Privacy Policy
Last updated: [DATE]
Version: 1 (informational only — acceptance of this document is bundled with the Terms and Conditions under one terms_version value; see CURRENT_TERMS_VERSION in lib/terms.ts.)
DRAFT NOTICE: Starting draft for lawyer review, written with DPDP Act 2023 structure in mind. Not final.
1. Who This Policy Covers
This Privacy Policy explains how [LEGAL ENTITY NAME] ("we," "us") collects, uses, and protects information when doctors ("you") use OncoLedger, and how patient data entered by doctors is handled.
2. What We Collect
About you (the doctor):
- Name, email, phone, specialty, clinic name
- Account credentials (passwords are hashed, never stored in plain text)
- Usage data (login times, actions taken in the app) for security and support purposes
About your patients, entered by you:
- Name, phone number, caregiver phone (if provided), date of birth, sex, preferred language
- Cancer type, stage, surgery date, and related clinical notes you choose to enter
- Follow-up appointment history and reminder delivery status
We do not independently collect patient data; it is entered solely by the treating doctor.
3. How We Use This Data
- To operate the Service: generating follow-up schedules, sending reminders, displaying your dashboard
- To provide customer support to doctors
- To maintain security, detect abuse, and improve reliability
- We do not use patient data for advertising, and we do not sell patient or doctor data to any third party.
4. Where Data Is Stored
All patient and account data is stored on servers located in Mumbai, India. Application hosting infrastructure is also configured to route through India-based regions where technically available.
5. Who Can Access Your Data
- Each doctor can only access their own patients' data. This is enforced at the database level (row-level security), not just in the application interface.
- A small number of authorized Company personnel may access data only as strictly necessary to provide technical support or comply with law, under confidentiality obligations.
- We do not grant other doctors, or any third party outside Section 6, access to your patient data.
6. Third-Party Service Providers
We use the following categories of service providers, solely to operate the Service:
- Database and hosting infrastructure (India-based)
- Messaging providers for delivering WhatsApp/SMS/email reminders — these providers receive only the minimum information necessary to send a message (e.g., phone number and a neutral message template that does not disclose diagnosis)
- Payment processor for billing doctors (does not receive patient data)
We do not permit these providers to use the data for any purpose other than delivering the specific service to us.
7. Patient Rights
Patients whose data is entered into the Service by their doctor may exercise rights available to them under the DPDP Act, 2023 (such as access to, or correction/erasure of, their personal data) by contacting their treating doctor directly, as the doctor is the Data Fiduciary responsible for that data. We support doctors in fulfilling such requests promptly.
8. Data Retention
- Patient data is retained for as long as the doctor's account is active and the patient is under active follow-up, or as required by applicable medical record-keeping law, whichever is longer.
- Upon account termination, data is available for export for a limited period (see Terms and Conditions, Section 10) and then permanently deleted, except where retention is legally required.
9. Security Measures
- Encryption of data in transit (HTTPS) and at rest
- Row-level access control scoping every doctor's data strictly to their own account
- Regular database backups
- Reminder message content is deliberately neutral and does not reveal diagnosis, to reduce harm if a message is seen by someone other than the intended recipient
No system can guarantee absolute security. We will notify affected doctors without undue delay in the event of a data breach affecting their account, as required by law.
10. Cookies and Analytics
[TO BE COMPLETED based on actual analytics/cookies used, if any, once the marketing site is built — disclose specifically what's used and for what purpose.]
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to doctors, and continued use of the Service after such changes constitutes acceptance.
12. Grievance Officer
In accordance with the DPDP Act, 2023, our Grievance Officer can be contacted at:
Name: [NAME] Email: [EMAIL] Address: [REGISTERED ADDRESS]
We aim to respond to grievances within [30] days.
Placeholders in [BRACKETS] must be completed before production use. This draft has not been reviewed by a lawyer.