Skip to content
RxNitiRxNiti

Privacy Policy

How RxNiti handles clinic and patient data under the Digital Personal Data Protection Act, 2023 — what we hold, who else touches it, where it lives, and how long we keep it.

Version

Jump to a clause

1. Who we are

RxNiti is a clinic management platform operated by Antatah Arogyam, Vani, Nashik, Maharashtra, India ("we", "us"). Clinics use it to run patient records, prescriptions, consent, billing, pharmacy stock and in-patient care.

Under the Digital Personal Data Protection Act, 2023, the clinic using RxNiti is the Data Fiduciary for its patients' data. We are the Data Processor: we hold and process that data only to provide the service to that clinic, on its instructions. This policy explains what we do with it, where it goes, and how long we keep it.

2. What data we handle

On behalf of clinics: patient name, date of birth or age, gender, contact number, address and, where the clinic records them, ABHA identifiers; clinical data (case sheets, examination findings, diagnoses, prescriptions, treatment plans, uploaded images and documents); consent records including the captured signature; billing and payment records (invoices, amounts, payment mode and status); and appointment, admission and treatment history.

About clinic staff: name, role, mobile number and email where provided, a hashed login PIN (never the PIN itself), the device and session a person signs in from, and a record of the actions they take in the app.

Automatically: technical logs needed to run and secure the service — request and error diagnostics, sign-in attempts, and page-performance measurements.

We do not store card, UPI or bank credentials. Payments are handled entirely by our payment gateway.

3. Legal basis

Patient data is processed for the provision of healthcare by the clinic, and on the consent the clinic obtains from the patient at registration and before treatment. Staff account data is processed on the basis of the contract between us and the clinic. Security and audit logging is carried out to meet our obligations under the DPDP Act, 2023 and the Information Technology Act, 2000.

We process patient data only on the clinic's documented instructions. We do not use patient data for our own purposes, we do not sell it, and we do not use it to train machine-learning models.

4. How the data is used

To show records to the authorised staff of the clinic that entered them; to produce prescriptions, invoices, consent forms and discharge summaries; to send appointment, follow-up and billing messages to patients on the clinic's instruction; to run the clinic's own reports; and to keep the audit trail that tells the clinic who did what.

Clinic separation is enforced in the database itself, not only in the screens: a clinic can reach its own rows and no others.

5. Where your data is stored and processed

Records and uploaded files are stored in India — Supabase on AWS Mumbai (ap-south-1).

Two parts of the service run outside India, and you should know about them. The application servers that render pages and run the API are hosted by Vercel in their US East region, so data passes through the United States while a request is being served; it is not stored there. Error diagnostics go to Sentry's United States region. Both are covered by contractual protections with those providers, and both are listed below.

We are moving the application servers to Vercel's Mumbai region. This section will be updated when that is done, not before.

6. Sub-processors

We use the following processors to run the service. Each has access only to what its function requires, and each is bound by its provider agreement to confidentiality and to processing only on our instructions.

  • Supabase (AWS Mumbai, India) — database, file storage and backups of clinical and billing records.
  • Vercel (United States) — application hosting; also provides aggregate page-performance and traffic counts that contain no patient data.
  • Amazon Web Services (S3) — encrypted off-site copies of clinic backups.
  • Razorpay (India) — subscription and add-on payments. Card and UPI details go to Razorpay directly and never reach us.
  • MSG91 (India) — WhatsApp and SMS delivery for appointment, follow-up and billing messages. Message content only.
  • SendGrid (United States) — transactional email, such as PIN reset and platform notices.
  • Sentry (United States) — error and crash diagnostics. Request bodies and query strings are stripped before an error report leaves the browser or server.
  • AI providers — Google (Gemini) and, as fallbacks, Anthropic, Groq and OpenAI. See section 7.

We will publish changes to this list here before a new sub-processor begins handling clinic data.

7. AI-assisted features

Some optional features use a third-party AI model: dictation of clinical notes, reading a supplier bill, and mapping the columns of a spreadsheet during import.

Before any text is sent to a model, it passes through an automatic redaction step that removes Aadhaar numbers, phone numbers, email addresses and dates of birth, and every such call is recorded in the audit trail with how many identifiers were removed. Even so, the clinical content of a note is sent to the provider to be processed, so a clinic that does not want that should not use those features; nothing else in RxNiti depends on them.

The output of an AI feature is a draft for the treating practitioner to check. It is not a diagnosis and carries no clinical authority.

8. How long we keep data

  • Patient medical records — at least 3 years from the last treatment, per the Indian Medical Council (Professional Conduct) Regulations and the Medical Records Rules, 2016. The clinic decides what happens after that.
  • Billing and tax records — 7 years, as required for GST.
  • Deleted records — moved to the clinic's recycle bin and permanently removed after 30 days. Until then the clinic can restore them.
  • Audit trail — the full before-and-after snapshot of a change is kept for 12 months, and the record that the change happened for 3 years.
  • Backups — 30 daily snapshots. A record deleted today disappears from the last backup within 30 days.
  • Sign-in attempts and device sessions — kept while needed to detect and investigate misuse of an account.

When a clinic leaves, it can export its data for 30 days. After that we delete the clinic's data, except where a law above requires us to keep it, and except for copies inside backups that age out on the schedule above.

9. Security

Data is encrypted in transit (TLS 1.3) and at rest. Staff sign in with a PIN stored as a salted, peppered bcrypt hash — we cannot read it, and a stolen copy of the database is not enough to sign in. Access follows the role each clinic assigns. Every change to a record is written to an audit trail the clinic can read and nobody can quietly edit.

No system is beyond compromise. If a breach affects a clinic's data, we will tell that clinic without undue delay and give them what they need to meet their own duty to notify the Data Protection Board of India and the affected patients.

10. Patient rights

Under the DPDP Act, 2023, a patient may ask to see their data, correct it, have it erased (subject to the retention periods above), nominate someone to act for them, and withdraw consent.

Those requests go to the clinic that treated them: the clinic holds the relationship, and the law makes the clinic the Data Fiduciary. We give clinics the tools to answer, and we will help any clinic that asks. A patient who cannot get an answer from their clinic may write to our Grievance Officer below.

11. Children and guardians

A child's record is created and managed by the clinic on the consent of a parent or guardian, whom the clinic identifies at registration. We do not knowingly hold a child's data that reaches us any other way. We do not profile children, track them for advertising, or use their data for anything but the clinical and billing purposes the clinic entered it for.

12. Cookies and local storage

We set one cookie: the session that keeps a staff member signed in. It is essential — without it the app cannot tell who you are — and it carries no advertising or cross-site tracking.

The browser also stores small preferences on the device: theme, sidebar width, unsent drafts, and records cached so the app keeps working when the connection drops. Those never leave the device except as part of normal use of the app.

We run Vercel's traffic and page-speed measurement on public pages. It counts visits and load times; it does not use cookies to identify you, and it never sees patient data. We do not use advertising or cross-site tracking tools.

13. Grievance Officer

Questions, complaints and requests about how we handle personal data go to the Grievance Officer:

Grievance Officer, Antatah Arogyam Vani, Nashik, Maharashtra, India Email: privacy@antatah.com WhatsApp: +91 75883 55113

We acknowledge a grievance within 7 working days and answer it within 30 days. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.

14. Changes to this policy

We will post any change here and, where the change is material, tell clinics inside the app. The date of the current version is shown at the top of this page. Continuing to use RxNiti after a change means the clinic accepts the updated policy.

Privacy policy