Legal
Privacy Policy
Your medical history is the most personal thing you will ever put in an app. This page says exactly what we hold, who can open it, and how to get it back or get it deleted — in plain words, not in legalese.
Effective [DD MMM YYYY] · Last updated [DD MMM YYYY]
Who we are
DigiDoctor.app is software used by clinics in India to run their appointments and keep their patients’ medical records. It is operated by [LEGAL ENTITY NAME] ([CIN]), registered at [REGISTERED ADDRESS]. In this policy, “we”, “us” and “DigiDoctor.app” mean that company.
This policy covers the patient mobile app, this website, and the patient portal. It does not cover the clinic-facing software your doctor uses, which is governed by our agreement with the clinic.
Your clinic’s role and ours
This is the most important section on the page, because it decides who you go to for what.
Your clinic decides what goes in your medical record. We only store it. Your consultation notes, diagnoses, prescriptions and reports are created and controlled by the clinic that treats you. We hold them on the clinic’s behalf and act on the clinic’s instructions.
In the language of the Digital Personal Data Protection Act, 2023, this means two different things are true at once:
- For your clinical record, your clinic is the Data Fiduciary and we are its Data Processor. If you want a diagnosis corrected or a consultation note changed, the clinic has to do it — we are not permitted to alter a doctor’s clinical entry, and you would not want a software company that could.
- For your DigiDoctor.app account, we are the Data Fiduciary. Your login, your mobile number and email, your app settings and your device logs are ours to answer for. Ask us directly about those.
If you are not sure which applies, write to us anyway. We will either handle it or tell you which clinic to ask, and pass your request on.
What we collect
We collect what the clinic needs to treat you and what the app needs to work. Nothing is collected for advertising.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Name, mobile number, email address, password (stored only as a one-way hash, never in readable form), your role | You, when you register |
| Patient profile | Name, date of birth, gender, blood group, address, city, state, PIN code, your registration number at the clinic, your consulting doctor | You, or the clinic front desk |
| Clinical record | Consultation notes, chief complaints, diagnoses, ICD codes, vital signs (blood pressure, temperature, pulse, weight, height, SpO2), prescriptions, assessments and questionnaire answers, follow-up dates | Your doctor and clinic staff |
| Appointments | Which doctor, which branch, date and time, status, cancellations | You, or the clinic |
| Documents | Lab reports, scans and other files the clinic attaches to your record | The clinic, or you |
| Billing | Invoices, amounts, whether you paid by cash, card or UPI, and a payment reference if one was noted | The clinic |
| Activity log | A record of who viewed or changed what, and when. This exists to protect you — it is how misuse gets caught | Generated automatically |
| Technical | IP address, device and app version, error logs, timestamps | Generated automatically |
We do not take your card details. Payments are made directly to your clinic. We store only what the clinic records about a payment — the amount, the method and a reference. No card numbers, no UPI credentials, no bank details pass through DigiDoctor.app.
Most of this is legally “sensitive”
Under the Information Technology Act, 2000 and the rules made under it, some categories of information get extra protection — specifically your physical, physiological and mental health condition, your medical records and history, your passwords and any financial information. Nearly everything in your DigiDoctor.app record falls into that group.
We treat all of it as sensitive, and we handle it under the Digital Personal Data Protection Act, 2023 as well.
Why we use it
- To let you book appointments and to show your clinic that you have.
- To show your doctor your history at the time of consultation.
- To show you your own records, prescriptions and reports.
- To send you appointment reminders and account emails such as verification and password reset.
- To generate the clinic’s invoices.
- To keep the service secure, find and fix faults, and investigate misuse.
- To meet legal and medical record-keeping obligations.
We never sell information that identifies you. We do not share your records with advertisers, data brokers, insurers or employers, and we do not use your medical records to target advertising.
We do build anonymised statistics from what is in DigiDoctor.app, and we may license or sell those. Section 05 explains exactly what that means, what is stripped out first, and how to opt out.
Research and statistical data
We create anonymised, aggregated datasets from the information held in DigiDoctor.app, and we may use, license, sell or transfer those datasets to third parties — for research, statistical analysis, public-health work, and to develop and sell our own products.
We are telling you this plainly rather than burying it, because it is the part of this policy most people would want to know about.
What is removed before anything leaves
A dataset is only released once it has been stripped and aggregated so that it no longer identifies anyone. Before release we remove:
- Your name, and any family member’s name.
- Your mobile number, email address and postal address.
- Your clinic registration number and every internal identifier that links back to your account.
- Your doctor’s and clinic’s identity, unless the clinic has separately agreed to be named.
- Free-text consultation notes, which we do not release at all, because notes written by hand can name people.
- Uploaded documents, scans and lab report files. These are never included.
Dates are reduced to month and year, and location to district or state level rather than PIN code.
What our commitments are
- Aggregate only, never row-by-row. What we release are counts, rates and trends — for example, how many patients in a district were treated for a condition in a quarter — not one line per person.
- Small groups are suppressed. Where a figure would describe fewer than [N] people, we do not publish it, because a small enough group stops being anonymous.
- Re-identification is contractually banned. Anyone we give or sell a dataset to must agree in writing never to attempt to identify an individual from it, and never to combine it with other data to do so.
- No onward sale of identifiers, ever. If a dataset cannot be safely anonymised, we do not release it.
Being honest about the limits: no anonymisation is perfect, and health data is harder to anonymise than most, because an unusual combination of condition, age and place can point to one person. That is exactly why we suppress small groups, drop free text, coarsen dates and locations, and contractually forbid re-identification — rather than simply deleting your name and calling it anonymous.
Your choice
You can tell us not to include your information in these datasets. Write to [PRIVACY EMAIL], or use the setting in the app [BUILD THIS SETTING — an opt-out you advertise but don't provide is worse than no opt-out]. Opting out costs you nothing and changes nothing else about the service.
Once a dataset has already been aggregated and released, we cannot pull your contribution back out of it — there is no longer anything in it that points to you. Opting out applies to everything built from that point on.
[REQUIRED BEFORE THIS CLAUSE IS RELIED ON: your clinic agreement must expressly grant you this right. For clinical records the clinic is the Data Fiduciary and you are its Processor — patient consent alone is not enough, the clinic must permit it too. See section 02.]
Consent and your choices
You give consent when you register and when you book. You can withdraw it at any time by writing to us or to your clinic. Withdrawing consent stops future processing; it does not undo what was lawfully done before, and it does not erase a clinical record your clinic is legally required to keep.
Some things are optional and you can decline them without losing the service:
- Inclusion in the research and statistical datasets in section 05.
- The AI features in section 07.
- Optional email, as opposed to service messages.
[CONFIRM EACH OF THESE IS ACTUALLY TOGGLEABLE IN THE APP]
Messages we send you
We send two kinds of message. Service messages — email verification, password resets, appointment confirmations and reminders — are part of the service, and you cannot switch them off while your account is open, because switching them off would break the thing you came for. Anything else is optional, and every optional message carries a way to stop it.
If you give us your mobile number, you agree we may contact you about your appointments even if that number is registered on the DND or NCPR list under the Telecom Commercial Communications Customer Preference Regulations, 2018 — because an appointment reminder is a service message, not marketing. We will not send you marketing on that basis. [CONFIRM: does the product send SMS today, or email only?]
Keeping your details right
Please keep your details accurate. A wrong date of birth or blood group in a medical record is a safety problem, not a formality. You can correct your own account details in the app; clinical entries are corrected by your clinic.
AI features
Some parts of DigiDoctor.app use an external artificial-intelligence service to help your doctor — for example, summarising your history before a consultation and surfacing patterns across past visits. We would rather tell you this plainly than bury it.
When a doctor uses these features, your clinical information is sent to a third-party AI provider outside India ([NAME THE PROVIDER — currently OpenAI by default]). What is sent can include your name, age, gender, blood group, diagnoses, ICD codes, vital signs, prescriptions and consultation notes.
The provider processes it to produce the summary and returns it to your doctor. [CONFIRM: provider contractually barred from training on your data and required to delete it]
The output is a drafting aid for a clinician, not a diagnosis. Your doctor remains responsible for every clinical decision. Nothing generated by these features is shown to you as medical advice.
[DECISION NEEDED: offer patients an opt-out from AI processing, and say how to exercise it here]
Data leaving India
Your records are stored in [REGION]. The AI features in section 07 send clinical information outside India for processing. Some email delivery may also be processed outside India.
Transfers are made under the Digital Personal Data Protection Act, 2023, which permits transfer to countries other than those the Central Government restricts, and under contracts requiring the recipient to protect the data and use it only for the purpose we specify.
How we protect it
- Everything travels over HTTPS. Nothing moves in the clear.
- Passwords are stored only as one-way hashes. Nobody, including us, can read your password.
- Each clinic’s data is separated, and every request is checked against the clinic you belong to.
- Documents are not public. They are fetched through short-lived, single-use links that expire in minutes.
- Access to your record is logged — who, what, when.
- Backups are taken regularly and restricted. [CONFIRM: frequency and whether encrypted at rest]
No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board of India as required by law, and tell you what happened and what to do about it.
How long we keep it
Medical records are kept for as long as your clinic is required to keep them. Clinics in India are generally expected to retain records for at least three years, and longer in some cases; where a clinic is bound by a longer period, that period wins. [CONFIRM RETENTION PERIODS WITH COUNSEL]
Account data is kept while your account is active. If you delete your account we remove your login and app data, but your clinical record stays with your clinic for as long as the clinic must keep it — deleting an app cannot erase a medical record.
Technical logs are kept for [PERIOD].
Your rights
Under the Digital Personal Data Protection Act, 2023 you can:
- Get a copy of the personal data we hold about you, and a summary of how it is processed and who it has gone to.
- Have it corrected if it is wrong, incomplete or out of date. Clinical entries are corrected by your clinic (see section 02).
- Have it erased, unless we or your clinic are required by law to keep it.
- Nominate someone to exercise these rights for you if you die or become unable to act.
- Complain to us first, and then to the Data Protection Board of India if we do not resolve it.
Write to [PRIVACY EMAIL]. We will respond within [N] days. We may ask you to confirm your identity first — we are not going to hand a medical record to whoever asks.
Children
A child under 18 must be registered by a parent or legal guardian, who gives consent on the child’s behalf. We do not knowingly let a child create an account on their own. We do not use children’s data for tracking, behavioural monitoring or advertising.
If you believe a child has registered without a guardian’s consent, tell us and we will remove the account. [CONFIRM: how guardian consent is actually captured in the app today]
If our business changes
If DigiDoctor.app is ever merged, acquired, or its assets sold, patient data may transfer to the new owner as part of that. If it does, the new owner will be bound by this policy for the data it receives, and we will tell you before the transfer takes effect so you can export your records or close your account first.
If the company shuts down, we will give you reasonable notice and a way to get your records out, and we will tell your clinic so it can meet its own record-keeping duties. [CONFIRM NOTICE PERIOD]
Changes to this policy
If we change this policy we will update the date at the top. If the change materially affects how your data is handled we will tell you in the app or by email before it takes effect, not after.
Contact and grievances
For anything about your data, write to [PRIVACY EMAIL].
Grievance Officer
As required by the Information Technology Act, 2000 and the rules made under it:
- Name: [NAME]
- Designation: [DESIGNATION]
- Email: [GRIEVANCE EMAIL]
- Address: [ADDRESS]
We will acknowledge a complaint within 24 hours and resolve it within 15 days of receiving it.
If you are not satisfied with our response, you can complain to the Data Protection Board of India.