Privacy Policy
Last updated: 31 August 2026
This Privacy Policy explains how FrontDigit Labs LLP (“we”, “us”, “our”), operating the clinic management platform and brand HealthPlot, collects, uses, shares, and protects personal data. It applies to this website (healthplot.in), the HealthPlot platform used by clinics and their patients, and the SMS, WhatsApp, and email messages we send in connection with the platform.
It is written to comply with India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 made under it. Because the DPDP framework comes into force in phases, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”) continue to apply in the meantime. This policy is intended to satisfy both, and it serves as the notice required under Section 5 of the DPDP Act and Rule 4 of the SPDI Rules.
1. Who we are and our role
HealthPlot is a product of FrontDigit Labs LLP, a Limited Liability Partnership (LLP) registered in India (GSTIN 29AAIFF4631L1Z3), with its registered office at:
301/302, 3rd Floor, InstaOffice Business Solutions Private LimitedSarjapura Main Road, near Saket Callipolis, DoddakannelliBengaluru, Bengaluru Urban, Karnataka – 560035, India
Where we are the Data Fiduciary. For personal data we collect for our own purposes — visitors to this website, the accounts and sign-in details of clinic owners and team members, the contact details and messaging preferences we use to deliver platform communications, and the technical and security logs of the platform — FrontDigit Labs LLP decides the purpose and means of processing and is the Data Fiduciary under the DPDP Act (and the “body corporate” under the SPDI Rules).
Where we are a Data Processor. When a clinic records information about its patients on the platform — profiles, visit notes, treatment plans, billing entries — the clinic is the Data Fiduciary for that data: it decides why and how the data is processed, and it is responsible for giving its patients notice and obtaining their consent. We process that data as the clinic’s Data Processor, only on the clinic’s instructions and under a written contract as Section 8(2) of the DPDP Act requires. Requests about such records should go to the clinic; we assist the clinic in responding (see Section 9).
2. Personal data we collect
- Identity and contact details — name, phone number, email address, date of birth, and gender, provided when you or your clinic create your profile.
- Sign-in data — your phone number or email address, used to send a one-time password (OTP), and the record of each sign-in. We do not use passwords.
- Appointment and service records — bookings, attendance, invoices, receipts, and payment records relating to your clinic visits. We do not collect or store card or bank details; payments a clinic collects are handled by the clinic and its own payment provider.
- Health information entered by your clinic — conditions, treatment plans, prescribed exercise programs, check-in responses, and progress notes. This is “sensitive personal data or information” under the SPDI Rules. We process it on your clinic’s behalf, as described in Section 1.
- Communication records — the service messages sent to you (SMS, WhatsApp, email), their delivery status, and your messaging preferences, including any opt-out.
- Technical data — device and browser information, IP address, and usage logs collected when you use the platform, to keep it secure and working. This public website sets no cookies and uses no analytics or advertising trackers; the platform uses cookies only to keep you signed in.
We collect personal data directly from you, from the clinic you receive care from, and — for delivery status only — from our messaging providers. We do not buy personal data, and we do not collect it from social networks or data brokers.
3. Purposes and lawful basis
We process personal data only for the following purposes:
- to create and secure your account, and to sign you in with OTPs;
- to run clinic operations — scheduling, billing and GST invoicing, records, and care programs;
- to send service communications about your care (see Section 4);
- to respond to enquiries, support requests, and grievances;
- to maintain security, prevent misuse, and keep the audit trails a health-records system requires; and
- to meet our legal obligations, including under tax, accounting, and telecom regulation.
Our lawful basis under the DPDP Act is your consent (Section 6), taken when you sign up or first use the platform, together with the legitimate uses recognised in Section 7 — for example, where you have voluntarily given us your details to receive a service and have not objected to their use for that purpose, where processing is needed to comply with a law or court order, or where it is needed to respond to a medical emergency involving a threat to life or health. We keep a record of the consent you give and of any withdrawal.
We use personal data only for the purpose it was collected for, and we do not use it for advertising, profiling, or selling to third parties. You may withdraw consent at any time (see Section 8), as easily as you gave it. Withdrawing consent for processing that the service depends on may mean parts of the service no longer work for you; it does not affect processing already carried out, or processing we must continue under law.
4. SMS, WhatsApp, and email messages
The platform keeps patients informed through transactional and service messages: one-time passwords for sign-in, appointment confirmations and reminders, receipts, and updates about services you have signed up for at your clinic. These are not promotional messages. We do not sell your contact details, and we do not send third-party advertising.
SMS
Service SMS are sent under the sender ID (header) HLTPLT, registered to FrontDigit Labs LLP as a Principal Entity on the TRAI Distributed Ledger Technology (DLT) platform in accordance with the Telecom Commercial Communications Customer Preference Regulations, 2018. Each message template is registered on the DLT platform before use. SMS are delivered through our registered telemarketer / SMS aggregator, Turain Software Pvt Ltd, which processes phone numbers and message content on our behalf solely to deliver these messages.
WhatsApp messages are sent from the business name “HealthPlot” using the WhatsApp Business Platform operated by Meta Platforms (and, where applicable, an authorised WhatsApp Business Solution Provider). Meta processes your phone number and message content to deliver messages, under its own terms and privacy policy. WhatsApp messages are sent only to numbers that have been registered with a clinic for care, and only using message templates approved by Meta.
OTPs and service emails are delivered through our transactional email provider (currently Resend), which processes email addresses and message content on our behalf.
Consent and opt-out
We send these messages because you (or your clinic, on your request) registered your contact details for care at a clinic using HealthPlot. You can opt out of non-essential messages — such as reminders — at any time by telling your clinic, writing to support@healthplot.in, or using the controls WhatsApp provides in the chat; we act on opt-outs promptly and keep a record of them. Some messages, such as the OTP needed to sign in, are integral to the service and are sent only when you request them.
5. Sharing and processors
We do not sell personal data. We share it only with service providers (Data Processors) who need it to run the platform, each under a contract that limits their use of it to providing the service to us:
- Cloud hosting — our application and databases run on Railway, with network delivery and security by Cloudflare;
- SMS delivery — Turain Software Pvt Ltd (registered telemarketer / aggregator);
- WhatsApp delivery — Meta Platforms (WhatsApp Business Platform);
- Email delivery — Resend.
We also share your care and billing records with your own clinic — that is what the platform is for. Within a clinic, access is limited by role, so team members see only what their role requires. We may disclose personal data where the law requires it — for example, to tax authorities, or to a court, government agency, or law-enforcement authority under a lawful order — and, with notice where the law permits, in connection with a merger, reorganisation, or sale of the business, to a successor bound by this policy.
6. Cross-border transfers
Some of our service providers store or process data on infrastructure located outside India, including in the United States. Where that happens, we transfer personal data in accordance with Section 16 of the DPDP Act and the SPDI Rules, subject to contractual safeguards that require the same level of protection this policy provides, and we do not transfer personal data to any country or territory to which transfers have been restricted by the Central Government.
7. Retention
We keep personal data only while it is needed for the purpose it was collected for, and afterwards only for as long as the law requires. In particular:
- Account and contact details — while your account or your clinic’s relationship with us is active, and for a short period afterwards to handle any queries.
- Invoices, receipts, and payment records — for the periods prescribed by GST, income-tax, and LLP law (up to eight years).
- Health records — for the periods prescribed by the regulations that apply to the clinic and its practitioners (commonly at least three years from the last entry, and longer where a State’s clinical-establishment rules require). These periods are set by the clinic as Data Fiduciary.
- Consent and opt-out records, and audit trails — for as long as needed to demonstrate compliance.
- Message logs — delivery records are kept for the period telecom regulation requires; OTPs expire within minutes and are not retained after use.
When personal data is no longer needed, or when you withdraw consent and no legal reason to keep it remains, we erase it, and we require our processors to do the same (Section 8(7) of the DPDP Act). Data we keep only to meet a legal obligation is retained solely for that purpose and not otherwise used.
8. Your rights
Under the DPDP Act, you have the right to:
- Access (Section 11) — request a summary of the personal data we process about you, how it is processed, and the Data Fiduciaries and Data Processors it has been shared with;
- Correction, completion, and updating (Section 12) — have inaccurate or incomplete data corrected or updated;
- Erasure (Section 12) — request erasure of your personal data, unless retention is required by law;
- Withdraw consent (Section 6) — withdraw your consent at any time, with effect for future processing;
- Grievance redressal (Section 13) — have your complaint heard and addressed (see Section 10); and
- Nomination (Section 14) — nominate a person to exercise these rights on your behalf in the event of your death or incapacity.
To exercise any of these rights, write to support@healthplot.in from your registered email address, or from another address with enough detail for us to verify your identity. Where a request concerns records controlled by your clinic, we will forward it to the clinic and assist the clinic in responding. We do not charge for handling these requests.
You may also give, manage, or withdraw consent through a Consent Manager registered with the Data Protection Board of India, once such services are available and integrated with the platform.
9. Your duties
Section 15 of the DPDP Act also places duties on you as a Data Principal: to give us accurate particulars, not to impersonate another person, not to suppress material information when providing personal data, and not to register a false or frivolous grievance. Please keep your contact details with your clinic up to date so that OTPs and appointment messages reach you and not someone else.
10. Children and dependants
The platform lets a parent or lawful guardian manage a dependant’s profile — for example, a child under 18 receiving care, or a person with a disability who has a lawful guardian. We process a child’s personal data only with the verifiable consent of a parent or lawful guardian, as Section 9 of the DPDP Act and the DPDP Rules require, and the clinic — as Data Fiduciary for the child’s health records — is responsible for obtaining that consent (subject to any exemption the DPDP Rules allow clinical establishments and healthcare professionals for processing limited to providing health services). We do not track or monitor the behaviour of, or direct advertising at, children — or anyone else.
11. Grievance Officer
If you have a question, concern, or complaint about how your personal data is handled, contact our Grievance Officer, designated under Section 8(9) of the DPDP Act and Rule 5(9) of the SPDI Rules:
Sreejith KEmail: support@healthplot.inPhone: +91 87922 81416FrontDigit Labs LLP, 301/302, 3rd Floor, InstaOffice Business Solutions Private Limited, Sarjapura Main Road, near Saket Callipolis, Doddakannelli, Bengaluru, Bengaluru Urban, Karnataka – 560035, India
We acknowledge grievances promptly and resolve them within 30 days of receipt. If you are not satisfied with our response, or receive none within that period, you may complain to the Data Protection Board of India (Section 13(3) of the DPDP Act).
12. Security
We protect personal data with reasonable security practices and procedures, as Section 8(5) of the DPDP Act and Rule 8 of the SPDI Rules require, appropriate to a health-records system: encryption in transit, role-based access controls so clinic team members see only what their role requires, tenant isolation between clinics, audit trails of access to records, redaction of personal identifiers from system logs, and regular backups. No system is perfectly secure. If a personal data breach affecting you occurs, we will notify you and the Data Protection Board of India without delay, as Section 8(6) of the DPDP Act and the DPDP Rules require, and we will tell you what happened and what you can do.
13. Changes to this policy
We may update this policy as the platform or the law changes. The “Last updated” date above always reflects the current version, and material changes will be notified through the platform or by message before they take effect.
14. Contact
General questions about this policy: contact@healthplot.in · +91 87922 81416. See also our Terms of Service.