Version 1.1 · Effective 16 August 2026 · Previous version 1.0, 10 June 2026
Treatlly Healthtech Private Limited (“Treatlly”, “we”, “us”, “our”, or the “Platform”) operates a multi-tenant, cloud-based doctor appointment booking and practice management software-as-a-service (“SaaS”) designed for Indian doctors, clinics, and hospitals (“Tenants”). We provide the technology infrastructure that enables Tenants to manage their appointment scheduling, patient interactions, and practice operations. This Privacy Policy explains how we collect, use, store, disclose, and protect your personal data in compliance with the Information Technology Act, 2000 (“IT Act”), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and the Digital Personal Data Protection Act, 2023 (“DPDP Act”) of India.
Important Disclaimer: Treatlly is solely a technology infrastructure and service provider. We do not provide any medical treatment, medical advice, diagnosis, or healthcare services. We do not guarantee doctor availability, appointment time slots, or the quality of medical treatment provided by Tenants. All medical services are rendered independently by the respective Tenant (doctor, clinic, or hospital), and we bear no responsibility or liability whatsoever in relation to such services.
1
Information We Collect
We collect different categories of information depending on whether you are a Tenant (doctor/clinic/hospital), a patient, or a visitor to our website:
Tenant & Practitioner KYC Information: Clinic or hospital name, registered address, GSTIN (if applicable), contact details of authorised personnel, bank account or UPI details for settlement, professional registration numbers (e.g., MCI/NMC/State Medical Council registration), and subscription and billing records. Where our payment-gateway partners require it to activate fund settlement, we also collect Know-Your-Customer (KYC) identifiers and documents of the Tenant and its practitioners, which may include PAN and government-issued identity documents (such as Aadhaar). Such identity documents are collected and shared solely for payment-onboarding and statutory compliance, and are not used for any other purpose.
Doctor & Staff Information: Name, qualifications, specialisation, contact details, role-based access credentials, and profile information displayed on the Tenant’s booking page.
Patient Information: Name, mobile number (used for SMS OTP authentication), age, gender, and optionally your address, profile photo and the details of family members you add so you can book on their behalf. Also your appointment history, consultation notes and prescriptions (as entered by the Tenant), and payment transaction records.
Health Information You Provide: Where the clinic asks for it before a consultation, the reason for your visit, symptoms and how long you have had them, existing conditions, allergies, current medications, and measurements such as weight. You may also upload health documents (for example prior reports or scans). Providing these is optional — you can book an appointment without them.
ABHA / Ayushman Bharat Health Account (optional): Only if your clinic offers ABHA and you choose to use it. Creating an ABHA requires your Aadhaar number and a one-time password, which are sent to the National Health Authority to verify you; linking an existing ABHA uses your ABHA number or address. We do not store your Aadhaar number for any other purpose, and ABHA is never required in order to book an appointment or be treated.
Video Consultations: If you have a video consultation, live audio and video is carried between you and the doctor. Treatlly does not record or store these calls.
Automatically Collected Data: IP address, device type, browser information, operating system, app version, access timestamps, referring URLs, and usage analytics for platform improvement and security of OTP-based authentication flows. From your IP address we derive an approximate location (city or region level) to help clinics understand where bookings come from and to detect suspicious sign-in activity — we do not use your device’s GPS and the apps do not ask for location permission. If you allow notifications, we also store a push notification token for that device so we can send you appointment alerts.
Payment Information: Payment amounts, transaction IDs, payment status, and settlement records processed through our RBI-authorised payment-gateway partners. We do not store full credit/debit card numbers, CVV, or net-banking credentials — these are handled entirely by the payment gateway under its PCI-DSS-compliant infrastructure.
2
How We Use Your Information
To provision and maintain Tenant accounts, including white-label booking pages and doctor dashboards.
To facilitate appointment booking, SMS/OTP notifications, appointment reminders, and patient communication on behalf of Tenants.
To facilitate appointment payments and the automatic settlement of those funds to Tenants through our RBI-authorised payment-gateway partners, as per the gateway’s settlement timelines.
To generate invoices, manage subscription billing, and provide accountant-level reporting dashboards to Tenants.
To improve platform performance, troubleshoot issues, prevent fraud, and ensure security of authentication systems.
To comply with applicable Indian laws, respond to lawful requests from government authorities, and enforce our Terms of Use.
We do not sell, rent, or trade personal information or patient health data to any third party for marketing or advertising purposes.
3
Role as Infrastructure Provider
Treatlly operates as a technology infrastructure provider, offering a SaaS platform to Tenants (doctors, clinics, and hospitals). In relation to patient data, we act as a data processor — meaning we process such data strictly on behalf of and under the instructions of the respective Tenant (who is the data fiduciary/controller). Each Tenant is independently responsible for obtaining the necessary consent from their patients for collecting and processing personal and health information.
However, for a limited set of data that we process for our own purposes — namely Tenant account administration, subscription billing, platform analytics and performance monitoring, fraud prevention, and platform security — Treatlly is itself the data fiduciary and is directly responsible for that processing under the DPDP Act, 2023.
4
Data Sharing & Third-Party Processors
We may share personal data with the following categories of third parties, strictly for the purposes described in this Policy:
Payment Gateways: RBI-authorised payment aggregators that process appointment-fee payments and settle those funds directly to the Tenant’s linked settlement account via the gateway’s split-settlement facility. Treatlly does not receive, hold, pool, or control patient funds.
SMS & Communication Providers: To deliver OTP codes, appointment reminders, and transactional notifications.
Cloud Hosting & Infrastructure Providers: Our application servers, database, and uploaded files are hosted with a cloud infrastructure provider on servers located in India.
Clinical AI & Transcription Providers: Where your clinic has enabled AI-assisted features, clinical text — and, where a doctor uses voice dictation, the recorded audio — is processed by specialist AI service providers under contract, solely to structure it into prescription or assessment fields and to produce advisory suggestions the doctor then reviews. This can include the reason for visit, symptoms, duration, existing conditions, age and sex. We do not attach your name, mobile number or patient ID to these requests; free-text notes and dictation are, however, sent as written, so if a doctor types or speaks a name it would be carried in that text. Some of this processing takes place outside India — see Section 5.
Video Consultation Infrastructure: Live audio and video for a video consultation is carried by a specialist real-time communications provider, configured to India-region infrastructure. Treatlly does not record these calls.
Push Notification Services: Alerts to the mobile apps are delivered through the push notification services operated by the Android and iOS platforms. Notification content can include appointment details, and alerts sent to clinic staff can include a patient’s name or mobile number. These messages pass through platform infrastructure that operates outside India.
Analytics & Error Monitoring Providers: Where a clinic enables app analytics, pseudonymous usage events — app opens, bookings, cancellations and transaction values — are shared with an analytics provider from our servers, using a randomly generated installation identifier; your name, mobile number and health information are not included. Separately, when something goes wrong, a diagnostic error report is shared with an error-monitoring provider so we can find and fix the fault; these reports are configured not to carry personal data, and sensitive fields are filtered before they are sent.
Ayushman Bharat Digital Mission (ABDM) / National Health Authority: Only where a clinic has enabled ABHA (Health ID) features and you choose to use them. Creating or linking an ABHA sends your Aadhaar number and the one-time password you receive, or your ABHA number, to the National Health Authority. ABHA is entirely voluntary and never required to book an appointment.
Government & Legal Authorities: When required under applicable Indian law, court orders, or lawful government requests.
We do not sell, rent or trade personal data or health information, and we do not share it with advertising networks. Where a provider above is a processor acting on our instructions, it is bound by contract to process the data only for the purpose described and for no other. A current list naming each of our sub-processors is available to clinics and institutional customers on request under a data processing agreement — write to our Grievance Officer (Section 10).
5
Data Storage, Residency & Security
Where your data is stored. Our database, application servers and uploaded files — including appointments, prescriptions, clinical notes and health documents — are hosted on servers located in India. Live video consultations are configured to run on India-region infrastructure. This is the system of record, and it does not leave India.
Limited transfers outside India. A small number of specific functions are carried out by service providers that process data outside India, and only for the purpose named: (a) AI-assisted clinical features, where a clinic has enabled them — your name, mobile number and patient ID are not attached to those requests, though free-text notes and dictation are sent as written; (b) delivery of push notifications, whose content can include appointment details and, for clinic staff, a patient’s name; (c) app analytics, where a clinic enables them, which exclude your name, contact details and health information; and (d) diagnostic error monitoring, configured to exclude personal data. These transfers are made under the DPDP Act, 2023, which permits transfer to any country the Central Government has not restricted, and each provider is bound by contract to process the data only for the purpose above. If you would rather your clinic did not use the AI or analytics features, ask the clinic — both are switched on per clinic, not by you.
We implement reasonable security practices and procedures as required under the SPDI Rules and the DPDP Act, including encryption of data in transit, role-based access controls, logical tenant data isolation, and periodic security reviews. No method of transmission or storage is completely secure, and we continue to strengthen our safeguards over time.
OTP codes are short-lived and automatically expire. Session tokens are secured with industry-standard measures.
Multi-tenant architecture ensures logical data isolation — one Tenant cannot access another Tenant’s patient or operational data.
6
Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable Indian law. Tenant account data is retained for the duration of the subscription and for 60 (sixty) days after account termination, during which Tenants may request a data export.
Deletion is not always total, and we would rather say so plainly. When you ask us to delete your account, we remove your identifying details — your name, email, mobile number, profile photo, registered devices and login sessions. But Indian law requires certain records to be kept, and those we do not delete. Instead we de-identify them: the record stays, stripped of your name and contact details, so it can no longer be traced back to you through our systems.
Financial records (invoices, payment receipts, GST documents) — kept for 8 years, as required by the Income Tax Act and the Companies Act.
Medical records (prescriptions, lab orders, admission and discharge records, consultation notes) — kept for the period set by the medical-records guidance applicable to that clinic, typically 3 years for outpatient records and longer where a case is in active litigation. These records belong to the clinic, not to Treatlly, and the clinic decides on requests about them.
Backups — automated database backups may still contain your data for a short period. Backups age out within 7 days and are not restored into the live system except in an emergency, in which case we re-run the deletion afterwards.
We complete deletion within 30 days of verifying who you are. Full details, including how to make the request for each type of account, are on our Account & Data Deletion page.
7
Your Rights Under Indian Law
Subject to applicable provisions of the DPDP Act, 2023 and SPDI Rules, you have the following rights:
Right to Access: You may request confirmation of whether we hold your personal data and obtain a copy of such data.
Right to Correction: You may request correction of inaccurate or incomplete personal data.
Right to Erasure: You may request deletion of your personal data, subject to applicable legal retention requirements.
Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.
Right to Grievance Redressal: You may raise a grievance with our Grievance Officer (details below).
For Patients: Since we process patient data on behalf of Tenants, patients should first contact their respective doctor, clinic, or hospital for data access, correction, or deletion requests. If the Tenant is unresponsive, patients may contact us directly.
8
Children’s Privacy
Our Platform is not intended to be used directly by individuals under the age of 18. Where an appointment is booked for a minor, it must be initiated by a parent or lawful guardian, who is responsible for providing consent on the child’s behalf.
Under the DPDP Act, 2023, the processing of a child’s personal data requires verifiable consent of a parent or lawful guardian. As the data fiduciary for patient data, each Tenant (doctor, clinic, or hospital) is responsible for obtaining such verifiable parental consent before a minor’s data is processed through the Platform, and Treatlly provides the technical means to support this. We do not undertake any tracking, behavioural monitoring, or targeted advertising directed at children. If we become aware that a minor’s personal data has been processed without the required verifiable parental consent, we will take steps to delete it promptly.
9
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Any material changes will be communicated via email to registered Tenants or by posting a prominent notice on the Platform. Continued use of the Platform after such changes constitutes acceptance of the updated Policy.
10
Grievance Officer & Contact
In accordance with Section 5(2) of the SPDI Rules and the DPDP Act, 2023, the name and contact details of the Grievance Officer are as follows:
Treatlly Healthtech Private Limited
CIN: U86909BR2026PTC084623
Registered office: 1R-T5, Saakaar Aquacity, Patna 801105, Bihar, India
We shall acknowledge your grievance within 48 hours and endeavour to resolve it within 30 days from the date of receipt. Nothing in this Policy limits your right to approach the Data Protection Board of India or any other competent authority under applicable law.
11
Governing Law & Jurisdiction
This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of India. Any disputes arising out of or in connection with this Privacy Policy between Treatlly and any Tenant (doctor, clinic, or hospital) shall be subject to the exclusive jurisdiction of the Civil Courts at Patna, Bihar, India.