🏛️ PMJAY Claim Trust ENGINE ← Back to Portal

Privacy Policy

Effective Date: 12 August 2026 Last Updated: 12 August 2026

PMJAY Claim Trust Engine (“PMJAY Claim Trust Engine”, “we”, “our”, or “the Platform”) respects the privacy and confidentiality of information processed through our application.

This Privacy Policy explains what information we collect, how information is processed, how claim and patient information is handled, and the security measures used to protect information.

By accessing or using the Platform, you acknowledge this Privacy Policy.

1. Our Privacy Approach

PMJAY Claim Trust Engine follows a data-minimization and local-first processing approach for supported claim-processing workflows.

The Platform is designed to keep patient and claim-processing information separate from account and authentication information.

Where a claim-processing feature is identified as local browser processing, imported claim files are processed within the user’s browser and are not intentionally transmitted to or stored in the Platform’s application database.

2. Information We May Collect

Depending on how you use the Platform, we may process:

Account Information

  • Name
  • Email address
  • Account credentials
  • Account status
  • Subscription information
  • Package or plan information
  • Device verification information
  • Authentication/session information

This information is used to provide and protect your account and provide requested services.

3. Patient and Claim Information

The Platform may be used by authorized users to process claim-related information. Examples may include:

  • Registration ID
  • Beneficiary information
  • Patient-related claim information
  • Procedure information
  • Claim amount
  • Approved amount
  • Paid amount
  • Deduction information
  • TDS information
  • Doctor information
  • Doctor payout information
  • UTR/payment reference information
  • Other information contained in an imported claim file

Local Processing

For supported local-processing workflows:

  1. The user selects a claim file from their device.
  2. The browser reads the selected file.
  3. Claim information is processed locally within the browser.
  4. Validation and calculations are performed locally.
  5. Reports/results are generated for the user.
  6. Claim records are not intentionally transmitted to the Platform’s application server.
  7. Claim records are not intentionally written to the Platform’s account database.

Users remain responsible for protecting files and reports downloaded or exported to their devices.

4. Server-Side Account Information

The Platform’s server-side systems may process information required for:

  • User accounts
  • Authentication
  • Subscriptions
  • Packages
  • Payment records
  • Device verification
  • Demo requests
  • Consultation requests
  • Application configuration

The account database is not intended to function as a repository for patient claim spreadsheets in supported local-processing workflows.

5. Authentication Information

Authentication services may process:

  • Email address
  • Securely processed password credentials
  • OTP verification information
  • Authentication/session information
  • Account status
  • Device verification information

Passwords must not be stored in plain text.

6. Payment Information

Where payments or subscriptions are supported, payment processing may involve authorized payment providers.

The Platform may maintain transaction or payment-reference information required for subscription management, verification, accounting, customer support, or fraud prevention.

7. Analytics

The current application architecture does not intentionally use third-party analytics services to collect patient or claim information.

The Platform does not intentionally send patient names, claim numbers, claim amounts, UTR numbers, or similar claim fields to analytics services.

8. Error Reporting

The current application architecture does not intentionally use third-party error-monitoring services to collect patient or claim information.

9. Cookies and Browser Storage

The Platform may use cookies or browser storage required for application functionality. Browser storage may include:

  • Authentication/session information
  • User preferences
  • Theme preferences
  • Application configuration
  • Calculation preferences

Supported claim-processing workflows are designed so that patient and claim spreadsheet records are not intentionally stored in persistent browser storage.

10. Data Security

We use reasonable technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, or destruction. Security controls may include:

  • HTTPS/TLS encrypted communications
  • Secure authentication
  • Password hashing
  • OTP verification
  • Session controls
  • Access controls
  • Server-side secret management
  • Input validation
  • Data minimization
  • Separation of authentication and claim-processing workflows
  • Local browser processing for supported claim workflows

No software system can be guaranteed to be completely immune from security threats.

11. Patient Information Protection

Users should only process patient or claim information for which they have appropriate authorization. Users should:

  • Use authorized devices.
  • Protect account credentials.
  • Protect exported reports.
  • Avoid unnecessary sharing of patient information.
  • Follow applicable hospital policies.
  • Follow applicable government and data-protection requirements.

12. Data Retention

For supported local-processing workflows, claim information is processed within the user’s browser and is not intentionally retained in the Platform’s application database.

Claim files and reports saved to the user’s device remain subject to the user’s device storage, backup, and deletion practices.

Account information may be retained as reasonably necessary to provide services, maintain security, resolve disputes, and meet applicable legal requirements.

13. Data Sharing

We do not intentionally sell patient or claim information.

Patient and claim information processed through supported local-processing workflows is not intentionally transmitted to third-party analytics or advertising services.

Account-related information may be shared with service providers where necessary to operate the Platform, including hosting, payment, authentication, email/OTP, or technical infrastructure providers.

14. Government Portals

PMJAY Claim Trust Engine is a software workflow and governance platform. It does not replace official government systems.

Where a hospital is required to submit, verify, or update information through an official government portal, the hospital remains responsible for completing that process through the applicable official system.

15. User Responsibility

Users are responsible for:

  • The legality of information they process.
  • Having appropriate authorization.
  • Accuracy of imported information.
  • Protecting downloaded files.
  • Protecting login credentials.
  • Verifying generated calculations and reports.
  • Following applicable healthcare, government, contractual, and data-protection requirements.

16. Security Incidents

If we become aware of a security incident involving information processed by our systems, we will assess the incident and take reasonable steps appropriate to the circumstances, including investigation, containment, remediation, and notification where required by applicable law.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be published on this page with a revised “Last Updated” date.

18. Contact

Privacy & Support Email: ask@support.pmjayclaimtrustengine.com

Address:
SHREE KRUPA SANDAM MITRA NAGAR
BEED 431122

19. Important Scope

Statements regarding local browser processing apply specifically to features technically implemented as local-processing workflows. Future features requiring server-side processing or storage must be reviewed and appropriately disclosed.