Trust · India

DPDP: what is built, and what is still open.

The DPDP Act is the law MedAppz was built for, so more of it is in the product: consent notices by version, a rights-request desk, a breach register with its notice deadlines. The data is not in India: our server is in the United States. Our processor agreements are not signed yet.

Status as of 24 September 2026MedAppz India
An illustration of a clinic team reviewing a shared, secured workspace

Where we stand, as of 24 September 2026

This covers the Digital Personal Data Protection Act, 2023. MedAppz does not claim compliance with it or any certification under it. This is a programme in progress, and this table is where it stands. Records are stored on one server: Boston, United States · Hostinger VPS. Data is not stored in India.

ItemStatusNote
Consent notices, by version, with withdrawalIn placeChecked at each send; withdrawal cancels what is queued.
Rights requests: access, correction, erasure, nomination, withdrawal, objectionIn placeLogged in the Security Centre on a 30-day clock. Erasure pseudonymises where medical-record retention rules apply.
Breach register with CERT-In and Data Protection Board noticesIn placeIncidentIQ: a breach cannot close until each notice is sent or waived with a reason.
Aadhaar and ABHA numbers never stored in fullIn placeA hash and the last four digits only, enforced by a database constraint.
Data stored in IndiaNot startedNo. Records are stored on one server: Boston, United States · Hostinger VPS. DPDP allows transfer outside India unless the government restricts the destination country.
Processor agreements with sub-processorsNot startedWe hold no signed agreement with any sub-processor yet: not the host, not the AI or speech vendors, not the SMS, email or WhatsApp providers.
Backups off-site and encrypted at restIn progressBuilt, not yet switched on.

In place in the product today

Each of these runs in the product now. The line under each one names the part of the law it relates to. That is a pointer for your own review, not a claim that the clause is met.

An audit trail that cannot be editedRecord opens, searches and exports are written once: who, when, from where, under which permission. The log is append-only by database trigger and hash-chained day by day; the chain is re-verified nightly.Audit schema and AuditLens · Reasonable security safeguards — s.8(5)
One clinic cannot read another’s rowsRow-level security on every tenant table, bound to the transaction. The account the application runs as cannot switch it off.Database row-level security · Reasonable security safeguards — s.8(5)
Emergency access that expires and is reviewedBreak-glass access needs a written reason, lasts at most four hours (a database constraint), and lands on a review queue.BreakGlass · Reasonable security safeguards — s.8(5)
Consent records, by notice versionMessages are gated on the consent notice the patient accepted, by version, at the moment of sending. Withdrawal cancels what is queued.ConsentVault and the consent service · Notice and consent — ss.5–6
Access reviews with two-person revocationThe Security Centre runs dated access-review campaigns over privileged grants (full patient data, money, platform, emergency access). A challenge raises a two-person approval; a campaign cannot close with unread items.Security Centre · Reasonable security safeguards — s.8(5)
Strong sign-in and short sessionsArgon2id password hashing, lockout after five failures, optional or organisation-required app-based two-factor, 15-minute access tokens with rotating refresh tokens, and a five-minute idle-out on shared devices.Identity
Encryption in transit, and sealed credentialsTLS on every connection, with certificates renewed automatically. Keys and passwords a clinic gives us are sealed with AES-256-GCM, bound to the organisation, and never shown back.TLS and the secrets envelope
Nightly verified backups, with a rehearsed restoreThe database and files are dumped every night and each dump is checked before the run counts as a success. A full restore was rehearsed on 3 September 2026.ops/backup.sh · Reasonable security safeguards — s.8(5)
Exports are whitelisted and recordedOnly listed views can be exported, each needs its permission, and each export is recorded with its row count and data classes.Exports · Purpose limitation — s.4
AI you can switch off, or send redactedOne setting per organisation: off, redacted (the default) or full. Redacted strips the name, date of birth, hospital number, phone and email before the request leaves our server. A named person accepts every draft.AI governance

What you would need to do

  • Show patients your own consent notice and name your grievance contact. The product carries the notice; you decide its words.
  • Answer rights requests on time. The desk keeps the clock; a person has to act.
  • Report a breach to CERT-In and the Data Protection Board when the law requires it.
  • Run the free DPDP self-audit to see which duties are yours alone.
This page describes our product. It is not legal advice; take your own advice on how the law applies to your practice.

Sub-processors and where they are

Every outside service the product can send data to, where it processes it, and whether an agreement is signed. The list is generated from the register the product itself reads, the same one the Trust Centre shows.

ServiceLocationAgreement
HostingerThe rented server the database, the application and the uploaded files run onOne rented regionNone signed yet
S3-compatible object storageWhere uploaded files and documents live when object storage is switched onThe bucket region the deployment configuredNone signed yet
AnthropicAI drafting and answeringUnited StatesNone signed yet
OpenAIAI drafting and answeringUnited StatesNone signed yet
Google (Gemini)AI drafting and answeringUnited StatesNone signed yet
NVIDIA NIMAI drafting and answeringUnited StatesNone signed yet
The configured speech-to-text serviceTurning a consultation recording into a transcriptWherever SPEECH_API_BASE_URL points — api.openai.com (United States) unless changedNone signed yet
The clinic’s own Jitsi serverCarrying the live audio and video of a video visitWherever the clinic hosts itNone signed yet
ResendSending emailUnited States / European UnionNone signed yet
MSG91Sending SMSIndiaNone signed yet
Meta (WhatsApp Business)Sending WhatsApp messages through the official APIMeta’s global networkNone signed yet
The clinic’s paired WhatsApp numberSending WhatsApp messages from the clinic’s own handset sessionMeta’s global network, through the clinic’s own numberNone signed yet
Google (Firebase Cloud Messaging)Delivering push notifications to a phoneGoogle’s global networkNone signed yet
RazorpayTaking a payment online, and holding a standing UPI Autopay or e-mandate authorisationIndiaNone signed yet
PhonePeTaking a payment onlineIndiaNone signed yet
StripeTaking a payment onlineUnited StatesNone signed yet
Pine LabsTaking a card payment on the counter terminalIndiaNone signed yet
Google SheetsReceiving a scheduled exportGoogle’s global networkNone signed yet
Google Business Profile and MetaReading reviews and publishing the clinic’s repliesGoogle and Meta’s global networksNone signed yet
The clinic’s own mail serverThe mailbox MedAppz proxies rather than copiesWherever the clinic’s mail is hostedNone signed yet
The hospital’s own GST Suvidha ProviderRegistering the hospital’s own patient invoices with the Invoice Registration PortalIndiaNone signed yet
The clinic’s own Tally serverReceiving the accounting export, and answering which vouchers it tookWherever the clinic runs TallyNone signed yet
A database the clinic bringsA destination the clinic asked the product to write toWherever the clinic hosts itNone signed yet

Send us your DPDP questions

Your security questionnaire is longer than this page. Leave a number and we will answer it line by line, including where the answer is “not yet”.

We use your name, phone number and clinic name for one thing: to answer this enquiry about MedAppz. It is stored on our own server, in the single region our trust centre names, and it is not sold or passed to anyone else.

Email us

You can withdraw either at any time: write to hello@medappz.com, or tell whoever calls you, and we will delete what you gave us.