How Galant processes personal data through HealNTrack, VaidSetu and related healthcare modules when acting as a processor for customer organisations.
Effective date: July 28, 2026 | Last updated: July 28, 2026
HealNTrack and VaidSetu are generally provided to hospitals, clinics, healthcare professionals and other organisations. The customer organisation normally decides why patient, staff and operational information is processed and therefore acts as the Data Fiduciary or Controller. Galant normally processes that information on the customer’s documented instructions as its Data Processor or Processor.
The customer’s privacy notice, consent process, medical-record policy and professional obligations apply to its use of the product. This notice explains Galant’s product role and baseline practices. Where Galant provides a direct-to-individual feature and determines the purpose of processing, Galant will provide an additional feature-specific notice.
See also the Corporate Website Privacy Policy for galantit.com inquiries and recruitment.
Depending on product configuration and authorised use, the product may process:
The exact data set is defined in the customer order form, implementation record or processing schedule.
Galant may process customer-controlled information only to:
Galant will not repurpose customer-controlled clinical data for unrelated advertising.
Unless a separate written agreement expressly states otherwise and the processing is legally permitted:
Where voice features are enabled, the user interface and deployment documentation must state whether audio is processed locally, in Galant infrastructure or by a subprocessor; when recording begins; retention periods; hosting region; and how users review or correct transcripts. Transcription errors can occur. No product page should state that audio is deleted immediately unless deletion has been verified across temporary files, queues, logs, provider systems and backups.
AI-generated or automatically extracted content is a draft or support output. Authorised healthcare professionals remain responsible for reviewing patient identity, clinical accuracy, medication details, contraindications, dosage, allergies, investigations, diagnosis, treatment and follow-up before use.
The product must not be used as the sole basis for emergency, diagnosis, prescribing, treatment or discharge decisions unless that use has been specifically validated, approved and licensed where required.
See also the AI & Medical Use Disclaimer for short-form notices, academic and evaluation use on this website, and safety reporting.
Galant may use approved subprocessors for cloud hosting, processing, speech recognition, model inference, communications, support, monitoring, backup and security under appropriate confidentiality, security and data-processing terms. A current subprocessor list is provided to customers under contract. No production vendor may receive patient or clinical data merely because it is convenient for development.
Depending on the deployment, measures may include encryption in transit and at rest, role-based access, administrative MFA, tenant separation, audit logs, monitoring, backups, vulnerability management and incident-response procedures. Security is a shared responsibility. Customers must configure users, roles, endpoints, integrations and local procedures appropriately.
The hosting region and subprocessors for each deployment are identified in the order form or deployment documentation. Cross-border processing occurs only as authorised by contract and applicable law. Where HIPAA applies, an executed Business Associate Agreement is required before Galant handles PHI as a business associate.
Customer-controlled information is retained according to the customer agreement, documented instructions and applicable healthcare-record requirements. Galant does not promise immediate deletion where backups, incident evidence or law require controlled retention.
Patients and product users should normally submit access, correction, deletion, consent or grievance requests to the hospital, clinic, employer or organisation controlling the account. Galant will assist the customer as required by the agreement and law.
Healthcare customers may process children’s information for lawful healthcare purposes with the involvement of parents, guardians or other authorised persons as required by applicable law and the customer’s policies.
Galant maintains an incident-response process. Customers must promptly report suspected unauthorised access or disclosure. Galant will notify customers and authorities according to the contract and applicable law.
Hosting provider, region, subprocessors, voice/AI retention, export formats and deletion timelines for each production environment are documented in the customer order form, deployment facts sheet and Data Processing Addendum — not on this public summary page.
Privacy email: privacy@galantit.com
Support: info@galantit.com