Privacy Policy

How eKiosk Health collects, uses, shares and protects personal data โ€” for the clinics and hospitals we serve, and the patients they care for.

Last updated: [DATE] ยท Effective from: [DATE]
๐Ÿšง Pre-launch notice This is a draft policy, published ahead of our full commercial launch โ€” it will be finalized, with our registered entity details and appointed Grievance Officer, before paid plans go live. Questions in the meantime: sales@ekioskhealth.com.

On this page

  1. 1. Who we are
  2. 2. Our two roles: your data vs. your patients' data
  3. 3. What personal data we collect
  4. 4. How we use personal data
  5. 5. Who we share data with
  6. 6. How long we keep data
  7. 7. How we protect data
  8. 8. Your rights
  9. 9. Children's data
  10. 10. Cross-border data transfer
  11. 11. Grievance Officer
  12. 12. Changes to this policy
  13. 13. Contact us

1. Who we are

eKiosk Health ("we", "us") operates the eKiosk Health platform โ€” a multi-tenant software-as-a-service product for outpatient management, self-service kiosks, pharmacy, laboratory and related hospital operations, including the website at ekioskhealth.com. Our full registered entity name, office address and GSTIN will be published here ahead of our commercial launch.

This policy explains how we handle personal data under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and applicable rules made under it.

2. Our two roles: your data vs. your patients' data

It matters, legally, whose data we're talking about:

3. What personal data we collect

WhoWhat we collectWhen
Clinic / hospital accountClinic name, contact person name, phone, email, address, password (hashed), payment/billing detailsSign-up, plan purchase, support requests
Staff users (on behalf of the hospital)Name, email, role, login activityAccount creation by hospital admin
Patients (on behalf of the hospital)Name, phone/email (for OTP & notifications), demographic and visit details the hospital configures, queue/token number, payment referenceKiosk check-in, registration, service requests
Website visitorsPage visited (no cookies, no IP-level fingerprint) via Cloudflare Web AnalyticsAny page load on ekioskhealth.com

We deliberately minimise what's collected for a given purpose โ€” for example, WhatsApp notifications for queue numbers and payment confirmations carry only a phone number, an amount and a token number; we do not include patient name, diagnosis or department in those messages.

4. How we use personal data

5. Who we share data with

We share personal data only with service providers who process it on our behalf, under contract, strictly for the purpose stated:

ProviderPurposeWhat they see
Meta (WhatsApp Business Platform)Queue-number & payment-confirmation notifications, OTPPhone number, amount, token number โ€” never patient name or diagnosis
Zoho (email)Email OTP, invoices, notificationsEmail address, message content
Razorpay / UPI providerPayment processingPayment/billing details (we do not store full card numbers)
Google / Gemini (AI)AI-assisted triage, summaries, prescription draftingDe-identified clinical text (PII redacted before sending โ€” see our PII-redaction safeguard), never used to train the underlying model
CloudflareWebsite analytics, bot protectionPage path only (analytics is cookie-free); Turnstile bot-check token (login/registration forms)

We do not sell personal data, and we do not share it for third-party advertising.

6. How long we keep data

We retain account and clinical data for as long as the hospital's subscription is active and as required by applicable medical-records retention law, then delete or anonymise it within a reasonable period after a verified deletion request or contract termination, unless a longer period is required by law (e.g. financial/tax records).

7. How we protect data

8. Your rights

Under the DPDP Act, you have the right to:

Patients should raise data requests about their own clinical records with their hospital first, since the hospital is the Data Fiduciary for that data; we will assist the hospital in fulfilling verified requests.

9. Children's data

Our clinic/hospital accounts are for adults (staff and account holders). Where a patient is a minor, their data is provided and consented to by a parent/guardian as part of the hospital's own registration process, under the hospital's responsibility as Data Fiduciary.

10. Cross-border data transfer

Some of our processors (e.g. Meta, Google) operate infrastructure outside India. We only transfer the minimum data necessary for the specific feature (e.g. a phone number for a WhatsApp notification) and only to countries not currently restricted by the Indian Government under the DPDP Act. We do not transfer full clinical records to these providers.

11. Grievance Officer

If you have a complaint about how your personal data has been handled, contact our Grievance Officer:

We're in the process of appointing a dedicated Grievance Officer, who will be named here once registration is complete. Until then, email sales@ekioskhealth.com โ€” we aim to acknowledge within 48 hours and resolve within 15 business days.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified via the website or email before they take effect. The "Last updated" date at the top of this page always reflects the current version.

13. Contact us

Questions about this policy: sales@ekioskhealth.com