1.About this policy
HISGrace PACS Viewer (the "App") is a desktop DICOM viewer for Windows, macOS and Linux developed by Rawlemon ("we", "us"), based in Jakarta, Indonesia. This policy covers the App, including the version installed from the Microsoft Store, and the licensing, account and payment services on the Rawlemon website that relate to the App.
When the App is used at a hospital and connected to that hospital's own HISGrace SIMRS server, that server is operated by the hospital and governed by the hospital's privacy policy.
We process personal data in accordance with Indonesia's Personal Data Protection Law (Law No. 27 of 2022) and other applicable laws.
2.Medical images & patient data
The App opens DICOM images from files on your computer, patient CDs/DVDs, or a PACS you connect to. All image processing, including MPR, 3D reconstruction, measurements, segmentation and report writing, happens on your computer.
Images, patient names or record numbers, study identifiers (Study UIDs), radiology reports and your PACS addresses are never sent to Rawlemon servers.
Patient data is only sent to destinations you configure yourself:
- PACS & DICOM nodes: querying, retrieving and sending studies (C-FIND, C-GET, C-MOVE, C-STORE, DICOMweb), including any auto-routing rules you create.
- DICOM film printers: when you print film.
- Webhooks: URLs you enter receive notifications with study and patient data (such as ID, name, date of birth, sex and accession number) and the sending computer's name. Every request is HMAC-signed.
- Local network (PACS mini & LAN sharing): other computers can access the local archive only after you allow them.
- Your hospital's HISGrace SIMRS server: in hospital mode, studies, reports, reading status, chat messages and voice messages go to your hospital's server, not to Rawlemon.
- Exports: image, video, PDF, DICOMDIR or CD files you save to a location you choose, and images you copy to the clipboard.
The healthcare facility using the App is the controller of patient data. It is responsible for the legal basis, access control and retention of that data under medical-records and data-protection rules. Rawlemon has no access to it.
The anonymization feature removes patient-identifying DICOM attributes following the DICOM PS3.15 Basic Profile. Text burned into the image pixels is not removed. The App flags such images, so review them before sharing.
3.Information we receive
The App connects to Rawlemon servers only for the purposes below. Every connection is encrypted with HTTPS.
License activation (Pro/Max plans)
- When
- When you activate a license with a license key or by signing in to your account in the browser.
- Data sent
- The license key, or the device approval from your account
- Computer name (hostname)
- Operating system & CPU architecture, App version
- Device fingerprint: a one-way SHA-256 hash of the operating system's machine ID (the raw ID is not sent)
- Purpose
- To issue the license, limit each subscription to one PC, and list your PCs on your Account page so you can release or move them.
License renewal
- When
- Automatically once a day while online, only when a license is active.
- Data sent
- A digitally signed license token containing your account email, subscription & device IDs, the device fingerprint and the plan
- Purpose
- To keep the license valid and detect licenses that have been released or have ended.
License policy & pricing
- When
- When the App starts, then every 6 hours. Prices are fetched when the License window opens.
- Data sent
- No personal data. Only technical request information such as your IP address.
- Purpose
- To show the latest license rules and prices.
Anonymous usage statistics
- When
- About 20 seconds after the App starts, then every 6 hours. Applies to all plans.
- Data sent
- Installation ID: a SHA-256 hash of the machine ID with a different salt from the license fingerprint, not linked by us to any account
- App version, operating system & architecture, language
- Plan & license status, connection mode (hospital, standalone PACS, local), number of saved PACS connections
- Daily counts of features used, such as the App being opened, studies opened (from PACS, local or LAN) and viewer tools used
- Purpose
- To learn which features are actually used and which versions and operating systems to support, and to improve the product. This data contains no patient data, study identifiers, computer name, hospital name, PACS addresses, account or email.
Reviews & bug reports
- When
- Only when you send one from the Help menu.
- Data sent
- Type (review or bug), rating and your message
- Your email, if you choose to enter it (optional)
- Installation ID, App version, operating system, plan, connection mode, language
- Purpose
- To respond to feedback and fix problems. No screenshots, logs or study data are attached. Please do not include patient names or identifiers in your message.
App updates
- When
- About 15 seconds after the App starts, then every 6 hours. Microsoft Store versions are updated through the Microsoft Store.
- Data sent
- No personal data. The distribution server (GitLab) receives technical request information such as your IP address.
- Purpose
- To check for and download new versions. An update is installed only after you approve it. The portable viewer for patient CDs is also downloaded from this server when you ask for it.
If you create an account or buy a subscription on the Rawlemon website, we also receive:
- Account data: name, email, password (stored as a hash), and phone number and institution if you provide them. If you sign in with Google, we receive your name, email and profile picture from Google.
- Payment data: plan, period, amount, method and payment status. Payments are processed by Midtrans, which receives your name and email for the bill. We never receive or store your card number or banking credentials.
- Session security: your IP address and browser type when you sign in to the website, to protect your account.
Every connection to our servers carries your IP address. For usage statistics and feedback, the IP address is only used briefly in memory for rate limiting and is not stored with that data.
4.Data stored on your computer
The following data is stored only on your computer and is not sent to Rawlemon:
- Settings: language, theme, PACS connections, DICOM destinations, printers, routing rules, webhook URLs, reading-physician details (name, license number, signature image) and report letterhead.
- Local archive & reports: DICOM files, study and patient metadata, comments, albums and radiology reports, in an archive folder whose location you choose.
- Image cache: temporary copies of studies opened from a PACS (20 GB by default; the least recently used are removed automatically).
- Annotations & measurements: per study in local mode.
- Usage counters: kept temporarily (up to 35 days) until they are sent as anonymous statistics.
- Credentials: the license token, HISGrace session tokens and webhook secrets are kept in the operating system's secure credential store (Windows Credential Manager, macOS Keychain or Secret Service on Linux). The App does not store account passwords.
The App does not separately encrypt the archive and image cache. Protect the computer with a password-protected user account and disk encryption such as BitLocker or FileVault, especially when storing patient data. Release builds of the App do not write diagnostic logs to disk.
You can delete studies, reports and the cache from within the App, or delete the App's data folder. Uninstalling the App may not remove an archive folder you moved to another location.
5.Device & network access
- Microphone: used only when you record a voice message in HISGrace chat (hospital mode). Recordings go to your hospital's HISGrace server, not to Rawlemon.
- Files: the App only opens and saves files you choose or drag into it.
- Receiving DICOM: when a C-MOVE profile or PACS mini is enabled, the App opens a DICOM listening port (11113 by default) and only accepts connections from IP addresses you allow.
- Local network discovery (mDNS): the App listens for other DICOM devices on the local network. It only announces itself (AE title, a display name that defaults to the computer name, and version) when you enable PACS mini and LAN sharing.
- LAN PACS scan: runs only when you press the scan button.
- Other: system notifications, and the clipboard for copying images. The App does not use the camera, location, contacts or advertising ID.
6.How we use information
- To provide the App, issue and verify licenses, and prevent abuse.
- To process payments, issue receipts, and send account emails such as activation, password resets and subscription reminders.
- To answer questions, reviews and bug reports.
- To develop and improve the product using aggregated usage statistics.
- To meet legal obligations, including tax.
We do not sell personal data, use it for advertising or profiling, or share it with others for marketing.
8.Retention
- Account: while your account is active. When you delete your account, its profile data, sign-in methods and sessions are removed immediately.
- Licensed devices: for the life of the subscription. History of released devices is kept as part of the subscription record, and all licenses end immediately when the account is deleted.
- Payments: for as long as tax and accounting regulations require. After an account is deleted, these records are kept without your name, email or contact details.
- Usage statistics & feedback: for as long as they are needed for product development and support.
- Data on your computer: entirely under your control.
9.Security
We protect data with HTTPS connections, digitally signed license tokens, hashed device fingerprints, hashed passwords, attempt limits, and internal access restricted to authorized staff. No system is completely risk-free. If a personal data breach occurs, we will notify you and the relevant authorities as required by law.
10.Your rights
Under the Personal Data Protection Law and other laws that apply where you live, you have the right to:
- Know about and obtain a copy of your personal data.
- Correct inaccurate data.
- Ask us to delete your data and account.
- Withdraw consent, and restrict or object to certain processing.
- Lodge a complaint with a data protection authority.
- Delete your account yourself: sign in to the website, go to Account → Profile → Delete account, and confirm with your email (and password, if your account has one). Profile data, sign-in methods and sessions are removed immediately, all licenses end, and a confirmation email is sent to your address. If a bill is still awaiting payment, complete it or wait until it expires first.
- Release a licensed PC: on the Account page, or with "Release license" in the App.
- Other requests: such as a copy of your data, corrections, or deleting feedback you sent: email [email protected] from the address registered to your account.
Deleting your account does not delete data on your computer. Local archives, reports and settings remain until you delete them yourself or uninstall the App.
Anonymous usage statistics are always on because they contain no personal data. The App keeps working normally if connections to this service are blocked, for example by your organization's firewall.
11.Children
The App is intended for healthcare professionals and facilities, not for children. We do not knowingly collect personal data from children under 18 through our accounts or forms.
12.Changes to this policy
We may update this policy when the App or our services change, and we will update the effective date above. For significant changes, we will let you know through the website, the App or email.
13.Contact
Rawlemon, Jakarta, Indonesia. Email: [email protected]. Phone/WhatsApp: +62 815-999-7268.
Questions about privacy?
Get in touch. We respond to every request about personal data.