Legal

Privacy Policy

Last updated: June 16, 2026

Aurora Blossom (ClinicFlow247) ("ClinicFlow", "we", "our") operates the ClinicFlow247 platform — a clinic appointment management service accessible at clinicflow247.com. This Privacy Policy explains what personal and health data we collect, why we collect it, how we use and protect it, and your rights under applicable Indian law.

By creating an account or using our services you agree to this Policy. If you do not agree, please do not use ClinicFlow.


1. Applicable Laws

ClinicFlow operates in India and complies with:

  • The Information Technology Act, 2000 (IT Act) and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
  • The Digital Personal Data Protection Act, 2023 (DPDP Act)
  • Any sector-specific guidelines issued by the Ministry of Health & Family Welfare

2. Data We Collect

2.1 Account & Identity Data

  • Full name, email address, phone number
  • Date of birth, gender (optional)
  • Encrypted password (bcrypt hash — we never store plaintext passwords)

2.2 Health & Appointment Data

  • Appointment bookings, dates, times, and status
  • Doctor and clinic information associated with your appointments
  • Digital prescriptions issued by your doctor via ClinicFlow

2.3 Usage & Technical Data

  • IP address, browser type, device type, operating system
  • Pages visited, features used, timestamps of actions
  • Error logs for debugging and improving the service

3. How We Use Your Data

  • To create and manage your account and authenticate you securely
  • To book, confirm, and remind you about appointments
  • To display your queue position and estimated wait time
  • To send transactional emails (booking confirmations, reminders, password reset)
  • To display doctor profiles and availability
  • To allow clinic admins and doctors to manage their operations
  • To detect and prevent fraud, abuse, or security incidents
  • To improve the platform through aggregated, anonymised analytics

We process your data only for the purposes listed above. We do not use your health data for advertising, profiling, or sale to third parties.


4. Legal Basis for Processing

  • Consent — you provide explicit consent at registration by agreeing to this Policy
  • Contract — processing is necessary to deliver the appointment booking service you signed up for
  • Legitimate interest — security logging, fraud prevention, and service improvement
  • Legal obligation — compliance with court orders or government directives under Indian law

5. Data Sharing & Disclosure

We share your data only in the following limited circumstances:

  • Clinic and Doctor — the clinic and doctor you book with can see your name, contact, and appointment details to provide care
  • Infrastructure Providers — Google Cloud (hosting, database) under strict data processing agreements
  • Email Provider — Gmail SMTP to send transactional emails; only your email address is shared
  • Legal Authorities — when required by a court order, government directive, or to protect rights and safety

We do NOT sell, rent, or share your personal or health data with advertisers or data brokers.


6. Data Security

  • All data is transmitted over HTTPS/TLS 1.2+
  • Passwords are stored as bcrypt hashes (never plaintext)
  • Authentication uses short-lived JWT tokens with role-based access control
  • Backend and database are hosted on Google Cloud Run with VPC isolation
  • Access to production systems is restricted to authorised personnel only

7. Data Retention

We retain your account and appointment data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law (e.g., medical records under applicable health regulations, which may be retained for up to 7 years).


8. Your Rights (DPDP Act 2023)

As a Data Principal under the DPDP Act, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — update or correct inaccurate personal data from your profile page
  • Erasure (Right to be Forgotten) — request deletion of your account and personal data
  • Grievance Redressal — raise a complaint with our Grievance Officer (see Section 10)
  • Withdraw Consent — you may withdraw consent at any time by deleting your account; withdrawal does not affect the lawfulness of prior processing

To exercise any of these rights, email us at privacy@clinicflow247.com or use the "Delete My Account" option in your Profile settings.


9. Cookies & Tracking

ClinicFlow uses browser localStorage to store your session token so you stay logged in between visits. We do not use third-party advertising or tracking cookies. No cross-site tracking is performed.


10. Grievance Officer

In accordance with the IT Act 2000 and DPDP Act 2023, we have appointed a Grievance Officer to address data-related concerns. You may reach them at:

Grievance Officer — ClinicFlow247

Email: privacy@clinicflow247.com

Response time: within 30 days of receiving your grievance


11. Children's Privacy

ClinicFlow is not directed at children under the age of 18. We do not knowingly collect personal data from minors without verifiable parental consent. If you believe a minor's data has been submitted without consent, please contact us immediately at privacy@clinicflow247.com.


12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top and notify registered users by email if the changes are material. Continued use of ClinicFlow after changes take effect constitutes acceptance of the updated Policy.


13. Contact Us

For any questions about this Privacy Policy or how we handle your data:

Aurora Blossom (ClinicFlow247)

Email: privacy@clinicflow247.com

Website: clinicflow247.com