Skip to content
Sqavio Doctor

Security

Your patients’ data, handled properly

Health records and money in the same product means the bar is higher than for ordinary software. This page says exactly what we do — and, just as deliberately, what we do not claim.

How it is built

Eight things that protect a clinic

A separate database for every clinic

Your clinic’s records live in their own database, not in a shared table with a column to tell clinics apart. There is no query another clinic could run that reaches your patients, because there is no shared table to run it against. It also means your export on the way out is genuinely yours alone.

Encrypted in transit and at rest

Every connection is HTTPS. Databases and backups are encrypted on disk. Passwords are stored as slow one-way hashes — we cannot read them, and neither can anyone who takes a copy.

Access that matches the job

Reception sees the front desk. A doctor sees consults and, only if your clinic bills that way, money. The owner sees everything. Hiding a menu item is not access control, so the rules are enforced on the server: typing an address you are not entitled to gets you sent back, not in.

An audit trail

Who created, changed or viewed what, and when, with the account that did it. Records that matter — a signed prescription, a recorded payment — are not quietly editable; a correction leaves a trail.

Backups and recovery

Databases are backed up on a schedule and restores are tested. Retention and the recovery targets we commit to are written down in the SLA rather than described vaguely here.

Where your data is hosted

Clinic and patient data is stored in Germany. If that ever changes, this page and the sub-processor list change with it, before the data does.

We never see a card number

Online payments go to Razorpay or Cashfree, who are the ones regulated to handle card data and who carry the PCI-DSS obligation. Card numbers, CVVs and UPI PINs never reach a Sqavio server, so there is nothing of that kind for us to leak.

Support access is limited and logged

Our team does not browse clinic data. Support access to a clinic account is deliberate, time-limited and recorded in the audit trail, so you can see it happened.

The law

Where you stand under the DPDP Act

The Digital Personal Data Protection Act, 2023 and the rules made under it in 2025 give the two of us different jobs. Being clear about which is which is most of the work.

Your clinic is the Data Fiduciary

You decide why patient data is collected and what happens to it. The statutory duties to your patients — notice, consent, responding to their requests — sit with you, as they already do with your paper records.

Sqavio is the Data Processor

We hold and process that data only to run the service you asked for, on your instructions. We do not sell it, we do not mine it, and we do not use one clinic’s patients for anything to do with another.

What we do to help you meet your duties

Consent and its withdrawal are recorded with a timestamp. Patient notices are shown at the point of booking. Exports and deletion are available so you can answer a patient who asks. Our DPA puts all of this in writing.

If there is a breach

We tell you promptly and with enough detail for you to meet your own reporting duty to the Data Protection Board and to affected people, including the 72-hour detailed report. The commitment is in the DPA and the SLA, not just on this page.

What we deliberately do not claim

We do not say “HIPAA compliant” — HIPAA is a United States law and it does not apply to an Indian clinic; anyone selling you HIPAA compliance for a clinic in India is selling you a badge, not a protection. We do not claim ISO 27001 or SOC 2, because we do not hold those certificates today; if we earn them, the certificate number will be on this page. And we say “built to support your DPDP obligations” rather than “DPDP compliant”, because compliance is something you and we do continuously, not a sticker.

Your data

It stays yours

Export whenever you like

Patients, prescriptions and billing records, while your account is active and on the way out.

Deletion on exit

After you cancel we keep data for the window set out in the Terms so you can change your mind, then delete it.

A named list of sub-processors

Every third party that touches your data, what they do, and where — published and kept current.

Found a security problem?

Write to [email protected] with enough detail for us to reproduce it. We will acknowledge, keep you updated while we fix it, and we will not threaten anyone who reports a genuine issue in good faith. Please do not test against a live clinic’s data — ask us and we will give you somewhere safe to test.

Ask us the hard questions on the call

Where the data sits, who can reach it, what happens if you leave. We would rather answer before you sign than after.

Book a free demoCall