On this page
- 1. Who we are
- 2. Our two roles: your data vs. your patients' data
- 3. What personal data we collect
- 4. How we use personal data
- 5. Who we share data with
- 6. How long we keep data
- 7. How we protect data
- 8. Your rights
- 9. Children's data
- 10. Cross-border data transfer
- 11. Grievance Officer
- 12. Changes to this policy
- 13. Contact us
1. Who we are
eKiosk Health ("we", "us") operates the eKiosk Health platform โ a multi-tenant software-as-a-service product for outpatient management, self-service kiosks, pharmacy, laboratory and related hospital operations, including the website at ekioskhealth.com. Our full registered entity name, office address and GSTIN will be published here ahead of our commercial launch.
This policy explains how we handle personal data under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and applicable rules made under it.
2. Our two roles: your data vs. your patients' data
It matters, legally, whose data we're talking about:
- When a clinic or hospital signs up, pays for a plan, or its staff use our portal โ we are the Data Fiduciary for that account/billing data, and this policy applies directly to you.
- When patients register, check in, or receive a token/receipt at a hospital using our platform โ the hospital is the Data Fiduciary for that patient data (they decide why it's collected and what it's used for), and we act only as their Data Processor, processing it strictly on their instructions and for the purpose they've configured. Patients should also refer to their hospital's own notice/policy for how their health data is used.
3. What personal data we collect
| Who | What we collect | When |
|---|---|---|
| Clinic / hospital account | Clinic name, contact person name, phone, email, address, password (hashed), payment/billing details | Sign-up, plan purchase, support requests |
| Staff users (on behalf of the hospital) | Name, email, role, login activity | Account creation by hospital admin |
| Patients (on behalf of the hospital) | Name, phone/email (for OTP & notifications), demographic and visit details the hospital configures, queue/token number, payment reference | Kiosk check-in, registration, service requests |
| Website visitors | Page visited (no cookies, no IP-level fingerprint) via Cloudflare Web Analytics | Any page load on ekioskhealth.com |
We deliberately minimise what's collected for a given purpose โ for example, WhatsApp notifications for queue numbers and payment confirmations carry only a phone number, an amount and a token number; we do not include patient name, diagnosis or department in those messages.
4. How we use personal data
- To provide the service you or your hospital signed up for (registration, queueing, billing, pharmacy, lab, AI-assisted clinical workflow).
- To verify identity via one-time codes sent by email, SMS or WhatsApp.
- To process payments and send receipts/invoices.
- To secure accounts (fraud/bot detection, rate limiting, login-attempt monitoring).
- To respond to support requests and legal/regulatory obligations.
- Aggregated, de-identified analytics to improve the product โ never to train third-party AI models on your or your patients' identifiable data.
5. Who we share data with
We share personal data only with service providers who process it on our behalf, under contract, strictly for the purpose stated:
| Provider | Purpose | What they see |
|---|---|---|
| Meta (WhatsApp Business Platform) | Queue-number & payment-confirmation notifications, OTP | Phone number, amount, token number โ never patient name or diagnosis |
| Zoho (email) | Email OTP, invoices, notifications | Email address, message content |
| Razorpay / UPI provider | Payment processing | Payment/billing details (we do not store full card numbers) |
| Google / Gemini (AI) | AI-assisted triage, summaries, prescription drafting | De-identified clinical text (PII redacted before sending โ see our PII-redaction safeguard), never used to train the underlying model |
| Cloudflare | Website analytics, bot protection | Page path only (analytics is cookie-free); Turnstile bot-check token (login/registration forms) |
We do not sell personal data, and we do not share it for third-party advertising.
6. How long we keep data
We retain account and clinical data for as long as the hospital's subscription is active and as required by applicable medical-records retention law, then delete or anonymise it within a reasonable period after a verified deletion request or contract termination, unless a longer period is required by law (e.g. financial/tax records).
7. How we protect data
- Tenant isolation โ every record is scoped to a hospital ID; one hospital can never read another's data.
- Encryption in transit (TLS/HTTPS) for all traffic.
- Two-factor authentication, brute-force lockout, and role-based access control for staff accounts.
- Bot protection (CAPTCHA) and rate limiting on public forms, including login.
- PII redaction before any image/document is sent to an AI provider.
- Masked logging โ identifiers like phone numbers are partially masked in our own system logs.
8. Your rights
Under the DPDP Act, you have the right to:
- Access a summary of personal data we hold about you.
- Correct or update inaccurate or incomplete data.
- Erase data that is no longer necessary for the purpose it was collected, subject to legal retention requirements.
- Withdraw consent where processing is based on consent, and register a grievance if you believe your data has been misused.
Patients should raise data requests about their own clinical records with their hospital first, since the hospital is the Data Fiduciary for that data; we will assist the hospital in fulfilling verified requests.
9. Children's data
Our clinic/hospital accounts are for adults (staff and account holders). Where a patient is a minor, their data is provided and consented to by a parent/guardian as part of the hospital's own registration process, under the hospital's responsibility as Data Fiduciary.
10. Cross-border data transfer
Some of our processors (e.g. Meta, Google) operate infrastructure outside India. We only transfer the minimum data necessary for the specific feature (e.g. a phone number for a WhatsApp notification) and only to countries not currently restricted by the Indian Government under the DPDP Act. We do not transfer full clinical records to these providers.
11. Grievance Officer
If you have a complaint about how your personal data has been handled, contact our Grievance Officer:
We're in the process of appointing a dedicated Grievance Officer, who will be named here once registration is complete. Until then, email sales@ekioskhealth.com โ we aim to acknowledge within 48 hours and resolve within 15 business days.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified via the website or email before they take effect. The "Last updated" date at the top of this page always reflects the current version.
13. Contact us
Questions about this policy: sales@ekioskhealth.com
