Privacy notice
This document is a working draft prepared by the engineering team to describe how the platform is designed to support compliance. It is not legal advice and has not yet been reviewed by counsel. Do not rely on it as a final policy until this banner is removed.
Last updated: 26 September 2026 (draft)
1. Who we are and our role
Achal Technology ("we") provides Achal Technology Healthcare Management Software to clinics, labs and hospitals ("healthcare providers").
- For patient data entered by a healthcare provider, the provider is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) and we act as its Data Processor, processing only on its documented instructions (see the DPA template).
- For account data of our customers (clinic owners, staff users) and website visitors, we are the Data Fiduciary.
2. What data we process
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, phone, email, address, date of birth/age, sex, guardian details | Patient / provider |
| Health data | Visits, vitals, diagnoses, allergies, prescriptions, clinical documents, images, reports | Provider |
| Financial | Invoices, payments, refunds (card data is handled by the payment gateway, not stored by us) | Provider / patient |
| Communications | WhatsApp/email/SMS delivery records, reminders | System |
| Technical | Login events, device/IP, access logs, audit trail | System |
3. Why we process it (purposes)
- Providing healthcare-operations services to the provider (registration, appointments, clinical records, billing).
- Sending reminders, prescriptions, bills and reports that the provider or patient has chosen to receive.
- Security, fraud prevention, audit and legal compliance (including medical-record retention obligations).
- Service improvement using aggregated, de-identified statistics only (opt-in for platform benchmarks).
We do not sell personal data and do not use health data for advertising or to train AI models.
4. Consent and legitimate uses
Providers collect patient consent (and guardian consent for children) at registration or before specific activities (teleconsultation, sharing with another provider). Consent for optional processing can be withdrawn at any time; withdrawal does not affect records a provider must keep by law. Sharing across providers happens only with the patient's recorded consent, and copies that have become part of the receiving provider's legal medical record are retained even if sharing is later revoked.
5. Where data is stored
All production data is stored in India on Google Cloud: primary region Mumbai (asia-south1), disaster-recovery copies in Delhi (asia-south2). Some subprocessors may process limited data outside India where stated in the subprocessor list, under contractual safeguards.
6. How long we keep it
See the retention policy. Medical records are retained for the periods required by law and by the provider's policy, even when an erasure request is received.
7. Security
Backend-only data access with tenant isolation, encryption in transit and at rest, envelope encryption for especially sensitive fields, least-privilege access, audit and access logs, daily backups with point-in-time recovery, and regular security testing.
8. Your rights
You can request access, correction, completion, updating and erasure of your personal data, nominate another person to exercise your rights, and raise a grievance. See data-principal rights. Patients should normally contact their healthcare provider first; we assist providers in responding.
9. Grievance officer
Grievance Officer: TBD — to be appointed before general availability. Contact channel: TBD (email and postal address will be published here). You may also complain to the Data Protection Board of India.
10. Changes
We will post changes here and notify customers of material changes in advance.