Privacy Policy

Last updated: June 2026

1. Overview

Ayusathi ("we", "us") is committed to protecting the privacy and security of personal data in accordance with the Digital Personal Data Protection Act 2023 (DPDP Act) and applicable Indian regulations. This policy explains how we collect, use, store, and protect data.

2. Data We Collect

  • Practitioner data: Name, qualifications, registration number, contact details, chamber addresses.
  • Patient data: Name, phone number, appointment history, clinical notes (entered by the practitioner).
  • Communication data: WhatsApp messages exchanged between clinic numbers and patients (with explicit consent).
  • Usage data: Analytics on feature usage, session duration, error logs.

3. Lawful Basis & Consent (DPDP Act)

Health data is classified as Sensitive Personal Data under the DPDP Act. We process it only with explicit consent obtained at the point of collection (booking forms, WhatsApp opt-in reply). Consent can be withdrawn at any time by the data principal (patient).

4. Data Storage & Residency

All patient data is stored on servers located in India (Mumbai region). Data is encrypted at rest (AES-256) and in transit (TLS 1.3). We retain patient records for a minimum of 8 years as required by NMC clinical record retention regulations.

5. WhatsApp Communication

We use the WhatsApp Cloud API to send appointment confirmations, reminders, and follow-up messages. Only utility templates (not promotional content) are sent. Every message includes an opt-out option ("Reply STOP"). We never send unmasked ABHA IDs, Aadhaar numbers, or detailed lab values in message bodies.

6. Data Sharing

We do not sell personal data. Data may be shared with: (a) Supabase (our database provider, India region); (b) Meta (WhatsApp Cloud API, for messaging delivery only); (c) Payment processors (Razorpay) for billing. Each processor is bound by data processing agreements.

7. Your Rights

  • Access, correct, or delete your personal data.
  • Withdraw consent for WhatsApp communications at any time.
  • Request data portability in a machine-readable format.
  • Lodge a grievance with the Data Protection Board of India.

8. Data Breach Notification

In the event of a personal data breach, we will notify affected users and the Data Protection Board within 72 hours of becoming aware of the breach, as required by the DPDP Act.

9. Contact & Grievance Officer

For privacy queries or to exercise your rights, contact our Grievance Officer at privacy@ayusathi.com. We respond within 30 days.