is completely secure; Clinics must protect devices, credentials, mailboxes, provider accounts, and recovery phrases.

We keep data only as long as reasonably needed to provide the Service, meet contractual and legal duties, preserve security and audit evidence, resolve disputes, and enforce agreements. Clinics control their patient-record retention subject to law and their agreement with Positron. The fixed desktop backup rules are stated in section 6.

11. Rights, requests, grievance redressal, and nomination

Subject to applicable law, a person may request access to a summary of personal data and processing, correction, completion or updating, erasure, withdrawal of consent, grievance redressal, and nomination of another individual to exercise rights in the event of death or incapacity. Consent withdrawal does not affect processing already lawfully completed and may prevent an optional feature from continuing.

For patient or Clinic-managed records, first contact the relevant Clinic. Positron will reasonably assist the Clinic where it acts as processor. For data controlled by Positron, email admin@somiraa.com or write to the address in section 1. State your name, relationship to the Clinic, registered email/mobile or account identifier, the right requested, and enough detail to locate the relevant record. We may request proportionate identity verification.

Positron will acknowledge and address a grievance within a reasonable period not exceeding 90 days, subject to verification, applicable exemptions, and lawful retention. If internal grievance redressal does not resolve the matter, you may escalate to the Data Protection Board of India where applicable under Indian law.

12. International processing

Positron and service providers may process data in India and other permitted countries. We use safeguards appropriate to the data, provider, and applicable transfer restrictions.

13. Children’s data

SOMIRAA is a business service for Clinics, not a consumer service directed to children. A Clinic may process a minor patient’s data only when authorised and in compliance with healthcare, privacy, parental-consent, and professional requirements.

14. Changes

We may update this Policy for changes in law, the Service, or our practices. We will publish the updated version and date. Somiraa Desktop requires an authorised Clinic representative to accept a new version when we designate re-acceptance as required.