Our commitment and the law
We protect personal data as the Digital Personal Data Protection Act, 2023 requires, together with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and — for billing — the Consumer Protection Act, 2019.
This policy explains how those duties are met in practice: what is processed, on what basis, how it is secured, how long it is kept, and what you can demand.
The roles we each play
A DATA FIDUCIARY decides why and how personal data is processed. A DATA PRINCIPAL is the person the data is about. A DATA PROCESSOR processes it on the fiduciary’s behalf.
For patient records, the clinic is the data fiduciary and we are the data processor: we store, display, back up and support it on the clinic’s instructions, and nothing else.
For account, subscription and support data, the operator of this deployment is the data fiduciary.
Where the law gives the data principal a right against a fiduciary, the clinic answers for patient records and we answer for ours — and we help the clinic answer, because we hold the technical means.
Notice and a lawful basis
Personal data is processed only for a purpose that is clear to the person it is about, and only where there is consent for it or a legitimate use that the Act allows.
Operating the service the clinic asked for, securing it, running the subscription, meeting tax and record-keeping duties and answering a legal request are legitimate uses that do not depend on a fresh consent each time.
What consent has to look like
Where consent is the basis, it must be free, specific, informed, unconditional and unambiguous — a clear affirmative action, not a pre-ticked box or silence.
Consent may be withdrawn as easily as it was given, and withdrawal does’t undo what was lawfully done before it.
Consent for a child comes from a verifiable parent or guardian.
Rights of a Data Principal
You may, in relation to personal data about you:
- obtain a summary of what is being processed and with whom it has been shared;
- require correction of anything that is inaccurate or misleading, and require completion of anything incomplete;
- require erasure of personal data that is no longer needed for the purpose it was collected for;
- have a grievance answered through the Grievance Redressal mechanism, within the time the law allows;
- nominate another person to exercise these rights for you, including after your death.
How to exercise those rights
Write to the clinic for a patient record — the clinic is the fiduciary for it — and to support@clinicsutra.com for account, subscription or support data. We act on a verified request, and help the clinic act on one, within the time the law sets.
We never charge for a first request, and never respond by dark patterns or by pushing you towards a sale.
Security safeguards
Reasonable security practices and procedures are applied to personal data, technically and organisationally:
- a separate database per clinic, so one tenant cannot read another’s records;
- encrypted transport, hashed passwords, and least-privilege access limited to the staff who need it;
- logged, reviewed access to the production systems, and background checks on those with it;
- backups taken on a schedule and restorable from inside the application;
- a change process: reviewed before it ships, tested, and reversible;
- security awareness for everyone who touches the data, and a signed confidentiality duty.
If personal data is ever breached
Any suspected breach is contained and assessed as soon as it is found. Where the assessment shows a personal data breach, we notify the Data Protection Board of India in the manner the law prescribes, and tell the affected data principals about what happened, what was affected and what they can do.
The clinic is told at once for anything touching its records, with what it needs to discharge its own duties to its patients.
Retention
Personal data is kept only as long as the purpose it was collected for needs it, or as the law requires — clinical records and tax records have their own statutory periods, and those decide the clinic’s retention.
When neither applies, the data is deleted or anonymised, and backups age out on their rolling cycle.
Children’s personal data
Children’s data is processed only with verifiable consent from a parent or guardian, is never tracked, is never subject to behavioural monitoring, and is never used to target advertising at a child.
Transfers outside India
Personal data may be transferred outside India except to countries restricted by the Central Government, and only with the safeguards this policy describes. In practice, your data and its backups stay in India.
Accountability
We keep this policy under review against the law as it is brought into force and as the rules under it evolve. Where the Act requires a Data Protection Officer — for a significant data fiduciary — the contact is published here; until then the Grievance Officer named on the Grievance Redressal page answers the same questions.
Contact
Questions about this policy, or a request about your own data: support@clinicsutra.com, WhatsApp +919428953367. Operator: [Company legal name], [Registered address]. Complaints follow the Grievance Redressal page.