Privacy Policy

Effective Date: 9 September 2026

ClinikNote is a digital register and clinic management tool for solo medical practitioners in India. This Privacy Policy explains what personal data we collect, how we use it, and the rights you have under the Digital Personal Data Protection Act, 2023 (DPDP Act).

In this policy, “we” / “us” refers to ClinikNote (the Data Fiduciary for doctor account data, and the Data Processor acting on the doctor’s behalf for patient data). “You” refers to the doctor using the app.

1. Personal Data We Collect

  • Doctor / clinic information: name, qualification, registration number, clinic name and address, mobile number, email address.
  • Patient information you enter: name, contact details, date of birth, gender, medical history, allergies, diagnoses, vitals, clinical notes, prescriptions, uploaded documents, payment records.
  • Account and usage data: login events, device identifiers, and basic diagnostic logs used to keep the service running.

2. Purpose and Legal Basis

We process personal data for these purposes only:

  • To provide the ClinikNote service to you.
  • To help you maintain records required for clinical practice and Income Tax compliance in India.
  • To keep the service secure and to fix issues you report to us.

The legal basis for processing is your consent (given when you sign up and use the app) and, where applicable, our legitimate use to provide the service you have signed up for.

3. Consent

By creating a ClinikNote account and adding patient records, you consent to us storing that data on your behalf and to the processing described in this policy. Consent is specific, informed, and given for the purposes above. You may withdraw consent at any time by emailing our Grievance Officer (see section 9). Withdrawing consent will end your ability to use the service; existing data will be handled per section 6.

4. How We Share Data

  • We do not sell personal data to any third party.
  • Patient data is visible only to the registered doctor who created it. It is not shared across doctor accounts.
  • We use a small set of infrastructure providers to deliver the service: Neon (Postgres database, hosted in the United States), Cloudflare R2 (document storage), Clerk (authentication), and Vercel (web hosting). These providers process data only to run the service and are contractually bound to appropriate security standards.
  • We may disclose data if legally required by an order of a competent Indian authority.

5. Cross-Border Transfer

Some of the infrastructure providers listed above host data outside India (for example, Neon is hosted in the United States). By using ClinikNote you acknowledge that personal data may be stored and processed outside India in jurisdictions permitted under the DPDP Act. We choose providers that maintain industry-standard security controls.

6. Data Retention

We keep personal data for as long as your account is active, or as needed to provide the service to you. Deleted patient records are soft-deleted (retained in the database but hidden from the app) for recovery in case of accidental deletion. If you close your account, we will delete or anonymise your data within 90 days, except where Indian law requires longer retention (for example, income-tax record retention obligations that apply to you as a doctor).

Our full retention schedule is published on the Data Retention Policy page.

7. Data Security

We use encryption in transit (HTTPS/TLS on every request) and encryption at rest at our storage providers. Access to production systems is restricted to the developer team on a need-to-fix basis and is not used to read patient data. We keep no analytics or tracking on the doctor-facing pages of the app.

8. Your Rights as a Data Principal

Under the DPDP Act you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct data that is inaccurate or incomplete.
  • Erasure — ask us to delete your account and associated data (subject to any legal retention requirement).
  • Grievance redressal — raise a complaint about how we handle your data.
  • Nominate — designate a person to exercise these rights on your behalf if you are deceased or incapacitated.
  • Withdraw consent — at any time, by email to the Grievance Officer.

To exercise any of these rights, email our Grievance Officer using the contact in section 9. We will acknowledge your request within seven (7) working days and resolve it within thirty (30) days.

9. Grievance Officer

In accordance with the DPDP Act and the Information Technology Act, 2000, you may contact our Grievance Officer for any question about this policy, to exercise your rights, or to raise a complaint:

Name: Amit Gaikwad
Email: support@cliniknote.app
Response time: acknowledgment within seven (7) working days; resolution within thirty (30) days.

10. Data Breach Notification

If a personal data breach affecting your account occurs, we will notify you and the Data Protection Board of India as required under the DPDP Act, including a description of the breach, the data affected, and the steps we are taking in response.

11. Children’s Data

The app is intended for use by registered medical practitioners (adults) only. Patient records may include data about minors; in that case, the doctor is responsible for obtaining any consent required from the patient’s parent or guardian before entering data.

12. Changes to This Policy

We will update this policy when the service or applicable law changes. The “Effective Date” at the top will reflect the latest revision. Material changes will be communicated through the app or by email.

13. Contact

For any question about this policy, email support@cliniknote.app.