Medovra Privacy Policy

This policy explains, in plain language, what personal data Medovra handles, why, who we share it with, and the choices and rights you have. It is written for the clinics that use Medovra, their staff, and the patients whose appointments are managed through it.

1. Who we are

Medovra is clinic booking software (offered as software-as-a-service), a business based in India ("Medovra", "we", "us").

Medovra helps clinics manage appointments, patients, visits and prescriptions. It is a booking and clinic-management app only. It does not process payments.

2. Two different roles: ours and the clinic's

India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") gives different responsibilities to different organisations. In Medovra, there are two situations:

Whose dataWho decides why and how it's usedMedovra's role
Clinic account and staff user data (for example, the clinic owner's, doctors' and receptionists' names, emails, phone numbers and logins), and enquiries made to us through our websiteMedovraData Fiduciary. We are responsible for this data under this policy.
Patient data that a clinic enters into Medovra or collects through it (bookings, patient records, visits, prescriptions, messages)The clinicData Processor. We process it only on the clinic's behalf and on its instructions, to provide the service.

If you are a patient: the clinic you booked with is responsible for your data. It decides what to collect, why, and for how long. Please contact the clinic first for any request about your data. If the clinic asks us, we will help it respond. You can also contact our Grievance Officer (section 13), and we will pass your request to the clinic or help as the law requires.

3. What data we handle

3.1 Clinic account and staff data (Medovra is the Data Fiduciary)

3.2 Patient data (the clinic is the Data Fiduciary; Medovra is the Data Processor)

Depending on how the clinic uses Medovra:

Health information is sensitive. We treat it with extra care. We limit who can see it inside the clinic through roles, and we do not use it for advertising or sell it.

3.3 Website visitors

When you visit medovra.com, our servers may record basic technical information such as your IP address, browser type and the pages requested, as most websites do. See section 11 on cookies.

4. Why we use data (purposes)

Clinic account and staff data: to create and run your account, let your staff sign in with the right access, provide support, respond to demo requests and enquiries, send service-related messages (such as account or security notices), improve and secure the service, and meet legal obligations.

Patient data (on the clinic's behalf): only to provide the service the clinic has asked for. That means taking and managing bookings, sending booking confirmations, reminders and other appointment messages, keeping patient and visit records, producing prescriptions and reports, and the AI features described in section 6 (prescription screening, the patient-history summary and, if enabled, the AI chat). We do not use patient data for our own marketing, we do not sell it, and we do not use it for purposes the clinic has not asked for.

5. Consent and legal basis

6. AI features

Medovra's AI features help doctors. They don't make medical decisions:

Clinics can switch the AI features off. If they do, no data is sent to OpenAI for those features. We send only the text, records or images needed for the task. OpenAI processes this data under its own terms as our service provider and may process it outside India (see section 8). AI output can be wrong. It is a draft to help the clinic, not medical advice.

7. Who we share data with

We share personal data only with service providers that help us run Medovra, only as needed for the service, and never sell it:

ProviderWhat forWhere
HostingerHosting: the shared server where Medovra and its database runIndia
OpenAIAI prescription screening, AI patient-history summary, and the AI chat assistant if enabledMay be outside India
Twilio, using Meta's WhatsApp Business platformSending and receiving WhatsApp booking messages, confirmations and reminders, where the clinic uses WhatsAppMay be outside India
Messaging service providersSending email and SMS messages, where the clinic has turned these channels on

We may also share data where the law requires it (for example, a valid order from a court or government authority), or to protect the rights, safety or property of Medovra, our users or others, as the law allows.

If Medovra's business is sold or merged, personal data may pass to the new owner. It will remain protected by this policy or one at least as protective, and we will tell clinics before that happens.

8. Data processed outside India

Our main hosting is in India. Some service providers, such as OpenAI and Twilio (and Meta for WhatsApp), may process data outside India. The DPDP Act allows such transfers except to countries the Government of India restricts. We will follow any such restrictions.

9. How long we keep data, and deletion

10. How we protect data

We take reasonable security safeguards to protect personal data, including:

No system is perfectly secure, and we can't promise data will never be accessed without permission. Clinics that need their data kept fully separate can ask for a dedicated or on-premises deployment. This is available on request at extra cost.

11. Cookies and similar technologies

Medovra uses only the browser storage needed for the site and app to work (for example, keeping you signed in, or recovering if a page fails to load). We do not currently use advertising cookies. If we add analytics or other non-essential cookies, we will update this policy and, where the law requires, ask for your consent.

12. Your rights

If your personal data is handled by Medovra as a Data Fiduciary (clinic and staff data), you have the right, under the DPDP Act, to:

To use these rights, contact our Grievance Officer (section 13). We may need to verify your identity first. We will respond within the time the law requires.

Patients: your rights over data held in Medovra are exercised through the clinic, because the clinic is the Data Fiduciary. We will help the clinic respond.

If you are not satisfied with our response, you may complain to the Data Protection Board of India, as the law provides.

13. Grievance Officer and contact

14. Personal data breaches

If a personal data breach happens, we will act to contain it and will inform the Data Protection Board of India and affected people as the DPDP Act and its rules require. Where the breach involves patient data, we will also inform the affected clinic promptly so it can meet its own obligations.

15. Children's data

Medovra is a service for clinics and is not meant to be used directly by children. Clinics may record data about patients who are minors (under 18). In that case the clinic is the Data Fiduciary and is responsible for getting verifiable consent from a parent or lawful guardian, as the DPDP Act requires. Medovra does not use children's data for tracking, behavioural monitoring or targeted advertising.

16. Changes to this policy

We may update this policy as the service or the law changes. We will post the new version with a new "Last updated" date and, for significant changes, tell clinics by email or in the app.

17. Governing law

This policy is governed by the laws of India.