Eleven modules · one clinical record · See all
HomeLegalPrivacy
Legal · Privacy

What we do with
clinical data.

A plain-language summary of our privacy position. The binding Privacy Policy is issued before the platform accepts real patient data.

Who is responsibleThe clinic is the data fiduciary for its patients under the Digital Personal Data Protection Act 2023. We act as a data processor on the clinic’s behalf, under a written agreement.
What we processPatient identity fields captured at registration, the clinical record produced during the consultation, and operational data about the clinic’s own use of the software.
Lawful basisConsent, obtained by the clinic at the point of care, and the legitimate uses the Act permits for the provision of medical treatment.
Where it is storedIn India, on empanelled infrastructure. Production data never appears in a lower environment.
How longFor as long as the clinic requires the record, subject to the retention periods clinical records are held to. A clinical history is not a session log.
Patient rightsAccess, correction, erasure and withdrawal of consent, exercised through the clinic or through the national consent framework. Amendment creates a version; nothing is silently overwritten.
SharingNothing moves without consent. Exchange with another clinic or an institution happens on the patient’s instruction, through the consent framework.
Special protectionHealth data receives the highest protection in our handling, our access controls and our audit.
Contactsupport@cad.care
This is an orientation summary, not a binding document. The final Privacy Policy will be published before the platform accepts real patient data or a single enquiry through this site.
Get started

Questions on data or terms?

We can share full policies and a data-processing agreement.