These Terms and Conditions ("Terms") govern your access to and use of the Medbus clinic management software platform ("Platform"), associated mobile applications, and the Medbus website at medbus.in ("Website"), operated by Techbus Private Limited ("Medbus", "we", "us", or "our"), a company incorporated under the laws of India, with its registered office in Kochi, Kerala.
By accessing the Platform, registering for an account, or using any of our services, you ("User", "Client", "you") agree to be bound by these Terms in their entirety. If you do not agree, you must discontinue use immediately.
1. Definitions
- "Platform" — The Medbus cloud-based clinic management software, accessible via web browser and mobile applications.
- "Clinic Data" — All patient records, appointments, billing data, prescriptions, and clinical notes entered into the Platform by Users.
- "User" — Any individual or organisation accessing the Platform, including clinic owners, administrators, doctors, and staff.
- "Subscription" — A paid plan granting access to Platform features as described on our Pricing page.
- "Authorised User" — An individual granted access credentials by the account holder (clinic owner or administrator).
- "Unauthorised Access" — Any access to the Platform or Clinic Data by persons not explicitly authorised by the account holder.
2. Account Registration & Eligibility
- You must be at least 18 years of age and legally authorised to operate a healthcare or related business to register for Medbus.
- You agree to provide accurate, current, and complete information during registration and to keep it updated.
- You are solely responsible for maintaining the confidentiality of your login credentials (username, password, OTP codes, and API keys).
- You must notify us immediately at admin@techbus.org if you suspect any unauthorised access to your account.
- Medbus reserves the right to suspend or terminate accounts that are used in violation of these Terms.
3. User Responsibility for Account Security & Unauthorised Access
⚠️ IMPORTANT — Please read this section carefully.
Medbus implements industry-leading security measures, role-based access control, multi-factor authentication, audit trails, and High security data storage. However, the security of your account depends significantly on actions taken by you and your staff.
You are solely and entirely responsible for any unauthorised access to your account or Clinic Data that results from:
- Sharing your login credentials, passwords, or OTP codes with any unauthorised person, whether intentionally or negligently.
- Failing to enable available security features such as two-factor authentication (2FA).
- Allowing staff members, contractors, vendors, or any third party to use your account credentials.
- Failing to revoke access for former employees or terminated staff in a timely manner.
- Using weak, reused, or easily guessable passwords for your Medbus account.
- Accessing the Platform on unsecured, public, or shared devices or networks without appropriate precautions.
- Falling victim to phishing, social engineering, or other attacks where credentials are disclosed to malicious actors.
- Granting system-level access or third-party integrations without proper vetting.
- Leaving active sessions unattended or failing to log out from shared devices.
Medbus shall bear no liability, financial or otherwise, for any loss, damage, breach, or consequence arising from unauthorised access caused by the actions, negligence, or omissions of the account holder or any person acting under their authority or with credentials obtained from them.
Medbus's liability extends only to breaches that originate within systems under our exclusive control and result solely from our negligence or wilful misconduct.
4. Data Breach & Security Incidents
- Medbus maintains a comprehensive Information Security Management System (ISMS) and conducts regular security audits, penetration testing, and vulnerability assessments.
- In the event of a security incident originating from within our systems, we will notify affected users within 72 hours of discovery, in accordance with applicable data protection regulations.
- Medbus will cooperate fully with affected users and relevant authorities in investigating and containing any breach that originates from our infrastructure.
- However, if a data breach results from the account holder sharing credentials, granting unauthorised access, or any act or omission on the user's side, Medbus bears no responsibility for notification obligations, regulatory fines, or any resulting damages.
- Users are responsible for maintaining their own incident response plans and ensuring compliance with applicable healthcare data regulations (including DPDP Act 2023, HIPAA, and applicable state health data laws) in their jurisdiction.
- Medbus is not liable for breaches caused by integrations or third-party applications connected to the Platform by the user without Medbus's explicit endorsement.
5. Permitted Use
- The Platform is licensed for use solely to manage clinic operations, patient care, billing, and administrative tasks within your registered healthcare practice.
- You may not sublicense, resell, rent, lease, or transfer your subscription to any third party.
- You may not reverse engineer, decompile, disassemble, or attempt to derive the source code of the Platform.
- You may not use the Platform to store, transmit, or process data unrelated to your registered healthcare business.
- You may not use automated scripts, bots, or scrapers to access the Platform without written permission.
- You may not upload malware, viruses, or any malicious code to the Platform.
6. Data Ownership & Patient Data
- You retain full ownership of all Clinic Data entered into the Platform. Medbus does not claim any ownership rights over patient records, clinical notes, billing data, or any other data you create.
- Medbus acts as a Data Processor on your behalf. You are the Data Controller and are responsible for ensuring your use of Clinic Data complies with all applicable laws.
- You are responsible for obtaining all necessary consents from patients for the collection, storage, and processing of their health data.
- Medbus processes Clinic Data only as directed by you and as necessary to provide the Platform services.
- Clinic Data stored within the Medbus Platform is never sold, shared, rented, or disclosed to any third party without your explicit consent, except as required by law or as described in our Privacy Policy.
- Upon termination of your subscription, you may export your Clinic Data for 30 days. After 30 days, data will be securely deleted from our systems.
7. Website Enquiries & Marketing Data
📢 Note regarding website enquiry forms:
Information submitted through enquiry forms, demo request forms, newsletter subscriptions, or contact forms on the Medbus website (medbus.org) may be used for marketing and advertising purposes. Specifically:
- Enquiry data (name, email, phone) collected on this website may be shared with Facebook (Meta) and Google as part of our targeted advertising campaigns to reach similar potential customers.
- This sharing occurs through custom audience features on advertising platforms and is governed by Facebook's and Google's respective privacy policies.
- This practice applies only to the Medbus marketing website and does NOT apply to Clinic Data processed within the Medbus application platform.
- You may opt out of this by contacting us at admin@techbus.org.
8. Subscription, Payment & Refunds
- Subscriptions are billed in advance on a monthly or annual basis as selected at the time of purchase.
- All subscription fees are exclusive of applicable taxes (including GST), which will be added at the prevailing rate.
- Medbus reserves the right to modify subscription pricing with 30 days' written notice to existing subscribers.
- Refunds are available within 7 days of the initial subscription purchase if you are dissatisfied with the Platform for any reason.
- After the initial 7-day period, subscription fees are non-refundable.
- Failure to pay subscription fees may result in suspension of access to the Platform.
- In the event of suspension due to non-payment, Clinic Data will be retained for 30 days to allow you to settle outstanding amounts and restore access.
9. Service Availability & Uptime
- Medbus targets a 99% uptime SLA excluding scheduled maintenance windows.
- Scheduled maintenance will be announced at least 24 hours in advance via email and in-app notifications, and will typically occur during off-peak hours.
- Medbus is not liable for downtime caused by factors outside our reasonable control, including internet service provider failures, DNS failures, distributed denial-of-service (DDoS) attacks, or force majeure events.
- In the event of unplanned outages, Medbus will use commercially reasonable efforts to restore service as quickly as possible and will communicate status updates.
10. Intellectual Property
- The Medbus Platform, including all software, code, design, logos, trademarks, and content, is the exclusive intellectual property of Techbus Private Limited.
- You are granted a limited, non-exclusive, non-transferable licence to use the Platform solely for your registered healthcare business during your active subscription period.
- Nothing in these Terms transfers any intellectual property rights in the Platform to you.
- You may not reproduce, distribute, or create derivative works from any part of the Platform without our written consent.
11. Limitation of Liability
- To the maximum extent permitted by applicable law, Medbus's total aggregate liability to you for any claim arising from or related to these Terms or the Platform shall not exceed the total subscription fees paid by you in the 3 months immediately preceding the event giving rise to the claim.
- Medbus shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, loss of data, business interruption, or reputational damage.
- Medbus shall not be liable for any losses arising from your failure to maintain adequate security practices, including those described in Section 3 of these Terms.
- Medbus does not warrant that the Platform will be error-free, uninterrupted, or meet your specific clinical requirements.
- The Platform is a management tool and does not constitute medical advice. All clinical decisions remain the sole responsibility of licensed healthcare professionals using the Platform.
12. Indemnification
You agree to indemnify, defend, and hold harmless Medbus, Techbus Private Limited, and their officers, directors, employees, and agents from and against any claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising from:
- Your violation of these Terms.
- Your unauthorised use of the Platform or Clinic Data.
- Any breach of data protection obligations on your part.
- Unauthorised access caused by your disclosure of credentials or negligent security practices.
- Any third-party claim arising from your use of the Platform in connection with your healthcare practice.
13. Third-Party Integrations
- The Platform integrates with third-party services including Razorpay, Stripe, Zoom, WhatsApp (via Interakt), Google Calendar, Brevo, Mailchimp, and others.
- These integrations are provided for convenience. Medbus is not responsible for the availability, accuracy, or security of third-party services.
- Your use of third-party integrations is governed by those third parties' own terms and privacy policies.
- Medbus does not share Clinic Data with third-party integration providers beyond what is strictly necessary to provide the integration functionality you have enabled.
14. Termination
- Either party may terminate the subscription by providing 30 days' written notice.
- Medbus may terminate your access immediately and without notice if you materially breach these Terms, engage in fraudulent activity, or use the Platform for illegal purposes.
- Upon termination, your right to access the Platform ceases immediately. Clinic Data will be available for export for 30 days post-termination.
15. Governing Law & Dispute Resolution
- These Terms shall be governed by and construed in accordance with the laws of India.
- Any dispute arising from these Terms shall first be subject to good-faith negotiation between the parties.
- If negotiation fails, disputes shall be resolved by binding arbitration in Kochi, Kerala, India, under the Arbitration and Conciliation Act, 1996.
- The courts of Kochi, Kerala shall have exclusive jurisdiction over any legal proceedings not subject to arbitration.
16. Changes to These Terms
Medbus reserves the right to update these Terms at any time. We will notify you of material changes via email and an in-app notice at least 14 days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the revised Terms.