Privacy notice
Last updated 4 September 2026. Written under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.
Who this covers
1OPD is clinic management software. It is used by clinics, and by their patients when a clinic sends them a booking link, a reminder or a prescription. Two different relationships follow:
- If you are a patient, your clinic decides why your data is collected and how long it is kept. Under the Act your clinic is the data fiduciary; we are its data processor and act only on its instructions. Requests about your records go to your clinic first; its contact is on its own website and prescription.
- If you are a clinic (or visit this site to evaluate the software), we are the data fiduciary for the details you give us to set up and run your account.
What is processed, and why
- Patient records — name, mobile, age or date of birth, sex, address, visit notes, vitals, prescriptions, bills, lab values and messages — to run the clinic that entered them: appointments, treatment, billing and follow-up. Nothing else.
- Voice dictation — a doctor's spoken notes are converted to text by a speech service and the text is stored with the visit. The audio is not kept after transcription.
- Prescription voice notes — the prescription text is converted to Hindi speech and the audio file is stored so the patient can replay it.
- Clinic account details — clinic name, address, contact person, staff logins — to provide the service and to reach you about it.
- Server logs — IP address, time, page requested — for security and fault-finding.
Where it is processed
Each clinic's records live in a database that holds that clinic only. Third parties that touch data, and what they see:
- Microsoft Azure Speech (Central India region) — doctor dictation to text, and prescription text to Hindi speech.
- A WhatsApp Business messaging provider — the message text and the patient's mobile number, only for messages the clinic sends.
- Hosting — servers operated by Hetzner Online GmbH in Germany today. Migration to data centres in India is scheduled ahead of the Act's compliance date; this notice will be updated when it completes.
How it is protected
- Encrypted connections everywhere; patient pages are never cached by intermediaries.
- Staff sign in with individual accounts and roles; sessions expire; deactivated staff lose access immediately.
- Actions on records are logged with the staff member and time.
- Regular consistent backups; a clinic can obtain its complete database as one file at any time.
Your rights
Under the Act you may ask for access to your personal data, for correction or erasure, to withdraw consent, to nominate someone to act for you, and to have a grievance heard. Medical records are kept for the period the National Medical Commission requires even after a request for erasure, and the clinic will tell you when that applies. A clinic must respond to a request within the period it publishes, and in any case within 90 days.
Children
Clinics treating patients under 18 record a parent or guardian as the contact for messages and consent. Clinical establishments are permitted under the Rules to process a child's data for the child's health care; the software does not profile children or send them advertising.
Breaches
If personal data is compromised, the affected clinic and its affected patients are informed without delay with what happened, the likely consequences, what has been done, and whom to contact, and the Data Protection Board of India is notified as the Rules require.
Grievances
A grievance contact for the platform will be published here. Patients should contact their clinic in the first instance; every clinic on this platform publishes its own contact on its website.
1OPD. This notice describes the platform; each clinic's own notice describes its practice.