Skip to main content

Privacy notice

DRAFT — requires legal review

This document is a working draft prepared by the engineering team to describe how the platform is designed to support compliance. It is not legal advice and has not yet been reviewed by counsel. Do not rely on it as a final policy until this banner is removed.

Last updated: 26 September 2026 (draft)

1. Who we are and our role​

Achal Technology ("we") provides Achal Technology Healthcare Management Software to clinics, labs and hospitals ("healthcare providers").

  • For patient data entered by a healthcare provider, the provider is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) and we act as its Data Processor, processing only on its documented instructions (see the DPA template).
  • For account data of our customers (clinic owners, staff users) and website visitors, we are the Data Fiduciary.

2. What data we process​

CategoryExamplesSource
Identity & contactName, phone, email, address, date of birth/age, sex, guardian detailsPatient / provider
Health dataVisits, vitals, diagnoses, allergies, prescriptions, clinical documents, images, reportsProvider
FinancialInvoices, payments, refunds (card data is handled by the payment gateway, not stored by us)Provider / patient
CommunicationsWhatsApp/email/SMS delivery records, remindersSystem
TechnicalLogin events, device/IP, access logs, audit trailSystem

3. Why we process it (purposes)​

  • Providing healthcare-operations services to the provider (registration, appointments, clinical records, billing).
  • Sending reminders, prescriptions, bills and reports that the provider or patient has chosen to receive.
  • Security, fraud prevention, audit and legal compliance (including medical-record retention obligations).
  • Service improvement using aggregated, de-identified statistics only (opt-in for platform benchmarks).

We do not sell personal data and do not use health data for advertising or to train AI models.

Providers collect patient consent (and guardian consent for children) at registration or before specific activities (teleconsultation, sharing with another provider). Consent for optional processing can be withdrawn at any time; withdrawal does not affect records a provider must keep by law. Sharing across providers happens only with the patient's recorded consent, and copies that have become part of the receiving provider's legal medical record are retained even if sharing is later revoked.

5. Where data is stored​

All production data is stored in India on Google Cloud: primary region Mumbai (asia-south1), disaster-recovery copies in Delhi (asia-south2). Some subprocessors may process limited data outside India where stated in the subprocessor list, under contractual safeguards.

6. How long we keep it​

See the retention policy. Medical records are retained for the periods required by law and by the provider's policy, even when an erasure request is received.

7. Security​

Backend-only data access with tenant isolation, encryption in transit and at rest, envelope encryption for especially sensitive fields, least-privilege access, audit and access logs, daily backups with point-in-time recovery, and regular security testing.

8. Your rights​

You can request access, correction, completion, updating and erasure of your personal data, nominate another person to exercise your rights, and raise a grievance. See data-principal rights. Patients should normally contact their healthcare provider first; we assist providers in responding.

9. Grievance officer​

Grievance Officer: TBD — to be appointed before general availability. Contact channel: TBD (email and postal address will be published here). You may also complain to the Data Protection Board of India.

10. Changes​

We will post changes here and notify customers of material changes in advance.