1Who We Are
- Elena Digital Pvt. Ltd.
- Registered Address: [REGISTERED ADDRESS]
- Email: [GENERAL EMAIL]
- Privacy Contact: [PRIVACY CONTACT NAME/ROLE]
- Privacy Email: [PRIVACY EMAIL]
- Phone: [PHONE NUMBER]
For applicable data-protection purposes, our role may differ depending on the data and processing activity. We may determine the purposes and means of processing certain information ourselves and may process information on behalf of a doctor or healthcare organisation under applicable contractual arrangements.
Where applicable, we will comply with the obligations imposed on us under applicable data-protection laws.
2Information We Collect
Depending on how you use the Application, we may collect the following categories of information.
2.1 Doctor Account Information
When a doctor registers, we may collect:
- First name and last name;
- Mobile number;
- Email address, if provided;
- Country;
- Referral code, if applicable;
- Password or authentication information;
- OTP verification information;
- Profile photograph, if provided;
- Account preferences; and
- Login/session and security information.
Mobile verification is mandatory during doctor registration; an email address is optional.
2.2 Patient Information
Doctors may enter patient information into the Application, including:
- First name and last name;
- Mobile number;
- Email address, if provided;
- Age;
- Gender;
- Fever/temperature;
- Blood pressure;
- Patient ID;
- Visit information;
- Prescription information;
- Medicine information;
- Dosage and frequency;
- Duration;
- Prescription instructions and notes; and
- Amount charged.
A mobile number may be shared by multiple patient records, including family members. The Application therefore treats the patient record/Patient ID separately from the mobile number.
3Prescription and Medical Information
The Application may process information contained in prescriptions and related medical records.
This may include:
- Medicines;
- Potency;
- Dosage;
- Form;
- Frequency;
- Duration;
- Prescription instructions;
- Clinical notes entered by the doctor;
- Vitals such as fever and blood pressure;
- Prescription history; and
- Images of physical prescriptions.
This information is processed to provide the patient-management and prescription-management functionality of the Application.
4Prescription Images and Camera Data
The Application may allow doctors to capture or upload photographs of existing physical prescriptions.
Where this feature is used:
- The Application may request access to the device camera;
- The doctor may select an image from the device gallery;
- The image may be cropped or rotated;
- The resulting image may be stored with the relevant patient prescription record.
We do not access your camera or gallery continuously. Access is requested when required for an applicable feature and subject to the permissions provided through your device.
5Compounder Information
A doctor may create an account for an authorised compounder.
We may collect:
- Compounder's name;
- Mobile number;
- Email address, if provided;
- Login/OTP information;
- Account status; and
- Access and security information.
The compounder receives restricted access and does not receive the same information available to the doctor. Compounder access is restricted to the information necessary for dispensing, such as patient name, prescribed medicine, potency and served/not-served status.
6Device and Technical Information
When you access the Application, we may automatically collect certain technical information, where necessary for operation, security and troubleshooting, such as:
- IP address;
- Device type;
- Operating system;
- Browser type;
- Application version;
- Device identifiers, where applicable;
- Login timestamps;
- Session information;
- Error logs;
- Security events; and
- Other technical information necessary to operate and secure the Application.
The Application may display the app version/build number for troubleshooting purposes.
7How We Use Personal Information
We may process personal information for purposes including:
Account and Authentication
- Creating and maintaining accounts;
- Verifying mobile numbers;
- Sending OTPs;
- Authenticating users;
- Password recovery;
- Preventing unauthorised access; and
- Managing login sessions.
Patient and Prescription Management
- Creating patient records;
- Maintaining prescription records;
- Displaying prescription history;
- Uploading and storing prescription images;
- Searching patient records; and
- Providing medicine auto-suggestion functionality.
Compounder Management
- Creating and managing authorised compounder accounts;
- Providing role-based access;
- Tracking access and account status; and
- Revoking access when required.
Service and Support
- Responding to support requests;
- Troubleshooting technical problems;
- Sending service-related communications;
- Maintaining application performance; and
- Improving reliability and security.
Security and Compliance
- Detecting fraud and unauthorised activity;
- Protecting user and patient information;
- Maintaining appropriate audit/security records;
- Investigating security incidents; and
- Complying with applicable legal obligations.
8Legal Basis / Consent
Where required by applicable law, we will process personal information based on appropriate legal grounds, including consent or another lawful basis available under applicable law.
Where processing is based on consent, you may withdraw consent through the mechanism made available by us, subject to legal and operational limitations.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
The DPDP Rules, 2025 require notices to clearly explain the personal data being processed and the specific purposes for processing, and provide mechanisms for withdrawal of consent and exercise of rights.
9Patient Data Entered by Doctors
Doctors may enter patient information into the Application as part of providing healthcare services.
The doctor remains responsible for ensuring that patient information is collected and processed lawfully and that any required patient notice, consent or other authorisation is obtained.
Where the doctor uses the Application on behalf of a clinic, hospital or other healthcare organisation, the relevant organisation may have additional responsibilities under applicable law and contractual arrangements.
We do not require patients to create an Application account merely because their information is entered by a doctor.
10Use of WhatsApp, SMS and Email
We may use third-party communication providers to send:
- OTPs;
- Login verification messages;
- Password recovery communications;
- Security alerts;
- Service notifications;
- Support communications; and
- Promotional communications where legally permitted and appropriately authorised.
If you opt in to promotional WhatsApp, SMS or email communications, you may withdraw that preference using the available unsubscribe or notification-control mechanism.
Essential service and security communications may still be sent where necessary.
11Sharing of Personal Information
We do not sell personal information as a standalone product.
We may share or provide access to information where reasonably necessary with:
Service Providers
Technology providers supporting:
- Cloud hosting;
- Database infrastructure;
- Authentication;
- SMS/OTP delivery;
- WhatsApp messaging;
- Email delivery;
- Security;
- Monitoring;
- Customer support; and
- Other infrastructure necessary to provide the Application.
Authorised Users
Information may be accessible to the doctor who manages the relevant patient record and to authorised compounders/staff only to the extent permitted by their assigned role.
Legal and Regulatory Authorities
We may disclose information where required by applicable law, legal process, court order, governmental authority or other lawful request.
Business Transactions
Information may be transferred as part of a merger, acquisition, restructuring, financing, sale of assets or similar transaction, subject to applicable law and appropriate safeguards.
12Role-Based Access
We use role-based access controls to limit the information available to different users.
Doctors may access patient and prescription information associated with their records.
Compounders receive restricted access. Under the current Application requirements, compounders cannot access full prescription notes, patient contact information, vitals or billing/amount information.
We may modify access controls as the Application evolves, provided that applicable privacy and security requirements continue to be addressed.
13Data Security
We implement reasonable technical and organisational security measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction.
These measures may include:
- Encryption in transit;
- Encryption at rest;
- Role-based access controls;
- Authentication and OTP verification;
- Access restrictions;
- Security monitoring;
- Secure session management;
- Backup and recovery controls;
- Security testing and maintenance; and
- Audit/security logs.
The Application is required to encrypt patient data and prescriptions in transit and at rest, and to give each role only the access to patient records appropriate to it.
No digital system can guarantee absolute security. Users must also protect their passwords, OTPs, devices and account access.
14Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, to provide the services, to maintain appropriate records, to resolve disputes, to enforce agreements, to maintain security, or to comply with applicable legal obligations.
Retention periods may vary depending on:
- The type of information;
- Whether the account remains active;
- The nature of the healthcare record;
- Legal or regulatory requirements;
- Security and fraud-prevention requirements;
- Dispute resolution; and
- Backup and disaster-recovery requirements.
When information is no longer required, we may delete, anonymise or otherwise securely dispose of it, subject to applicable law and legitimate retention requirements.
15Data Transfers
Personal information may be processed or stored using service providers located in India or other jurisdictions, subject to applicable law.
Where personal information is transferred across jurisdictions, we will implement applicable contractual, technical and organisational safeguards as required by law.
16Children's Data
The Application is intended primarily for healthcare professionals and authorised staff.
Patient records may nevertheless relate to children.
Where personal information relating to a child is processed, we will apply the requirements applicable to children’s personal data under relevant data-protection laws.
Doctors and other users must not knowingly use the Application to circumvent applicable requirements relating to children or parental/guardian consent.
17Your Privacy Rights
Subject to applicable law, individuals may have rights relating to their personal information, including rights to:
- Obtain information about processing;
- Request access to personal information;
- Request correction of inaccurate information;
- Request deletion/erasure where applicable;
- Withdraw consent where processing is based on consent;
- Raise grievances;
- Nominate another person to exercise applicable rights in certain circumstances; and
- Exercise other rights provided by applicable data-protection law.
The availability and scope of these rights may depend on the applicable law and the role of the relevant party in the processing.
18How to Exercise Privacy Rights
To submit a privacy request, contact:
- Privacy / Grievance Contact: [PRIVACY CONTACT NAME/ROLE]
- Email: [PRIVACY EMAIL]
- Address: [REGISTERED ADDRESS]
- Phone: [PHONE NUMBER]
Please include sufficient information for us to identify the relevant account or request.
We may request reasonable information to verify your identity before processing a request.
We will respond within the period required by applicable law.
19Complaints and Grievances
If you have a privacy-related complaint or believe your personal information has been processed improperly, you may contact our designated privacy/grievance contact at:
- [GRIEVANCE OFFICER / PRIVACY CONTACT]
- Email: [GRIEVANCE EMAIL]
- Phone: [PHONE NUMBER]
- Address: [REGISTERED ADDRESS]
If applicable law provides a right to escalate a complaint to a regulatory authority or the Data Protection Board of India, you may exercise that right in accordance with the applicable procedure.
20Cookies and Similar Technologies
The web version of the Application may use cookies or similar technologies necessary for:
- Authentication;
- Session management;
- Security;
- Preferences;
- Performance monitoring; and
- Other functionality.
Where non-essential cookies or similar technologies are used, appropriate consent or controls will be provided where required by applicable law.
21Analytics
If analytics or product-performance tools are used, they may collect technical or usage information such as:
- Pages/screens accessed;
- Feature usage;
- Device information;
- Application performance;
- Error information; and
- General usage patterns.
Analytics should not be used to access or disclose patient medical information beyond what is necessary and legally permitted for the stated purpose.
22Third-Party Services
The Application may integrate with third-party services such as WhatsApp, SMS providers, email providers, cloud infrastructure providers, authentication services and other technology providers.
Those providers may process information according to their own terms and privacy policies.
Where appropriate, users will be provided with relevant information about such third-party processing.
23Data Breach and Security Incidents
If we become aware of a personal-data breach affecting information processed through the Application, we will assess and respond to the incident in accordance with applicable law.
Where notification to affected individuals, authorities or other parties is legally required, we will provide the required notification within the applicable timeframe.
24Account Closure
A doctor may request closure of their account by contacting [SUPPORT EMAIL].
Account closure does not necessarily result in immediate deletion of every record.
Certain information may need to be retained for legal, regulatory, security, dispute-resolution, contractual or other lawful purposes.
Where deletion is appropriate, information will be deleted or anonymised subject to applicable retention requirements.
25Changes to This Privacy Policy
We may update this Privacy Policy when our services, data-processing practices, technology or legal obligations change.
When material changes are made, we will provide appropriate notice through the Application, website, email or another reasonable method.
The "Last Updated" date at the top of this Privacy Policy indicates when it was most recently revised.
26Contact Us
For general questions about this Privacy Policy:
- Elena Digital Pvt. Ltd.
- Address: [REGISTERED ADDRESS]
- Email: [PRIVACY EMAIL]
- Phone: [PHONE NUMBER]
- Website: [WEBSITE]
For privacy requests and complaints:
- Privacy / Grievance Contact: [PRIVACY CONTACT NAME/ROLE]
- Email: [GRIEVANCE EMAIL]
27Acknowledgement
By using the Application, you acknowledge that you have had an opportunity to review this Privacy Policy.
Where consent is required for a particular processing activity, the Application will seek the relevant consent through an appropriate mechanism.