Legal
Privacy policy
Last updated 18 September 2026
Who we are
Curanto ("we", "us") builds and operates the Curanto hospital management system and this website, curanto.in. We are based in Ahmedabad, Gujarat, India. For anything in this policy, write to hello@curanto.in.
Two kinds of data
On this website we are a data fiduciary for the details you give us (for example on the demo form). Inside the Curanto product, the hospital or clinic that subscribes is the data fiduciary for its patients' and staff's data, and we process that data on its instructions under our agreement with it. This policy covers both, and says which is which.
What we collect on this website
- What you type into the demo, quote or contact form: name, work email, phone, organisation, facility details and your message.
- Attribution parameters in the link you arrived by (for example a campaign tag), so we know which page brought you here.
- Standard server logs: IP address, browser, pages requested and timestamps, kept for security and capacity planning.
- A bot-check token from Cloudflare Turnstile on the form, if enabled. No tracking cookies are set by this website. Your theme preference is stored only in your browser.
Why, and for how long
- To reply to your request and, if you ask, to run a demo, send a quote and plan onboarding. Kept while the conversation is live and for up to 24 months after our last contact, then deleted or anonymised.
- To keep the website secure and available. Server logs are kept for up to 90 days.
- We do not sell personal data, and we do not use it for advertising networks.
Data inside the product
- Stored in India, encrypted at rest and in transit, isolated per organisation by database row-level security, and audited with an append-only log.
- Processed only to provide the service to the subscribing hospital or clinic, which controls access through roles and permissions.
- Patient consent records, data-principal requests (access, correction, erasure) and retention rules are features of the product the hospital operates; we support them with tooling and, when the hospital asks, with direct help.
- Crash reports and analytics from the product are scrubbed of patient data before they leave the device or server.
Who else touches the data
We use a small number of processors to run the service: Indian-region cloud hosting and storage, a transactional email provider for reminders and notifications, a payment gateway for subscriptions and patient payments, and error and analytics monitoring configured to exclude personal data. Each is bound by contract to process data only on our instructions. A current list is available on request.
Your rights
Under the Digital Personal Data Protection Act, 2023 you can ask what personal data we hold about you, ask for it to be corrected or erased, withdraw consent, and nominate someone to exercise these rights for you. Write to hello@curanto.in and we respond within 30 days. If you are a patient of a hospital using Curanto, please raise your request with the hospital first; we will help them fulfil it.
Changes
When this policy changes we update the date above. Material changes to how product data is handled are notified to subscribing organisations in advance.