Privacy policy
Version 1.0 · September 2026 · MedSaakshi, Tirupati, Andhra Pradesh, India. This policy is written to comply with the Digital Personal Data Protection Act, 2023 and will be reviewed by counsel before commercial launch.
1. Who we are
MedSaakshi ("we") provides a web application through which hospitals and doctors record informed consent and explanations given to patients and their families. Contact: [email protected].
2. Two kinds of data
| Data | Whose it is | Our role |
|---|---|---|
| Patient records made in the app: names, ages, phone numbers, procedures, signatures, audio and video recordings, attendee details | The hospital or doctor that created them (the Data Fiduciary) | Data Processor: we store and process it only on their instructions |
| Account data of hospital staff and doctors: name, mobile number, role, login activity | The individual staff member | Data Fiduciary for the purpose of providing the service |
| Website enquiries: name, organisation, phone, email, message | The person enquiring | Data Fiduciary, used only to respond to the enquiry |
3. Patient data
Patients give consent to the recording of the consent conversation directly to their hospital; the consent text read to them states that the conversation is recorded and kept as part of the medical record. The hospital decides what is recorded and for how long it is kept (10 years by default). We never use patient data for any purpose other than providing the service to that hospital, never sell it, never share it, and never train models on it. Requests by patients to access or correct their records should be made to the hospital, which we assist.
4. Where data is stored
All data is stored on servers located in India (currently Mumbai) and backed up to object storage with an Asia-Pacific location. Data is encrypted in transit. Access to production systems is limited to named MedSaakshi staff and is logged.
5. Staff account data
We collect a staff member's name, mobile number and role so that each record shows who created it and who signed. Login PINs are stored only as salted hashes. We keep audit logs of logins and of every record view, print and playback because the medico-legal value of the record depends on it.
6. Website enquiries
Enquiry details are used to respond to you and are deleted within 12 months if no business relationship follows. We do not use tracking cookies or third-party analytics on this website.
7. Retention and deletion
Patient records are retained for the period set by the hospital, never less than the statutory minimum for medical records in the hospital's state, and are then deleted on the hospital's written instruction. If a hospital ends its subscription, its records remain readable; only new recordings stop. If MedSaakshi ever ceases operation, every hospital receives at least 90 days' notice and a complete export of its data.
8. Your rights
Staff members and enquirers may ask what personal data we hold about them, ask for corrections, or ask for deletion where the law allows, by writing to the grievance officer below. Patients should contact their hospital, which is the Data Fiduciary for their records.
9. Breaches
If we become aware of a personal data breach affecting a hospital's records, we notify that hospital without undue delay and, where required, the Data Protection Board of India and the affected individuals.
10. Grievance officer
Dr. Ranadheer Cholaraju, MedSaakshi, Tirupati, Andhra Pradesh · [email protected]. We respond within 7 working days.