Security
Your patients’ data, handled properly
Health records and money in the same product means the bar is higher than for ordinary software. This page says exactly what we do — and, just as deliberately, what we do not claim.
How it is built
Eight things that protect a clinic
A separate database for every clinic
Your clinic’s records live in their own database, not in a shared table with a column to tell clinics apart. There is no query another clinic could run that reaches your patients, because there is no shared table to run it against. It also means your export on the way out is genuinely yours alone.
Encrypted in transit and at rest
Every connection is HTTPS. Databases and backups are encrypted on disk. Passwords are stored as slow one-way hashes — we cannot read them, and neither can anyone who takes a copy.
Access that matches the job
Reception sees the front desk. A doctor sees consults and, only if your clinic bills that way, money. The owner sees everything. Hiding a menu item is not access control, so the rules are enforced on the server: typing an address you are not entitled to gets you sent back, not in.
An audit trail
Who created, changed or viewed what, and when, with the account that did it. Records that matter — a signed prescription, a recorded payment — are not quietly editable; a correction leaves a trail.
Backups and recovery
Databases are backed up on a schedule and restores are tested. Retention and the recovery targets we commit to are written down in the SLA rather than described vaguely here.
Where your data is hosted
Clinic and patient data is stored in Germany. If that ever changes, this page and the sub-processor list change with it, before the data does.
We never see a card number
Online payments go to Razorpay or Cashfree, who are the ones regulated to handle card data and who carry the PCI-DSS obligation. Card numbers, CVVs and UPI PINs never reach a Sqavio server, so there is nothing of that kind for us to leak.
Support access is limited and logged
Our team does not browse clinic data. Support access to a clinic account is deliberate, time-limited and recorded in the audit trail, so you can see it happened.
The law
Where you stand under the DPDP Act
The Digital Personal Data Protection Act, 2023 and the rules made under it in 2025 give the two of us different jobs. Being clear about which is which is most of the work.
Your clinic is the Data Fiduciary
You decide why patient data is collected and what happens to it. The statutory duties to your patients — notice, consent, responding to their requests — sit with you, as they already do with your paper records.
Sqavio is the Data Processor
We hold and process that data only to run the service you asked for, on your instructions. We do not sell it, we do not mine it, and we do not use one clinic’s patients for anything to do with another.
What we do to help you meet your duties
Consent and its withdrawal are recorded with a timestamp. Patient notices are shown at the point of booking. Exports and deletion are available so you can answer a patient who asks. Our DPA puts all of this in writing.
If there is a breach
We tell you promptly and with enough detail for you to meet your own reporting duty to the Data Protection Board and to affected people, including the 72-hour detailed report. The commitment is in the DPA and the SLA, not just on this page.
What we deliberately do not claim
Your data
It stays yours
Export whenever you like
Patients, prescriptions and billing records, while your account is active and on the way out.
Deletion on exit
After you cancel we keep data for the window set out in the Terms so you can change your mind, then delete it.
A named list of sub-processors
Every third party that touches your data, what they do, and where — published and kept current.
Found a security problem?
Write to [email protected] with enough detail for us to reproduce it. We will acknowledge, keep you updated while we fix it, and we will not threaten anyone who reports a genuine issue in good faith. Please do not test against a live clinic’s data — ask us and we will give you somewhere safe to test.
Ask us the hard questions on the call
Where the data sits, who can reach it, what happens if you leave. We would rather answer before you sign than after.