Privacy Policy
Last updated: 29 May 2026
For patient data handled by a specific clinic, see that clinic's privacy notice linked at booking and in the patient portal.
1. Scope and who we are
Clinith OS ("Clinith OS", "we", "us") operates the Clinith OS platform and website. This Privacy Policy explains how we handle Personal Data when you visit our marketing site, create a platform account, or interact with us as a customer or prospect.
This policy does not replace the privacy notice your clinic must provide to patients. When clinics use our software to manage patient records, the clinic is typically the Data Fiduciary / controller for patient data; we process that data on the clinic's instructions as a Data Processor / service provider.
2. Controller and processor roles
- We act as an independent controller for: platform marketing site analytics (if enabled), sales inquiries, customer account and billing records for clinic staff and administrators, security logs relating to platform access, and compliance communications with customers.
- We act as a processor for: patient and clinical data, appointment records, billing line items tied to patients, documents uploaded by clinics, and other Customer Data submitted through the product on a clinic's behalf.
- Questions about patient records should be directed to the relevant clinic first. Questions about our processing as a platform operator may be sent to privacy@clinithos.com.
3. Categories of Personal Data
Depending on how you interact with us, we may process:
- Identity and contact data: name, email, phone, clinic name, job title.
- Account and authentication data: login identifiers, password hashes, MFA settings, session metadata, role assignments.
- Billing and subscription data: plan, invoices, payment references processed by payment providers (we do not store full card numbers).
- Usage and technical data: IP address, device/browser type, timestamps, audit and security logs, error diagnostics (configured to avoid unnecessary PHI in logs).
- Support and sales communications: emails, tickets, and call notes you send us.
- Customer Data submitted by clinics: patient demographics, contact details, clinical notes, vitals, prescriptions, insurance information, documents, appointment history, and messaging content where clinics enable reminders or portal features.
4. Purposes and lawful bases
We process Personal Data to:
Clinics must ensure they have an appropriate lawful basis (including consent where required under the DPDP Act or other law) before submitting patient Personal Data and enabling patient-facing features such as booking, reminders, or the patient portal.
- Provide, maintain, and improve the Services (contract / legitimate interest).
- Authenticate users, enforce tenant isolation, and protect against fraud and abuse (contract / legitimate interest / legal obligation).
- Process subscriptions and payments (contract / legal obligation).
- Send service, security, and transactional communications (contract / legitimate interest).
- Respond to support requests and sales inquiries (contract / legitimate interest / consent where required).
- Comply with law, respond to lawful requests, and establish or defend legal claims (legal obligation / legitimate interest).
- Generate aggregated, de-identified analytics that do not identify individuals (legitimate interest).
5. Sharing and subprocessors
We do not sell Personal Data. We share Personal Data only as described below:
A current subprocessor list is available on request at security@clinithos.com. We will provide notice of material subprocessor changes as required by our customer agreements.
- Subprocessors that help us run the Services, such as cloud hosting and database providers, email and SMS delivery, WhatsApp messaging (Meta), payment processors (e.g., Razorpay), and infrastructure monitoring. These providers are bound by confidentiality and data protection terms appropriate to their access.
- Clinic-authorized integrations configured by the customer.
- Professional advisers, auditors, or insurers under confidentiality obligations.
- Law enforcement or regulators when required by applicable law, or to protect rights, safety, and security.
- Successors in a merger, acquisition, or asset sale, with notice where required.
6. International transfers
Our infrastructure and subprocessors may process data in India and other countries. Where Personal Data is transferred across borders, we implement appropriate safeguards required by applicable law, such as contractual clauses, vendor assessments, and region selection where offered.
Customers are responsible for assessing whether cross-border processing meets their regulatory requirements and for executing required agreements (DPA, BAA, or standard contractual terms).
7. Retention
We retain Personal Data only as long as necessary for the purposes above, including:
- Platform account data: for the subscription term and a reasonable period thereafter for backups, billing records, and legal claims.
- Security and audit logs: per our security policy and customer-configured retention where applicable.
- Customer Data: according to clinic retention settings, product features (including anonymization workflows), and legal requirements. Clinics should configure retention in Settings and maintain their own records policies.
8. Security measures
We implement administrative, technical, and organizational measures designed to protect Personal Data, including HTTPS encryption in transit, access controls and role-based permissions, tenant isolation, password and OTP hashing, encryption of selected integration secrets, audit logging for sensitive actions, rate limiting, and webhook signature verification.
No method of transmission or storage is completely secure. Customers should use strong passwords, enable MFA for staff, limit permissions, and report suspected incidents promptly to security@clinithos.com.
9. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to certain processing, withdraw consent where processing is consent-based, and lodge a complaint with a supervisory authority.
India (DPDP Act): Data Principals may exercise rights including access, correction, erasure, and grievance redressal. Nomination rights apply as provided under the Act. Contact your clinic for patient data; contact us for platform account data.
US (HIPAA): Where we are a Business Associate, patient rights regarding PHI are generally handled by the covered entity (the clinic) under HIPAA and our BAA.
To exercise rights relating to data we control directly, email privacy@clinithos.com. We may verify your identity before responding. We will respond within timelines required by applicable law.
10. Grievance officer (India)
Under the DPDP Act, you may contact our Grievance Officer for complaints relating to our processing of Personal Data as a platform operator:
Name / designation: Grievance Officer, Clinith OS
Email: privacy@clinithos.com
Address: India
If you are not satisfied with our response, you may escalate to the Data Protection Board of India as provided under applicable rules.
11. Children's data
The Services are intended for use by clinics and authorized staff, not by children directly. Patient records for minors should be managed by clinics with appropriate parental or guardian authority and notices as required by law.
12. Cookies and similar technologies
We use essential cookies and similar technologies for authentication, security, and session management. We do not use third-party advertising cookies on the core product. If we enable optional analytics on the marketing site, we will update this section and provide controls where required.
13. Personal data breach
We maintain incident response procedures. If we become aware of a personal data breach affecting Personal Data we control, we will notify affected customers and/or individuals as required by applicable law and our contractual commitments, and cooperate with clinics in their notification obligations for Customer Data.
14. Changes to this policy
We may update this Privacy Policy for legal, regulatory, or product reasons. We will post the updated version with a revised date and provide additional notice for material changes where appropriate.
15. Contact
Privacy: privacy@clinithos.com
Grievance Officer: privacy@clinithos.com
Security incidents: security@clinithos.com
Related: Terms of Service · Compliance overview
