Legal
Privacy policy
This policy explains how Digital Monster Uganda (“we”, “us”) handles personal data when you visit the HospitalMgr website, request a demo, or use the HospitalMgr hospital, clinic, and pharmacy software. It sits alongside our Terms of use. A signed hospital contract, data-processing addendum, or government tender may add stricter rules for that facility; those documents control if they conflict with this page.
1. Who we are
HospitalMgr is operated by Digital Monster Uganda, a Kampala software company. We design, host or support, implement, and maintain HospitalMgr for hospitals, clinics, pharmacies, dental practices, health centres, and government facilities.
Privacy questions: info@healthmgr.com or the contact page.
2. Two different data worlds
Website visitors
If you only browse this marketing site or send a demo request, we are the organisation deciding why that contact data is used (controller for that website activity).
Hospital software
If a facility uses HospitalMgr, that facility is responsible for its patients, staff, invoices, and clinical records. We process that data to provide the product they bought. Each live hospital is a tenant: records are scoped by hospital, not mixed into a shared clinical pool.
3. What we collect on this website
- Demo and contact forms: name, facility, facility type, and the message you type. Submissions are sent to hello@digitalmonster.ug.
- Technical logs that a normal web host keeps: IP address, browser, pages requested, and approximate time. We use these to keep the site up and to investigate abuse.
- Email and WhatsApp if you write to us. WhatsApp numbers published on this site may be placeholders until production contact details are confirmed.
We do not sell website leads. We do not use them to train public AI models.
4. What HospitalMgr stores for a facility
Depending on which modules the hospital switches on, HospitalMgr may hold:
- Patient registration, documents, visits, and related clinical notes.
- Appointments, prescriptions, laboratory and radiology orders and reports.
- Pharmacy stock, batches, sales, and suppliers.
- IPD / beds, antenatal, dental, ambulance, and insurance records.
- Finance, accounting, HR, payroll, and internal reports.
- User accounts, roles, permissions, branding, and login logs.
- Hospital-scoped backups and restore history.
- Optional AI settings: catalog choices and encrypted API keys for providers the hospital configures. Keys are stored encrypted at rest; we do not need them in plain text to run other modules.
The hospital chooses which modules and users are live. Turning a module off does not automatically erase historical rows unless the hospital asks us to delete them under its retention policy.
5. Why we use personal data
- To reply to demo and support requests.
- To run, host, back up, and restore the software a paying facility contracted.
- To create accounts, enforce roles, and keep an audit of logins.
- To bill, implement, train, and support the facility.
- To protect the service against unauthorised access, fraud, and data loss.
- To meet Uganda’s Data Protection and Privacy Act, 2019, and any other law that applies to a given contract (for example a government facility’s own rules).
6. Sharing
We do not sell patient lists. We may share data only:
- With people at the facility who already have a HospitalMgr login and the right role.
- With infrastructure providers we use to host, email, or back up the product, under confidentiality.
- With a regulator, court, or police when the law requires it.
- With professional advisers (lawyers, auditors) bound to keep it confidential.
- If the hospital itself exports or prints records (that is the hospital’s act, not ours).
Optional AI features send only what the hospital’s configured provider needs for that request. The hospital is responsible for what it pastes into AI tools and for the provider’s terms.
7. Storage, backups, and security
Facility data is kept in the hospital tenant. Backups are gzip archives of that tenant’s tables, not a dump of every hospital on the platform. Restore is a permissioned action.
We use role-based access, encrypted API keys for AI settings, HTTPS on the web product, and passwords that staff must keep private. No system is perfect. The hospital must also lock rooms, retire unused accounts, and not share the admin password.
If we become aware of a personal-data breach that must be reported, we will notify the affected facility so it can meet its duties to patients and the Personal Data Protection Office where required.
8. How long we keep data
- Website enquiries: typically up to 24 months after the last useful contact, unless a contract follows.
- Hospital records: for the life of the subscription plus any extra period the facility’s law or contract requires (medical records often outlast a software licence). After offboarding we follow the written exit plan: export, then delete or archive as agreed.
- Login logs and backups: as long as needed for security and restore, then rotated.
9. Cookies
This marketing site is static HTML. When you click Accept cookies we store one first-party flag (hm_cookie_choice) in your browser so we do not ask again. Reject stores the same flag as “no”. We do not run advertising pixels. Your browser may still cache pages, fonts, and images. The live HospitalMgr system at system.hospitalmgr.com uses a login session so staff stay signed in; that is required for the product.
10. Your rights
Under Uganda’s Data Protection and Privacy Act, 2019, a data subject may request access, correction, deletion, or restriction, and may object to certain processing, subject to medical-record, accounting, and legal exceptions.
- If your data sits in a hospital’s HospitalMgr tenant (you are a patient or staff member of that facility), contact that facility first. They control the record. We will help the facility fulfil a valid request.
- If you only wrote to us from this website, email info@healthmgr.com with enough detail to find your message.
You may also complain to Uganda’s Personal Data Protection Office.
11. Children and clinical care
HospitalMgr is sold to facilities, not to children. Paediatric and maternity modules will contain minors’ health data because hospitals treat children. That processing is the facility’s clinical and legal duty. We do not use children’s records for marketing.
12. International use
HospitalMgr is offered to facilities in Uganda and other English-speaking African countries. Hosting location is as stated in the hospital’s contract. If support staff or a host are outside the facility’s country, transfers happen only to run the service.
13. Changes
We will update this page when the product or the law changes. The date at the top is the current version. Material changes that affect a live hospital will also be sent through the account contact we have on file.