Privacy Policy
Last updated: 3 September 2026
This policy explains what personal information is collected when you use CAREZENIX, why it is collected, who it is shared with, and what you can ask us to do with it. It covers the CAREZENIX web application and the appointment, prescription, billing and messaging features inside it.
1. Who is responsible for your information
Two different organisations are involved, and the difference matters for your rights.
- Your clinic or hospital decides what patient information is recorded, who on its staff may see it, and how long it is kept. Under India's Digital Personal Data Protection Act, 2023, the clinic is the Data Fiduciary for its patients' records.
- Vikalp Development Private Limited builds and operates the software and its servers, and handles that information only on the clinic's instructions. In the same law, we are the Data Processor. We do not sell patient data, and we do not use it to advertise anything to you.
If you are a patient and want a record corrected or erased, the clinic that treated you is the right place to start. If they cannot resolve it, contact us using the details in section 10.
2. Information we collect
| What | Examples | Why it exists |
|---|---|---|
| Identity and contact | Name, mobile number, email address, date of birth, gender, postal address, and the clinic-issued patient number (UHID) | To identify you correctly at the clinic and to reach you about your visit |
| Health information | Appointments, complaints and diagnoses recorded by your doctor, prescriptions, recommended lab tests, and visit notes | To provide and record your treatment. This is sensitive personal data and is treated as such |
| Billing | Invoices, amounts, payment status, and the reference number returned by the payment gateway | To bill you and to keep the accounting records the law requires |
| Account and security | Your role, sign-in times, one-time passwords, IP address, browser and device type | To sign you in, to keep accounts secure, and to investigate misuse |
| Message records | Which SMS or WhatsApp messages were sent to you, when, and whether they were delivered and read | So the clinic can prove a reminder was actually sent, and so failures can be retried |
We do not ask for and do not want your Aadhaar number, PAN, bank account details or card numbers. Card details, where online payment is used, are entered on the payment gateway's own page and never reach our servers.
3. How we use it
- To let clinic staff book, reschedule and record your appointments.
- To let your doctor write, print and share prescriptions and invoices with you.
- To send you appointment confirmations, reminders and, after a visit, an invitation to leave feedback.
- To send the one-time password that signs you in.
- To keep the service running, secure and free of abuse, and to fix faults.
- To meet legal, tax and medical record-keeping obligations.
We do not profile you for advertising, and we do not make automated decisions about your treatment. Clinical decisions are made by your doctor, not by this software.
4. Messages you receive, and how to stop them
Appointment and feedback messages may be delivered by SMS or by WhatsApp. WhatsApp messages are sent using message templates approved in advance by Meta, and only for the purposes listed above. Your mobile number is shared with the messaging provider purely to deliver that message.
You can ask your clinic to stop sending you non-essential messages at any time, or reply STOP to a WhatsApp message to block further messages from that number. One-time passwords are a security measure rather than a notification and are always sent by SMS; they cannot be switched off while your account is active.
5. Who we share information with
Only with the following, and only as much as each needs to do its job:
- Your clinic's own staff, according to the roles and permissions the clinic sets.
- Messaging providers — Meta Platforms (WhatsApp Business Cloud API), and an SMS gateway such as MSG91, Gupshup or Twilio — to deliver the messages described above.
- The payment gateway, where a clinic accepts online payment, to process that payment.
- Hosting and error-monitoring providers that run our servers and alert us to faults.
- Government authorities or courts, where we are legally required to disclose information.
We do not sell personal information, and we do not share it with advertisers or data brokers. Some of these providers operate servers outside India; where that happens, the transfer is limited to what the service needs and is permitted by law.
6. How long we keep it
Medical records are retained for at least 3 years from the date of the last entry, in line with medical record-keeping practice in India, and longer where a law, a tax rule or an active dispute requires it. Sign-in and message logs are kept for a shorter period, sufficient for security investigation and billing verification.
When a clinic stops using CAREZENIX, its records are returned or deleted on the clinic's instruction, subject to the retention periods above.
7. How we protect it
- All traffic is encrypted in transit using HTTPS.
- Sensitive integration credentials are stored encrypted, not in plain text.
- Sign-in uses a one-time password sent to your registered mobile number, not a password you might reuse elsewhere.
- Each clinic's data is separated from every other clinic's, and staff see only what their role allows.
- Administrative actions are recorded so misuse can be traced.
No system is perfectly secure. If a breach affects your information, we will notify the affected clinic and the Data Protection Board of India as the law requires.
8. Your rights
Subject to the DPDP Act and to medical record-keeping law, you may ask to:
- see the personal information held about you;
- have inaccurate information corrected;
- have information erased where it is no longer needed and no law requires it to be kept;
- withdraw consent for messages that are not essential to your care;
- nominate someone to exercise these rights if you are unable to;
- complain about how a request was handled.
A correction request that changes a clinical record is decided by the treating doctor, who may add a correction rather than overwrite the original — that is deliberate, and it is how medical records are meant to work.
9. Cookies
We use only the cookies the service needs to function: one that keeps you signed in, one that protects forms against cross-site request forgery, and one that remembers which clinic's branded link you arrived through. We do not use advertising or cross-site tracking cookies. Blocking these cookies will prevent sign-in from working.
10. Contact and grievances
For anything about your own records, contact your clinic first — they hold them. For anything about this policy or the platform itself:
- Vikalp Development Private Limited, Bengali Colony, Mahavir Enclave, New Delhi - 110045, Delhi, India
- Grievance Officer: Vikash Singh — marketing@vikalpdevelopment.com
We aim to respond to a grievance within 30 days of receiving it.
11. Changes to this policy
If this policy changes, the "last updated" date above changes with it, and material changes are notified to clinics before they take effect. Continuing to use CAREZENIX after a change means the updated policy applies.
See also our Terms of Service.