LegalVersion 2.0

Privacy Policy

Mediziner Healthcare Technology Private Limited. This Privacy Policy explains how Mediziner collects, uses, shares, and protects personal information in connection with the platform. It forms part of, and should be read together with, our Terms & Conditions of Service.

Mediziner is a technology provider, not a healthcare provider. For patient data entered by clinics, the clinic is the Data Fiduciary / controller and Mediziner acts only as a Data Processor on the clinic's instructions. If you are a patient, please direct data requests to your clinic in the first instance.

Jump to a section
01

Introduction and Scope

1.1 About This Policy

Mediziner Healthcare Technology Private Limited ("Mediziner", "we", "us", or "our") is committed to protecting the privacy of the individuals and organizations that use our cloud-based clinic management platform. This Privacy Policy describes the categories of personal information we handle, how and why we process it, with whom we share it, how long we keep it, and the rights available to you under applicable law.

1.2 Who This Policy Applies To

This Privacy Policy applies to:

  • Customers: clinics, healthcare organizations, and individual practitioners that subscribe to the platform;
  • Authorized Users: doctors, receptionists, pharmacists, laboratory staff, and administrative personnel who access the platform under a Customer account;
  • Website visitors: individuals who browse our website or request a demo; and
  • Patients: individuals whose data is entered into the platform by a Customer, to the extent described in Section 8.

1.3 Relationship With the Terms

This Privacy Policy is incorporated into, and forms part of, Mediziner's Terms & Conditions of Service. Capitalized terms not defined here have the meaning given to them in the Terms. In the event of any inconsistency between the Terms and this Privacy Policy in relation to the processing of personal data, this Privacy Policy shall prevail.

02

Definitions

The following key terms are used throughout this Privacy Policy:

Personal Data
means any data about an individual who is identifiable by or in relation to such data, including name, contact details, and identifiers.
Patient Data
means personal, demographic, and medical or health-related information about a Customer's patients that is entered into or generated by the platform. Patient Data constitutes Sensitive Personal Data under applicable Indian law.
Data Fiduciary
means the person who, alone or with others, determines the purpose and means of processing personal data. For Patient Data, the Customer (clinic) is the Data Fiduciary.
Data Processor
means a person who processes personal data on behalf of a Data Fiduciary. Mediziner acts as Data Processor for Patient Data.
Data Principal
means the individual to whom the personal data relates (for example, a patient or an Authorized User).
Usage Analytics
means anonymized and aggregated technical data from which no individual can be identified, owned by Mediziner and excluded from Customer Data.
DPDP Act
means the Digital Personal Data Protection Act, 2023, and the rules made thereunder, as and when they come into force.
03

Our Role in Data Processing

3.1 Mediziner as Data Processor

For all Patient Data and other Customer Data entered into the platform, the Customer is the Data Fiduciary (controller) and Mediziner acts solely as a Data Processor. We process such data only on the documented instructions of the Customer and as necessary to provide the Services. We do not determine the purposes for which Patient Data is processed and do not use it for our own purposes.

3.2 Mediziner as Data Fiduciary

For a limited set of information that we collect directly — such as Customer registration and account details, billing contacts, website enquiries, and technical/usage data about how our platform performs — Mediziner acts as the Data Fiduciary (controller) and processes that information in accordance with this Privacy Policy.

3.3 Customer Responsibilities

As Data Fiduciary for Patient Data, the Customer is responsible for:

  • establishing a lawful basis and obtaining any consent required before entering patient information into the platform;
  • providing patients with a clear privacy notice about how their data is used;
  • responding to patient rights requests within the timescales required by law; and
  • ensuring its use of the platform complies with the DPDP Act, the Information Technology Act, 2000, and other applicable laws.
04

Information We Collect

4.1 Information You Provide

  • Account & Registration Data: clinic or organization name, practitioner name, email address, phone number, professional details, and login credentials.
  • Billing Data: billing contact, GST details, and payment method information (payment card details are handled by our payment processor, not stored by Mediziner).
  • Support & Communications: information you provide when you contact us, request a demo, report an issue, or submit feedback.

4.2 Patient Data Entered by Customers

Authorized Users enter patient information into the platform in the course of clinical operations, including appointment records, patient profiles, electronic medical records, clinical notes, diagnoses recorded by the practitioner, prescriptions, billing records, and contact information. Mediziner processes this data strictly as a Data Processor on the Customer's behalf.

4.3 Information Collected Automatically

  • Technical Data: IP address, device and browser type, operating system, and log data.
  • Usage Data: pages and features accessed, actions taken, timestamps, and session information, recorded in audit logs.
  • Diagnostics: anonymized crash and performance data via Firebase Crashlytics and Firebase Analytics.
  • Cookies: as described in Section 9 and our Cookie Policy.
05

How We Use Information

We use personal information for the following purposes:

  • Provide the Services: to operate, maintain, and deliver the platform and its features to Customers and Authorized Users.
  • Process Patient Data on instruction: to store, structure, and make available Patient Data solely as directed by the Customer.
  • Account management: to create and administer accounts, authenticate users, and manage roles and permissions.
  • Billing and payments: to process Subscription Fees, issue invoices, and comply with tax obligations.
  • Communications: to send service, transactional, security, and administrative messages, and to respond to support requests.
  • Security and fraud prevention: to monitor for, detect, and prevent unauthorized access, abuse, and security incidents.
  • Improve the platform: to analyse anonymized Usage Analytics for product development, performance, and reliability.
  • Legal compliance: to comply with applicable law, regulatory requirements, and lawful requests from authorities.

We do not sell personal data, and we do not use Patient Data to target advertising at patients or Authorized Users.

06

Legal Basis for Processing

Where Mediziner acts as Data Fiduciary, we rely on one or more of the following bases to process personal data: (a) performance of our contract with the Customer; (b) the Customer's or user's consent, where required; (c) our legitimate interests in operating and securing the platform, balanced against the rights of individuals; and (d) compliance with a legal obligation. Where we act as Data Processor for Patient Data, the lawful basis is established and maintained by the Customer as Data Fiduciary, and we process such data on the Customer's instructions.

07

How We Share Information

7.1 Service Providers and Third Parties

We share personal information only with trusted third parties that help us deliver the Services, under appropriate contractual and confidentiality safeguards:

  • Amazon Web Services (AWS): cloud hosting, database, and storage infrastructure underpinning the platform.
  • Razorpay: payment gateway and processing for Subscription Fees; complete payment card details are handled by Razorpay and not stored by Mediziner.
  • WhatsApp Business (Meta Platforms): delivery of prescriptions and communications where the Customer uses WhatsApp sharing.
  • SMS Service Providers: delivery of appointment reminders, notifications, and one-time passwords.
  • Email Service Providers: delivery of prescription PDFs, confirmations, and system notifications.
  • Firebase (Google LLC): anonymized crash and performance analytics.

7.2 Legal and Regulatory Disclosure

We may disclose personal information where required to comply with applicable law, a valid court order, or a lawful request by a regulatory or law-enforcement authority, or to protect the rights, safety, and security of Mediziner, our Customers, or the public. Where we are legally permitted, we will notify the affected Customer before disclosing Customer Data.

7.3 Business Transfers

If Mediziner is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to the receiving party being bound by protections consistent with this Privacy Policy.

7.4 No Sale of Personal Data

Mediziner does not sell, rent, or trade personal data, and does not share Patient Data with any third party for that third party's own commercial or marketing purposes.

08

Patient Data and Consent

Patients do not currently create independent Mediziner accounts. Patient Data is entered and controlled by the Customer clinic, which is responsible for obtaining the consents and providing the notices required by law before entering patient information into the platform. Patients may receive prescriptions, appointment confirmations, and related communications generated by Authorized Users. If you are a patient and wish to exercise your rights over your data, please contact the clinic that treats you, which is the Data Fiduciary for your information. Mediziner will support Customers in responding to such requests as a Data Processor.

09

Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve the platform. These fall into the following categories:

  • Necessary Cookies: essential for login, session management, and secure access; the platform cannot function without them.
  • Preference Cookies: remember your settings, such as working hours, default templates, and language.
  • Analytics Cookies: help us understand feature usage in an anonymized way so we can improve the experience.

You can manage or disable cookies through your browser settings, though disabling necessary cookies may affect platform functionality. Further detail is available in our Cookie Policy.

10

Data Storage, Location, and Security

10.1 Where Data Is Stored

Customer Data is hosted on Amazon Web Services (AWS) infrastructure, which maintains ISO 27001, SOC 2, and other internationally recognized security certifications. We aim to store and process data in a manner consistent with applicable Indian data protection requirements.

10.2 Security Measures

We implement technical and organizational measures to protect personal information, including:

  • Encryption in Transit: TLS protocols (minimum TLS 1.2) for data moving between devices and the platform.
  • Encryption at Rest: AES-256 or equivalent industry-standard encryption for stored data.
  • Role-Based Access Control (RBAC): access restricted to the data necessary for each user's role.
  • Audit Logs: tamper-evident logs of significant actions, including access and record changes.
  • Secure Authentication: enforced password policies, session timeouts, and session management.
  • Internal Access Controls: access to systems containing personal data limited to authorized personnel on a need-to-know basis.

No digital system can be guaranteed to be completely secure. We cannot warrant absolute security, but we work to protect your information and to respond promptly to any incident.

10.3 Data Breach Notification

If we become aware of a confirmed security incident affecting personal data, we will notify the affected Customer without undue delay and, to the extent required by law, within the mandated period, and will cooperate with the Customer in meeting any regulatory notification obligations.

11

Data Retention and Deletion

We retain personal information for as long as necessary to provide the Services and to comply with our legal obligations. Following the cancellation or termination of a Customer's subscription, Customer Data is retained for a Retention Period of ninety (90) calendar days, during which the Customer may export its data using the platform's built-in export tools. After the Retention Period expires, we may permanently and irreversibly delete Customer Data, except where longer retention is required by law, court order, or for the resolution of a subsisting dispute. Anonymized Usage Analytics, which cannot identify any individual, may be retained indefinitely.

12

Your Rights

12.1 Rights of Data Principals

Subject to applicable law, including the DPDP Act as it comes into force, you may have the right to:

  • Access: obtain confirmation of, and access to, the personal data we process about you.
  • Correction: request correction of inaccurate or incomplete personal data.
  • Erasure: request deletion of personal data where there is no lawful basis to retain it.
  • Portability: obtain a copy of certain data in a machine-readable format; Customers can export data via the dashboard.
  • Grievance Redressal: raise a complaint about how your data is handled.
  • Nominate: nominate another individual to exercise your rights in the event of death or incapacity, where provided by law.

12.2 How to Exercise Your Rights

Customers and Authorized Users may exercise these rights by contacting us at operations@medizinerhealthcare.com. Patients should contact their clinic, which is the Data Fiduciary for their data; we will assist the clinic as Data Processor. We may need to verify your identity before acting on a request and will respond within the timescales required by applicable law.

13

Children's Privacy

The platform is intended for use by clinics and healthcare professionals and is not directed to children as users. Where a Customer records data about a child patient, the Customer is responsible for obtaining any consent required from a parent or lawful guardian in accordance with applicable law, including the DPDP Act. Mediziner processes such data only as a Data Processor on the Customer's instructions.

14

International Data Transfers

Our infrastructure and certain service providers may process data outside your state or, where applicable, outside India. Where personal data is transferred across borders, we take steps to ensure that it remains protected in accordance with this Privacy Policy and applicable law, including any restrictions or requirements imposed under the DPDP Act and rules made thereunder.

15

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or the law, including the commencement of the DPDP Act. Where changes are material, we will endeavour to provide advance notice by email to registered Customers or through a prominent in-platform notification. The effective date of the current version will always be shown, and continued use of the platform after an update constitutes acceptance of the revised Policy.

16

Grievance Officer and Contact

For any questions, concerns, or grievances regarding this Privacy Policy or how your personal information is handled, or to exercise your rights, please contact us at:

  • Mediziner Healthcare Technology Private Limited
  • Website: https://www.medizinerhealthcare.com
  • Privacy and Grievances: operations@medizinerhealthcare.com

We will acknowledge grievances within two (2) Business Days and endeavour to resolve them within the timeframes prescribed by applicable law or, where none applies, within a reasonable period.

This Privacy Policy is subject to amendment before publication and does not constitute legal advice. It will be updated to reflect the Digital Personal Data Protection Act, 2023 and its rules as they come into force.
© Mediziner Healthcare Technology Private Limited. All rights reserved.

Questions about this Privacy Policy? We’re happy to help.

Speak to our team