Last updated: 21 July 2026 · 7Unit Softwares Private Limited

Security & data processing

These pages describe how Hally is designed to operate. They are not a substitute for legal advice. Contact hello@gethally.com for a formal DPA or counsel-reviewed schedule.

1. Purpose

This page summarises how Hally is designed to process and protect personal data — especially health-related data — when used by healthcare organisations. It complements our Privacy Policy and commercial data-processing terms.

It is a product architecture summary for customers and prospects, not a substitute for a signed Data Processing Agreement (DPA) where one is required.

2. Roles

Customer (healthcare organisation): typically the data fiduciary / controller for patient data collected in care workflows.

7Unit: processor / service provider for Customer patient data; controller for our own CRM, billing, and website enquiry data.

3. Security controls (product design)

Multi-tenant isolation: tenant context is derived from authenticated sessions; database access is constrained with row-level security patterns so one organisation cannot read another’s data.

Encryption at rest: sensitive / PHI fields are encrypted with AES-256-GCM using organisation-scoped data encryption keys (envelope encryption model), supporting stronger isolation and erasure practices.

Access control: role-based access (for example organisation admin, doctor, staff, read-only) gates product features and data visibility.

Auditability: access to patient data is designed to be written to durable audit logs for Customer accountability.

Consent workflows: WhatsApp and intake flows are designed to capture consent before health-related questions, with verbatim consent event storage for DPDP-aligned accountability.

Integrations boundary: external AI, speech, and object-storage providers are accessed through controlled integration layers rather than ad-hoc calls from arbitrary application code.

4. Data residency

Hally is designed for Indian healthcare customers with an India-first deployment posture (including Mumbai-region options for production deployments). Specific residency for a Customer environment is confirmed in the commercial / deployment agreement.

5. Subprocessors

Depending on configuration, processing may involve infrastructure and specialist providers (hosting, email, speech-to-text, large language models for summarisation/assistance, WhatsApp Business via Meta). A current subprocessor list can be provided to Customers under NDA or as an schedule to the DPA.

6. Customer instructions

We process Customer patient data only to provide the service and as otherwise instructed in writing by the Customer or required by law.

Customers are responsible for lawful collection, patient notices, staff training, and deciding which modules and integrations to enable.

7. Breach notification

Security incidents affecting Customer data are handled under our incident response process and contractual notification commitments. Contact security-related concerns at hello@gethally.com with subject line “Security”.

8. More detail

For enterprise security questionnaires, penetration-test summaries (under NDA), or a formal DPA, contact hello@gethally.com.