Who this notice is for
This Privacy Notice describes how Doxyte Patient processes personal data when an invited adult uses the Doxyte Patient personal health record (PHR), health journal and related features for themselves. Nalan on WhatsApp is currently in controlled testing and is not yet available for patient use.
The first real-data pilot is invitation-only. It does not support public registration, accounts for minors, guardian-managed accounts or use on behalf of another person.
Doxyte Patient is separate from a clinic’s electronic medical record. A clinic must give you its own privacy information for information it holds in its Clinic record.
Who is responsible
Doxyte is a product and business under incorporation in India (“Doxyte”, “we”, “us” or “our”). The proposed company name is Doxyte Healthcare Private Limited. The proposed company is not represented as incorporated by this notice. Its exact legal identity, Corporate Identity Number and registered-office address will be added after incorporation.
Privacy and grievance contact: privacy@doxyte.com.
When you send selected information to a clinic, or a clinic validly publishes information to your PHR, Doxyte records the exchange and preserves its provenance. After a clinic validly receives a copy, that clinic is responsible for its Clinic copy under its own notice and record obligations.
Personal data we process and why
We receive information directly from you, from a clinic that invites you or publishes a record to your PHR, from approved identity and service providers, and from the Doxyte service when it creates audit, provenance, derived or AI-assisted output.
We do not use your information for advertising, sale of health information, insurance underwriting, clinical-trial matching or Doxyte-owned model development under this notice. Any such future purpose requires a separate approved programme, updated notice and any required permission.
| Category | Examples | Why we process it |
|---|---|---|
| Identity and account | Name, contact and identity-provider reference, invitation, clinic link and account state | Create, secure, recover and correctly associate your Patient account |
| Patient-authored longitudinal history | Health-journal entries, symptom episodes, patient-authored messages, corrections and confirmed summaries | Build and display your longitudinal health journal and current-care context |
| Uploads and derived information | Reports and documents, metadata, OCR or laboratory extraction, and source-to-derived links | Organize, retrieve and let you review patient-provided health information |
| Received clinic records | Signed summaries and documents validly published by a clinic | Maintain an attributable historical Patient copy without changing the Clinic source |
| AI inputs and outputs | Selected wording or context, schema and prompt version, Nalan organization output, and content-free usage metadata | Organize selected information for the Patient feature you request |
| WhatsApp channel | Your WhatsApp or phone identifier, Doxyte business-number and provider-message identifiers, messages you send, timestamps and delivery state, and notice, opt-out and account-link state | Receive and reply to requested messages, prevent duplicate processing, secure the channel, record your choices and link only the journal content you explicitly confirm |
| Sharing and clinic links | Selected share package, recipient clinic, grant or revocation, preview and acceptance state | Send only selected records for clinic review and preserve what was shared |
| Appointments and reminders | Appointment request and optional reminder preference when enabled | Manage your requested appointment workflow and any separately activated reminder choice |
| Rights, support, audit and recovery | Notice and terms evidence, safe request identifiers, content-free logs, audit events, export and closure evidence, and restricted backups | Rights handling, support, security, accountability, record integrity and recovery |
How Nalan and other AI assistance work
Nalan may organize selected information you provide and help you prepare a clearer health journal or summary. Approved providers may also perform document extraction or other requested assistance. Doxyte sends only the information selected and required for that task, not your complete longitudinal history by default.
AI output may be incomplete, inaccurate or misleading. Nalan is not a doctor and does not provide diagnosis, treatment, medical reassurance or emergency care. Review the output before saving or sharing it. Seek advice from a qualified healthcare professional for medical decisions.
An activated provider must pass Doxyte’s contractual, location, retention, security and no-provider-training requirements. Current active-provider details will be maintained at doxyte.com/subprocessors. Candidate providers do not receive real patient information merely because Doxyte is evaluating them, and Doxyte does not automatically send real patient information to another provider after a provider failure.
This notice does not authorize Doxyte or a provider to train a model on your Patient content.
When enabled, WhatsApp is an optional third-party channel for talking with Nalan; it is not a private Doxyte application. Before processing health information from a new sender, Doxyte provides a first-use notice and requires the exact acceptance response shown in the conversation. The first message may be held for up to 24 hours while that choice is pending. Declining removes the pending message, and STOP opts the sender out of further companion processing.
Processed inbound message content is scrubbed from the transport record. Ordinary active-topic and reply content is kept for no more than 24 hours. An unfinished journal draft follows the Patient journal lifecycle until it is confirmed, discarded or closed; an entry you explicitly review and confirm becomes part of your durable Patient history. Sender/link state, notice choice, delivery state and content-minimized security or audit evidence follow the service lifecycle described below.
Linking WhatsApp to Doxyte Patient requires an authenticated action in Doxyte. Linking by itself does not open, share or change a health record, and you can unlink the channel. Anyone who can access your phone or WhatsApp chat may see the conversation. Unlinking, deleting the chat or sending STOP does not delete your Patient account or previously confirmed journal history.
Sharing with a clinic
You choose the records included in a share and the clinic that will receive them. Doxyte must show you the selected package and recipient before you confirm the share.
Revoking a share stops covered future access where technically and legally possible. It does not erase a copy already validly received and incorporated into the clinic’s record. A Patient PHR copy and a Clinic copy have separate lifecycles and retain their source and history.
A record published by a clinic cannot be silently rewritten through the Patient service. You may hide it from your ordinary personal view, mark it disputed, or request a correction from the originating clinic without altering the clinic-issued source.
Who may receive personal data
We disclose personal data only as needed for the current service. We do not sell your health information.
- A clinic you select when you confirm a share
- You, when a clinic validly publishes a record to your PHR
- Approved providers supplying hosting, storage, identity, security, support, communications, document extraction or LLM processing
- Meta and WhatsApp as needed to transmit WhatsApp messages and delivery events when you use that optional channel
- The approved Nalan AI-processing provider, only when enabled and for the requested task, subject to Doxyte’s no-provider-training requirement
- Restricted Doxyte personnel who require access for approved support, security or operations
- Professional advisers under confidentiality where reasonably necessary
- A court, public authority or other recipient where required by law or needed to establish, exercise or defend a legal claim
Where personal data is processed
The production service is intended to keep Doxyte-controlled personal data and approved processing in India. Before this notice becomes effective, Doxyte will replace this paragraph with the verified production regions and the exact contractual location commitments of every active provider. Real patient information will remain blocked until those facts are verified.
The current provider register and effective date will be available at doxyte.com/subprocessors.
How long we keep information
Doxyte preserves your Patient PHR and longitudinal health journal while the Patient service purpose continues, including when your account is inactive but has not completed an approved closure process. This includes your journal, symptom history, uploads, received Clinic records, accepted derived information and the provenance, authorship, corrections and links needed to interpret that history. There is no universal five-year deletion date.
Exporting, hiding, unlinking, archiving or revoking access does not by itself delete valid longitudinal history. A correction to clinically meaningful patient-authored information preserves the previous value and records what changed, when and by whom.
After closure or authorized deletion, restricted compliance evidence and unexpired recovery copies may remain only for their disclosed purpose and schedule. They are not available for ordinary service use or secondary use. A scoped legal hold or applicable law may require longer retention.
| Information | Retention approach |
|---|---|
| Temporary processing files | Deleted when processing finishes; abandoned files swept within 24 hours |
| Raw provider diagnostic artifacts | No more than 30 calendar days from receipt, download or terminal job state, unless held |
| AI-only abandoned working output | Deleted after a 30-day recovery and review period; saved patient-authored history and content-bearing sources remain visibly attributed |
| WhatsApp transient content | A first message awaiting notice acceptance expires within 24 hours; processed transport content is scrubbed, and ordinary active-topic and reply content is retained for no more than 24 hours. Unfinished journal drafts follow the Patient journal lifecycle, and explicitly confirmed entries become durable Patient history |
| Content-free operational and security logs | 365 calendar days in India, unless held or otherwise legally required |
| Expired or revoked session evidence | 365 calendar days after expiry or revocation; raw session tokens are not retained |
| Daily database and non-current durable-object recovery copies | Rolling 30-calendar-day recovery window |
| Point-in-time database recovery logs | Seven calendar days for precise recent recovery |
| Explicit Patient account closure | 30-day recoverable closure period, then removal from active service and legally permitted erasure; restricted evidence and recovery copies expire separately |
Security and accountability
We use access controls, encryption, authentication controls, content-minimized logs, audit trails, restricted provider access and recovery controls appropriate to the service. You must protect your credentials and review the recipient before sharing information. No system can guarantee absolute security.
If you suspect unauthorized access, disclose no health information through an unapproved support channel. Contact security@doxyte.com promptly.
Your rights and choices
Use doxyte.com/privacy/requests or contact privacy@doxyte.com to request access or export, seek correction, withdraw an optional permission, request account closure or raise a privacy grievance. We may need to verify your identity before acting.
You may correct patient-authored information while preserving clinically meaningful history. A request about a clinic-issued record is routed to the originating clinic; Doxyte will not silently rewrite that signed source.
Withdrawal does not make earlier lawful processing invalid, erase an independently retained Clinic copy, or override information that must remain under applicable law. If processing is required to provide the Patient service, withdrawal may require account closure.
For WhatsApp, STOP stops further companion processing and UNLINK removes the channel link where available. Neither command is an account-closure or deletion request. Use the rights route or privacy contact above for access, correction, deletion or account closure.
After first giving Doxyte an opportunity to resolve a privacy grievance, you may use the applicable complaint route to the Data Protection Board of India when that route is legally available.
- A summary of your personal data being processed and the processing activities
- Information about the entities with which your personal data has been shared
- Correction, completion or updating of inaccurate or incomplete information
- Erasure where retention is no longer necessary for the specified purpose or law
- Withdrawal of consent for future consent-based processing with comparable ease
- Grievance redressal
- Nomination of another individual to exercise applicable rights in the event of your death or incapacity
Account closure
An explicit closure request requires identity verification. We will offer you an export before starting a 30-calendar-day recoverable closure period. During that period the account remains closed to ordinary use but may be restored after appropriate verification.
After the recovery period, Doxyte removes the Patient PHR from active service and erases it where legally permitted. Restricted compliance evidence and rolling recovery copies follow their own disclosed schedules and cannot be used to continue the service or for a secondary purpose.
Closing your Patient account does not delete a clinic’s validly retained clinical record. Deleting a WhatsApp chat, sending STOP or unlinking the channel does not itself close the account or erase previously confirmed Patient history.
Changes to this notice
We will maintain the version and effective date of this notice. If we materially change the purposes, data categories, recipients, AI processing, retention or rights, we will provide notice before the change applies and request a new acknowledgement or consent where required. Earlier versions and acknowledgement evidence will be preserved.
Contact and grievances
Doxyte, a company under incorporation in India
Privacy questions and grievances: privacy@doxyte.com
Rights route: doxyte.com/privacy/requests
General support: info@doxyte.com
Security reports: security@doxyte.com
For correction or erasure decisions about a clinic-controlled record, contact the clinic shown as the source of that record. Doxyte will route a request received through the above address when the responsible clinic can be identified.

