DocBase (“Company”, “we”, “us”, “our”) is committed to protecting the privacy and security of personal information entrusted to us by healthcare providers, patients, and other users of the DocBase platform (“Service”, “Platform”). This Privacy Policy explains what information we collect, how we use and protect it, and your rights in relation to it. By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please discontinue use of the Platform.
This Policy should be read together with our Terms of Service, which govern your use of the Platform.
1. Scope and Applicability
This Privacy Policy applies to all personal information collected through the DocBase platform, including our website, web application, mobile interfaces, APIs, and any related services. It covers:
- Healthcare Providers — clinics, hospitals, doctors, and their staff who subscribe to DocBase;
- Patients — individuals who book appointments, access health records, or otherwise interact with a Provider through the Platform;
- Visitors — individuals who visit our website or marketing pages without creating an account.
DocBase operates primarily as a data processor in respect of patient data. The Healthcare Provider (your clinic or doctor) is the data controller for patient information and is responsible for ensuring lawful processing. For information about our own users (Providers, staff, and visitors), DocBase acts as the data controller.
2. Information We Collect
We collect the following categories of information:
2.1 Information You Provide Directly
- Account registration: name, email address, phone number, organisation name, and login credentials;
- Healthcare Provider profile: medical registration number, specialisation, clinic address, logo, and practice details;
- Patient information: name, date of birth, gender, contact details, UHID (Unique Health ID), and medical history entered by the Provider;
- Appointment data: date, time, reason for visit, and status;
- Visit records: clinical notes, diagnoses, prescriptions, consultation fees, and payment details entered by the Provider;
- Communications: messages, feedback, and support requests submitted to us.
2.2 Information Collected Automatically
- IP address, browser type and version, operating system, and device identifiers;
- Pages visited, time spent on pages, and navigation patterns (via server logs and analytics);
- Session tokens and authentication cookies necessary for secure login;
- Error logs and performance metrics used to maintain and improve the Platform.
2.3 Information from Third-Party Integrations
- If you connect the Platform to third-party services (e.g., WhatsApp messaging, email gateways, payment processors), we may receive confirmation data such as delivery status or transaction references;
- We do not receive your full payment card details — payment processing is handled by our payment processor and subject to their own privacy policies.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: to operate, maintain, and provide all features of the Platform, including appointment scheduling, patient record management, prescriptions, billing, and reporting;
- Communications: to send appointment reminders, follow-up messages, WhatsApp notifications, and system alerts to patients and Providers on behalf of the Provider;
- AI-powered features: to process voice recordings for transcription, generate clinical note drafts, patient summaries, and AI-assisted prescription suggestions — all subject to Provider review and approval;
- Authentication and security: to verify your identity, protect your account, and detect and prevent fraud or unauthorised access;
- Billing and payments: to manage subscriptions, generate invoices, and process payments;
- Customer support: to respond to your enquiries and resolve issues;
- Product improvement: to analyse aggregated, anonymised usage data to improve and develop the Platform;
- Legal compliance: to meet our obligations under applicable law, including healthcare data regulations and tax requirements.
We will not use patient data for any purpose beyond providing the Service to the Healthcare Provider, unless required by law or with your explicit consent.
4. Legal Basis for Processing
We process personal information under the following legal bases, as applicable under the Digital Personal Data Protection Act 2023 (India) and other applicable privacy laws:
- Contractual necessity: processing required to perform our contract with Healthcare Providers and to deliver the Service;
- Consent: where you have given explicit consent (e.g., patients consenting to receive communications through the Platform);
- Legitimate interests: for security monitoring, fraud prevention, and product analytics (where not overridden by your rights);
- Legal obligation: where processing is required to comply with applicable laws, including tax, healthcare, and data retention regulations.
5. Sharing of Information
We do not sell your personal information. We share information only in the following circumstances:
- Healthcare Providers: Patient information is shared with the Healthcare Provider(s) you engage with through the Platform, as necessary to deliver the healthcare service you have requested. The Provider is your primary point of contact for your health data.
- Sub-processors and service providers: We engage trusted third-party providers to help operate the Platform, including cloud hosting, database services, email and SMS delivery, AI model providers, and analytics tools. These parties process data solely on our instruction and are contractually bound to protect it.
- Communication services: Message content (appointment reminders, follow-up notifications) is transmitted via third-party gateways (e.g., WhatsApp Business API, email providers). Transmission is governed by those providers' own policies.
- Legal requirements: We may disclose information where required by law, court order, regulatory authority, or to protect the rights, property, or safety of DocBase, its users, or the public.
- Business transfers: In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will provide notice before any such transfer and the acquiring entity will be bound by equivalent privacy commitments.
6. AI Features and Data Processing
DocBase uses artificial intelligence and machine learning to provide features such as voice transcription, clinical note drafting, patient summaries, and prescription assistance. With respect to these features:
- Voice recordings submitted for transcription are processed by AI service providers under our sub-processor agreements and are not used to train AI models without explicit consent;
- AI-generated outputs (notes, summaries, prescriptions) are drafts only and must be reviewed and approved by the Healthcare Provider. They do not constitute medical advice from DocBase;
- Patient data used to generate AI outputs is processed solely to provide that specific feature to the Provider and is not retained beyond what is necessary for the service;
- Healthcare Providers who enable AI features are responsible for ensuring appropriate patient consent is obtained in their jurisdiction.
7. Data Security
We implement appropriate technical and organisational security measures to protect personal information against unauthorised access, alteration, disclosure, or destruction, including:
- Encryption of data in transit using TLS and encryption of sensitive data at rest;
- Role-based access controls ensuring staff access only data necessary for their function;
- Multi-tenant data isolation so that each Healthcare Provider's data is logically separated;
- Session authentication with secure, HttpOnly cookies;
- Regular security assessments and dependency updates;
- Audit logging of access to sensitive records.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your information, we cannot guarantee its absolute security. In the event of a data breach affecting your data, we will notify you as required by applicable law.
8. Cookies and Tracking Technologies
We use cookies and similar technologies to operate and improve the Platform:
- Essential cookies: required for authentication, session management, and CSRF protection. The Platform cannot function without these;
- Analytics cookies: used to understand how the Platform is used so we can improve it. These are anonymised and do not identify individual users;
- Preference cookies: used to remember your settings and preferences.
You can control non-essential cookies through your browser settings. Disabling essential cookies may prevent you from using the Platform. We do not use cookies to serve third-party advertising.
9. Data Retention
We retain personal information for as long as necessary to:
- Provide the Service under your active subscription;
- Comply with applicable legal, regulatory, and tax obligations (including healthcare record retention requirements, which in India may extend to 7–10 years for medical records);
- Resolve disputes and enforce our agreements.
Upon termination of a subscription, we retain your data for 30 days to allow you to export it. After this period, your data will be permanently deleted from our systems, subject to any legal retention obligations.
Anonymised and aggregated data that cannot identify any individual may be retained indefinitely for analytics and product improvement purposes.
10. Healthcare Data and Regulatory Compliance
DocBase processes health-related information on behalf of Healthcare Providers. We are committed to supporting compliance with applicable healthcare data regulations, including:
- Digital Personal Data Protection Act 2023 (India) — we act as a “data processor” for patient data and process it only on the lawful instruction of the Healthcare Provider (“data fiduciary”);
- Indian Medical Council (Professional Conduct) Regulations — Providers are responsible for ensuring their use of the Platform complies with their professional obligations;
- HIPAA (United States) — where applicable, we are willing to enter into Business Associate Agreements (BAAs) with covered entities. Please contact us at team@docbase.in to request a BAA;
- GDPR (European Union) — where EU residents' data is processed, we apply equivalent protections and data subject rights.
Healthcare Providers are solely responsible for obtaining all required patient consents before collecting, entering, or processing patient data through the Platform.
11. International Data Transfers
DocBase is based in India and our primary data storage is within India. Where we use sub-processors located in other jurisdictions (e.g., AI model providers or cloud infrastructure providers), we ensure that appropriate safeguards are in place, including contractual clauses or other mechanisms recognised by applicable law, to protect your data in accordance with this Privacy Policy.
12. Your Rights
Depending on your location and applicable law, you may have the following rights in relation to your personal information:
- Access: request a copy of the personal information we hold about you;
- Correction: request that we correct inaccurate or incomplete information;
- Deletion: request that we delete your personal information, subject to legal retention obligations;
- Portability: request your data in a structured, machine-readable format;
- Restriction: request that we limit the processing of your information in certain circumstances;
- Objection: object to processing based on legitimate interests;
- Withdrawal of consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
For patients: your primary point of contact for exercising rights over your health records is the Healthcare Provider who entered and manages that data. DocBase will assist Providers in fulfilling patient data requests.
To exercise any of these rights directly with DocBase, please contact us at team@docbase.in. We will respond within the timeframes required by applicable law (typically 30 days).
13. Children's Privacy
The Platform is not directed at children under 18 years of age for the purpose of creating accounts or subscriptions. Healthcare Providers may enter health records for minor patients as part of their clinical practice, in which case the Provider is responsible for ensuring lawful processing and obtaining consent from a parent or guardian as required by applicable law. If you believe we have inadvertently collected personal information from a child without appropriate consent, please contact us immediately at team@docbase.in.
14. Third-Party Links and Services
The Platform may contain links to third-party websites or integrate with external services. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party service before providing your information. DocBase is not responsible for the privacy practices of third-party services.
15. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or applicable law. Where changes are material, we will notify you by email or by prominent notice on the Platform at least 14 days before the changes take effect. The “Last updated” date at the top of this page will always reflect the most recent revision. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our privacy team at:
We aim to respond to all privacy enquiries within 30 days. If you are not satisfied with our response, you may have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.
BY ACCESSING OR USING THE DOCBASE PLATFORM, YOU CONFIRM THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND CONSENT TO THE COLLECTION AND USE OF YOUR INFORMATION AS DESCRIBED HEREIN.