1.DPDP notice (India) — plain-language summary
This section is the itemized notice intended for India's DPDP Act / Rules. Full counsel draft: repository docs/compliance/DPDP-NOTICE-DRAFT.md. Hindi or other regional translations are deferred unless the operator decides otherwise.
- Categories: account identity and security data; patient documents and derived facts/summaries/copilot messages you create; operational audit and rate-limit metadata.
- Purposes: provide documentation intelligence; authenticate and secure the Service; enforce plan limits; meet legal duties — not advertising.
- Roles: we control account data; for patient cases you (or your clinic) are the Data Fiduciary and we process on your instructions after you attest a lawful basis (typically patient consent).
- Cross-border storage: the default hosted deployment runs in the UK/EU (London region). You are notified here; revisit if Rules impose localization.
- Processors: infrastructure and AI providers listed under sharing / your deployment register (Supabase, Vercel, Cloudflare R2, Sender, AI provider; Sentry only if enabled).
- Retention: account and case lifetime as above; encrypted backups ~30 days; append-only audit for accountability.
- Rights: access, correction, erasure, withdrawal of consent, grievance via grievance officer.
- Withdrawal: as easy as giving — withdraw case processing consent in-product (freezes processing); delete cases or your account through the confirmed flows.
2.Two kinds of data, two roles
Your account data (who you are as a user): for this, we are the data controller.
Patient case data (the records you upload and the facts, timelines, summaries and questions derived from them): this belongs to your professional practice. You are the controller; the Service processes it only on your instructions — creating a case, uploading a document, generating a summary, asking the copilot, sharing. Before a case can hold patient data you must attest to the patient's consent or another lawful basis, and that attestation is stored.
3.What we collect
- Account: name, email address, a securely hashed password (never the password itself), your work country, and optional multi-factor settings.
- Patient cases: the documents you upload, extracted clinical facts with their source locations, verification decisions, timelines, generated summaries, copilot questions and answers, and sharing records.
- Operational records: an append-only audit trail (who did what, to which resource, when, from which IP) and short-lived rate-limit counters that protect the platform from abuse.
There is no advertising tracking: no ad pixels, no analytics profiles, no sale of data — ever.
4.How data is used
- to provide the product: storing documents, extracting and verifying facts, building timelines, generating cited summaries, answering grounded questions;
- to secure it: authentication, access control, abuse prevention, and the audit trail that healthcare data handling requires;
- to communicate operationally: verification emails, password resets, share invitations — not marketing;
- to comply with legal obligations that apply to us or to your deployment.
5.AI processing
Documents are processed by machine-learning models to extract facts and generate summaries and answers. Every output is tied to its source: facts carry page-level provenance, summaries cite per sentence and fail closed when a citation cannot be verified, and the copilot answers only from verified facts and refuses diagnostic questions.
Production deployments use AI endpoints under data-processing agreements; your content is not used to train models under those agreements.
6.How data is protected
- encryption in transit (TLS) and at rest, including managed-key column encryption with rotation support;
- row-level security in the database — every query is scoped to the owner, an accepted grantee, or an administrator, and API clients get no wider path;
- multi-factor authentication and layered, per-user and per-IP rate limiting;
- malware scanning of every upload before it is stored;
- logs engineered not to contain patient data, with redaction backstops;
- encrypted off-site backups whose restore procedure is actually rehearsed.
Data residency follows your deployment: the platform is portable by design and can run in-region or fully on-premises where regulations or your organisation require it.
8.Retention
- account data: kept while your account exists; deleted on verified account-deletion requests, subject to legal holds;
- patient case data: kept until the owning clinician deletes it or the operating agreement with your organisation ends;
- audit trail: append-only and retained for the period healthcare accountability rules require — it records access, not clinical content;
- backups: encrypted and aged out on a fixed rotation.
9.Your rights
Depending on where you are, these include access, correction, deletion, portability, restriction and objection, and the right to complain to your supervisory authority. India's DPDP Act adds a grievance-redressal route; the UK and EU GDPR add theirs. Patients exercise their rights through the clinician who controls their case — we support that clinician in honouring them.
To exercise a right, use the in-product controls where they exist (export, deletion, revocation) or contact the operator of your deployment; the finalised version of this document will name the responsible entity, its privacy contact and its grievance officer.
10.Grievance officer
A named grievance officer for India DPDP redressal has not yet been published for this deployment. Until then, contact the operator of your deployment through the address published with it. Once designated, set GRIEVANCE_OFFICER_NAME / EMAIL / PHONE so this section populates automatically (India pilot gate B5).
12.Children
The Service is a professional tool and not directed at children as users. Records concerning minors may lawfully appear inside patient cases under the responsible clinician's legal basis and consent process.
13.Changes and contact
Material changes to this policy will be announced in the product before they take effect, and the notice version you accepted at signup is recorded. See also the Terms of Service. Until the responsible entity's contact details are finalised here, reach the operator of your deployment through the address published with it.