In short
We handle three very different kinds of data and this policy keeps them apart, because your rights depend on which one you are: visitors to this website, clinic users who log in, and patients whose records a clinic keeps in Sqavio.
For patient data we are the processor, not the decision-maker — the clinic is. We do not sell personal data, we do not use patient records for advertising, and you can withdraw a consent as easily as you gave it.
1.Who we are
Sqavio Doctor is operated by SQABY Technologies (“Sqavio”, “we”, “us”), registered at ⟨to be added: full postal address of the registered office⟩.
- Company
- SQABY Technologies
- Registered office
- ⟨to be added: full postal address of the registered office⟩
- CIN
- Privacy contact
- [email protected]
- Grievance Officer
- Saurabh Sharma
This policy is written against the Digital Personal Data Protection Act, 2023 and the rules made under it, which are being brought into force in stages. Where those rules impose something on a date in the future, we have built for the end state rather than waiting.
2.The three kinds of data, and our role in each
This is the most important section in the document. Everything below depends on which of these you are.
- Website visitors
- Anyone reading sqaivo.com or filling the demo form. We are the data fiduciary: we decide what we collect and why.
- Clinic users
- Doctors, owners and staff with a login. We are the data fiduciary for your account details, and the processor for what you put into the product.
- Patients of a clinic
- People whose records a clinic keeps in Sqavio. The clinic is the data fiduciary. We are the processor and act on the clinic’s instructions — we do not decide what happens to your records.
If you are a patient and want your records corrected or deleted, ask the clinic. They can do it themselves inside the product, and we will help them if they ask. The patient privacy notice is written for you specifically.
3.What we collect, and why
From website visitors. If you submit the demo form: your name, clinic name, city, speciality, phone number, email address, how many doctors you have, and anything you type in the message box. We collect it to contact you about the demo you asked for. We also record which version of this policy you agreed to, and when, because a consent record has to be provable.
We keep only strictly necessary cookies today. See the cookie policy for the full list and for how to change your choices.
From clinic users. Your name, email address, phone number, role, clinic, and the security data a login needs: a hashed password, session records, IP address and browser, and an audit record of significant actions. We use it to run your account, keep it secure, bill you, and support you.
Patient data, processed for a clinic. Whatever the clinic records — name, phone, age, gender, address, visit history, vitals, complaints, diagnoses, prescriptions, investigations, invoices and payment records. We hold it so the clinic can run its practice. We do not decide what is collected, and we do not use it for anything except providing the service.
Payment data. Card numbers, CVVs and UPI PINs never reach our servers. Razorpay and Cashfree handle them. We store the fact of a payment: amount, mode, gateway reference, status and time.
4.On what basis we process it
- Your consent — the demo form, marketing messages, and non-essential cookies. Consent is asked for in plain words, never bundled with something else, and never pre-ticked.
- Performance of our contract with the clinic — running the account, storing the records the clinic puts in, sending service messages, taking subscription payments.
- Legitimate uses and legal obligations — keeping the service secure, preventing abuse, keeping accounting and tax records for as long as Indian law requires.
For patient data, the consent that matters is the one the patient gives the clinic. We present the notice and record the answer on the clinic’s behalf; the responsibility for obtaining it remains the clinic’s.
6.Where your data is stored
On servers in Germany, operated by our hosting provider and listed on the sub-processors page. Not in India — we would rather tell you that than let you assume otherwise.
The DPDP Act permits transferring personal data outside India except to countries the Central Government restricts by notification, and no such restriction applies today. Data is encrypted in transit and at rest wherever it sits, and the same access rules apply.
7.How long we keep it
- Demo enquiries
- Up to 24 months from your last contact with us, unless you ask us to delete it sooner.
- Clinic account and users
- For as long as the clinic subscribes.
- Patient records
- For as long as the clinic keeps them. The clinic decides — medical records carry long retention expectations under medical council norms, and a clinic should align its instructions to us with the rules that apply to it.
- After a clinic cancels
- Data is retained for the window set out in the Terms so the clinic can export or change its mind, then deleted.
- Invoices and accounting records
- For the period Indian tax and company law requires, regardless of the above.
- Security and audit logs
- Up to 12 months, longer only where an investigation needs it.
8.Your rights
Under the DPDP Act you can ask us to:
- tell you what personal data of yours we hold and who it has been shared with,
- correct or complete anything inaccurate,
- erase data we no longer need for the purpose it was collected for,
- take a grievance to our Grievance Officer, and
- nominate someone to exercise these rights if you die or become incapacitated.
Write to [email protected]. We answer within 30 days and will tell you if we need longer and why.
If you are a patient, direct these requests to your clinic. Only the clinic can decide what happens to its records; if you cannot get an answer, write to us and we will contact them.
9.Withdrawing consent
Withdrawal is as easy as consent was. Marketing messages carry an opt-out and it works immediately. Cookie choices can be changed from the cookie preferences link in the footer of every page.
Withdrawing consent does not undo what was lawfully done before, and where processing is needed to run a subscription you have, ending it means ending the subscription rather than the processing alone.
10.How we protect it
Each clinic has its own database rather than a shared table. Traffic is encrypted with HTTPS, data and backups are encrypted at rest, and passwords are stored as slow one-way hashes. Access inside the product is limited by role and enforced on the server, not by hiding menu items. Significant actions are recorded in an audit trail.
Our staff do not browse clinic data; support access is deliberate, limited and logged. The security page describes this in more detail, including what we deliberately do not claim.
No system is perfectly safe. If a breach affects you, we will notify you and the Data Protection Board as the rules require, and give clinics enough detail and speed to meet their own obligations.
11.Children’s data
This website and the clinic software are for adults running a clinic; we do not knowingly collect data directly from children through them.
A clinic will inevitably hold records of child patients. Where the DPDP Act requires verifiable parental consent for a child’s data, obtaining it is part of the clinic’s duty as data fiduciary — the same duty it already has on paper. We do not use children’s data for tracking, profiling or advertising in any form.
12.Grievances
If something we have done with your data is wrong, tell our Grievance Officer: Saurabh Sharma, [email protected]. We acknowledge within 3 working days and resolve within 90 days. The full process is on the grievance redressal page, and you may also complain to the Data Protection Board of India.
We are not a Significant Data Fiduciary today. If we are ever notified as one, we will appoint a Data Protection Officer and publish their contact details here.
13.Changes to this policy
When this policy changes materially we publish the new version with a new date and, where you have an account with us, we tell you before it takes effect. Where a change needs your consent, we ask again rather than assuming the old answer carries over — which is why a consent record stores the version it was given against.
Questions about this document? Write to [email protected]. If you are not satisfied with the answer, the grievance route is open to you.