This Privacy Policy explains how Medplix.AI, a brand and product of Medplix AI Private Limited ("Medplix", "we", "us", or "our"), collects, uses, discloses, retains and safeguards information in connection with our website at https://medplix.ai, our cloud-based healthcare management platform, our Medplix Sales CRM, and all related applications, modules and services (collectively, the "Services"). It also explains our different roles under Indian data-protection law depending on whether we are handling business and website information as a fiduciary, or handling patient and clinical records on behalf of our customers as a processor.
Please read this Policy together with our Terms & Conditions and our Data Security Policy. By using the Services, you acknowledge the practices described here. If you do not agree with this Policy, please do not use the Services.
On this page
Introduction & scope Data we collect How we use data Legal bases under the DPDP Act Patient & clinical data — our role as processor Cookies & analytics Sharing & sub-processors Data retention Security Your rights under the DPDP Act Children & minors International / cross-border processing Grievance Officer & data contact Changes to this Policy How to contact us1. Introduction & scope
Medplix.AI provides cloud-based healthcare management software for hospitals, clinics, laboratories, diagnostic centres and pharmacies in India. Our Services include modules for OPD, IPD, ICU, OT, laboratory information (LIS), pharmacy, GST-ready billing, HR and payroll, owner dashboards and analytics, the Medplix Bazaar wholesale procurement marketplace, AI Connect (a secure, read-only, tenant-isolated connector that lets an organisation's authorised users query their own data through AI assistants such as Claude or ChatGPT), and the Medplix Sales CRM at crm.medplix.ai (which also powers the lead form embedded on our website).
This Policy covers two distinct categories of activity, which carry different responsibilities under Indian law:
- Data we handle as a Data Fiduciary (controller): business account and contact data, website and CRM lead data, billing data, and usage, log and device data. For this data we decide the purposes and means of processing, and this Policy governs how we do so.
- Data we handle as a Data Processor on behalf of our customers: patient, clinical, diagnostic and pharmacy records that a customer (a hospital, clinic, laboratory or pharmacy) enters into or generates within the platform. For this data, our customer is the Data Fiduciary and we process it only on that customer's documented instructions, as described in Section 5.
References in this Policy to Indian law include the Digital Personal Data Protection Act, 2023 (the "DPDP Act"); the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules"); and applicable GST, clinical-establishment, medical and pharmacy regulations. The Services are designed to work with, and are working towards compatibility with, the Ayushman Bharat Digital Mission (ABDM) / ABHA ecosystem where a customer chooses to use such features.
2. Data we collect
The categories of data we collect depend on how you interact with us.
Business / account & contact data. When an organisation subscribes to or is onboarded onto the Services, we collect the name and contact details of authorised representatives and users (such as owners, administrators, doctors and staff), the organisation's name, facility type, address, city, GSTIN and other registration details, and the credentials and role assignments needed to provision and administer accounts.
Website & CRM lead data. When you request a demo, submit an enquiry, or complete the lead form on our website or in the Medplix Sales CRM, we collect the information you provide — typically your name, phone number, email address, city, facility type (hospital, clinic, laboratory or pharmacy) and role — together with any message you send us. We may also collect follow-up communications you exchange with us by email, phone or WhatsApp.
Billing data. To set up and bill a subscription, we collect the details needed for invoicing and payment. Card and other payment-instrument details are handled by secure third-party payment gateways; we do not store full card numbers on our systems.
Usage, log and device data; cookies. When you visit our website or use the platform, we automatically collect basic technical information such as IP address, browser and device type, operating system, pages and features viewed, timestamps, and referring URLs. We also maintain application logs and audit trails of activity within the platform (for security, troubleshooting and accountability), and we use cookies and similar technologies as described in Section 6.
Patient & clinical data processed on behalf of customers. When our customers use the Services, they enter and generate patient, clinical, diagnostic, laboratory and pharmacy records — which may include health information and other sensitive personal data of patients. We store and process this data only as a processor on the customer's instructions. We do not decide the purposes for which this data is collected, and we do not use it for our own marketing or advertising. See Section 5.
3. How we use data
For data we handle as a fiduciary, we use it to:
- Provide and operate the Services — create and administer accounts, deliver the modules you subscribe to, and enable features you turn on (including AI Connect and the Medplix Sales CRM).
- Respond to enquiries and leads — contact you about a demo you requested, answer your questions, and follow up about the Services.
- Billing and administration — process subscriptions, generate GST-compliant invoices, collect payments and maintain business records.
- Support and communication — provide 24/7 support, send service and security notices, and, where you have consented, share relevant offers (you can opt out of marketing at any time).
- Improve and secure the Services — understand usage, diagnose problems, develop new features, and protect the platform against fraud, abuse and security incidents.
- Meet legal obligations — comply with applicable law, respond to lawful requests, and enforce our Terms.
We do not sell your personal data, and we do not use patient or clinical records processed on behalf of customers for advertising or for training AI models.
4. Legal bases under the DPDP Act
Where we act as a Data Fiduciary, we process personal data on the following bases recognised under the DPDP Act:
- Consent — for example, when you voluntarily submit your details through a demo request, lead form or enquiry, or when you opt in to receive marketing communications. Consent is sought for a specified purpose, and you may withdraw it at any time (withdrawal does not affect processing already carried out).
- Performance of contract and necessary services — to provision, deliver, bill and support the Services under our agreement with a subscribing organisation.
- Legitimate uses and legal obligations — as permitted under the DPDP Act and other applicable law, including maintaining security and audit records, preventing fraud or misuse, and complying with legal, tax and regulatory requirements.
Where we act as a Data Processor for patient and clinical data, the legal basis for that processing (including obtaining any patient consent required by law) is established and managed by our customer as the Data Fiduciary, and we process such data only in accordance with the customer's instructions and our agreement with them.
5. Patient & clinical data — our role as processor
When a hospital, clinic, laboratory or pharmacy uses Medplix.AI, that customer is the Data Fiduciary (owner and controller) of the patient, clinical, diagnostic and pharmacy records held in the platform. Medplix.AI acts as a Data Processor and processes such data only on the customer's documented instructions and to provide the Services.
- Tenant isolation. Each customer's data is logically separated and is accessible only to that customer's authorised users, subject to the role-based access controls the customer configures.
- Patient consent and rights. The customer is responsible for establishing a lawful basis for its collection and use of patient data, for obtaining any patient consents required by law, and for responding to requests from patients (data principals) to access, correct or erase their data. Where a customer needs our assistance to fulfil such a request, we will provide reasonable support consistent with our processor role.
- AI Connect. AI Connect is a secure, read-only, tenant-isolated connector. It exposes a given organisation's data only to that organisation's authorised users through the AI assistant they choose to connect (such as Claude or ChatGPT). It does not grant one customer access to another customer's data, and patient records are not used to train AI models.
- No secondary use. We do not sell patient or clinical data, do not use it for advertising, and do not process it for our own purposes beyond providing and securing the Services.
On termination of a customer's subscription, we handle return and deletion of customer data as described in Section 8 and in our agreement with the customer.
6. Cookies & analytics
Our website and platform use cookies and similar technologies. Essential cookies are needed for the site and the application to function (for example, to keep you signed in and to secure sessions). We may also use analytics cookies to understand how the website is used so we can improve it. You can control or disable cookies through your browser settings; disabling some cookies may affect how parts of the Services work. Where required by law, analytics that rely on your consent are used only after you provide it.
7. Sharing & sub-processors
We do not sell personal data. We share data only where necessary to deliver the Services, and with appropriate confidentiality and data-protection commitments in place. Categories of recipients (sub-processors and service providers) include:
- Cloud hosting and infrastructure providers — to host the platform, store data and run backups.
- Payment gateways — to process subscription payments securely (they handle payment-instrument details directly).
- Communication providers — SMS, email and WhatsApp providers used to send notifications, one-time passwords and service messages that you or our customers configure.
- AI Connect providers — the AI assistant provider a customer chooses to connect (such as Claude or ChatGPT), engaged only to deliver the read-only, tenant-isolated AI Connect feature at the customer's request.
We may also disclose data to legal and regulatory authorities where required by applicable law, regulation or valid legal process, and in connection with a merger, acquisition or business transfer, with notice where required by law. We engage sub-processors under contractual obligations to protect data and to process it only for the purposes we specify.
8. Data retention
We retain personal data only for as long as necessary for the purposes described in this Policy or as required by applicable law (including tax, accounting, clinical-establishment and other regulatory requirements). Website and CRM lead data is retained for as long as needed to respond to your enquiry and for related follow-up, unless you ask us to delete it earlier. Business, account and billing records are retained for the life of the relationship and for any period afterwards required by law.
For patient and clinical data processed on behalf of customers, retention is governed by the customer's instructions and applicable law. On termination of a subscription, the customer may request export of its data within a reasonable period, after which the data may be deleted from active systems in accordance with our agreement, subject to residual copies in routine backups that expire on a rolling basis.
9. Security
We apply reasonable security safeguards designed to protect data against unauthorised access, alteration, disclosure or destruction. These include encryption in transit (TLS) and at rest, automatic daily backups, role-based access control, full audit logs and trails, tenant isolation, 24/7 support and regular updates. Our practices are designed around and are working towards alignment with recognised information-security standards.
No method of transmission or storage can be guaranteed to be completely secure, and we do not promise that the Services will be free from every security risk. We do, however, work to protect data, limit access on a need-to-know basis, and respond to incidents responsibly. For a fuller description of our measures, please see our Data Security Policy.
10. Your rights under the DPDP Act
Subject to applicable law, and where Medplix.AI is the Data Fiduciary for your data, you (as a data principal) may:
- Access a summary of the personal data we hold about you and how it is processed.
- Correct or complete personal data that is inaccurate or incomplete, and update it.
- Erase personal data that is no longer required for the purpose it was collected, subject to legal retention requirements.
- Withdraw consent where processing is based on consent, and opt out of marketing communications.
- Grievance redressal — raise a concern about our handling of your data and receive a response (see Section 13).
- Nominate another individual to exercise your rights in the event of death or incapacity, as provided under the DPDP Act.
To exercise these rights, contact us using the details below. Where your data was entered into the platform by one of our customers, that customer is the Data Fiduciary and you should direct your request to them; we will support them as their processor.
11. Children & minors
Our website, CRM and business-facing Services are intended for businesses and their authorised representatives, and are not directed to children. Where we act as a fiduciary, we do not knowingly collect personal data of children (persons under 18) without verifiable parental or guardian consent as required by the DPDP Act. Where patient records processed on behalf of a customer relate to minors, the customer, as Data Fiduciary, is responsible for obtaining any consent of a parent or lawful guardian required by law.
12. International / cross-border processing
We primarily process and store data on infrastructure intended to serve customers in India. Some sub-processors or supporting services may process limited data outside India. Where this occurs, we do so in accordance with the DPDP Act and other applicable law, and we require appropriate contractual protections. AI Connect involves a customer's chosen AI assistant provider only for the read-only feature the customer enables, and only on that customer's instructions.
13. Grievance Officer & data contact
If you have any question, concern or complaint about how your personal data is handled, or wish to exercise your rights, you may contact our grievance contact for data matters. We will acknowledge and address grievances within the timelines required under applicable law.
- Grievance Officer: Mr. Saikrishna Bandaru, Medplix AI Private Limited
- Email: support@medplix.ai
- Grievance Officer direct: +91 95506 67759
- Support phone (call & WhatsApp): +91 95158 31777
- Alternate phone: +91 95408 89999
- Address: Medplix AI Private Limited, Innov8 Q Parc, Ghansoli/Rabale, Thane – 400701, Maharashtra, India
- CIN: U62013MR2026PTC477850
If your data was entered into the platform by one of our customers, please also contact that customer, who is the Data Fiduciary for such data.
14. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, technology or applicable law. The "Last updated" date at the top reflects the latest version. Where changes are material, we will take reasonable steps to notify you. Continued use of the Services after an update means you acknowledge the revised Policy.
15. How to contact us
For any privacy questions, requests or grievances relating to this Policy or your data:
- Email: support@medplix.ai
- Phone (call & WhatsApp): +91 95158 31777
- Alternate phone: +91 95408 89999
- Address: Medplix AI Private Limited, Innov8 Q Parc, Ghansoli/Rabale, Thane – 400701, Maharashtra, India
- CIN: U62013MR2026PTC477850
See also our Terms & Conditions and our Data Security Policy.