DPDPA 2023 · DPDPA 2023 + IT Rules 2011 SPDI · DPDPA Data Protection Board + CERT-In

Privacy policy

Version v3.0-2026-05-14-AU · Effective 14 May 2026

1. Who we are (DPDPA s5 — open and transparent management)

Medslots is operated by the company behind it (the “we”, “us”) — a managed marketing & patient-acquisition service for Indian healthcare clinics. We use a SaaS platform we built ourselves to handle WhatsApp patient enquiries on the clinic’s behalf. The platform is bundled with our service and is not sold separately.

Under the DPDPA 2023 and the DPDPA + SPDI Rules Principles, the clinic is the data fiduciary for its patients and Medslots acts on the clinic’s behalf under a written data-processing agreement. Health information is “sensitive information” under s6 of the Act and attracts the higher protections in DPDPA s5+s6 (collection) and DPDPA s7 (use & disclosure). Our application and patient database run in AWS Mumbai (ap-south-1). AI inference runs on the OpenAI API(api.openai.com) under OpenAI’s standard API terms, which prohibit model training on data submitted via the API (zero-training default since March 2023).

Platform operator disclosure (DPDPA s16): Medslots is operated by Letex Media Co., an Indian-registered company. Although your patient data is stored in AWS Mumbai (Indian data residency), platform staff in India have read access to support, troubleshoot, and operate the service. Under DPDPA s16.1 the clinic remains accountable for this overseas disclosure; we take reasonable steps under DPDPA s16.2 (binding employee agreements, role-based access, AES-256-GCM encryption at rest, audit logs) to ensure the recipient does not breach the APPs. OpenAI processes inference requests on US infrastructure under the same DPDPA s16 framing.

This notice is DPDPA s5 transparency information. You can request a printable copy from hello@medslots.com.

2. What we collect (DPDPA s5+s6 — collection of solicited personal information)

  • From clinics: business identity (GSTIN, GST status, NMC registration numbers for the principal practitioner, addresses, business hours), billing details, the clinic’s WhatsApp Business credentials.
  • From patients enquiring through a clinic’s WhatsApp: name, mobile number, locality/PIN code, the message content of the conversation, click-to-WhatsApp ad attribution metadata if the conversation came from a Meta ad. Phone numbers are AES-256-GCM encrypted at rest and additionally hashed (SHA-256) so opt-out lookups never decrypt.
  • What we deliberately do not collect: medical history, diagnoses, symptoms, conditions, treatment plans, ABHA (Ayushman Bharat Health Account) numbers or ABHA addresses, Health Professional Registry (HPR) or Health Facility Registry (HFR) IDs, Ayushman Bharat PM-JAY card numbers, government or private health-insurance numbers (unless a patient volunteers them — see below).

Collection is lawful and fair, and only by lawful and fair means, in accordance with DPDPA s6. Health information is collected only where reasonably necessary for the clinic to deliver health services and where consent has been provided under DPDPA s6.

3. Notification of collection (DPDPA s5)

Whenever we collect personal information, we take reasonable steps to notify the individual at or before collection (DPDPA s5). At the point of WhatsApp opt-in or lead-form submission, patients see: the clinic’s identity, the fact that Medslots is acting on the clinic’s behalf, the purposes of collection, the consequences of not providing the information, this Privacy Policy URL, and how to access & correct the information.

4. Voluntary disclosures

The bot will never ask a patient to share medical information. If a patient nevertheless volunteers it (“my back has been hurting for two weeks”), the bot will redirect: “Got it, I’ll flag this for the practitioner — they’ll go through it with you at the visit.”

Conversations that contain a voluntary disclosure are flaggedcontains_voluntary_disclosure = trueand follow a tighter retention schedule (see below).

The Medslots bot is a booking assistant — it never gives clinical advice. When a patient asks a clinical question, the bot redirects to the NMC-registered practitioner at the clinic.

5. Use and disclosure (DPDPA s7)

We use and disclose personal information only for the primary purpose it was collected — running marketing campaigns, qualifying enquiries, booking appointments, sending reminders, and reporting to the clinic. We do not use it for any secondary purpose unless we have your consent, the secondary purpose is directly related and within your reasonable expectations, or another DPDPA s7.2 exception applies. We never sell or rent personal information.

6. Direct marketing (DPDPA s7 + TRAI DLT)

We use personal information for direct marketing only with consent, in line with DPDPA s7 and the TRAI DLT (Cth). Every commercial electronic message identifies the sender, includes accurate sender information, and provides a functional unsubscribe (one click, or reply “STOP”). Withdrawal is processed within five business days and acknowledged immediately.

7. Cross-border disclosure (DPDPA s16)

Patient data is stored in India (AWS Mumbai ap-south-1). Three classes of cross-border disclosure apply, each enumerated so the clinic can satisfy its DPDPA s5 notification obligation downstream:

  • Platform operator (India) — Letex Media Co., the Indian-registered company that operates Medslots, has staff in India with role-based read access for support and operations. Access is logged, MFA-gated, and governed by binding employee confidentiality terms.
  • OpenAI (United States)— chat-completion inference for the WhatsApp AI bot and inbox summaries. Submitted via OpenAI’s API which carries a zero-training commitment (no model fine-tuning on customer data). 30-day abuse-monitoring retention applies by default; Zero-Data-Retention is requested where offered.
  • Operational metadata only (US-based) — Sentry error reports (PHI scrubbed at the SDK layer via a beforeSend hook) and Postmark / Resend transactional email metadata (no PHI in message bodies).

We remain accountable under DPDPA s16.1 for any act or practice of these overseas recipients and impose contractual obligations equivalent to the APPs in our written DPAs.

8. Security (IT Rules 2011 SPDI) + retention

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure (IT Rules 2011 SPDI.1). Specifically: AES-256-GCM at rest with per-tenant key derivation, TLS 1.2+ in transit, role-based access with MFA on administrative actions, append-only audit logging, Indian data residency, and Postgres row-level security for tenant isolation.

Retention (IT Rules 2011 SPDI.2):

  • Logistics-only conversations (no voluntary disclosure): chat messages are hard-deleted 90 days after the last activity. The lead record is anonymised and retained for business analytics only.
  • Conversations with a voluntary disclosure: chat messages and the disclosure excerpt are hard-deleted 7 days after the booking is marked “complete” or “no-show”.
  • Audit logsare retained for the longer of: 7 years (IT Rules 2011 SPDI reasonable-steps baseline + a conservative read of state health-records retention requirements such as the Karnataka HRIP Act 2002 and equivalent state provisions) or whatever the clinic’s applicable medical-records retention period requires.

9. Access (DPDPA s52)

You can request a copy of any personal information we hold about you (DPDPA s52). Email hello@medslots.com from the address we have on file. We respond within 30 days at no cost for routine requests. We may refuse access only on a ground in DPDPA s52.3 and will give written reasons. The clinic /dashboard/patients/[id] page offers a one-click JSON export that satisfies the access right.

10. Correction (DPDPA s53)

If you believe the information we hold about you is inaccurate, out-of-date, incomplete, irrelevant, or misleading, you can ask us to correct it under DPDPA s53. We respond within 30 days. If we refuse, we provide written reasons. We will also take reasonable steps to notify any data fiduciary to whom the incorrect information was disclosed (DPDPA s53.3).

You can also withdraw consent at any time by replying “STOP” to any clinic WhatsApp message. Withdrawal doesn’t affect prior lawful processing.

11. Notifiable Data Breaches (DPDPA Data Protection Board + CERT-In scheme)

If a suspected eligible data breach occurs, we assess within 30 days (Privacy Act Part IIIC). If we determine an eligible breach has occurred — that is, unauthorised access, disclosure or loss of personal information likely to result in serious harm where remediation cannot prevent it — we notify the DPDPA Data Protection Board and affected individuals “as soon as practicable” with the statement prescribed by s26WK. Our breach SOP is documented internally and our primary breach contact is named in our DPA.

12. Subprocessors

Full live list at /security. Application + database live in AWS Mumbai (ap-south-1). AI inference runs on the OpenAI API (United States) under OpenAI’s zero-training API terms. Email + error-tracking use US-region providers; no patient health information is sent in email bodies, and Sentry receives only scrubbed metadata. Platform staff in India (Letex Media Co.) operate the service.

13. Complaints

If you have a privacy concern, contact us first at hello@medslots.com. We acknowledge within 5 business days and aim to resolve within 30 days. If your complaint isn’t resolved by us, you can escalate to the Data Protection Board of India Information Commissioner (DPDPA Data Protection Board) at dpdpa.dpb.gov.in.

14. Contact

Privacy contact
Medslots Privacy Officer
hello@medslots.com (planned address — currently routes to hello@medslots.com)
Response within 30 days, per DPDPA s52.4 + DPDPA s53.4.

Updates: any substantive change bumps the version at the top and is announced via the dashboard banner 14 days before it takes effect.