Scope of this policy
This policy covers the ClinicSutra application, this website and the support conversations you have with us. It explains the personal data handled to run the service — it does not explain the clinic’s own record-keeping, which is the clinic’s responsibility to its patients.
Who is responsible for the data
Patient records — names, addresses, phone numbers, visits, prescriptions, bills — are entered by the clinic about its own patients. For that data the CLINIC is the data fiduciary: it decides why and how it is kept, and it must give patients the notice and choice Indian law requires.
We process that data only on the clinic’s instructions, to store it, display it, back it up and support it.
For account and billing data — the clinic’s name, its contact details, the subscription, and support messages — we are the data fiduciary.
What is collected
The service handles:
- Account data: clinic name, doctor and staff names, username, contact number, email address, and the password, which is stored only as a hash.
- Patient data: whatever the clinic types in — identity, contact details, allergies, visit notes, prescriptions, billing, follow-ups and stock movements.
- Usage and technical data: sign-in times, the pages and actions used, the browser or device, and server logs needed to keep the service secure.
- Subscription data: plan, term, invoices, payment confirmations. Card and UPI credentials are entered with the payment provider and are never stored on our servers.
- Support data: whatever you send us in an email, a WhatsApp message or a support report.
How it is used
To provide the service you asked for: to store and show your clinic’s records, to print prescriptions and bills, to build reports and reminders, and to restore a backup when you ask.
To run the subscription: invoices, renewals, expiry notices and the read-only switch on an unpaid subscription.
To secure and improve the service: detecting misuse, diagnosing faults, understanding which features are used and which break, and planning what to fix next.
To answer you: support requests, and messages about outages or changes.
The legal ground for each use
Under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 with its 2011 rules, personal data is processed on consent, on a legitimate use, or because it is needed to do what you asked us to do.
Delivering the service you signed up for, keeping it secure, running the subscription and complying with tax and legal duties do not need fresh consent each time. Anything outside that — a new marketing message, for example — we will ask for.
Sharing
We do not sell personal data, do not rent it, and do not hand it to advertisers. It is shared only where the service cannot be delivered without it:
- the company hosting your database, under contract, in India;
- the payment provider, when you pay, and only the payment details that provider needs;
- our own support staff, when you ask us to look at a problem;
- public authorities, where a lawful order or the law requires it — including mandatory reporting duties that apply to a clinic;
- a buyer of the whole business, if there ever is one, under the same protections and with notice to you.
Transfers outside India
Where data is transferred outside India, it is done in the way the Digital Personal Data Protection Act, 2023 permits and only to countries the Central Government allows. In practice your database and its backups stay in India.
How long it is kept
Patient records are kept for as long as the clinic keeps its practice records, because Indian law and professional rules require a clinic to retain them — the retention decision is the clinic’s.
Account and billing records are kept while the account is open and for the period tax and company law requires afterwards.
Server logs are kept for a short, rotating window used for security.
Backups age out on a rolling cycle, so data removed today disappears from backups as those cycles roll over.
Ask for deletion at any time and we will act on it, subject to what the law obliges us to keep.
How it is protected
Each clinic’s records sit in their own database, so one clinic never queries another’s. Connections use encrypted transport, passwords are hashed, access to the servers is restricted to the few people who need it, and every change is logged.
Backups can be taken from inside the application and restored the same way. No system is perfectly secure, and the Data Protection Policy explains what we do if there is ever a breach.
Your rights
You can ask for a summary of what is held about you, correct what is wrong, have it erased, have a complaint answered, and nominate someone to exercise your rights for you — those are the rights the Data Protection Policy sets out in full.
For a patient record, start with the clinic that holds it, because the clinic is the fiduciary for that record. We will help the clinic answer you.
Children
A clinic may treat children, and their records are entered by the clinic under its own duties. We do not track children, do not profile them, and do not target advertising at them.
Cookies and local storage
The service signs you in with a session cookie and remembers a "keep me signed in" choice with a cookie of its own, and stores your display preferences in the browser. There is no advertising cookie and no cross-site tracking. The Cookie Policy has the detail.
Changes and how to reach us
The date at the top of this page shows when it last changed; a material change is announced before it takes effect.
Privacy questions, or a request about your own data: support@clinicsutra.com, WhatsApp +919428953367. Operator: [Company legal name], [Registered address]. Complaints are handled on the Grievance Redressal page.