My Hospital · For hospital administrators

Privacy Policy

How Sasthotech handles information in My Hospital, the mobile app that gives hospital owners, administrators and authorised managers a live view of their hospital in Sasthotech HMS.

Effective 6 October 2026 Last updated 6 October 2026 Android package com.sasthotech.admin.hrms

In short

  • My Hospital is a management app for hospital owners, administrators and staff they authorise. Accounts are created and controlled by the hospital in Sasthotech HMS. Patients do not use the app.
  • Your hospital's records belong to your hospital. Sasthotech processes them only to provide the service.
  • We use information to sign you in, show the data your role allows, and send the notifications you rely on.
  • No advertising, no analytics trackers, and we never sell personal information.
  • You can request deletion of your account at any time on our account deletion page.

1Who we are and our role

Sasthotech ("Sasthotech", "we", "us") builds Sasthotech HMS, hospital management software used by hospitals, clinics and diagnostic centres ("Hospitals"). My Hospital (the "App") is the companion mobile app for the people who run those Hospitals.

  • Hospital records such as bills, payments, income and expenses, patient activity, admissions, appointments, inventory, staff, attendance and payroll belong to the Hospital. The Hospital decides how they are used and is responsible for them. Sasthotech processes them on the Hospital's instructions.
  • Account, session and device information described in section 3 is processed by Sasthotech to run and secure the App.

2For hospital administrators

If you manage a Hospital that uses My Hospital:

  • You control access. Your Hospital decides who has an account, which role they hold and what they can see. Roles and permissions set in Sasthotech HMS apply to the App.
  • You can end access quickly. Disabling a user in HMS, or asking us to revoke their sessions, signs them out of the App on every device.
  • Patient and staff data stays your Hospital's. Your Hospital remains responsible for having a lawful basis to record patient and staff information in HMS and for informing them as local law requires. The App only displays what is already in your Hospital's system.
  • Requests on behalf of your Hospital. Administrators can ask us to delete staff accounts, export Hospital data, or delete Hospital data when the service ends. Send requests from your Hospital's registered administrator email to admin@sasthotech.com.
  • Confidentiality. Sasthotech staff access Hospital data only when needed to provide support, fix a problem or meet a legal obligation.

3Information we collect

Category What it includes Source
Account Name, email address or username, phone number, role and Hospital. Your password is sent securely to our servers to verify you and is never stored on your device. Your Hospital and you
Session and security Sign-in and last-activity time, IP address, and device and app details (device model, OS version, user agent). A session token on your device keeps you signed in; our servers keep only a cryptographic hash of it. Collected automatically
Notifications A Firebase Cloud Messaging push token, an app installation ID, and the notifications sent to you (title, message, time, read status). Your device and our servers
Hospital records The financial, operational and staff information your role permits. These may include patient names and health-related service details recorded by your Hospital. Your Hospital's HMS
Preferences Settings such as light or dark theme, stored only on your device. You

We do not collect precise location, contacts, photos, files, camera or microphone data, and we do not use advertising identifiers.

4How we use information

  • Verify your identity, sign you in and keep your session secure.
  • Show the Hospital records your role is authorised to access.
  • Send notifications and reports about activity at your Hospital.
  • Detect and investigate unauthorised access or misuse, for example by reviewing active sessions and revoking lost devices.
  • Maintain, troubleshoot and improve the App's reliability.
  • Provide support and respond to requests.
  • Comply with legal obligations and enforce our agreements.

We process this information to provide the service your Hospital has engaged us for, for our legitimate interest in keeping the App secure and reliable, and where the law requires it. We do not use it for advertising or sell it.

5How we share information

  • Your Hospital. Your Hospital's administrators can see account and activity information for their organisation.
  • Service providers working for us under confidentiality and security obligations:
    • Google Firebase Cloud Messaging delivers push notifications (Firebase privacy).
    • Cloud hosting providers run our servers and databases.
  • Legal reasons. When required by law, court order or a valid government request, or to protect the safety and rights of patients, users, Hospitals or Sasthotech.
  • Business transfers. As part of a merger, acquisition or sale of assets, with this policy continuing to apply.

6Device permissions

  • Internet is required to reach your Hospital's data.
  • Notifications are optional. You can allow or block them at any time in your device settings; the App works without them.

7Security

  • All traffic between the App and our servers is encrypted (HTTPS/TLS).
  • Session tokens are stored on our servers only as cryptographic hashes.
  • Access to Hospital records is limited by Hospital and by role.
  • Sessions expire, end when you sign out, and can be revoked remotely.
  • Production systems are accessible only to authorised Sasthotech personnel.

No system is perfectly secure. If a security incident affects your information, we will notify affected Hospitals and users as required by law.

8How long we keep information

  • Sessions: until they expire or are revoked, then up to 90 days for security auditing.
  • Push tokens: removed when you sign out, the device is revoked, or the account is deleted.
  • Notifications: kept while your account is active.
  • Hospital records: retained as your Hospital instructs and as its legal, tax and medical record-keeping duties require.
  • Server logs: up to 90 days for security and troubleshooting.

9Your choices and rights

Depending on the law that applies to you, you may ask us to:

  • give you access to the personal information we hold about you;
  • correct inaccurate information;
  • delete your account and associated personal information;
  • restrict or object to certain processing; and
  • stop processing based on consent, such as notifications.

Email admin@sasthotech.com from the address on your account. We will verify the request and reply within 30 days. Requests about Hospital records may be completed together with your Hospital.

10Where information is processed

Information may be processed on servers outside your country, including by our service providers. When we transfer information we take steps to keep it protected in line with this policy and applicable law.

11Children

The App is for hospital administrators and staff and is not directed to anyone under 18. We do not knowingly collect personal information from children through the App.

12Changes to this policy

We will update this policy when the App changes, for example when we add new features. We will change the "Last updated" date and, for material changes, notify users in the App or through their Hospital before the change takes effect.

13Contact us

Sasthotech
Rajshahi, Bangladesh
admin@sasthotech.com