Sanjeevani HealthBILLING Staff sign in

SANJEEVANI HEALTH BILLING

Privacy Policy

Last updated

Sanjeevani Health operates Sanjeevani Health Billing for authorised clinic staff. This policy covers staff using the application and people whose patient or financial details are entered by the clinic. The public overview and policies can be read without signing in.

Bookings on our patient website are covered by its separate website Privacy Policy.

Information entered by the clinic

We use these records to administer clinic billing, maintain accurate accounts, record collections, prepare reports, control staff access, and resolve support requests. Patient and financial information is entered by the clinic; it is not obtained from Google.

Google data we access

Staff sign-in requests only these basic Google permissions:

Our authentication system also receives sign-in tokens and stores account linkage information. Google handles your Google password; Sanjeevani Health does not receive or store it.

We do not request Gmail messages, Google Drive files, Calendar, Contacts, or other Google account content. Patients do not need Google sign-in to receive a bill.

How we use Google data

We use your account identifier and verified email address to identify you, check the approved staff list, and create your signed-in session. Basic profile information is stored with your login account. The clinic administrator assigns your role and branch access.

Google data is used for authentication, access control, account support, and security. We do not send patient or billing records to Google through sign-in, sell personal information, or use Google user data for advertising, credit scoring, or training AI models.

Our use of Google user data follows the Google API Services User Data Policy, including its Limited Use requirements. Personnel access is limited to authorised administration, requested support, security, and legal obligations.

Storage and security

The application runs on Cloudflare Workers. Cloudflare D1 stores authentication, patient, billing, payment, referral, and audit records. Authentication records include basic Google profile information, account identifiers, tokens, and session information. Google access and refresh tokens are encrypted by the authentication system before database storage. HTTPS protects information in transit.

Approved staff access is checked against roles and branch permissions. Hosted sessions use secure, HTTP-only cookies. Session records can include IP addresses and browser information; authentication rate-limit and operational logs support service security and diagnosis.

The browser may retain unfinished forms and pending billing requests in session storage so staff can recover work and safely retry interrupted submissions. Successful sign-out clears the application's saved drafts in that tab. Use trusted devices and sign out after use, especially on shared devices.

Sharing and service providers

Providers may process information outside your location. We may disclose information where required by law or needed to investigate abuse and protect the service. Google data is shared only for the disclosed sign-in and hosting functions, requested support, security, or legal obligations.

Cookies and public pages

Public pages do not require an application session. The staff workspace uses session cookies to keep approved staff signed in. Cloudflare may process connection information for delivery and security.

Retention and deletion

Staff accounts and Google authentication records are retained while needed to provide and secure access. Signing out ends the current session; it does not delete the profile, Google account linkage, or business records. Administrators can disable staff access. Account and token deletion requests are handled manually; there is no self-service account deletion.

Patient, billing, payment, referral, and audit records are retained as needed for clinic operations, accounting, disputes, and applicable recordkeeping obligations. Removing a staff account does not remove issued bills or audit history. We assess deletion requests against these obligations and explain information that must be retained. Backup copies may remain until removed through the applicable retention and recovery processes. This application does not automatically delete financial history after a fixed period.

Your choices and contact

You can choose not to authorise Google sign-in; you will still be able to read the public pages. You can review or revoke access through Google Account connections. Revoking Google access does not automatically delete stored records or end an existing application session. Also sign out and contact us if you want staff access disabled or stored account information deleted.

For access, correction, deletion, or privacy requests, tell us whether your request concerns a patient record or staff Google account. We may verify your identity before disclosing or changing records.

Sanjeevani Health
Phone: +91 62962 22497
Ward Number 7, Opposite Congress Party Office, Mekhliganj Bajar, Mekhliganj, Cooch Behar, West Bengal 735304, India.

You can also use the Sanjeevani Health contact page. Do not share your Google password or sign-in tokens.

Changes to this policy

We update this page when practices change and display its update date above. New uses of Google data will be disclosed before they begin, with additional consent where required. See also our Terms of Use.