Privacy Policy
Commitment to Patient & Doctor Trust: The CliniQ AI is designed for outpatient healthcare practices in India. We adhere strictly to the Digital Personal Data Protection (DPDP) Act, 2023, Information Technology (IT) Rules, 2011, and Meta Platform / WhatsApp Business Platform Data Policies. We never sell, monetize, or broker patient health data.
1. Overview and Scope
This Privacy Policy explains how The CliniQ AI Technologies ("The CliniQ AI", "we", "us", or "our") collects, processes, stores, and protects personal data when licensed healthcare professionals, clinic staff ("Clinic Users"), and patients ("Patients") utilize our clinic operating system, web platform, voice reception interface, and WhatsApp integration.
2. Categories of Information We Collect
Depending on how you use our platform, we process the following categories of data:
- Clinic & Doctor Account Information: Doctor name, medical registration number (NMC/State Medical Council), clinic name, address, business email, phone number, and subscription billing details.
- Patient Operational Data: Patient full name, age/gender, contact phone number (WhatsApp-enabled), appointment date/time, token queue status, and visit reason provided during registration.
- Clinical Encounter Data (Doctor-Entered): Diagnosis notes, vitals, symptoms, electronic prescriptions, lab test requests, and follow-up schedules created and authorized by the licensed doctor.
- WhatsApp Communication Metadata: Message delivery timestamps, delivery status receipts, and appointment confirmation responses handled via the WhatsApp Business API.
- AI Voice Reception Records (Where Add-On is Enabled): Inbound phone audio recordings, real-time speech-to-text transcripts, and caller appointment preferences logged by the clinic's optional automated voice receptionist.
3. Purpose and Legal Basis for Processing
We process personal and health data strictly for legitimate clinical and operational purposes under Section 7 of the DPDP Act 2023:
- To enable doctors and outpatient staff to schedule consultations, maintain queue tokens, and generate official electronic prescriptions.
- To transmit automated appointment confirmations, reminders, clinic directions, and digital prescription PDFs to patients over WhatsApp on behalf of their consulting doctor.
- To process subscription payments and generate GST-compliant invoices for clinics.
- To maintain security audits, prevent fraudulent access, and ensure high system availability.
4. WhatsApp Business Platform & Meta Policy Compliance
Our platform integrates with Meta’s WhatsApp Business Platform to dispatch clinic communications. We operate under rigorous Meta compliance guidelines:
- Explicit Purpose Limitation: Patient phone numbers are utilized strictly for sending clinic-related transaction alerts (prescriptions, appointment updates, follow-up notifications, and token updates) initiated by the clinic.
- No Third-Party Sharing: We do not share, lease, or distribute patient contact details with advertisers, pharmaceutical sponsors, or external data brokers.
- Patient Opt-Out: Any patient may opt out of automated WhatsApp messages at any time by replying "STOP" or "UNSUBSCRIBE" to the clinic's WhatsApp chat, or through our Data Deletion Instructions page.
5. Data Architecture, Encryption & Security Safeguards
We implement multi-layered administrative, technical, and physical safeguards:
- Data Isolation: Clinic databases are architected with strict multi-tenant logical isolation, ensuring clinic data cannot be accessed by other clinics.
- Encryption Standards: All data in transit is protected using TLS 1.3 with high-grade ciphers. All persistent databases, electronic prescription records, and backups are encrypted at rest using AES-256.
- Role-Based Access Control (RBAC): Clinic owners can configure granular access permissions for receptionists, associate doctors, and staff members.
6. Medical Record Retention & NMC Exceptions
Under the regulations of the National Medical Commission (NMC), medical practitioners are legally required to retain clinical records and treatment charts for a statutory period (typically 3 years from the consultation date). Consequently, while patient contact profiles and WhatsApp subscriptions will be purged immediately upon request, clinical history legally mandated for statutory medical defense will be securely archived as required by Indian healthcare laws.
7. Your Rights Under DPDP Act 2023
As a Data Principal under Indian law, you have the right to:
- Right to Access: Request a summary of the personal information stored in our system.
- Right to Correction & Erasure: Request the correction of inaccurate details or the erasure of personal data that is no longer necessary, subject to medical statutory laws.
- Right of Grievance Redressal: Register grievances directly with our designated Data Protection desk.
- Right to Nominate: Nominate another individual to exercise your data rights in the event of death or incapacity.
To exercise any of these rights, visit our Data Deletion Instructions page or contact our Grievance Officer.
8. Grievance Officer Contact Details
In accordance with the Information Technology Act 2000 and the DPDP Act 2023, the details of our Grievance Officer are provided below:
Grievance & Data Protection Officer
The CliniQ AI Technologies
Address: B-604, Platina Society, Kala Khadak, Wakad, Pune - 411057, Maharashtra, India
Email: privacy@thecliniqai.com
Response SLA: Grievance acknowledgment within 48 hours; resolution within 30 days.
9. Updates to this Policy
We may periodically update this Privacy Policy to reflect regulatory evolutions or product enhancements. Substantial modifications will be highlighted through in-app notices or direct email communications to clinic administrators.