Privacy Policy
Clinic Management Software, Doctor Listings & Online Consultations
Effective 2026-05-14 · Last updated 2026-05-14 · Version 1.0
1. About This Policy
This Privacy Policy (the “Policy”) explains how ilaaj.app (the registered business operating the brand “vcure”) collects, uses, shares, stores and protects information that we obtain from Users of our platform (the “Platform”), including the website, mobile application(s), the Clinic Management Software (CMS), the public Doctor Directory, and the Online Consultation service.
vcure is committed to handling personal information lawfully, transparently, and securely, in accordance with applicable Pakistani law including the Prevention of Electronic Crimes Act, 2016 (PECA), the Electronic Transactions Ordinance, 2002, State Bank of Pakistan regulations on data security and payment systems, the PMDC Code of Ethics (in relation to patient confidentiality), and any other data-protection law in force in Pakistan from time to time (including the proposed Personal Data Protection Bill, when enacted).
By using the Platform, you confirm that you have read, understood and consented to the practices described in this Policy. If you do not agree, you must stop using the Platform.
2. Who This Policy Applies To
- Patients / End-Users: individuals who view doctor profiles, book Consultations, communicate with Doctors, and pay through the Platform.
- Doctors / Healthcare Providers: registered medical practitioners who list on vcure and/or use the CMS.
- Clinics / Institutional Subscribers: healthcare establishments that subscribe to the CMS.
- Website Visitors: anyone who visits the vcure website or app without registering.
3. Information We Collect
The categories of information we collect depend on the User’s role on the Platform.
3.1 Information You Provide Directly
- Account information: full name, CNIC (where applicable), gender, date of birth, mobile number, email address, postal address, and password.
- Doctor / Clinic verification information: PMDC registration number, qualification certificates, specialty, clinic registration documents, professional indemnity insurance details (where shared), tax registration numbers, and bank account details for payouts.
- Patient health information: details you provide to a Doctor before or during a Consultation, including symptoms, medical history, current medication, allergies, lab reports, prescriptions, and uploaded images or documents.
- Communications: messages, video/audio recordings of Consultations (where the User has been notified and consented), and correspondence with our support team.
- Payment information: billing name, billing address, transaction history, and payment-instrument metadata. Full card numbers, CVV and PINs are processed directly by the applicable payment service provider and the relevant card scheme, and are not stored on vcure’s servers.
3.2 Information Collected Automatically
- Device and technical information: IP address, device type, operating system, browser type, device identifiers, mobile network information, language settings.
- Usage information: pages viewed, features used, search queries, click-stream, time spent, login/logout times, error logs and crash reports.
- Location information: approximate location derived from IP address, and (with your permission) more precise location from your device, used for showing relevant Doctors or clinics.
- Cookies & similar technologies: we use cookies, local storage, and similar technologies. See Section 11.
3.3 Information from Third Parties
- Identity and credential verification providers (where used) for Doctor KYC;
- Payment service providers and partner banks for payment confirmation and chargeback handling;
- Communications and analytics providers (e.g., SMS, email, video infrastructure, crash reporting);
- Public registries (such as PMDC, where lawfully accessible) for the purpose of verifying Doctor credentials.
4. How We Use Information
We use the information we collect to:
- Create and manage your account and verify your identity (and, for Doctors, your professional credentials);
- Operate the Platform: enable bookings, run Consultations, host CMS data, send confirmations and reminders, and support customer service;
- Process payments, payouts, refunds and chargebacks through licensed payment service providers and partner banks;
- Detect, prevent and investigate fraud, abuse, security incidents, and breaches of these Terms;
- Comply with legal, regulatory and tax obligations under Pakistani law (including AML/CFT and SBP requirements);
- Improve and personalise the Platform, including analytics, debugging, and developing new features;
- Send service communications (booking confirmations, security alerts, policy updates) — these are essential and cannot be opted out of while you have an account;
- Send marketing communications about vcure features, promotions or partner offers — only with your consent, and you may unsubscribe at any time.
5. Patient Health Information & the Doctor / Clinic as Data Controller
When a Patient shares health information with a Doctor through the Platform, or when a Doctor or Clinic stores patient records in the CMS, the Doctor or Clinic is the “Data Controller” of that information and vcure acts as a “Data Processor” on their documented instructions.
This means the Doctor or Clinic is responsible for: (i) obtaining all required consents from the patient; (ii) using the information only for legitimate clinical purposes; (iii) keeping the information confidential as required by the PMDC Code of Ethics and applicable law; and (iv) responding to any rights requests from the patient.
vcure will not access, use or disclose patient health information except (a) as necessary to operate the Platform and provide the CMS services to the Doctor or Clinic; (b) to comply with law or a binding order of a competent authority; or (c) with the patient’s separate consent.
6. Legal Bases for Processing
We process personal information on one or more of the following bases:
- Performance of a contract: to provide the Platform, the CMS, Doctor listings, and Consultation services in accordance with the Terms and Conditions.
- Consent: where you have given specific consent (for example, for marketing communications, precise location, or recording of a Consultation).
- Legal obligation: to comply with applicable law, tax, AML/CFT, SBP rules, and lawful orders of competent authorities.
- Legitimate interests: to keep the Platform safe, prevent fraud, improve services, and protect vcure’s rights, in a manner consistent with your reasonable expectations.
7. How We Share Information
We do not sell your personal information. We share information only in the following circumstances:
7.1 With Doctors and Patients on the Platform
- Patient information (as relevant to the Consultation) is shared with the Doctor the Patient has booked.
- Doctor profile information (name, qualifications, specialty, fees, availability) is shown publicly on the Platform to enable booking.
7.2 With Service Providers and Sub-Processors
We share information with carefully selected third-party service providers who process information on our behalf, under written agreements and confidentiality obligations. Categories include:
- payment service providers, payment gateways and partner banks;
- cloud hosting and storage providers;
- video/audio infrastructure providers for online consultations;
- email, SMS and push-notification providers;
- analytics, monitoring and crash-reporting providers;
- identity-verification and KYC providers (for Doctor verification);
- courier and lab partners (where relevant to a specific service).
7.3 With Regulators, Law Enforcement, and Other Authorities
We may disclose information to government authorities, regulators, the courts, the State Bank of Pakistan, the FBR, the FIA, the PMDC, DRAP, or other competent bodies where we are legally required to do so, or where we believe in good faith that disclosure is necessary to protect rights, prevent fraud, comply with a court order, or address an imminent safety risk.
7.4 In Business Transfers
In the event of a merger, acquisition, financing, reorganisation, sale of business or assets, or insolvency, information may be transferred to the relevant counterparty, subject to confidentiality obligations and to the requirement that such counterparty observes this Policy or a substantially equivalent privacy policy.
8. International Transfers
Some of our service providers (for example, cloud hosting and analytics providers) may be located outside Pakistan. Where information is transferred outside Pakistan, we take reasonable steps, including contractual protections, to ensure that an adequate level of protection applies, and that the transfer complies with applicable Pakistani law.
9. Data Retention
- Account information: retained for as long as your account is active, and for a reasonable period thereafter to address legal, regulatory, tax, accounting and dispute-resolution requirements.
- Patient health records on the CMS: retained for the period directed by the Doctor or Clinic acting as Data Controller, subject to applicable retention requirements under Pakistani law for medical records.
- Transaction and payment records: retained for the periods required by tax law, AML/CFT regulations, and SBP rules — typically a minimum of five (5) years from the date of the transaction.
- Logs and security records: retained for a reasonable period to investigate incidents and improve security.
- Marketing data: retained until you withdraw consent, after which we will stop sending marketing but may retain minimal records of your opt-out.
When information is no longer required for the purposes above, we will delete or irreversibly anonymise it.
10. Security
vcure implements reasonable technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure or destruction. Measures include encryption in transit (HTTPS/TLS), access controls, role-based permissions, audit logging, regular security reviews, and reliance on PCI-DSS-compliant payment service providers for the handling of card data.
However, no system is completely secure, and no method of transmission over the internet or method of electronic storage is one hundred percent safe. You are responsible for keeping your account password confidential, choosing a strong password, and notifying us immediately of any unauthorised access (see Clause 4 of the Terms and Conditions). To the maximum extent permitted by law, vcure shall not be liable for security incidents caused by your own acts or omissions, or by Force Majeure.
11. Cookies & Similar Technologies
We use cookies, local storage, and similar technologies for purposes including: keeping you signed in, remembering preferences, securing the Platform, measuring usage, and improving features. Some cookies are strictly necessary for the Platform to function and cannot be disabled; others (such as analytics and marketing cookies) are optional and may be controlled through your browser settings or any cookie banner provided on the Platform.
12. Your Rights
Subject to applicable law and to the extent reasonably possible, you may exercise the following rights in relation to your personal information held by vcure as a Data Controller (this section does not, on its own, override the rights and obligations between a Patient and a Doctor/Clinic, where the Doctor/Clinic is the relevant Data Controller):
- Access: request a copy of the personal information we hold about you.
- Correction: request that inaccurate or incomplete information be corrected.
- Deletion: request that we delete your personal information where it is no longer needed and we are not legally required to retain it.
- Withdraw consent: withdraw any consent you have given (this will not affect the lawfulness of processing carried out before the withdrawal).
- Object / restrict: object to, or request restriction of, certain types of processing (such as marketing).
- Portability: where technically feasible, receive your data in a commonly used, machine-readable format.
To exercise these rights, please contact us at support@vcure.app. We may need to verify your identity before acting on a request. We will respond within a reasonable period and, where applicable, within any timeframes required by law.
13. Children
The Platform is not directed to children under the age of eighteen (18). Minors may use the Platform only under the supervision of a parent or legal guardian who agrees to be bound by the Terms and this Policy. If you believe that a child has provided personal information to us without parental consent, please contact us so we can take appropriate action.
14. Third-Party Links & Services
The Platform may contain links to or integrations with third-party websites and services (for example, payment service providers, video infrastructure, social media). Those third parties operate under their own privacy policies. vcure is not responsible for the privacy practices or content of such third parties. We encourage you to read their privacy policies before providing them with information.
15. Changes to This Policy
We may update this Policy from time to time. Where changes are material, we will notify Users via the Platform, email or in-app notice. The “Last Updated” date at the top of this Policy indicates when it was most recently revised. Continued use of the Platform after publication of the revised Policy constitutes acceptance of the changes.
16. Governing Law & Jurisdiction
This Policy is governed by the laws of the Islamic Republic of Pakistan. The competent civil courts located in Lahore, Punjab, Pakistan shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy, subject to the dispute-resolution provisions of the Terms and Conditions.
17. Contact Us
For any privacy-related question, concern, or rights request, please contact ilaaj.app (Brand: vcure) — Customer Support Email: support@vcure.app, Helpline: 0324-8118058, Registered Address: 352M, Model Town M Block, Lahore, Pakistan.
Contact Us
ilaaj.app (Brand: vcure)
352M, Model Town M Block, Lahore, Pakistan
Acknowledgement
By creating an account, subscribing to the CMS, listing as a Doctor, booking a Consultation, or otherwise using the vcure Platform, you confirm that you have read, understood and consented to this Privacy Policy in full.