Privacy Policy
Sateline ClinicOS holds patient records on behalf of the clinics that use it. The clinic decides what is collected and why; we store and process it under their instructions, and never sell it, share it for advertising, or use it to train artificial-intelligence models.
Last updated 30 August 2026
1.Who this policy covers
This policy is issued by Sateline Technologies Private Limited(“we”, “us”), which operates Sateline ClinicOS. It covers two different groups of people, and the distinction runs through everything below:
- Clinic users — the doctors, receptionists and staff who sign in. We hold their data directly and answer to them for it.
- Patients — the people a clinic treats. We hold their records on the clinic’s behalf. A patient has no account and does not sign in.
2.Who is responsible for patient data
Under the Digital Personal Data Protection Act, 2023, the party that decides why personal data is collected is the Data Fiduciary, and the party that processes it on their instructions is the Data Processor.
- The clinic is the Data Fiduciary for its patients. It decides which patients are registered, what is recorded about them, and how long its own records are kept.
- We are the Data Processor. We store and process patient data to provide the service, and for no other purpose.
- We are the Data Fiduciary for clinic staff accounts — the names, email addresses and sign-in activity of the people who use the software.
The practical consequence: a patient who asks us directly to produce or erase their records will be directed to their clinic. We cannot act on a patient request without the clinic’s instruction — we have no way to verify the request, and no authority to overrule the clinic’s own medical-record obligations.
3.What we hold
Data reaches us in three ways, and we hold nothing beyond them.
Entered by the clinic about its patients: name, mobile number, email address where given, date of birth or age, sex, address, medical notes, diagnoses, prescriptions, uploaded lab and scan reports, appointment history, invoices and payments.
Entered by or about clinic staff: name, email address, mobile number and role — and, where a clinic uses the staff-profile feature, qualifications, professional registration numbers and uploaded identity documents.
Generated by using the service: sign-in activity, and records of the sensitive actions described in section 6.
We use no advertising or analytics trackers of any kind. The only cookies set are the ones that keep you signed in.
4.What we use it for
To run the service the clinic is paying for, and nothing else: showing records to the staff authorised to see them, sending appointment confirmations, reminders, invoices and receipts to patients, producing prescription and invoice PDFs, and taking the clinic’s own subscription payment.
We do not sell personal data. We do not share it for advertising. We do not use patient data to train artificial-intelligence models, ours or anybody else’s.
5.Who else processes it
Running the service needs infrastructure we do not own. Each provider below processes data under contract, only for the purpose named, and none of them may use it for their own purposes.
| Provider | Purpose | What it handles |
|---|---|---|
| Supabase (PostgreSQL) | The database holding every clinic and patient record | All clinic, staff, patient, appointment, billing and prescription data |
| Vercel | Application hosting and scheduled jobs | Request data in transit; no separate copy of clinical records is stored |
| Clerk | Sign-in, sessions and clinic staff accounts | Staff name, email address and sign-in activity. No patient data |
| Cloudflare R2 | Stored files — reports, scans, signatures and clinic documents | Uploaded files, retrievable only through short-lived signed links |
| Razorpay | Subscription billing, and the clinic's own patient collections | Billing contact and payment details. Patient payments settle to the clinic's own account |
| Resend | Transactional email — confirmations, reminders, invoices and receipts | Recipient email address and the contents of that message |
| Meta (WhatsApp Business Platform) | WhatsApp notifications, only for clinics that switch them on | Patient mobile number and the message sent. Sent from the clinic's own WhatsApp Business Account |
Patient payments never pass through us.When a clinic collects by UPI, the money moves from the patient to the clinic’s own payment account directly. We hold no patient card or bank details at any point.
6.How it is protected
- Every record is scoped to one clinic. Separation between clinics is enforced on the server for every query, not by hiding menu items, and is covered by an automated test suite that runs before each release.
- Access follows role. What a receptionist, a doctor and an owner may each do is enforced server-side. A hidden button is never the only thing preventing an action.
- Data is encrypted in transit and at rest. Credentials a clinic gives us — payment keys, storage keys, messaging tokens — are encrypted a second time with keys held outside the database, so a copy of the database alone does not yield them.
- Uploaded files are not publicly addressable. Reports, scans and documents are reachable only through short-lived signed links issued to a signed-in, authorised user.
- Sensitive reads are recorded.Viewing a staff member’s identity document, and exporting patient records in bulk, are both logged with who did it and when. A staff member can read that log about themselves.
No system is immune. If a breach affects personal data we hold, we will notify the affected clinics and the Data Protection Board of India as the DPDP Act requires.
7.How long it is kept, and how it is erased
While a clinic’s subscription is active, its records are kept for as long as it wants them. When a subscription ends:
- Records become read-only for 90 days. Throughout that window the clinic can still open everything, and download a complete copy — every table and every stored file.
- The clinic is warned three times across that window before anything can be erased.
- After it, the clinic’s owner may request erasure. Erasure is then carried out by us — never automatically, and never unattended.
- Invoices survive erasure; clinical records do not.Indian tax law requires numbered invoices to be retained, so invoice rows are kept with the patient’s identifying details stripped out of them. Medical notes, prescriptions, reports and uploaded files are destroyed.
A clinic can download its complete data bundle at any time, not only on leaving. An export you can obtain only by cancelling is not a right.
8.Your rights
If you are clinic staff, you may ask us for a copy of the data we hold about you, ask us to correct it, ask who has viewed your identity documents, and ask us to erase your account once you no longer work at the clinic. Write to privacy@example.com.
If you are a patient, please contact your clinic — they hold your records and decide what happens to them, and we act on their instruction. If your clinic does not respond, write to our Grievance Officer in section 10 and we will take it up with them.
9.Changes to this policy
We will post any change here and update the date at the top of the page. Where a change materially affects how patient data is handled, we will email the owner of every active clinic before it takes effect.
10.Grievance Officer
As required by the Digital Personal Data Protection Act, 2023 and the Information Technology Rules, the officer below answers complaints about how personal data is handled.
TODO — Grievance Officer name
Grievance Officer, Sateline Technologies Private Limited
grievance@example.com
Coimbatore, Tamil Nadu, India
We acknowledge complaints within 30 days. Full contact details are on the contact page.