1. Overview
ClinikMate ("we", "our", "us") operates a cloud-based multi-tenant clinic management platform. This Privacy Policy governs how we collect, process, store, and protect personal data of clinic operators ("Tenants") and their patients across all ClinikMate services.
By creating an account and using ClinikMate, you acknowledge this policy and agree to its terms. Clinics acting as Data Controllers are responsible for obtaining appropriate patient consent before uploading patient health information to the platform.
2. Information We Collect
2.1 Clinic (Tenant) Account Data
- Account holder name, email address, and phone number
- Clinic name, physical address, GST/business registration number, and specialty
- Subscription plan, billing contact, payment history, and invoice records
- Configuration settings, feature preferences, branch details, and staff roles
2.2 Patient Data (Processed on Your Behalf)
When you store patient records, you upload Protected Health Information (PHI) which may include patient names, contact details, medical history, appointment records, vitals, EMR notes, prescriptions, lab results, invoices, and uploaded documents.
Each clinic's data is isolated from every other clinic. No clinic can ever access another clinic's patient records — every database query from a clinic's own staff is cryptographically scoped to that clinic's unique tenant ID. A small number of authorized ClinikMate platform administrators can access any clinic's records solely for customer support, billing, and technical troubleshooting; every such access is logged and auditable, and is never used for marketing or shared externally.
2.3 Technical and Usage Data
- Server access logs: IP address, timestamp, browser and device type, HTTP method, and response code
- Feature usage analytics — aggregated and anonymised; never linked to individual patient records
- Audit logs: which staff user performed which action, on which record, at what timestamp
- Error reports and performance metrics used exclusively for debugging and service improvement
3. How We Use Your Information
- To provide, operate, maintain, and continuously improve the ClinikMate platform and its features
- To provide opt-in AI features — structuring a doctor’s rough consultation notes, or suggesting a possible clinical assessment and treatment approach for the doctor to review — only when a doctor actively triggers them, never automatically
- To process subscription billing, send invoices, payment receipts, and renewal reminders
- To send essential service notifications, security alerts, and product update announcements
- To detect, investigate, and prevent fraud, abuse, and security incidents
- To generate anonymised aggregate usage reports for product research and development
- To comply with applicable legal obligations under Indian and international law
- To provide timely customer support and resolve technical issues or disputes
We will never sell, rent, or trade your data or patient records to any third party for marketing, advertising, or commercial purposes. Patient data is used solely to provide the ClinikMate service to your clinic — nothing else.
4. Data Storage and Security
Security is central to how ClinikMate is designed and operated. We implement layered technical safeguards aligned with HIPAA Security Rule and DPDP Act 2023 requirements:
TLS 1.3 in Transit
All API requests and data transfers encrypted end-to-end
AES-256 at Rest
Database rows and uploaded files fully encrypted on disk
15-min Token Expiry
JWT access tokens short-lived and automatically rotated
Hashed Refresh Tokens
bcrypt-hashed before storage — plain tokens never retained
Row-level Tenant Isolation
Every query cryptographically scoped to your tenant ID
30-day Encrypted Backups
Point-in-time recovery available for disaster scenarios
Global JwtAuthGuard
Every route protected by default — opt-out required for public
Regular Security Audits
Quarterly penetration tests and vulnerability assessments
Your database records are stored on servers located in India. Where you enable email or WhatsApp appointment reminders, the minimum contact information needed to deliver that message (patient name, phone number and/or email address, and appointment details) is transmitted to the third-party providers named in Section 5 to carry out delivery — those providers may process data on servers outside India as part of their standard service operation. No other patient data is transferred outside India without your explicit written consent.
7. Data Retention
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Active tenant & patient data | Duration of subscription | Contract performance |
| Data after cancellation / expiry | 30 days read-only for export, then deleted | Data portability (DPDP) |
| Audit logs (staff actions on PHI) | 7 years | Healthcare regulatory compliance |
| Billing records & invoices | 10 years | Income Tax Act / GST requirement |
| Customer support communications | 3 years | Dispute resolution & liability |
| Anonymised usage analytics | Indefinite — no PII included | Legitimate interest |
8. Your Rights
Under the DPDP Act 2023 and applicable privacy laws, you have the following rights regarding your data:
Right to Access
Request a complete copy of your personal data in machine-readable format (JSON/CSV)
Right to Rectification
Correct inaccurate or incomplete personal data without undue delay
Right to Erasure
Request deletion of your data, subject to legal retention obligations listed above
Right to Data Portability
Export all your data from Settings → Data Export at any time
Right to Object
Object to processing based on legitimate interest (e.g. analytics)
Right to Restriction
Limit processing while a dispute or correction request is being resolved
Submit requests to privacy@clinikmate.com. We acknowledge all requests within 5 business days and resolve them within 30 business days at no charge to you.
9. Children's Privacy
ClinikMate is intended solely for use by healthcare professionals, clinic administrators, and authorised staff members who are 18 years of age or older. We do not knowingly collect personal data directly from children under the age of 13.
Patient records for minor patients stored within the platform are managed by the clinic (acting as Data Controller) in accordance with applicable healthcare and child data protection regulations. Clinics must ensure they have obtained appropriate guardian or parental consent before storing minor patient records in the system.
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, regulatory requirements, or service features. We will notify you via email and an in-app notice at least 14 days before any material changes take effect.
Minor, non-substantive changes (grammar, formatting, clarifications that do not affect your rights) may be made without prior notice. The effective date at the top of this page reflects when the policy was last updated.
11. Contact and Data Protection Officer
For all privacy-related questions, concerns, data requests, or complaints, please contact our dedicated Data Protection Officer:
Data Protection Officer
ClinikMate · Gurugram, Haryana, India
Acknowledgement within 5 business days · Resolution within 30 days · No charge for requests
