Privacy Policy
This notice explains what personal data Homoeoclinics handles, why, who processes it on our behalf, how long we keep it, and the rights you have. It is given under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act").
Who we are
Homoeoclinics is practice-management software for homoeopathic clinics in India, operated by Homoeoclinics Pvt Ltd ("we", "us"). For the personal data described in this notice we are a Data Fiduciary under the DPDP Act; for a patient's clinical record, the clinic treating that patient and the platform act as joint Data Fiduciaries — the clinic decides what goes into the record, and we provide and secure the system that holds it.
This one page covers this website (homoeoclinics.com) and the application (app.homoeoclinics.com and the mobile apps), for all three kinds of account — doctor, patient and scholar. The audience-specific notices you accept inside the app say the same things in more detail for your own account type.
Visitors to this website
This website sets no advertising or analytics cookies and runs no third-party trackers. The only things it stores are your language and text-size choices, kept in your own browser's local storage and never sent to us. Reading this site tells us nothing about you beyond the ordinary server logs (IP address, page requested, time) that every web server keeps for security, and which we keep for no longer than 12 months.
Doctors and clinic staff
What we collect and why:
- Account details (name, phone, email) — to identify you and sign you in.
- Professional registration details — your registration number is shown to patients linked to your clinic, which is its purpose. Proof documents you upload for verification are never shown to patients.
- Clinic details (name, address, working hours) — to run your clinic's appointments, patients and prescriptions inside the service, and to publish your clinic's page if you choose to publish one.
- Usage records (what the app logs as you use it) — to keep the service working and secure.
- Payment details for your subscription are collected and processed by our payment processor, Razorpay, directly — we never see or store your card or banking details.
Patients
What the platform stores about a patient: the name, phone number and basic profile shared by your clinic; your appointments; prescriptions shown to you using the medicine labels chosen by your doctor; reminder and notification history; and your communication preferences.
Your clinic and doctor use this platform to manage your care; the platform processes this data only to provide that service. The doctor — not the platform — is responsible for clinical decisions and prescriptions, and the platform does not provide medical advice to you. Every clinical record is scoped to the clinic that created it: only that clinic's accounts can reach it.
Case notes never leave our infrastructure. The free-text case notes your doctor writes are read and analysed by our own software on our own servers. They are never sent to any third-party AI service or anywhere outside the application's infrastructure.
Scholars
A scholar account is a reading account, and nothing clinical is associated with it — no patients, no case records, no prescriptions. We store your name, phone number and email if you give one, your subscription and payment status, and the notes and highlights you create. Your notes and highlights are private to your account: they are not shared with any clinic, doctor or patient, are not used to train anything, and are not sold to anyone.
Service providers who process data on our behalf
- Razorpay — subscription payments (doctors and scholars). We do not store card or banking details ourselves.
- Firebase Cloud Messaging (Google) — push notifications to your device, if enabled.
- Meta's WhatsApp Business Cloud API — sign-in codes, follow-up booking reminders and clinic announcements, only where you have consented to WhatsApp messages. Clinical content — medicine names, labels, prescriptions, case data — is never sent over WhatsApp.
- Hosting infrastructure (DigitalOcean) — the virtual servers the application and its database run on.
Some of this infrastructure may process data on servers outside India. The DPDP Act permits transfers to any country not specifically restricted by the Central Government, and none is currently restricted for the categories above.
If a doctor connects a Google account
A doctor may optionally connect their own Google account so that online consultations they schedule get a Google Meet link on their own Google Calendar. If they do:
- We request only the calendar.events permission, and use it only to create, update and delete the consultation events the doctor schedules through Homoeoclinics. We do not read, and cannot see, any other event on the calendar.
- The events we create carry no patient-identifying information — no patient name, phone number or clinical detail is ever sent to Google.
- The connection can be disconnected at any time, either inside Homoeoclinics or from the doctor's own Google account permissions page, and disconnecting revokes our access.
- Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is never sold, never used for advertising, and never used to train any model.
What we never do
- We do not sell personal data.
- We do not use personal data for advertising, and the platform carries no advertising for anyone, of any age.
- We do not run behavioural tracking or profiling.
- We do not send case notes or any clinical text to third-party AI services.
Children
Where a patient is under 18, the DPDP Act requires verifiable consent from a parent or lawful guardian before a child's personal data is processed. On this platform that consent is given and recorded through a linked guardian account, which the guardian controls. We do not run behavioural tracking or targeted advertising directed at children.
How long we keep data
Records are kept while the account they belong to is active. After an account closes, or when you ask for data to be erased, we keep only what the law requires us to keep, for as long as it requires:
- Clinical records (case notes, prescriptions, appointment history) — retained for 3 years from the last entry, in line with Indian medical record-keeping norms for outpatient records, then deleted. A clinic may direct a longer period where its own regulatory obligations require one.
- Payment, subscription and invoicing records — retained for 8 years, as required for books of account under the Companies Act, 2013 and tax law.
- Security and audit logs — retained for 12 months, then deleted.
- Sign-in codes (OTPs) — expire within minutes and are purged automatically.
- Everything else (profile details, preferences, notes and highlights) — deleted within 90 days of account closure.
Security
Access to clinical data is scoped to the clinic that owns it and re-checked on the server for every request. Data in transit is encrypted (HTTPS everywhere). We apply security safeguards appropriate to health-adjacent data, but no system can promise absolute security, and nothing in this notice shifts responsibility for negligent platform operation onto you.
Your rights
Under the DPDP Act you may:
- Access a summary of your personal data and how it has been processed;
- Correct data that is inaccurate or incomplete;
- Request erasure of your personal data. Write to the Grievance Officer below and we will action the request, except for records the law requires us to keep (see the retention periods above) — those are erased when their retention period ends;
- Withdraw consent at any time — withdrawal does not undo processing already lawfully done before it;
- Nominate another person to exercise these rights on your behalf if you die or become incapacitated.
You may also give or manage consent through a Consent Manager registered with India's Data Protection Board, where one is available to you. If you are a patient, your clinic can also raise any of these requests for you from inside the app.
Grievance Officer
Grievance Officer, Homoeoclinics Pvt Ltd — grievance@homoeoclinics.com.
We aim to acknowledge a complaint within 3 working days and resolve it within 7. If you remain unsatisfied, you may complain to the Data Protection Board of India.
Emergencies
This platform is not for emergencies. For urgent medical situations contact emergency services or visit the nearest hospital.
Changes to this policy
When this policy changes, the "Last updated" date above changes with it, and changes that materially affect how your data is handled are notified inside the app before they take effect. Earlier versions are available from the Grievance Officer on request.