1. Who we are
IndRAH.AI Private Limited ("IndRAH", "we", "us") builds conversational and operational workflows for healthcare providers. This policy explains what information we collect when you interact with an IndRAH service via a web application, WhatsApp, telephony or SMS. Why we collect it, who processes it on our behalf, how long we keep it, and the rights you have over it.
Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), IndRAH acts as a Data Fiduciary for the information described here. Where a hospital or clinic deploys IndRAH for its own patients, that provider may also be a Data Fiduciary for the clinical record it holds, and its own privacy notice applies alongside this one.
2. Information we collect
Depending on the service and channel you use, we may collect:
- Identity and contact details — your name and, on WhatsApp, your phone number and WhatsApp profile name. At a hospital or clinic web app, basic demographics may be recorded by a staff: age and gender. Additionally, we collect preferred language of communication and the department and clinician you are visiting.
- Health information you share in conversation — the symptoms, history, medications, allergies and other details you describe to the IndRAH agents, in text or speech. This is sensitive personal data and is collected only to support your consultation with your clinician.
- Voice recordings — where you speak to the assistant, the audio of your own speech is captured to transcribe it. At kiosks, audio is recorded only after you give explicit consent; the assistant's Ai-generate voice is not stored only text.
- The assistant's output — the structured summary produced for your clinician prior to your scheduled consultation and internal logs for the specific healthcare provider staff to reference.
- Technical and usage data — timestamps, message identifiers, delivery status, language settings, device and browser information, and service telemetry (such as response times and errors) used to keep the service reliable.
3. Why we use it
- To run the conversation and produce a summary that helps your clinician prepare for your consultation.
- To route you to an appropriate department or specialist within the provider's facility.
- To operate, secure, monitor and improve the service, including diagnosing faults and measuring performance.
- For approved clinical research, only where you have separately consented under a study protocol approved by an institutional ethics committee. Research data is held in a separate, pseudonymised record.
- To meet legal obligations and respond to lawful requests.
The assistant does not diagnose or provide any treatment options, ever. It gathers information and produces a structured summary for a qualified clinician, who makes all clinical decisions. No medical decision about you is made solely by IndRAH.
4. Who processes your information on our behalf
We use a small number of specialist providers to deliver the service. Each acts on our instructions as a Data Processor and is bound by contractual confidentiality and security obligations.
- Speech, translation and language services — Sarvam AI (India), for converting your speech to text, translating between Indian languages and English, and producing the assistant's spoken replies.
- Language-model processing — OpenAI, which processes the text of your conversation to understand it and generate the assistant's questions and summary. Conversation text sent for this purpose is not used by OpenAI to train its models nor stored on any of their servers.
- Cloud hosting and storage — Google Cloud and Firebase. Our application and
databases run in Google's Mumbai region (
asia-south1). - Messaging transport (WhatsApp) — Meta Platforms, when you choose to interact with us over WhatsApp. Messages are carried through the WhatsApp Business Platform under WhatsApp's privacy policy.
- Service monitoring — Pydantic Logfire (EU-hosted), which receives service telemetry so we can detect and fix faults.
5. Where your information is stored and international transfers
Our primary systems and databases are located in India. Some processors named above operate outside India (for example, language-model processing and service monitoring). Where personal data is transferred outside India, we do so only to the extent permitted by the DPDP Act and with contractual safeguards in place.
6. How long we keep it
- Conversation records and summaries are retained for as long as needed to support your care with the provider and to meet the provider's record-keeping obligations.
- Voice recordings are retained only where consented and for the period stated in that consent; you may withdraw consent at any time (see Section 8).
- Research data is retained for the period defined in the approved study protocol.
- Technical logs and telemetry are retained for a short, rolling period sufficient to operate the service.
When information is no longer needed for these purposes, we delete or irreversibly anonymise it.
7. How we protect it
All data is encrypted in transit. Access to clinical records is restricted by role (for example clinician, administrator) and every access is logged. Secrets and credentials are managed with cloud key-management services. We do not sell personal information and do not use your health information for advertising.
8. Your rights
As a Data Principal under the DPDP Act, you may:
- Ask what personal data we hold about you and receive a summary of it;
- Ask us to correct, complete or update it;
- Ask us to erase it, subject to any legal retention duty of the healthcare provider;
- Withdraw consent (for example, consent to voice recording) at any time, without affecting the lawfulness of processing before withdrawal;
- Nominate another person to exercise these rights on your behalf; and
- Raise a grievance with us, and if unresolved, with the Data Protection Board of India.
To exercise any of these rights, or to request deletion of your data, see our Data Deletion Instructions or contact us using the details in Section 11.
9. Children
Our services are intended to be used by adults, or by a parent or lawful guardian on behalf of a child in a healthcare setting. We process a child's personal data only with the verifiable consent of a parent or lawful guardian, as the DPDP Act requires.
10. Changes to this policy
We may update this policy as our services evolve. Material changes will be signposted on this page with a new "Last updated" date.
11. Contact and grievance officer
IndRAH.AI Private Limited
Grievance Officer — Data Protection
Email: osborne@indrah.in
We aim to acknowledge requests within 14 days and resolve them within 30 days.