| Who is responsible | The clinic is the data fiduciary for its patients under the Digital Personal Data Protection Act 2023. We act as a data processor on the clinic’s behalf, under a written agreement. |
| What we process | Patient identity fields captured at registration, the clinical record produced during the consultation, and operational data about the clinic’s own use of the software. |
| Lawful basis | Consent, obtained by the clinic at the point of care, and the legitimate uses the Act permits for the provision of medical treatment. |
| Where it is stored | In India, on empanelled infrastructure. Production data never appears in a lower environment. |
| How long | For as long as the clinic requires the record, subject to the retention periods clinical records are held to. A clinical history is not a session log. |
| Patient rights | Access, correction, erasure and withdrawal of consent, exercised through the clinic or through the national consent framework. Amendment creates a version; nothing is silently overwritten. |
| Sharing | Nothing moves without consent. Exchange with another clinic or an institution happens on the patient’s instruction, through the consent framework. |
| Special protection | Health data receives the highest protection in our handling, our access controls and our audit. |
| Contact | support@cad.care |
This is an orientation summary, not a binding
document. The final Privacy Policy will be published before the platform accepts real patient data
or a single enquiry through this site.
Get started
Questions on data or terms?
We can share full policies and a data-processing agreement.