Last updated · January 2026
Gratiview, a Graticare product, is committed to protecting the privacy and security of the information entrusted to us by healthcare providers and the patients they serve.
This policy applies to the Gratiview DICOM viewer, its optional Workstation and OrthoPlan plugins, our website and any related applications. By installing or using the software you agree to the practices described here.
We process Protected Health Information (PHI) only as a processor on behalf of our healthcare partners and in accordance with HIPAA and applicable data-protection laws; a Business Associate Agreement is available. Because Gratiview runs locally, imaging data stays on your device unless you choose to sync it through Workstation. PHI is never sold or used for advertising.
Our information-security management system is certified to ISO/IEC 27001. Data is encrypted in transit and at rest, access is role-based and logged, and we publish a DICOM conformance statement. Workstation cloud storage runs on secured, continuously monitored infrastructure.
Studies you open locally remain under your control on your own device. Where you use Workstation, imaging and report data are retained according to the cloud storage included with your plan — 5 GB per licensed device, pooled — and your instructions. We delete or de-identify data when it is no longer required for the contracted purpose or by law.
Patients should direct requests regarding their health records to the healthcare provider that ordered the study, who is the controller of that information. Where we act as controller of account data, you may request access, correction or deletion subject to legal and contractual obligations.
Questions about this policy can be sent to [email protected] or by post to 4th Floor, Rukmini Tower, Harmu Road, Near Ratu Road Chowk, Ranchi, Jharkhand 834001, India.