Skip to content
Security-first

Growth that respects patient trust.

Clinics hold some of the most sensitive data that exists. We treat protecting it as a first principle — the reason clinics trust us, and the foundation the future platform is built on.

Layered protection of healthcare data — HIPAA, GDPR, DPDP and AI Act compliance
Our philosophy

Growth and patient trust are not a trade-off. Everything we build starts from that.

How we handle patient data

A plain-English data lifecycle.

No jargon. Here is exactly what happens to a patient enquiry, from the moment it arrives to the moment it’s gone.

  1. 01

    Capture

    Only what's needed, with explicit, logged consent.

  2. 02

    Store

    Encrypted, in a region appropriate to the data's origin.

  3. 03

    Process

    For the stated purpose only, with least-privilege access.

  4. 04

    Retain & delete

    Kept only as long as needed; erasable on request.

Regulatory posture

The frameworks we build around.

GDPR

The EU's data-protection regime. Patient health data is a special category demanding heightened safeguards.

Our posture — We act as a processor on the clinic's instructions, with a DPA in place, explicit consent for enquiry data, data-subject rights supported, and EU-region hosting for EU data.

India DPDP Act

India's Digital Personal Data Protection Act, with rules operationalising through phased enforcement toward 2027.

Our posture — We build consent capture and logging to DPDP's notice-and-consent model, host Indian data in-region, and help clinics get their growth-data house in order before enforcement bites.

EU AI Act

The EU's AI regulation, with transparency obligations phasing in through 2026.

Our posture — Where our systems use AI to interact with patients, we disclose it, keep a human in the loop, and document how the AI is used — transparency by design, not retrofit.

HIPAA (US context)

US rules governing Protected Health Information, relevant only for US-facing clients.

Our posture — For US engagements we operate as a Business Associate under a BAA with the corresponding safeguards. We do not present HIPAA as a blanket global badge — it applies only where it applies.

Data-handling principles

Six rules we don’t bend.

  • Data minimisation — we ask for the least we need, never more.
  • Consent is a logged record, not a checkbox — who, what, when, which policy.
  • Encryption in transit and at rest, everywhere.
  • Least-privilege access, with sensitive actions audited.
  • Region-appropriate residency for EU and Indian data.
  • Clean export always available — we never hold data hostage.
The platform foundation

Built for what we’re building next.

The patient-conversion platform we’re developing will capture, store, and process patient enquiries at scale — exactly the kind of system these regulations scrutinise most. Getting data handling right now, as a service company, is what lets us build that product on solid ground: encryption, access control, audit logs, data residency, and AI transparency are being designed in from the first line, not bolted on later.

We publish only what we have actually implemented. For a company whose entire brand is trust, a single overstated claim would be unacceptable — so we under-promise here and over-deliver in the architecture.

Grow with a partner that takes data seriously.

No pressure, no lock-in. We’ll show you where you’re losing patients and exactly how we’d fix it.

Book your Patient Revenue Audit