Back to Home

Privacy Policy

Last updated: August 2026

1. Information We Collect & Lawful Basis

This privacy policy is issued under the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 §43A, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).

When you use Aethis, we collect the following categories of personal data:

  • Account information: name, email, phone number, clinic name, professional registration details
  • Patient data (entered by you, the clinic): names, phone numbers, date of birth, gender, medical history, clinical notes, treatment records, diagnoses, prescriptions, allergies, clinical photographs, consent forms
  • Health data: all medical and clinical information entered into the platform by clinic staff constitutes "Sensitive Personal Data or Information" (SPDI) under the SPDI Rules 2011 and health data under the DPDP Act 2023
  • Financial data: billing records, payment transactions (processed via Razorpay — see Section 5)
  • Consent data: consent form records, consent status, withdrawal history, signature data
  • Usage data: log data, page visits, feature usage patterns (see Section 5 for analytics disclosure)
  • Lawful Basis for Processing:

  • For clinic account data: performance of a contract (Terms of Service) and legitimate business purposes
  • For patient health data (SPDI): we act as a Data Processor on behalf of the clinic (the Data Fiduciary/Controller). The clinic obtains consent from patients under DPDP Act §4(1) and maintains records of such consent. For sensitive personal data under SPDI Rules Rule 5, the clinic obtains specific, informed consent in writing (including electronic records) from the patient before collection
  • Consent is obtained through the Aethis consent form system, which includes DPDP-compliant notice elements (purpose specification, rights enumeration, withdrawal instructions, grievance officer contact). Consent notices are available in English and Hindi per DPDP Act §5(3)
  • 2. How We Use Your Information

  • To provide and maintain the Aethis clinic management service
  • To send appointment reminders and notifications (via WhatsApp, email, or SMS)
  • To improve our product based on aggregated, de-identified usage patterns
  • To communicate with you about updates, billing, and support
  • We process patient personal data (including SPDI) solely on the documented instructions of the clinic (the Data Fiduciary/Controller) under our Data Processing Agreement. We do not sell, rent, or share personal data with third parties except as necessary to provide the service (see Section 5).

    Under SPDI Rules Rule 5, sensitive personal data is processed only with the consent of the data subject and is not retained longer than necessary. Under DPDP Act §6(4), consent may be withdrawn at any time — see Section 6 for your rights.

    3. Data Storage & Security

    All data is encrypted at rest (AES-256-GCM) and in transit (TLS 1.3). We use PostgreSQL databases hosted on Indian cloud infrastructure (AWS Mumbai region, ap-south-1). Patient data is stored exclusively within India (see our Data Processing Agreement §13 for details on notification delivery sub-processors).

    We implement ISO-aligned reasonable security practices and procedures as required under SPDI Rules Rule 8 and DPDP Act §8(5), including:

  • Encryption: AES-256-GCM at rest, TLS 1.3 in transit, encrypted backups
  • Access control: Role-based access control (RBAC), multi-tenancy isolation, strong authentication with 2FA support
  • Audit: Comprehensive audit logging of all data access and modifications, with PII redaction in logs
  • Data lifecycle: Automated retention enforcement, secure deletion (cryptographic erasure), backup rotation
  • Organisational: Security awareness training, incident response plan, vendor security assessments
  • Our information security programme is aligned with ISO 27001 and is regularly reviewed. A comprehensive list of Technical and Organisational Measures (TOMs) is published in our Data Processing Agreement (DPA) at /dpa.

    4. Data Retention

    General Retention: We retain your data for as long as your account is active. If you cancel your account, you have 30 days to export your data. After 30 days, all data is permanently deleted from our systems in accordance with DPDP Act §8(7) — data shall be erased upon withdrawal of consent or when it is no longer necessary for the purpose for which it was collected, unless retention is required by applicable law.

    Legal-Retention Carve-Out: Notwithstanding the above, certain clinical records may need to be retained beyond the 30-day standard deletion period where required by applicable law, including:

  • Clinical Establishments (Registration and Regulation) Act, 2010 and applicable State Clinical Establishment Rules — which may mandate retention of medical records for specified periods (typically 3–7 years depending on the state)
  • National Medical Commission (NMC) Code of Ethics Regulations — which govern record retention by registered medical practitioners
  • Employee/occupational health records under applicable labour laws
  • In such cases, data is retained for the minimum period required by law, access is restricted to authorised personnel, and the data remains subject to encryption, confidentiality, and security obligations. Once the legal retention period expires, data is securely deleted.

    Under DPDP Act §12(3)/§6(5), data shall be erased upon withdrawal of consent. When a patient withdraws consent through our consent withdrawal mechanism, we flag the patient record for erasure evaluation per our erasure pipeline (see DPA §9 and §11).

    5. Third-Party Services & Analytics

    Aethis integrates with the following third-party services:

  • Razorpay — for subscription payment processing (RBI-compliant; payment data stored within India)
  • Twilio — for WhatsApp and SMS notification delivery (see DPA §13 for cross-border transfer details)
  • SMTP providers (e.g., SendGrid) — for email notification delivery (see DPA §13 for cross-border transfer details)
  • Each third party has its own privacy policy governing data handling. We ensure all third-party processors are contractually obligated to comply with Indian data protection laws through Data Processing Agreements that are no less protective than our own DPA.

    Analytics: Aethis uses Plausible Analytics (self-hosted, cookieless) for website analytics on aethis.com. Plausible does not use cookies, does not collect personal data, and does not track individuals across sessions or websites. No IP addresses are stored; country-level aggregation is derived from IP geolocation and discarded. This is disclosed under the DPDP Act §5 transparency obligation. No patient data from within the Aethis application is shared with any analytics service.

    A detailed sub-processor and cross-border transfer map is maintained at docs/compliance/india-transfer-map.md.

    6. Your Rights

    Under the Digital Personal Data Protection Act, 2023, you have the right to:

  • Access and obtain a copy of your personal data being processed, along with a summary of processing activities (Sec 11)
  • Request correction, completion, updating, or erasure of your personal data (Sec 12)
  • Grievance redressal — approach our Grievance Officer with any complaint regarding the processing of your personal data (Sec 13)
  • Nominate another individual to exercise your rights in the event of death or incapacity (Sec 14)
  • Withdraw consent at any time (Sec 6(4)). Upon withdrawal, we cease processing for that purpose (Sec 6(5)) and erase the data unless retention is required by law (Sec 12(3)/Sec 6(5))
  • File a complaint with the Data Protection Board of India (Sec 5(2)(c))
  • Additionally, under the SPDI Rules 2011, you have the right to:

  • Review the information provided and ensure it is not inaccurate or deficient (Rule 5(6))
  • Withdraw consent at any time in writing (Rule 5(7))
  • Children's Data: If your clinic treats patients under the age of 18, verifiable parental consent is required before processing the child's personal data, in accordance with DPDP Act §9. Aethis provides minor/guardian consent fields in the consent form module to support clinics in obtaining and recording parental consent. Under DPDP Act §9(3), Aethis does not engage in tracking or behavioural monitoring of children, nor does it process children's data for advertising purposes.

    To exercise any of these rights, contact us at hello@aethis.com or reach our Grievance Officer at grievance@aethis.in.

    7. Grievance Redressal

    In compliance with the Digital Personal Data Protection Act, 2023 §8(9) and §8(10) and the Draft DPDP Rules 2025 Rule 9, we have appointed a Grievance Officer to address any concerns, complaints, or queries you may have regarding the processing of your personal data.

    <b>Grievance Officer:</b> Grievance Officer, Aethis Health Pvt Ltd

    <b>Email:</b> grievance@aethis.in

    <b>Postal Address:</b> Aethis Health Pvt Ltd, Haridwar, Uttarakhand — 249401, India

    <b>Grievance Handling SLA:</b>

  • Acknowledgement of your complaint within <b>24 hours</b> of receipt
  • Resolution of your complaint within <b>7 calendar days</b> of receipt
  • If you are not satisfied with the resolution provided by our Grievance Officer, you have the right to file a complaint with the Data Protection Board of India (DPBI) under §5(2)(c) of the DPDP Act, 2023. Information about the DPBI and its complaint procedure is available at the official website of the Data Protection Board of India.

    8. Contact

    For general privacy-related inquiries: hello@aethis.com<br><br>For grievance redressal: grievance@aethis.in (see Section 7 above for SLA).<br><br>For data subject requests (access, correction, erasure, portability): grievance@aethis.in (see docs/compliance/india-dsar-intake-process.md for the intake process).