Data protection

How Clinic handles patient and clinic data, under India's Digital Personal Data Protection Act, 2023. Last updated 03 Sep 2026.

Where the data is kept

Everything this software stores — patient records, prescriptions, invoices, photographs, and the messages sent about them — is held on servers in India. Backups are held in India as well.

Some things necessarily leave: a WhatsApp message goes through Meta or the provider the clinic chose, a text through its SMS gateway, a payment through its payment gateway. What goes with them is only what the message or the payment needs — a name, a phone number, an amount, a date. Clinical notes are never sent to any of them.

Who holds what

The clinic is the data fiduciary for its patients' data: it decides what is collected and why, and its patients' relationship is with it. Clinic is a data processor acting on the clinic's instructions — we hold the data so the software works, and we do not sell it, share it, or use it to train anything.

For the clinic's own account — the people who log in, what they are billed, what they write to our support — Clinic is the fiduciary.

What is collected, and why

  • Patient details — name, phone, age, address, medical history: to keep the clinical record and to reach the patient about their own care.
  • Clinical records — visits, prescriptions, lab orders, photographs: the practice's case papers.
  • Money — invoices, payments, and what was paid for: to bill and to account.
  • Staff details — logins, attendance, salary records: to run the clinic.
  • Delivery records — which message went to which number and whether it arrived: so a clinic can prove a reminder was sent.

Consent

A patient's data is collected by the clinic, for their treatment, with their consent — and automatic messages are sent only for the things the clinic has switched on. Any patient can ask their clinic to stop messaging them, and the clinic can turn each kind of message off for the whole practice, or delete a patient's phone number so none is sent.

What a patient can ask for

Under the Act, a data principal may ask for a copy of their data, ask for a correction, ask for it to be erased, nominate someone to act for them, and complain. Those requests go to the clinic that treated them, which can do all of it from inside this software. Where a clinic needs us to help, we do.

Erasure has one limit worth stating: medical records that a clinic is required by law to keep are kept for as long as that requires, and are then deleted.

How long it is kept

For as long as the clinic's account is open. If a clinic closes its account, its data is kept for 90 days — long enough for it to change its mind or take an export — and is then deleted from our systems and from our backups on the backups' own cycle.

Security

Traffic is encrypted in transit. Credentials the clinic gives us for its own gateways are encrypted at rest and are never shown back in full. Access is by role: what a receptionist can open is not what an admin can. A breach affecting personal data is reported to the Data Protection Board and to the clinics affected, as the Act requires.

Children

A child's record is created by the clinic on the consent of a parent or guardian, who is present at the visit. Nothing here is directed at children, and no behavioural advertising or tracking is done, on any patient.

Getting in touch

Company:
Clinic

Grievance officer

Not yet published. Write to us at the address above and your complaint reaches the same desk.