In short
These are the only third parties that touch data we hold for you, and this is what each of them does. We add one only when the product needs it, and we tell account owners 30 days before it starts.
Where a company name is still being confirmed for this page, it is marked rather than guessed. Nothing here is an advertising network — we do not use any.
1.The current list
Razorpay Software Private Limited
- Purpose
- Online payment collection where a clinic connects its own Razorpay account, or where Sqavio collects on the clinic’s behalf.
- Data it sees
- Payer name, contact details, amount and payment reference. Card and UPI credentials are handled entirely by them and never reach us.
- Where
- India
Cashfree Payments India Private Limited
- Purpose
- The same, for clinics that use Cashfree instead of, or alongside, Razorpay.
- Data it sees
- Payer name, contact details, amount and payment reference. Card and UPI credentials never reach us.
- Where
- India
WhatsApp messaging provider (SentBot)
- Purpose
- Delivering the WhatsApp messages a clinic has switched on — confirmations, reminders, prescriptions and receipts.
- Data it sees
- Patient phone number, the message text, and any attachment the clinic chose to send, such as an invoice or prescription.
- Where
- India
Email delivery provider
- Purpose
- Delivering transactional email — the same messages, by email, plus account and billing email from us.
- Data it sees
- Recipient name and email address, message content, and attachments.
- Where
- Sent from our servers in Germany
Contabo GmbH
- Purpose
- Running the application servers, databases, backups and object storage on which the service runs.
- Data it sees
- All service data, at rest and in transit, encrypted.
- Where
- Germany
Cloudflare, Inc.
- Purpose
- DNS, TLS termination and protection against denial-of-service and abusive traffic in front of the service.
- Data it sees
- Connection metadata such as IP address and request headers, in transit. No stored clinical records.
- Where
- Global edge network
2.Where the data is, and what that means
Our servers are in Germany, not India. We say so plainly because a clinic buying health software has every right to ask, and because the answer is checkable.
Under the DPDP Act, personal data may be transferred outside India except to countries the Central Government restricts by notification; none applies to Germany today. If that ever changes, we will move the data rather than argue about it. Germany also sits under the GDPR, which is a stricter regime than the minimum Indian law requires — the practical effect is more protection, not less.
3.What is deliberately not on this list
No advertising or marketing tracker, no analytics service, no session-recording tool, and no third-party font or script served to a visitor’s browser. Fonts are served from our own servers precisely so that reading a page here does not report you to anyone else.
We do not send patient data to any artificial intelligence service, and we do not use it to train models — ours or anyone else’s.
4.How this list changes
We give account owners at least 30 days’ notice by email before a new sub-processor starts processing, and this page is updated first. If you object on reasonable data protection grounds within that period and we cannot resolve it, you may terminate the affected service and receive a pro-rata refund of the unused period — as set out in the DPA.
To be told when this page changes, write to [email protected] and ask to be added to the notification list.
Questions about this document? Write to [email protected]. If you are not satisfied with the answer, the grievance route is open to you.