Legal
Privacy policy
Effective 5 September 2026. Written to be read, not skimmed: what we hold, where, why, for how long, and what you can ask of us.
1. Who is responsible
Kliniqo is provided by Priyam Rupapara, trading as Kliniqo, Rajkot, Gujarat, India. Two situations arise:
- A laboratory's patients and doctors. The laboratory that registered you is the data fiduciary under the Digital Personal Data Protection Act, 2023: it decides what is collected and why. We are its data processor, acting on its instructions. Questions about your own record go first to your laboratory; its number is on your receipt and report.
- Laboratory staff, owners and visitors to this website. For your account details and for this website, we are the data fiduciary.
2. What is collected
About patients, entered by the laboratory or its instruments
- Identity and contact: name, sex, date of birth or age, mobile number, address, the doctor who referred you.
- Clinical: the tests ordered, samples, results, reports and their versions, critical-value calls, quality-control context.
- Money: bills, payments, refunds and dues with the laboratory.
- Consent: whether, when, where and to what wording you agreed to WhatsApp messages or to sharing a report.
- Portal use: sign-ins by mobile number and date of birth, which reports were opened, links shared and opened — each written to the laboratory's audit trail with your number masked.
About laboratory staff and doctors
- Name, email address, mobile number, role and permissions, password hash, optional authenticator secret, sign-in times and failures.
- Every clinical change made under your account, with the time — this is the audit trail the laboratory relies on.
About visitors to this website
- Server logs: the address a request came from, the page, the time. No advertising cookies, no third-party analytics.
3. Why it is used
- To run the laboratory's day: registering, billing, testing, verifying and releasing reports.
- To tell patients and doctors a report is ready, on WhatsApp, when the laboratory has recorded consent.
- To let a patient read their own and their family's reports, and to let a doctor see their own referrals.
- To keep the audit trail a laboratory needs for accreditation and the law.
- To keep the Service secure: rate limits, lockouts, the record of every attempt to sign in.
We do not sell personal data, profile people for advertising, or use patient data to train anything.
4. Where it is stored, and who else touches it
The database runs in Mumbai, India, and every laboratory's rows are isolated from every other's at the database level. The application runs on servers in India where the provider offers them. Our sub-processors, each under its own contract and security programme:
- Supabase — the PostgreSQL database, Mumbai region.
- Vercel — the application servers and network.
- Cloudflare — DNS, and file storage for report PDFs and images.
- Meta Platforms — WhatsApp messages, sent from the laboratory's own number under the laboratory's own Meta account; Meta's privacy terms apply to the delivery of the message.
No message carries clinical content: it says a report is ready and gives a link. The values live behind the sign-in.
5. How long it is kept
- Clinical records are kept for as long as the laboratory subscribes, and for ninety days after, so it can export them; the laboratory may be required by law to keep them longer and does so in its own copies.
- Audit trails are never edited or deleted while the laboratory's account exists.
- Sign-in and rate-limit records are cleared automatically within days.
- Server logs are kept for the period the law requires and then deleted.
6. Your rights
Under the DPDP Act you may ask to:
- See what is held about you. A patient can download everything the laboratory holds under their number from the portal in one click; the download is recorded in the laboratory's audit trail.
- Correct it. Ask the laboratory; the change is made at the counter and recorded.
- Erase it. A request is recorded and decided by the laboratory's owner. Approval removes your contact details; the clinical record itself is kept, because a medical record without a name is not a medical record and the law may require it to be produced.
- Withdraw consent to WhatsApp messages or to sharing at any time, from the portal or at the counter.
- Complain. To the laboratory first, then to us, then to the Data Protection Board of India.
7. Security
- Every connection is encrypted; every password is hashed; a laboratory's WhatsApp credentials are sealed at rest.
- Row-level security in the database means a laboratory can read only its own rows, whatever the application does.
- Repeated failed sign-ins lock the account or the number; staff may add an authenticator; sessions end when a password or a role changes.
- Every time we look inside a laboratory to help it, that is written to the laboratory's own access log, which its owner can read.
- If a breach affects you, we will tell the laboratory, and the laboratory will tell you and the Data Protection Board, as the Act requires.
8. Cookies
The Service sets only the cookies it needs to keep you signed in and to remember a preview you asked for. They are set to be sent to the site that set them and to nothing else. This website sets none for tracking.
9. Children
A child's tests are registered by a parent or guardian, who is the account holder for the mobile number, and who exercises the rights above on the child's behalf.
10. Changes
We will post changes here with a new effective date and tell laboratories inside the Service.
11. Contact and grievance
The person who answers questions about this policy and hears grievances is reached through the contact page or at rupaparapriyam@gmail.com. We answer within the time the Act requires.