Privacy
Last updated 30 August 2026
Two different sets of data
It matters which is which. Your account data — your name, email, phone, clinic details and payment records — is data we hold about you as our customer, and we decide how it is used. Patient data— everything your clinic records about the people it treats — belongs to your clinic. You decide what goes in it and who sees it. We only process it to run the service you asked for.
What we collect about you
- Account details you enter: name, email address, mobile number, clinic name and address, GSTIN, registration numbers and logo.
- Billing records: which plan you are on, what you paid and when. Card and UPI details go to Razorpay and never reach us.
- Operational logs: timestamps, IP address and browser, kept so we can investigate errors and abuse. Retained for 90 days.
There is no advertising, no tracking pixel and no third-party analytics on the signed-in application.
What your clinic collects about patients
Whatever you enter: identity and contact details, visit history, vitals, complaints, diagnoses, prescriptions, dispensed medicine, lab results, invoices and payments. We do not use any of it for anything other than showing it back to your clinic and sending the messages your clinic asks us to send. We never sell it, never train models on it, and never share it with another clinic.
Who else touches it
- Supabase — managed PostgreSQL, authentication and file storage, in Singapore.
- Cloudflare — serves this website and the application.
- Razorpay — subscription payments. Receives your billing details, not patient data.
- A messaging provider — receives a patient's name and phone number and the text of the reminder, only for messages your clinic sends.
That is the whole list. There are no other recipients.
Consent for patient messages
A patient can opt out of messages, and the opt-out is checked before a message is even composed — not at the point of sending. Once a patient has opted out, nothing further is queued for them.
Your rights, and your patients'
Under India's Digital Personal Data Protection Act, a person may ask for a copy of their data, ask for it to be corrected, and ask for it to be erased. For patient data, that request goes to the clinic, and the app gives you the tools to answer it: export a patient's full record, correct it, or delete it. If a request reaches us directly we will pass it to the clinic and help them answer it.
For your own account data, write to privacy@clinikr.xyz and we will answer within thirty days.
Retention and deletion
Clinical records are kept for as long as your clinic keeps them — medical record retention obligations are the clinic's to meet, and we will not delete anything on our own schedule. If you close your account, ask us to delete the clinic and we will remove it, including from backups, within thirty days. Before that, export everything; after it, we cannot recover it for you.
Breaches
If personal data is exposed, we will tell affected clinics and the Data Protection Board, with what we know and what we are doing about it, as soon as we have established the facts and in any case without undue delay.
Changes
If this policy changes in a way that affects you, we will email you before the change takes effect rather than quietly updating the date at the top.