| Roles | The clinic is the data fiduciary. We are the data processor. We process only on the clinic’s documented instruction. |
| Security commitments | Encryption in transit and at rest, managed keys and rotation, least privilege by default, role separation, and an append-only audit entry on every access to identified data. |
| Sub-processors | Named, listed, and notified before any change. Infrastructure is India-resident and empanelled. |
| Breach notification | Notification to the clinic without undue delay, with what was accessed, when, and by which identity — because the audit log is attributable. |
| Audit | The clinic may audit its own estate. Independent security assessment is completed before any real patient data, and current status is shared under NDA. |
| Export and wind-down | On termination, a usable export of the clinic’s own data, then documented deletion. Portability is the minimum honest position, not a feature request. |
| Personnel | Assistants cannot reach clinical narrative beyond what dispensing requires. Access is by role and is logged. |
| Device loss | Remote wipe of the local store on revocation, initiated by the clinic administrator. |
This is an orientation summary, not a binding
document. The final Data Processing Agreement will be published before the platform accepts real patient data
or a single enquiry through this site.
Get started
Questions on data or terms?
We can share full policies and a data-processing agreement.