← Back to home

This Privacy Policy explains how Medplix.AI, a brand and product of Medplix AI Private Limited ("Medplix", "we", "us", or "our"), collects, uses, discloses, retains and safeguards information in connection with our website at https://medplix.ai, our cloud-based healthcare management platform, our Medplix Sales CRM, and all related applications, modules and services (collectively, the "Services"). It also explains our different roles under Indian data-protection law depending on whether we are handling business and website information as a fiduciary, or handling patient and clinical records on behalf of our customers as a processor.

Please read this Policy together with our Terms & Conditions and our Data Security Policy. By using the Services, you acknowledge the practices described here. If you do not agree with this Policy, please do not use the Services.

1. Introduction & scope

Medplix.AI provides cloud-based healthcare management software for hospitals, clinics, laboratories, diagnostic centres and pharmacies in India. Our Services include modules for OPD, IPD, ICU, OT, laboratory information (LIS), pharmacy, GST-ready billing, HR and payroll, owner dashboards and analytics, the Medplix Bazaar wholesale procurement marketplace, AI Connect (a secure, read-only, tenant-isolated connector that lets an organisation's authorised users query their own data through AI assistants such as Claude or ChatGPT), and the Medplix Sales CRM at crm.medplix.ai (which also powers the lead form embedded on our website).

This Policy covers two distinct categories of activity, which carry different responsibilities under Indian law:

References in this Policy to Indian law include the Digital Personal Data Protection Act, 2023 (the "DPDP Act"); the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules"); and applicable GST, clinical-establishment, medical and pharmacy regulations. The Services are designed to work with, and are working towards compatibility with, the Ayushman Bharat Digital Mission (ABDM) / ABHA ecosystem where a customer chooses to use such features.

2. Data we collect

The categories of data we collect depend on how you interact with us.

Business / account & contact data. When an organisation subscribes to or is onboarded onto the Services, we collect the name and contact details of authorised representatives and users (such as owners, administrators, doctors and staff), the organisation's name, facility type, address, city, GSTIN and other registration details, and the credentials and role assignments needed to provision and administer accounts.

Website & CRM lead data. When you request a demo, submit an enquiry, or complete the lead form on our website or in the Medplix Sales CRM, we collect the information you provide — typically your name, phone number, email address, city, facility type (hospital, clinic, laboratory or pharmacy) and role — together with any message you send us. We may also collect follow-up communications you exchange with us by email, phone or WhatsApp.

Billing data. To set up and bill a subscription, we collect the details needed for invoicing and payment. Card and other payment-instrument details are handled by secure third-party payment gateways; we do not store full card numbers on our systems.

Usage, log and device data; cookies. When you visit our website or use the platform, we automatically collect basic technical information such as IP address, browser and device type, operating system, pages and features viewed, timestamps, and referring URLs. We also maintain application logs and audit trails of activity within the platform (for security, troubleshooting and accountability), and we use cookies and similar technologies as described in Section 6.

Patient & clinical data processed on behalf of customers. When our customers use the Services, they enter and generate patient, clinical, diagnostic, laboratory and pharmacy records — which may include health information and other sensitive personal data of patients. We store and process this data only as a processor on the customer's instructions. We do not decide the purposes for which this data is collected, and we do not use it for our own marketing or advertising. See Section 5.

3. How we use data

For data we handle as a fiduciary, we use it to:

We do not sell your personal data, and we do not use patient or clinical records processed on behalf of customers for advertising or for training AI models.

Where we act as a Data Fiduciary, we process personal data on the following bases recognised under the DPDP Act:

Where we act as a Data Processor for patient and clinical data, the legal basis for that processing (including obtaining any patient consent required by law) is established and managed by our customer as the Data Fiduciary, and we process such data only in accordance with the customer's instructions and our agreement with them.

5. Patient & clinical data — our role as processor

When a hospital, clinic, laboratory or pharmacy uses Medplix.AI, that customer is the Data Fiduciary (owner and controller) of the patient, clinical, diagnostic and pharmacy records held in the platform. Medplix.AI acts as a Data Processor and processes such data only on the customer's documented instructions and to provide the Services.

On termination of a customer's subscription, we handle return and deletion of customer data as described in Section 8 and in our agreement with the customer.

6. Cookies & analytics

Our website and platform use cookies and similar technologies. Essential cookies are needed for the site and the application to function (for example, to keep you signed in and to secure sessions). We may also use analytics cookies to understand how the website is used so we can improve it. You can control or disable cookies through your browser settings; disabling some cookies may affect how parts of the Services work. Where required by law, analytics that rely on your consent are used only after you provide it.

7. Sharing & sub-processors

We do not sell personal data. We share data only where necessary to deliver the Services, and with appropriate confidentiality and data-protection commitments in place. Categories of recipients (sub-processors and service providers) include:

We may also disclose data to legal and regulatory authorities where required by applicable law, regulation or valid legal process, and in connection with a merger, acquisition or business transfer, with notice where required by law. We engage sub-processors under contractual obligations to protect data and to process it only for the purposes we specify.

8. Data retention

We retain personal data only for as long as necessary for the purposes described in this Policy or as required by applicable law (including tax, accounting, clinical-establishment and other regulatory requirements). Website and CRM lead data is retained for as long as needed to respond to your enquiry and for related follow-up, unless you ask us to delete it earlier. Business, account and billing records are retained for the life of the relationship and for any period afterwards required by law.

For patient and clinical data processed on behalf of customers, retention is governed by the customer's instructions and applicable law. On termination of a subscription, the customer may request export of its data within a reasonable period, after which the data may be deleted from active systems in accordance with our agreement, subject to residual copies in routine backups that expire on a rolling basis.

9. Security

We apply reasonable security safeguards designed to protect data against unauthorised access, alteration, disclosure or destruction. These include encryption in transit (TLS) and at rest, automatic daily backups, role-based access control, full audit logs and trails, tenant isolation, 24/7 support and regular updates. Our practices are designed around and are working towards alignment with recognised information-security standards.

No method of transmission or storage can be guaranteed to be completely secure, and we do not promise that the Services will be free from every security risk. We do, however, work to protect data, limit access on a need-to-know basis, and respond to incidents responsibly. For a fuller description of our measures, please see our Data Security Policy.

10. Your rights under the DPDP Act

Subject to applicable law, and where Medplix.AI is the Data Fiduciary for your data, you (as a data principal) may:

To exercise these rights, contact us using the details below. Where your data was entered into the platform by one of our customers, that customer is the Data Fiduciary and you should direct your request to them; we will support them as their processor.

11. Children & minors

Our website, CRM and business-facing Services are intended for businesses and their authorised representatives, and are not directed to children. Where we act as a fiduciary, we do not knowingly collect personal data of children (persons under 18) without verifiable parental or guardian consent as required by the DPDP Act. Where patient records processed on behalf of a customer relate to minors, the customer, as Data Fiduciary, is responsible for obtaining any consent of a parent or lawful guardian required by law.

12. International / cross-border processing

We primarily process and store data on infrastructure intended to serve customers in India. Some sub-processors or supporting services may process limited data outside India. Where this occurs, we do so in accordance with the DPDP Act and other applicable law, and we require appropriate contractual protections. AI Connect involves a customer's chosen AI assistant provider only for the read-only feature the customer enables, and only on that customer's instructions.

13. Grievance Officer & data contact

If you have any question, concern or complaint about how your personal data is handled, or wish to exercise your rights, you may contact our grievance contact for data matters. We will acknowledge and address grievances within the timelines required under applicable law.

If your data was entered into the platform by one of our customers, please also contact that customer, who is the Data Fiduciary for such data.

14. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, technology or applicable law. The "Last updated" date at the top reflects the latest version. Where changes are material, we will take reasonable steps to notify you. Continued use of the Services after an update means you acknowledge the revised Policy.

15. How to contact us

For any privacy questions, requests or grievances relating to this Policy or your data:

See also our Terms & Conditions and our Data Security Policy.