On this page
Who we are
MediGent Technologies LLP ("Medigent", "we", "us") operates the Medigent platform at medigent.in, app.medigent.in, me.medigent.in and the Medigent mobile apps. This policy explains, in plain language, what personal and health data we collect, how we use and protect it, and the rights you have over it.
It follows India’s Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and the SPDI Rules, 2011, and applicable ABDM / MoHFW health-data standards.
The two ways we handle data
Medigent handles data in two distinct roles, and which one applies decides who is answerable for what.
Information we collect
- Account and identity — name, email, phone, clinic name, and KYC or registration documents where required.
- Health and clinical data — appointments, prescriptions, medical records (stored in the open FHIR R4 standard), vitals, medication logs and food logs.
- Voice and communications — recordings and transcripts of AI-receptionist calls, WhatsApp and chat messages, and support emails.
- Payment data — plan, wallet and transaction records. Card and UPI details are handled by our payment partners and are not stored by us.
- Technical data — device, browser, IP address, cookies and usage logs.
How we use your data
- Operate the AI receptionist, the EHR, reminders and the patient app.
- Process bookings, and send appointment reminders and follow-ups.
- Take payments and manage wallets and subscriptions.
- Provide AI features — answering calls, transcription, prescription reading — through our service providers.
- Keep the platform secure and prevent fraud and abuse.
- Comply with law and respond to lawful requests.
- Support you and improve reliability.
We do not sell your personal data, and we do not use patient health data for advertising.
Consent and legal basis
We process personal data with your consent and for the legitimate uses permitted under the DPDP Act — for example, to deliver a service you have asked for.
For clinic patient records, the clinic obtains and manages the patient’s consent, and Medigent provides consent-capture tools (such as the in-app User Consent Policy) to help. You can withdraw consent at any time, though some features may then stop working.
AI and automated processing
Delivering the AI receptionist means voice and text are processed by AI service providers — for speech-to-text, text-to-speech and language understanding — and by our cloud provider. These providers act under contract and confidentiality obligations, and process the data only to deliver the Medigent service.
Medigent does not make final clinical decisions. A person at the clinic confirms bookings and reviews records.
Who we share data with
- The patient’s own clinic, for patient data.
- Service providers under contract — cloud hosting (AWS), telephony (Plivo), payments (PayU, Stripe), messaging (WhatsApp Business) and the AI providers that power voice and text.
- Auditors, advisers and authorities where required by law.
- A successor entity in a merger or acquisition, under the same protections.
We never sell personal data.
Where your data is stored and how it is secured
Data is hosted on Amazon Web Services on ISO 27001 / SOC 2 certified infrastructure in India (AWS Asia Pacific — Mumbai). It is encrypted in transit and at rest, isolated per clinic and per patient, and access is restricted and logged.
Health data is handled to HIPAA safeguards under a Business Associate Addendum where applicable. Medical records are portable and exportable in the open FHIR R4 standard.
How long we keep it
We keep personal data for as long as your account is active and as long as needed for the purposes above, or to meet legal, tax and medical-record obligations. When data is no longer required we delete or anonymise it. Clinics control the retention and deletion of the patient records they own.
Your rights
Under the DPDP Act you can:
- Access a summary of the personal data we hold about you.
- Ask us to correct, complete or update it.
- Ask us to erase it, subject to legal limits.
- Nominate another person to exercise your rights.
- Withdraw consent, and raise a grievance.
To exercise any of these, email privacy@medigent.in. If your data sits inside a clinic’s records, we will route your request to that clinic and help fulfil it.
Grievance Officer
In line with the DPDP Act and the IT Rules, our Grievance Officer handles data complaints.
We acknowledge grievances promptly and respond within the timelines set by law.
Cookies
We use essential cookies to keep you signed in and the site working, and limited analytics to understand usage and improve the product. You can control cookies through your browser settings; disabling essential cookies may break parts of the site.
Children
Medigent is intended for clinics and adults. We do not knowingly collect data directly from children under 18 without verifiable parental or guardian consent. A minor’s medical record is created and managed by their clinic under the guardian’s consent.
Changes to this policy
We may update this policy as the product, our partners or the law change. We will post the new version here with a fresh last-updated date, and notify you of material changes where required.
Contact us
Medigent organises information and sends reminders. It is not a medical device and does not provide medical advice, diagnosis or treatment. Every clinical decision is made by the treating clinician.