Legal

Privacy Policy

CureByte Technologies ("we," "our," or "us") is committed to protecting the privacy and security of all individuals who interact with our platforms, websites, and digital systems — including doctors, patients, medical society members, conference delegates, and website visitors. This Privacy Policy explains how we collect, use, store, and safeguard your information across all our services.

01

Information We Collect

We collect different categories of information depending on how you interact with our services:

Information You Provide Directly

  • Conference Registrations: Name, email, phone number, professional designation, institution/clinic name, city, CNIC (for Pakistani conferences requiring identity verification), and payment information.
  • Doctor Directory Listings: Full name, qualifications, specialization, clinic/hospital address, contact numbers, consultation hours, and professional biography.
  • Patient Management System (VisionCare): Patient name, age, gender, contact details, clinical records, visual acuity data, diagnostic findings, prescriptions, and treatment history — entered by the authorized doctor or clinic staff.
  • Journal Submissions: Author names, affiliations, email addresses, manuscript files, and peer review communications.
  • Contact Forms & Inquiries: Name, email, phone, and message content.

Information Collected Automatically

  • Device type, operating system, browser type and version
  • IP address and approximate geographic location
  • Pages visited, time spent, and navigation patterns
  • Referral source and search queries that led to our platforms
02

How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, operate, and maintain our medical digitalization platforms and services
  • To process conference registrations, issue badges, and manage event logistics
  • To maintain and display doctor directory listings and facilitate patient appointment bookings
  • To store and retrieve patient clinical records within the VisionCare system for authorized healthcare providers
  • To manage manuscript submissions and editorial workflows for medical journals
  • To send service-related communications: registration confirmations, system notifications, and support responses
  • To improve our platforms through usage analytics and user feedback
  • To comply with legal obligations and protect against fraud or unauthorized access
03

Patient & Medical Data

Important: Patient data within the VisionCare Patient Management System is owned and controlled entirely by the subscribing doctor or clinic. CureByte Technologies acts solely as the technology provider and data processor — not a data controller for patient records.

Patient clinical data (visual acuity, diagnostic findings, prescriptions, treatment plans) is:

  • Stored in encrypted databases with access restricted to the subscribing doctor and their authorized staff only
  • Never shared with third parties for marketing, research, or any purpose beyond system operation without explicit written consent from the data controller (the doctor/clinic)
  • Accessible to CureByte technical staff only for system maintenance, troubleshooting, or data backup — under strict access logging and non-disclosure obligations
  • Subject to data export and deletion requests from the subscribing doctor/clinic at any time
04

Data Sharing & Third Parties

We do not sell, rent, or trade your personal information. We may share limited data with:

  • Cloud Infrastructure Providers: Data is hosted on secure cloud servers (e.g., AWS, DigitalOcean) with industry-standard encryption. These providers process data only as instructed by us under data processing agreements.
  • Payment Processors: Conference registration payments are processed through trusted third-party payment gateways. We do not store your full credit/debit card details on our servers.
  • Medical Society Partners: Conference delegate information may be shared with the organizing medical society (e.g., OSP Lahore, POOA, APOP) for event management purposes only, as disclosed during registration.
  • AI Technology Partners: For AI and decision support features, anonymized or de-identified data may be shared with international technology partners exclusively for model training and improvement — never in a personally identifiable form without explicit consent.
  • Legal Requirements: We may disclose information if required by law, court order, or government regulation.
05

Data Security Measures

We implement industry-standard security measures to protect your data:

SSL/TLS encryption for all data in transit
AES-256 encryption for data at rest
Role-based access control (RBAC) across all systems
Audit logging for all sensitive data access
Automated daily backups with geo-redundancy
Regular vulnerability scanning and security audits
06

Cookies & Tracking Technologies

Our websites use cookies and similar technologies for:

  • Essential Cookies: Required for login sessions, form submissions, and platform functionality. These cannot be disabled.
  • Analytics Cookies: Help us understand how visitors use our platforms so we can improve them. We use privacy-respecting analytics that do not track individuals across websites.

You can manage cookie preferences through your browser settings. Disabling essential cookies may affect platform functionality.

07

Your Rights

Depending on your jurisdiction and relationship with us, you may have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data, subject to legal retention requirements
  • Data Portability: Request your data in a structured, machine-readable format
  • Opt-Out: Unsubscribe from marketing communications at any time using the link in any email

To exercise any of these rights, contact us at privacy@curebytetechnologies.com. We will respond within 30 days.

08

Data Retention

  • Conference Data: Retained for 3 years after the event for record-keeping and certificate verification, then anonymized or deleted.
  • Directory Listings: Retained for as long as the doctor maintains an active listing. Upon removal request, data is deleted within 30 days.
  • Patient Records (VisionCare): Retained for the duration of the clinic's subscription. Upon subscription termination, the clinic receives a full data export, and server data is deleted within 60 days unless legally required to retain longer.
  • Journal Data: Published articles and metadata are retained permanently as part of the scientific record. Author contact information may be retained for editorial communication.
  • Server Logs & Analytics: Automatically deleted after 90 days.
09

Children's Privacy

Our platforms are not directed at individuals under the age of 16. We do not knowingly collect personal information from children. Patient data in the VisionCare system is entered by or on behalf of the responsible adult (parent/guardian) or the treating physician, in accordance with medical consent practices.

10

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. We will notify significant changes by posting the updated policy on this page with a revised "Last updated" date. For material changes affecting patient data handling, we will also notify affected VisionCare subscribers directly via email.