HealthPlotHealthPlot

Privacy Policy

Last updated: 31 August 2026

This Privacy Policy explains how FrontDigit Labs LLP (“we”, “us”, “our”), operating the clinic management platform and brand HealthPlot, collects, uses, shares, and protects personal data. It applies to this website (healthplot.in), the HealthPlot platform used by clinics and their patients, and the SMS, WhatsApp, and email messages we send in connection with the platform.

It is written to comply with India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 made under it. Because the DPDP framework comes into force in phases, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”) continue to apply in the meantime. This policy is intended to satisfy both, and it serves as the notice required under Section 5 of the DPDP Act and Rule 4 of the SPDI Rules.

1. Who we are and our role

HealthPlot is a product of FrontDigit Labs LLP, a Limited Liability Partnership (LLP) registered in India (GSTIN 29AAIFF4631L1Z3), with its registered office at:

301/302, 3rd Floor, InstaOffice Business Solutions Private LimitedSarjapura Main Road, near Saket Callipolis, DoddakannelliBengaluru, Bengaluru Urban, Karnataka – 560035, India

Where we are the Data Fiduciary. For personal data we collect for our own purposes — visitors to this website, the accounts and sign-in details of clinic owners and team members, the contact details and messaging preferences we use to deliver platform communications, and the technical and security logs of the platform — FrontDigit Labs LLP decides the purpose and means of processing and is the Data Fiduciary under the DPDP Act (and the “body corporate” under the SPDI Rules).

Where we are a Data Processor. When a clinic records information about its patients on the platform — profiles, visit notes, treatment plans, billing entries — the clinic is the Data Fiduciary for that data: it decides why and how the data is processed, and it is responsible for giving its patients notice and obtaining their consent. We process that data as the clinic’s Data Processor, only on the clinic’s instructions and under a written contract as Section 8(2) of the DPDP Act requires. Requests about such records should go to the clinic; we assist the clinic in responding (see Section 9).

2. Personal data we collect

We collect personal data directly from you, from the clinic you receive care from, and — for delivery status only — from our messaging providers. We do not buy personal data, and we do not collect it from social networks or data brokers.

3. Purposes and lawful basis

We process personal data only for the following purposes:

Our lawful basis under the DPDP Act is your consent (Section 6), taken when you sign up or first use the platform, together with the legitimate uses recognised in Section 7 — for example, where you have voluntarily given us your details to receive a service and have not objected to their use for that purpose, where processing is needed to comply with a law or court order, or where it is needed to respond to a medical emergency involving a threat to life or health. We keep a record of the consent you give and of any withdrawal.

We use personal data only for the purpose it was collected for, and we do not use it for advertising, profiling, or selling to third parties. You may withdraw consent at any time (see Section 8), as easily as you gave it. Withdrawing consent for processing that the service depends on may mean parts of the service no longer work for you; it does not affect processing already carried out, or processing we must continue under law.

4. SMS, WhatsApp, and email messages

The platform keeps patients informed through transactional and service messages: one-time passwords for sign-in, appointment confirmations and reminders, receipts, and updates about services you have signed up for at your clinic. These are not promotional messages. We do not sell your contact details, and we do not send third-party advertising.

SMS

Service SMS are sent under the sender ID (header) HLTPLT, registered to FrontDigit Labs LLP as a Principal Entity on the TRAI Distributed Ledger Technology (DLT) platform in accordance with the Telecom Commercial Communications Customer Preference Regulations, 2018. Each message template is registered on the DLT platform before use. SMS are delivered through our registered telemarketer / SMS aggregator, Turain Software Pvt Ltd, which processes phone numbers and message content on our behalf solely to deliver these messages.

WhatsApp

WhatsApp messages are sent from the business name HealthPlot using the WhatsApp Business Platform operated by Meta Platforms (and, where applicable, an authorised WhatsApp Business Solution Provider). Meta processes your phone number and message content to deliver messages, under its own terms and privacy policy. WhatsApp messages are sent only to numbers that have been registered with a clinic for care, and only using message templates approved by Meta.

Email

OTPs and service emails are delivered through our transactional email provider (currently Resend), which processes email addresses and message content on our behalf.

Consent and opt-out

We send these messages because you (or your clinic, on your request) registered your contact details for care at a clinic using HealthPlot. You can opt out of non-essential messages — such as reminders — at any time by telling your clinic, writing to support@healthplot.in, or using the controls WhatsApp provides in the chat; we act on opt-outs promptly and keep a record of them. Some messages, such as the OTP needed to sign in, are integral to the service and are sent only when you request them.

5. Sharing and processors

We do not sell personal data. We share it only with service providers (Data Processors) who need it to run the platform, each under a contract that limits their use of it to providing the service to us:

We also share your care and billing records with your own clinic — that is what the platform is for. Within a clinic, access is limited by role, so team members see only what their role requires. We may disclose personal data where the law requires it — for example, to tax authorities, or to a court, government agency, or law-enforcement authority under a lawful order — and, with notice where the law permits, in connection with a merger, reorganisation, or sale of the business, to a successor bound by this policy.

6. Cross-border transfers

Some of our service providers store or process data on infrastructure located outside India, including in the United States. Where that happens, we transfer personal data in accordance with Section 16 of the DPDP Act and the SPDI Rules, subject to contractual safeguards that require the same level of protection this policy provides, and we do not transfer personal data to any country or territory to which transfers have been restricted by the Central Government.

7. Retention

We keep personal data only while it is needed for the purpose it was collected for, and afterwards only for as long as the law requires. In particular:

When personal data is no longer needed, or when you withdraw consent and no legal reason to keep it remains, we erase it, and we require our processors to do the same (Section 8(7) of the DPDP Act). Data we keep only to meet a legal obligation is retained solely for that purpose and not otherwise used.

8. Your rights

Under the DPDP Act, you have the right to:

To exercise any of these rights, write to support@healthplot.in from your registered email address, or from another address with enough detail for us to verify your identity. Where a request concerns records controlled by your clinic, we will forward it to the clinic and assist the clinic in responding. We do not charge for handling these requests.

You may also give, manage, or withdraw consent through a Consent Manager registered with the Data Protection Board of India, once such services are available and integrated with the platform.

9. Your duties

Section 15 of the DPDP Act also places duties on you as a Data Principal: to give us accurate particulars, not to impersonate another person, not to suppress material information when providing personal data, and not to register a false or frivolous grievance. Please keep your contact details with your clinic up to date so that OTPs and appointment messages reach you and not someone else.

10. Children and dependants

The platform lets a parent or lawful guardian manage a dependant’s profile — for example, a child under 18 receiving care, or a person with a disability who has a lawful guardian. We process a child’s personal data only with the verifiable consent of a parent or lawful guardian, as Section 9 of the DPDP Act and the DPDP Rules require, and the clinic — as Data Fiduciary for the child’s health records — is responsible for obtaining that consent (subject to any exemption the DPDP Rules allow clinical establishments and healthcare professionals for processing limited to providing health services). We do not track or monitor the behaviour of, or direct advertising at, children — or anyone else.

11. Grievance Officer

If you have a question, concern, or complaint about how your personal data is handled, contact our Grievance Officer, designated under Section 8(9) of the DPDP Act and Rule 5(9) of the SPDI Rules:

Sreejith KEmail: support@healthplot.inPhone: +91 87922 81416FrontDigit Labs LLP, 301/302, 3rd Floor, InstaOffice Business Solutions Private Limited, Sarjapura Main Road, near Saket Callipolis, Doddakannelli, Bengaluru, Bengaluru Urban, Karnataka – 560035, India

We acknowledge grievances promptly and resolve them within 30 days of receipt. If you are not satisfied with our response, or receive none within that period, you may complain to the Data Protection Board of India (Section 13(3) of the DPDP Act).

12. Security

We protect personal data with reasonable security practices and procedures, as Section 8(5) of the DPDP Act and Rule 8 of the SPDI Rules require, appropriate to a health-records system: encryption in transit, role-based access controls so clinic team members see only what their role requires, tenant isolation between clinics, audit trails of access to records, redaction of personal identifiers from system logs, and regular backups. No system is perfectly secure. If a personal data breach affecting you occurs, we will notify you and the Data Protection Board of India without delay, as Section 8(6) of the DPDP Act and the DPDP Rules require, and we will tell you what happened and what you can do.

13. Changes to this policy

We may update this policy as the platform or the law changes. The “Last updated” date above always reflects the current version, and material changes will be notified through the platform or by message before they take effect.

14. Contact

General questions about this policy: contact@healthplot.in · +91 87922 81416. See also our Terms of Service.