01
Who we are
Nitya Aarogya is a product operated by Trinetra Technologies, a sole proprietorship of Shubham Desoria.
353, Trinetra Technologies, Ganj Bazaria, Near Old Bus Stand,Sehore, Madhya Pradesh – 466001, India.
Privacy and support contact: Shubham Desoria
business@nitya-aarogya.com
Clinics decide which patient information to enter, how it is used for care and clinic operations, and which staff may access it. We provide software and process clinic information to deliver the service under the clinic's instructions and our agreement with it. We also handle information for account administration, subscription billing, support and security.
A clinic may have its own privacy notice for its medical services. Patients should normally contact their clinic first about medical records; we can help coordinate a request received by us.
02
Information we process
The information depends on the features you or your clinic use. It may include:
- Clinic and staff names, contact details, professional information, roles, account credentials and activity.
- Patient names, contact details, age or date of birth, gender, address, photographs and patient identifiers. The application includes an Aadhaar information field; clinics should use it only where necessary and appropriately authorized.
- Appointments, consultation notes, medical histories, vital signs, prescriptions, reports, uploaded documents, pharmacy and laboratory records, and billing information.
- For connected messaging: phone and account identifiers, messages, attachment references, templates and delivery or read status.
- Subscription and payment references, transaction status, invoices and related customer details.
- Support messages, IP addresses, device or browser information, access and security logs, and notification tokens where the relevant service is enabled.
Information may be supplied by you, your clinic, authorized staff or a connected provider. Please provide only information necessary for the relevant service.
03
How we use information
We process information to provide accounts and clinic workflows; manage appointments, records, documents and billing; operate enabled communications and consultations; respond to support and privacy requests; protect the service; investigate errors or misuse; and meet applicable obligations.
Trinetra Technologies does not use customer or patient personal information for advertising or to train AI models. We do not sell that information or share it with marketing companies.
AI-assisted clinical summaries and translation are not configured in our production service as of the date above. Before enabling features that send information to an AI provider, we will update the relevant disclosures and establish the appropriate provider settings and permissions. Our statement about our own use of information is not a blanket claim about an independent provider's practices.
04
Providers and sharing
Google Cloud provides application hosting and file storage; MongoDB Atlas provides database hosting. The main website's hosting provider processes technical information needed to deliver the site. Razorpay supports subscription payment features; a payment provider may collect payment details directly through its checkout.
Where enabled, WhatsApp messaging involves Meta/WhatsApp, email delivery involves the configured email provider, and push notifications involve Google Firebase. We share information needed for the relevant function. Provider processing may also be governed by the provider's terms and privacy notice. Not every integration is enabled for every clinic or in every release.
Authorized clinic staff can access records according to their permissions. We may disclose information to comply with applicable law or a valid legal process, or as necessary to investigate misuse and protect rights or safety. Information may be processed outside India depending on the provider and service; we do not promise that every copy or every processing activity remains in India.
05
Connected features and browser storage
WhatsApp and other communications
Where messaging is enabled, clinics must obtain the appropriate messaging permission and honor opt-out requests. Tell the sending clinic if you want messages to stop, or contact us for help. Withdrawing messaging permission is separate from deleting medical records. Recipients and messaging providers may retain their own copies.
Browser storage
The applications store authentication tokens and preferences in your browser, including an optional remembered email address. Clearing this storage may sign you out; it does not delete server-side records. Website hosting and connected services may use technical cookies or similar storage needed to operate their features.
Video consultations
Our self-hosted MiroTalk service processes connection information to establish video consultations. Audio and video are transmitted between participants, with relay infrastructure when needed. The video software supports participant-initiated recording and download to the recording participant's device. Participants must obtain the necessary permissions before recording and protect any downloaded copies. Deletion from our systems does not remove recordings or other copies held independently by participants.
06
Retention and deletion
Clinic and patient information is retained while needed to provide the service, subject to the clinic's documented instructions and applicable record-keeping obligations. There is no single expiry period suitable for every medical record. Necessary billing, security or dispute-related information may be retained for the relevant purpose or obligation.
Cancelling a subscription does not automatically erase clinic data. The patient removal action deactivates a record and cancels scheduled appointments; it is not complete erasure of the record or related data. Contact us for a separate, verified deletion request.
After verification and agreement on the scope, we aim to complete approved active-system deletion within the request-handling period below, except for specifically identified required records. Our operational target for residual backups is removal within 90 calendar days after approved active-system deletion, subject to documented legal retention. This is a managed request process, not an automatic deletion guarantee: provider backup restrictions or other technical constraints may require a different schedule, which we will explain in our response. We do not represent that all systems currently have an automatic 90-day purge.
We will explain information that must be retained and the reason, and coordinate relevant provider-held copies where possible. Copies held independently by clinics, recipients or other providers may require a request to those organizations. See data-deletion instructions.
07
Your requests and complaints
Email business@nitya-aarogya.com, addressed to Shubham Desoria, for privacy questions, complaints, or requests concerning access, correction, deletion or withdrawal of permission, as applicable.
Include your name, relevant clinic or account, a contact method and a description of your request. Do not send passwords, full identity-document numbers or medical attachments in your initial email. We may need to verify identity and authority and coordinate with your clinic before acting.
Our service targets are to acknowledge requests within 7 calendar days and aim to resolve them within 30 calendar days after necessary verification. We will explain delays, remaining steps or lawful retention. Applicable shorter legal deadlines take precedence. These service targets do not limit your rights under applicable law.
08
Security and children's information
We use safeguards such as HTTPS, authentication and clinic-scoped access controls. These measures reduce risk but cannot eliminate every risk. Users should protect their login details and use appropriate access permissions.
Clinics may treat children and enter their records. Clinics are responsible for establishing the necessary authority and parent or guardian involvement where required. A parent or guardian may contact the clinic or our privacy contact about a child's information, subject to verification and applicable requirements.
09
Changes to this policy
We may update this policy as our services or requirements change. This page shows the last updated date. Where required, we will provide additional notice or obtain the necessary permission for material changes.