Medovra Privacy Policy
This policy explains, in plain language, what personal data Medovra handles, why, who we share it with, and the choices and rights you have. It is written for the clinics that use Medovra, their staff, and the patients whose appointments are managed through it.
1. Who we are
Medovra is clinic booking software (offered as software-as-a-service), a business based in India ("Medovra", "we", "us").
Medovra helps clinics manage appointments, patients, visits and prescriptions. It is a booking and clinic-management app only. It does not process payments.
2. Two different roles: ours and the clinic's
India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") gives different responsibilities to different organisations. In Medovra, there are two situations:
| Whose data | Who decides why and how it's used | Medovra's role |
|---|---|---|
| Clinic account and staff user data (for example, the clinic owner's, doctors' and receptionists' names, emails, phone numbers and logins), and enquiries made to us through our website | Medovra | Data Fiduciary. We are responsible for this data under this policy. |
| Patient data that a clinic enters into Medovra or collects through it (bookings, patient records, visits, prescriptions, messages) | The clinic | Data Processor. We process it only on the clinic's behalf and on its instructions, to provide the service. |
If you are a patient: the clinic you booked with is responsible for your data. It decides what to collect, why, and for how long. Please contact the clinic first for any request about your data. If the clinic asks us, we will help it respond. You can also contact our Grievance Officer (section 13), and we will pass your request to the clinic or help as the law requires.
3. What data we handle
3.1 Clinic account and staff data (Medovra is the Data Fiduciary)
- Name, email address, phone number and role (owner/admin, doctor, receptionist)
- Login details and account settings
- Clinic details: clinic name, branch addresses and phone numbers, departments, services, doctor schedules, clinic branding used on prescriptions
- Activity records needed to run and support the service (for example, which user created or changed an appointment)
- Messages you send us, and details you give us when you request a demo or join our founding-clinics list on our website
3.2 Patient data (the clinic is the Data Fiduciary; Medovra is the Data Processor)
Depending on how the clinic uses Medovra:
- Identity and contact details: name, mobile number, email (optional), address, date of birth or age
- Appointment details: branch, department, doctor, date and time, how the booking was made (website, WhatsApp, front desk, or AI chat if enabled), and status (booked, rescheduled, cancelled, attended, missed)
- Health information: visit records and prescriptions, which can include the complaint, diagnosis, examination findings, investigations, vitals (such as BP, pulse, SpO2, sugar, temperature, height and weight), allergies, medicines, advice and follow-up plans
- Prescription photos that a doctor chooses to upload for AI prescription screening
- AI-generated summaries and drafts: the patient-history summary and prescription overviews produced for the doctor
- Services and fees recorded for a visit (billing history and reports; Medovra does not take or process payments)
- Messages and message logs: confirmations, reminders and other patient messages, plus a log of each send (channel, recipient, time and any error)
- AI chat conversations on the clinic's booking page, if the clinic has enabled the AI chat
Health information is sensitive. We treat it with extra care. We limit who can see it inside the clinic through roles, and we do not use it for advertising or sell it.
3.3 Website visitors
When you visit medovra.com, our servers may record basic technical information such as your IP address, browser type and the pages requested, as most websites do. See section 11 on cookies.
4. Why we use data (purposes)
Clinic account and staff data: to create and run your account, let your staff sign in with the right access, provide support, respond to demo requests and enquiries, send service-related messages (such as account or security notices), improve and secure the service, and meet legal obligations.
Patient data (on the clinic's behalf): only to provide the service the clinic has asked for. That means taking and managing bookings, sending booking confirmations, reminders and other appointment messages, keeping patient and visit records, producing prescriptions and reports, and the AI features described in section 6 (prescription screening, the patient-history summary and, if enabled, the AI chat). We do not use patient data for our own marketing, we do not sell it, and we do not use it for purposes the clinic has not asked for.
5. Consent and legal basis
- Clinic and staff data: we rely on your consent, or on other grounds the DPDP Act allows (such as using data you voluntarily give us to provide the service you asked for, or meeting a legal obligation). You can withdraw consent at any time by contacting us (section 13). Withdrawal doesn't affect anything done before it. If you withdraw consent needed to run your account, we may not be able to keep providing the service.
- Patient data: the clinic is responsible for giving patients a proper notice and getting any consent the law requires before entering their data into Medovra or messaging them. This includes WhatsApp opt-in before patients are messaged on WhatsApp. If a patient withdraws consent, the clinic must tell us what to change, and we will act on the clinic's instructions.
6. AI features
Medovra's AI features help doctors. They don't make medical decisions:
- AI prescription screening. When a doctor uploads a photo of a prescription, the image is sent to OpenAI, which lays out the key details (such as complaint, vitals, medicines and advice) as a draft overview. The doctor reviews and edits it before anything is saved.
- AI patient-history summary. To give the doctor a short summary of a patient's past visits (when they came and what they were treated for), the relevant visit records are sent to OpenAI. The doctor reviews the summary and remains responsible for all clinical decisions.
- AI chat assistant (if enabled). If a clinic enables the AI chat on its booking page, the text of the conversation is sent to OpenAI to understand the request and suggest available slots.
Clinics can switch the AI features off. If they do, no data is sent to OpenAI for those features. We send only the text, records or images needed for the task. OpenAI processes this data under its own terms as our service provider and may process it outside India (see section 8). AI output can be wrong. It is a draft to help the clinic, not medical advice.
7. Who we share data with
We share personal data only with service providers that help us run Medovra, only as needed for the service, and never sell it:
| Provider | What for | Where |
|---|---|---|
| Hostinger | Hosting: the shared server where Medovra and its database run | India |
| OpenAI | AI prescription screening, AI patient-history summary, and the AI chat assistant if enabled | May be outside India |
| Twilio, using Meta's WhatsApp Business platform | Sending and receiving WhatsApp booking messages, confirmations and reminders, where the clinic uses WhatsApp | May be outside India |
| Messaging service providers | Sending email and SMS messages, where the clinic has turned these channels on |
We may also share data where the law requires it (for example, a valid order from a court or government authority), or to protect the rights, safety or property of Medovra, our users or others, as the law allows.
If Medovra's business is sold or merged, personal data may pass to the new owner. It will remain protected by this policy or one at least as protective, and we will tell clinics before that happens.
8. Data processed outside India
Our main hosting is in India. Some service providers, such as OpenAI and Twilio (and Meta for WhatsApp), may process data outside India. The DPDP Act allows such transfers except to countries the Government of India restricts. We will follow any such restrictions.
9. How long we keep data, and deletion
- Clinic account and staff data: kept while your account is active, and afterwards only as long as needed for the purposes above or as the law requires (for example, tax or accounting records). Then it is deleted.
- Patient data: the clinic decides how long to keep its patient records. Clinics may have their own legal duties to keep medical records for a period, and that is the clinic's responsibility. When a clinic deletes data in Medovra, or asks us to, we delete it, unless the law requires us to keep it.
- When a clinic's account ends: the clinic can ask us to export its data first (see our Terms of Service). After the account ends, we delete the clinic's data, except where the law requires us to keep something.
10. How we protect data
We take reasonable security safeguards to protect personal data, including:
- Tenant separation. Medovra is a multi-tenant service. All clinics' data is stored in a single database on a shared server, and each clinic's data is kept separate by tenant.
- Role-based access inside each clinic (owner/admin, doctor, receptionist), so staff see and do only what their role allows.
- Logging of patient messages sent through the service.
- Limited access by our own team: only what is needed to run and support the service.
No system is perfectly secure, and we can't promise data will never be accessed without permission. Clinics that need their data kept fully separate can ask for a dedicated or on-premises deployment. This is available on request at extra cost.
11. Cookies and similar technologies
Medovra uses only the browser storage needed for the site and app to work (for example, keeping you signed in, or recovering if a page fails to load). We do not currently use advertising cookies. If we add analytics or other non-essential cookies, we will update this policy and, where the law requires, ask for your consent.
12. Your rights
If your personal data is handled by Medovra as a Data Fiduciary (clinic and staff data), you have the right, under the DPDP Act, to:
- Access a summary of your personal data and how it is used
- Correct, complete or update inaccurate or incomplete data
- Erase data that is no longer needed, unless the law requires us to keep it
- Withdraw consent where we rely on consent
- Grievance redressal: raise a complaint with our Grievance Officer
- Nominate someone to exercise your rights if you die or become unable to
To use these rights, contact our Grievance Officer (section 13). We may need to verify your identity first. We will respond within the time the law requires.
Patients: your rights over data held in Medovra are exercised through the clinic, because the clinic is the Data Fiduciary. We will help the clinic respond.
If you are not satisfied with our response, you may complain to the Data Protection Board of India, as the law provides.
13. Grievance Officer and contact
14. Personal data breaches
If a personal data breach happens, we will act to contain it and will inform the Data Protection Board of India and affected people as the DPDP Act and its rules require. Where the breach involves patient data, we will also inform the affected clinic promptly so it can meet its own obligations.
15. Children's data
Medovra is a service for clinics and is not meant to be used directly by children. Clinics may record data about patients who are minors (under 18). In that case the clinic is the Data Fiduciary and is responsible for getting verifiable consent from a parent or lawful guardian, as the DPDP Act requires. Medovra does not use children's data for tracking, behavioural monitoring or targeted advertising.
16. Changes to this policy
We may update this policy as the service or the law changes. We will post the new version with a new "Last updated" date and, for significant changes, tell clinics by email or in the app.
17. Governing law
This policy is governed by the laws of India.