DPDPA + NMC aware by default

Security & privacy

Medslots handles patient data for Indian clinics. This page is the public summary of how we protect it. For compliance teams: email hello@medslots.com for our questionnaire and signed data-processing agreement.

What we do

Encryption everywhere

TLS 1.2+ in transit. Every patient data field AES-256-GCM encrypted at rest with a per-tenant key derived from a master key held in Vercel encrypted env vars. Database lives in Neon's AWS Singapore (ap-southeast-1) region.

Role-based access

Three clinic roles (admin / doctor / staff) plus a platform super-admin tier limited to billing. Admin actions require MFA.

Append-only audit log

Every read and write of patient data is recorded. Logs retained for 7 years, aligned with the longer of IT Rules 2011 SPDI reasonable-steps and state health-records legislation.

Tenant isolation

Every patient-data query is scoped to the requesting clinic's tenant context at the application layer before it reaches the database.

Patient rights built in

DPDPA s52 access export, DPDPA s53 correction workflow, STOP-keyword opt-out (TRAI DLT), and crypto-shred deletion are all first-class features. DPDPA Data Protection Board Notifiable Data Breach process documented.

DPDPA + NMC aware

Mapped to the DPDPA 2023 + DPDPA 2023 + IT Rules 2011 SPDI, the DPDPA Data Protection Board + CERT-In scheme, NMC Code §6.1 advertising rules, and the ASCI Code 2024 (No.3) 2021. The clinic remains the NMC-registered advertiser of record.

Regulatory framework

Privacy:The DPDPA 2023 and the IT Rules 2011 SPDI Rules govern how we collect, hold, use, and disclose personal information. Patient health information is “Sensitive Personal Data or Information” under the IT Rules 2011 and attracts the higher protections in DPDPA s5+s6 (collection) and DPDPA s7 (use & disclosure). The clinic is the data fiduciary for its patients; Medslots acts on the clinic’s behalf under a written agreement.

Security (IT Rules 2011 SPDI): We take “reasonable steps” — AES-256-GCM at rest with per-tenant key derivation, TLS 1.2+ in transit, role-based access with MFA on administrative actions, append- only audit logging, and encryption-at-rest via Neon AWS Singapore (ap-southeast-1).

Breach notification: The CERT-In Directions 2022 require reporting cyber security incidents to CERT-In within 6 hours of detection. Separately, under DPDPA 2023 we assess any suspected personal data breach and, where one is confirmed, notify the Data Protection Board and affected individuals without undue delay.

Cross-border (DPDPA s16): Patient data is hosted in AWS Singapore (ap-southeast-1) — a country not on the DPDPA s16 restricted list. A small set of operational metadata (Sentry error reports with PHI scrubbed via a beforeSend hook, Postmark/Resend transactional email metadata with no PHI in message bodies) is processed by US-based subprocessors. We disclose all subprocessor locations in the table below and remain accountable under DPDPA s16 for any act or practice of those overseas recipients.

Advertising (NMC + ASCI): NMC §6.1, the ASCI Code 2024, and (where applicable) the NMC clinical-claims rules (Dec 2023) govern what a healthcare advertiser may claim. The chatbot is configured to avoid testimonials about cosmetic procedures, comparative claims, outcome guarantees, and brand-name promotion of Schedule H drug list or Schedule X (controlled) drugs in consumer-facing copy.

State health legislation: The Karnataka Health Records and Information Privacy Act 2002 and equivalent state-level health-records provisions may additionally apply depending on where a clinic operates. DPDPA 2023 remains the national floor.

Subprocessors

The vendors below process or store patient data on our behalf. We have a signed data-processing agreement — or are actively obtaining one — with every vendor. Application + database live in AWS Singapore (ap-southeast-1).

VendorPurposeRegionDPA
Letex Media Co.Platform operator — staff access for support + operationsIndia (operator based in India; PHI hosted in AWS Singapore ap-southeast-1) Signed
VercelApplication hostingSingapore (sin1 / AWS ap-southeast-1) Signed
NeonPostgres database (patient data)AWS Singapore (ap-southeast-1) Signed
OpenAIAI chatbot + summarisation (chat completions)United States — zero-training API terms (no model fine-tuning on customer data) Signed
Meta WhatsApp BusinessPatient messaging (primary)Multi-region (Meta-controlled) In progress
PostmarkTransactional email (magic-links, receipts — metadata only, no PHI in body)United States Signed
ResendTransactional email (alerts — metadata only, no PHI in body)United States Signed
SentryError tracking (PII/PHI scrubbed via beforeSend hook)United States Signed

Reporting an issue

hello@medslots.com

Found a vulnerability or possible breach? Email us — we acknowledge within one business day and triage per the DPDPA Data Protection Board + CERT-In workflow.

Last updated 2026-09-04.