MediNITS is built with DPDP 2023 compliance from day one. Patient consent is captured digitally. Data is encrypted at rest. You own your clinic's data — we do not sell it, analyse it for advertising, or share it with third parties.
1. Overview
Marketers Data Solution Pvt. Ltd. ("MediNITS", "we", "us", or "our") operates the MediNITS clinic management platform at app.medinits.com and medinits.com. This Privacy Policy explains how we collect, use, store, and protect information when you use our platform.
By using MediNITS, you agree to the practices described in this policy. If you do not agree, please discontinue use of the platform.
2. DPDP 2023 Compliance (India)
MediNITS complies with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). As a Data Fiduciary, we:
- Collect patient data only for the legitimate purpose of clinical record management
- Obtain explicit, informed patient consent before collecting personal health data
- Allow patients to access, correct, and request deletion of their personal data
- Do not use patient data for advertising, profiling, or any purpose outside clinical management
- Notify affected persons in the event of a data breach as required by law
- Retain patient data only as long as necessary for clinical purposes
Your Rights Under DPDP 2023
- Right to Access: Request a full export of your data at any time via Settings → Export Data
- Right to Correction: Update any inaccurate personal data directly in the platform
- Right to Erasure: Request deletion or anonymization of patient records from Settings or by emailing [email protected]
- Right to Grievance Redressal: Contact our Data Protection Officer at [email protected] within 30 days for any data-related complaint
3. Information We Collect
3.1 Clinic / Doctor Information
- Name, email address, phone number, clinic name and address
- Specialization, city, GST number (if provided)
- Payment information (processed by Stripe — we never store card numbers)
- IP address and device information for security logging
3.2 Patient Data (collected by clinics using MediNITS)
- Patient name, age, gender, phone number, email address
- Medical history, diagnoses, prescriptions, vitals, allergies
- Invoice and payment records
- DPDP consent timestamp and method
- Appointment booking information
Patient data is collected by clinics (Data Fiduciaries) for clinical purposes. MediNITS acts as a Data Processor in this context and processes data only as instructed by the clinic.
3.3 Usage Data
- AI consultation queries (anonymized after processing)
- Feature usage statistics for platform improvement
- Error logs and performance monitoring data
4. How We Use Your Data
- To provide and operate the MediNITS platform
- To process payments via Stripe
- To send transactional emails (account creation, password reset, subscription receipts)
- To provide customer support
- To improve AI models using anonymized, aggregated consultation data
- To comply with legal obligations
We do not: Sell your data, share it with advertisers, use it for marketing profiling, or disclose patient data to any party without explicit consent or legal obligation.
5. Data Storage & Security
- Database: Supabase PostgreSQL (ap-southeast-2 region, AWS) with row-level security
- Encryption: Data encrypted at rest (AES-256) and in transit (TLS 1.3)
- Passwords: Hashed with SHA-256 — never stored as plain text
- API Keys: Stored in Supabase Vault (encrypted at rest, not accessible to application layer)
- Access Control: All data access via authenticated edge functions with RLS enforcement
- Backups: Automated daily backups with 30-day retention
6. Third-Party Services
- Stripe: Payment processing. Subject to Stripe's Privacy Policy. We share only billing information necessary for payment.
- Supabase: Database and authentication infrastructure. GDPR compliant. Data stored in AWS ap-southeast-2.
- Groq / OpenAI / Google: AI consultation processing. Patient data sent to AI APIs is used only for generating clinical notes and is not retained by AI providers for training purposes (per their enterprise terms).
- Cloudflare: CDN, DDoS protection, and edge delivery. May collect IP addresses for security purposes.
- Interakt (optional): WhatsApp messaging for clinics that configure it. Subject to Interakt's Privacy Policy.
7. Data Retention
- Clinic accounts: Retained while subscription is active and for 90 days after cancellation
- Patient records: Retained as long as the clinic account is active. Exported and deleted on clinic request.
- Security logs: Retained for 90 days
- AI consultation logs: Anonymized after 30 days
8. Cookies & Local Storage
MediNITS uses browser localStorage to store your clinic session and settings. We do not use third-party advertising cookies. We use session cookies strictly necessary for authentication. By using MediNITS, you consent to essential cookie use.
9. Security Incident Response
In the event of a data breach that affects personal data, we will notify affected users within 72 hours via email and take immediate remediation action. We will report to the Data Protection Board of India as required by DPDP 2023.
10. International Transfers
MediNITS is primarily designed for Indian clinics. Data is stored in the AWS ap-southeast-2 (Sydney) region. For international clinics, data is stored in the same region. We are working toward enabling regional data residency for EU and UAE customers.
11. Children's Privacy
MediNITS is not intended for use by individuals under 18 years of age. Pediatric patient records may be created by healthcare providers in the course of legitimate clinical practice, governed by applicable medical data laws.
12. Changes to This Policy
We may update this Privacy Policy. We will notify you of material changes via email and with a notice on the platform at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.
13. Contact Us
Data Protection Officer: [email protected]
WhatsApp: +91 9663769576
Response time: Within 72 hours for data requests, 30 days for formal complaints