Privacy Policy
Version 2026-09-25 · Effective 25 September 2026
1. Who we are and what this covers
[Kliniq Technologies Private Limited] (“Kliniq”, “we”) provides clinic software at kliniq.in and on each clinic's own kliniq.in web address. For the data described in this policy, we are the data fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the body corporate responsible under the Information Technology Act, 2000 and the SPDI Rules, 2011.
It covers:
- clinic owners and staff who use Kliniq, including people invited to a clinic;
- people who sign up, pay for, or contact us about Kliniq;
- visitors to our public website.
2. If you are a patient
When you book with or visit a clinic that uses Kliniq, that clinic is the data fiduciary for your personal and health data. It decides what is collected and why. Kliniq processes that data only on the clinic's instructions, under a Data Processing Agreement, and stores it in India.
Each clinic's booking page shows its privacy notice and its contact for questions and complaints. To see, correct or erase your data, or to make a complaint, please contact the clinic, or use the “My visits and records” link the clinic sent you. If you write to us instead, we will pass your request to the clinic promptly and tell you we have done so.
3. What we collect
| Category | Examples | Source |
|---|---|---|
| Account | Name, mobile number, email, role, clinic name, city, specialty, web address | You, at sign-up or when invited |
| Sign-in and security | One-time codes (stored only as hashes), trusted-device records, sign-in times, audit logs of actions | Generated when you use Kliniq |
| Billing | Legal name, GSTIN, billing address and state, plan, invoices, payment status | You, and our payment providers |
| Technical | IP address (stored as a one-way hash for abuse limits), browser type, error logs | Your device |
| Communications | Messages you send to support or through the contact form, and our replies | You |
4. Why we use it
| Purpose | Basis under the DPDP Act |
|---|---|
| Create and run your account, sign you in, provide the Service | Your consent at sign-up, and performing our contract with your clinic |
| Security: detect abuse, prevent fraud, keep audit logs | Consent and legitimate uses, including compliance with CERT-In directions |
| Billing, GST invoices and accounting | Legal obligations under tax and company law |
| Service messages: trial reminders, payment notices, changes to terms | Performing our contract |
| Product news and offers | Only if you opt in; you can opt out at any time |
| Answering questions and complaints | Your consent, given when you contact us |
We do not use your data for automated decisions that have legal effects on you, and we do not use patient data to train AI models.
7. Where your data is stored
Clinic, patient and account data, and its backups, are stored in India (AWS Mumbai, with backup copies in Hyderabad). Some providers, such as WhatsApp and our payment providers, may process limited data outside India to deliver a message or payment. Such transfers are allowed under section 16 of the DPDP Act, and we never transfer data to a country the Government of India has restricted.
8. How long we keep it
| Data | Kept for |
|---|---|
| Account data | While the account is active, then 30 days after closure so you can export, then deleted |
| Billing records and invoices | As long as tax and company law requires (currently up to 8 years) |
| Security and system logs | At least 180 days in India, as CERT-In requires, and at most 1 year unless needed for an investigation |
| Audit logs of clinic actions | At least 1 year, as the clinic's retention settings allow |
| Contact form and support messages | 2 years after the last reply |
| Backups | Expire within 35 days |
9. How we protect it
- Encryption in transit (TLS 1.2 or later) and at rest (AES-256).
- Sign-in with one-time codes, and a second code for owners and doctors.
- Role-based access and a tamper-evident audit log of every change.
- Strict separation between clinics, tested automatically before every release.
- Kliniq staff can see a clinic's data only with the owner's time-limited approval, and every such access is logged in the clinic's own audit log.
- A yearly external penetration test.
If a personal data breach happens, we report it to CERT-In within 6 hours and notify affected clinics within 24 hours. We also inform the Data Protection Board of India and affected people as the DPDP Rules, 2025 require.
10. Your rights
Under the DPDP Act you can:
- get a summary of the personal data we hold about you and how we use it;
- have inaccurate or incomplete data corrected, completed or updated;
- have data erased when it is no longer needed, unless the law requires us to keep it;
- withdraw consent at any time, as easily as you gave it (withdrawing does not affect processing already done);
- have your grievances addressed by us;
- nominate someone to exercise these rights if you die or become unable to.
Write to privacy@kliniq.in or use the contact form. We may ask you to confirm your identity. We aim to reply within 30 days, and always within the time the DPDP Rules allow.
If you are not satisfied with our response, you may complain to the Data Protection Board of India once you have used our grievance process. You also have the duties the DPDP Act sets out, such as not filing false or frivolous complaints.
11. Children
Kliniq accounts are for adults (18 or older) working in a clinic. We do not knowingly collect children's data for our own purposes. Clinics may process children's data as patients, with a parent's or guardian's consent recorded at booking, under the exemptions the DPDP Rules, 2025 provide for clinical establishments.
12. Changes to this policy
We will post any update here with a new version date. For material changes we will also email account owners at least 30 days before they take effect.
13. Contact, Grievance Officer and Data Protection Officer
For questions about this policy or your data, or to make a complaint, contact us here. These details are published as the SPDI Rules, 2011, the Intermediary Rules, 2021 and the DPDP Rules, 2025 require.
- Grievance Officer
- [Grievance Officer name]
- grievance@kliniq.in
- Data Protection Officer
- [Data Protection Officer name]
- privacy@kliniq.in
- Phone
- [+91 phone number]
- Post
- [Kliniq Technologies Private Limited], [Registered office address, City, State, PIN]
- Hours
- Monday to Saturday, 9 am to 7 pm IST (except public holidays)
Questions about this document? Write to hello@kliniq.in or use our contact form.