Privacy Policy

Effective Date: 04 September 2026 | Last Updated: 04 September 2026

Introduction

Easee (“Easee”, “we”, “us” or “our”) is committed to protecting personal information and handling it responsibly. This Privacy Policy explains how Easee may collect, use, disclose, retain and protect information when you visit our website, contact us, request a demonstration, purchase or use our software and services, or otherwise interact with us.

This Policy applies to the Easee website and, to the extent applicable, the Easee software platform and related services. Patient and clinical information processed through an Easee deployment is addressed in greater detail in the EMR & Patient Data Privacy section below.

By using the website or services, or by providing information to us, you acknowledge this Policy to the extent permitted by applicable law.

About Easee

Easee is an eye-care-focused SaaS platform providing specialized eye-care technology and electronic medical record (EMR) solutions for ophthalmology clinics, optometry practices, eye hospitals, eye-care professionals and related users.

Information We Collect

Depending on how you interact with Easee, we may collect:

We may also collect limited technical information such as IP address, browser and device information, operating system, pages visited, approximate usage information, and date and time of access.

How We Use Information

We may use information to:

Eye-Care and Patient Information

Easee is designed specifically for eye-care operations and clinical workflows as an eye-care SaaS and EMR platform. Ophthalmology clinics, optometry practices, eye hospitals and authorized users may use Easee to manage patient and clinical information relating to registration, optometry, AR/NCT, ophthalmology, diagnostics, surgical coordination, daycare/ward, operation theatre, health schemes, TPA/insurance and camp outreach.

Information entered into the Easee platform by a healthcare organization is different from information collected through the public Easee website. Healthcare organizations are responsible for ensuring that they have the necessary authority, notices, permissions and consents to collect and process patient information.

Easee will process customer and patient information for authorized service purposes and in accordance with applicable law and the applicable customer agreement.

Patient-identifiable, medical or confidential clinical information should not be submitted through general public website enquiry or demonstration forms unless the relevant form specifically states that such submission is supported.

Consent and Health Information Exchange

Where processing is based on consent, consent should be obtained in a manner that is appropriately informed, specific and capable of being withdrawn, subject to applicable law and legitimate retention requirements.

Where Easee supports integration with ABDM/ABHA or other health-information exchange mechanisms, information may be exchanged only in accordance with the applicable integration requirements, consent mechanisms and law. Easee does not represent that every Easee deployment has the same ABDM capability or certification; the applicable deployment and contractual documentation will govern.

ABDM's published materials emphasize consent-based exchange and state that health records remain with the healthcare provider while ABDM facilitates secure exchange between intended stakeholders.

Cookies and Similar Technologies

Easee may use cookies and similar technologies to operate the website, remember preferences, understand usage, improve performance and support security and analytics. You may manage cookies through browser settings, although disabling certain cookies may affect functionality.

Sharing and Disclosure

Easee may disclose information where reasonably necessary to:

Easee does not sell patient information as a commercial product. Where health information is exchanged through a consent-based health-information ecosystem, sharing is subject to the applicable consent and integration framework.

Security

Easee uses reasonable technical and organizational measures designed to protect information against unauthorized access, disclosure, alteration, loss or destruction. Depending on the service and deployment, safeguards may include access controls, authentication controls, monitoring, backups, secure communications and other operational security measures.

Access Control and Accountability

Access to information within the Easee platform should be limited to authorized users based on their role and legitimate operational need. Healthcare organizations remain responsible for assigning appropriate roles and permissions to their personnel and for protecting account credentials.

Where applicable, Easee may maintain records of access and processing activity for security, accountability, troubleshooting and compliance purposes.

Data Retention

Easee retains information only for as long as reasonably necessary for the purpose for which it was collected, to provide services, maintain appropriate business and clinical records, resolve disputes, protect security and comply with applicable legal or contractual obligations.

Data Subject / Data Principal Requests

Subject to applicable law and the relevant healthcare/customer relationship, individuals may have rights concerning their personal information, including access, correction, deletion or erasure where applicable, withdrawal of consent where processing is consent-based, and grievance or complaint mechanisms.

Requests may require identity verification. Where a healthcare organization controls the relevant patient record, the request may need to be directed to that healthcare organization. Easee may assist the customer as required by the applicable agreement and law.

Children's and Minor Patients' Data

Easee may process information relating to minor patients as part of healthcare services provided by healthcare organizations. Such processing must be carried out by the responsible healthcare organization and its authorized personnel in accordance with applicable law and required permissions or authorizations.

Easee will apply appropriate safeguards to information processed through its services, subject to the actual configuration and controls of the applicable deployment.

Third-Party Services

The website and platform may integrate with or link to third-party services. Those third parties may have their own terms and privacy policies. Easee is not responsible for the independent privacy or security practices of third parties outside its control.

Security Incidents

Easee maintains processes intended to identify, investigate, contain and remediate security incidents. Where an incident affects information processed for a customer, Easee will handle notification and cooperation in accordance with applicable law and the applicable customer agreement.

International Processing

Where information is processed, hosted or accessed across jurisdictions, Easee will apply the safeguards and contractual or legal requirements applicable to that processing. Specific hosting locations or cross-border arrangements may vary by service and customer deployment and should not be inferred from this Policy unless expressly stated.

Changes to this Policy

Easee may update this Policy from time to time. The latest version will be published with an updated Last Updated date. Material changes may be communicated where required or appropriate.

EMR & Patient Data Privacy Policy

Scope

This section applies to patient, clinical and eye-care information processed through the Easee eye-care EMR platform on behalf of ophthalmology clinics, optometry practices, eye hospitals and other eye-care customers.

Roles and Responsibilities

The healthcare organization or customer generally determines why patient information is collected and how it is used in the course of healthcare delivery. The customer is responsible for obtaining required permissions and consents, determining appropriate user access, maintaining clinical accuracy and complying with healthcare obligations.

Easee provides the technology platform and processes information as necessary to provide the contracted services, subject to applicable law and the customer agreement.

Categories of EMR Information

Depending on the modules and configuration used, the platform may process information such as patient identity and contact details, demographic information, appointment information, optometry and ophthalmology histories, AR/NCT and examination findings, visual and ocular findings, diagnoses, prescriptions, treatment information, diagnostic and imaging information, surgical coordination and operation-theatre information, daycare/ward information, health-scheme and TPA/insurance information, camp-outreach information, pharmacy and optical/low-vision-aid information, clinical laboratory information, contact-lens clinic information, OT stores information, uploaded documents, consent records, user/account information and audit information.

Purpose Limitation

Patient information should be processed only for defined and legitimate healthcare, administrative, billing, operational, security, interoperability and legal purposes applicable to the customer and service.

Easee should not use identifiable patient information for unrelated advertising or commercial resale.

Patient Consent

Where consent is required, the responsible healthcare organization should obtain and document appropriate consent. Consent for health-record exchange should be distinguished from consent for unrelated communications or marketing.

A withdrawal of consent does not necessarily require deletion of records where continued retention or processing is required by law, necessary for an ongoing legal obligation, or otherwise permitted under applicable law.

ABDM / ABHA Integration

Where an Easee deployment is integrated with ABDM/ABHA, applicable consent and interoperability requirements must be followed. ABDM states that health records are created and stored by healthcare providers and that ABDM facilitates secure exchange after patient consent.

Easee should describe only the ABDM/ABHA functionality and status actually enabled for the relevant deployment.

Role-Based Access

Customer administrators should configure access according to job role and legitimate need. Users should not access records outside their authorized responsibilities. Credentials must not be shared, and suspected unauthorized access should be reported promptly.

Auditability

Where supported by the deployment, access and significant processing activities may be logged to support security, accountability, troubleshooting, investigation and compliance. ABDM privacy materials emphasize audit trails and records of processing activities.

Data Security

Easee applies reasonable technical and organizational measures appropriate to the nature of the information and service. These may include authentication, access restrictions, secure communications, monitoring, backups, incident-response procedures and other safeguards.

Specific security architecture, encryption algorithms, certifications and hosting locations should be stated publicly only after technical verification.

Data Sharing

Patient information may be shared by the healthcare organization with authorized healthcare professionals, service providers, insurers, laboratories, other providers, or health-information networks where legally permitted and, where required, based on appropriate patient consent.

Easee may use service providers and subprocessors necessary to operate the platform, subject to contractual and legal safeguards.

Data Retention and Deletion

Retention periods may differ for medical records, billing information, account information, audit logs and other categories. The healthcare organization is responsible for applicable clinical-record retention obligations. Easee may retain information as necessary to provide services, satisfy contractual/legal requirements, maintain security records and resolve disputes.

Patient Access and Record Requests

Patients may request access to applicable information through the responsible healthcare organization or the applicable Easee-supported process. Identity verification and applicable legal or clinical-record requirements may apply.

Correction of Records

Requests to correct patient information should be handled through the responsible healthcare organization. Corrections should preserve appropriate clinical integrity and auditability rather than silently overwriting historical clinical information where a record of the original entry is required.

Export and Portability

Where supported by the service and applicable law, customers may request export of customer data in an available format. The scope and format of exports may depend on the service, technical limitations, legal requirements and the customer agreement.

Termination

Following termination, Easee may provide or facilitate data export in accordance with the customer agreement. Data may subsequently be deleted or retained where required for legal, security, billing, dispute-resolution or other legitimate purposes.

AI, Analytics and Automated Processing

Easee will not assume that identifiable patient information may be used for artificial-intelligence training, automated decision-making or unrelated analytics merely because it is available within the platform.

If an Easee service introduces AI or automated processing involving patient information, the applicable purpose, permissions, disclosures, safeguards and contractual terms should be established before such processing is enabled.

Research and De-identified Data

Identifiable patient information should not be used for unrelated research merely because it is stored in the EMR. Where permitted, anonymized or appropriately de-identified information may be used for legitimate analytics, research or service-improvement purposes subject to applicable law and contractual restrictions.

Eye-Care Platform Disclaimer

Easee is an eye-care technology platform and does not replace the professional judgment of ophthalmologists, optometrists or other qualified eye-care professionals. Eye-care organizations and qualified professionals remain responsible for diagnosis, treatment decisions, patient care, clinical accuracy, record accuracy and compliance with applicable requirements.

Grievances

Privacy or patient-record concerns may first be raised with the responsible healthcare organization where the organization controls the relevant patient record. Easee may be contacted for platform-related privacy or security matters using the contact details in this Policy. Where a formal grievance officer or other statutory contact is required, the applicable designated contact should be published separately.