Last updated: 21 July 2026 · 7Unit Softwares Private Limited

Privacy Policy

These pages describe how Hally is designed to operate. They are not a substitute for legal advice. Contact hello@gethally.com for a formal DPA or counsel-reviewed schedule.

1. Who we are

7Unit Softwares Private Limited (“7Unit”, “we”, “us”) operates the Hally platform and related product lines (Hally, Hally Connect, Hally Hospital, Hally Lite), including websites at https://www.gethally.com and application environments such as https://demo.gethally.com.

This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our marketing sites, request a demo or pilot, or when healthcare organisations use Hally to deliver outpatient workflows.

Healthcare organisations that deploy Hally (“Customers”) typically act as data fiduciaries / controllers for patient data. 7Unit acts as a data processor / service provider for Customer-controlled patient data, except where we process data for our own business purposes (for example, sales enquiries).

2. Scope

This policy covers: (a) visitors to gethally.com and related marketing pages; (b) prospective customers who contact us; and (c) the design of how Hally processes personal data on behalf of Customers.

Customer-specific processing is also governed by the Customer’s agreement with 7Unit, any data processing terms, and the Customer’s own privacy notice to patients.

3. Categories of data

Marketing and sales: name, organisation, role, email, phone, city, message content, and similar details you submit when booking a demo, applying for a pilot, or emailing us.

Website technical data: IP address, browser type, device information, pages viewed, and referrer — collected through server logs and, if enabled, privacy-safe analytics.

On the Hally product (Customer environments): patient identifiers and health-related information required for outpatient workflows (for example name, phone, appointment details, visit reason, clinical notes, consent records), staff identity and role data, and operational audit metadata. Exact fields depend on the modules a Customer enables.

4. How we use data

To respond to enquiries, schedule demos and pilots, and provide customer support.

To operate, secure, and improve the Hally platform (including multi-tenant isolation, encryption, access control, and audit logging).

To process outpatient workflows on behalf of Customers (WhatsApp journeys, booking, documentation assistance, reception and operations features) as instructed by the Customer.

To comply with applicable law and enforce our agreements.

5. Legal bases (India — DPDP Act 2023)

Where the Digital Personal Data Protection Act, 2023 applies, we process personal data based on consent and/or other lawful grounds permitted under the Act and rules, including processing that is necessary for employment/contractual purposes with Customers and for compliance with law.

For patient-facing WhatsApp and clinical workflows, Hally is designed so that Customers can capture consent before health-related intake, and retain consent records for accountability.

6. WhatsApp and Meta

Where Customers use WhatsApp-based journeys, messages are transmitted via Meta’s WhatsApp Business infrastructure. Meta’s terms and policies also apply to that channel. Usage charges from Meta may be billed separately from Hally subscription fees.

7. Sharing

We do not sell personal data.

We may share data with subprocessors that help us host and operate the service (for example cloud infrastructure, email delivery, transcription or AI providers used inside approved product integrations), under contractual confidentiality and security obligations.

We may disclose information if required by law or to protect rights, safety, and security.

8. Security

Hally is engineered with multi-tenant isolation, encryption of sensitive fields at rest (AES-256-GCM with organisation-scoped keys), access controls, and audit logging of access to patient data. See our Security & data processing page for a fuller description.

No method of transmission or storage is perfectly secure. Customers remain responsible for configuring access within their organisation and for their own device and staff practices.

9. Retention

Marketing enquiry data is retained as needed to manage the sales relationship and for legitimate business records.

Customer patient data retention follows the Customer agreement and Customer instructions, subject to legal holds and applicable healthcare record requirements.

10. Your rights

Depending on applicable law, individuals may have rights to access, correction, erasure, and grievance redressal regarding personal data.

If you are a patient of a Hally Customer, please contact that healthcare organisation first — they control your care record. You may also contact us at privacy@gethally.com and we will route the request appropriately.

If you are a website visitor or sales contact, email privacy@gethally.com or hello@gethally.com.

11. Children

Our marketing site is directed to healthcare organisations and professionals, not to children. Product workflows may involve paediatric patients only as configured and authorised by the Customer.

12. Changes

We may update this policy from time to time. The “Last updated” date at the top of this page will change when we do. Continued use of the site after updates constitutes notice of the revised policy for marketing-site visitors.

13. Contact

7Unit Softwares Private Limited

Email: privacy@gethally.com · hello@gethally.com

Web: https://www.gethally.com