Docwo
Last updated: September 12, 2026Version 1.0

Privacy Policy

Effective Date: March 15, 2026
Version: 1.0
Data Fiduciary: DOCWO SERVICES PRIVATE LIMITED
Registered Office: Building No. 5/257A8, Suite No. 162 B, Heiley Offices, Basement Floor, Pallath Square, Kalamassery, Ernakulam, Kanayannur, Kerala, India, 683104
Contact / Privacy Office: privacy@docwo.com | +91 99614 53665


1. Introduction and Scope

DOCWO SERVICES PRIVATE LIMITED ("Docwo", "We", "Us", or "Our") recognizes the supreme importance of privacy, confidentiality, and data security. This Privacy Policy ("Policy") governs the collection, processing, storage, encryption, disclosure, and protection of personal data and protected health information obtained when you access or interact with our web applications, mobile applications, APIs, and clinic management portals (the "Platform").

This Policy is formulated in strict compliance with:

  • The Digital Personal Data Protection Act, 2023 (DPDPA);
  • The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules);
  • The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
  • Technical standards benchmarked against the General Data Protection Regulation (EU GDPR 2016/679) and the Health Insurance Portability and Accountability Act of 1996 (US HIPAA) for cross-border data protection and healthcare institutional security.

2. Roles: Data Fiduciary and Data Processor

  1. Docwo as Data Fiduciary: In relation to user account management, authentication credentials, billing records, device identifiers, marketing preferences, and platform usage telemetry, Docwo acts as the Data Fiduciary (or "Data Controller" under GDPR).
  2. Docwo as Data Processor: In relation to specific clinical consultation notes, diagnostic findings, treatment plans, and e-prescriptions authored by independent medical practitioners during clinic visits, the respective Clinic or Doctor acts as the primary Data Fiduciary, and Docwo operates as a Data Processor providing secure, encrypted cloud hosting and transmission infrastructure.

3. Categories of Data Collected

We collect only such data as is strictly necessary to provide seamless, secure healthcare appointment and clinic queue management services.

3.1 Personal Identifiable Information (PII)

  • Identity & Contact Details: Full legal name, mobile phone number, email address, physical address, date of birth, gender, and profile image.
  • Verification Evidence: One-Time Password (OTP) verification timestamps and audit hashes.

3.2 Sensitive Personal Data or Information (SPDI) / Health Data

  • Clinical Details: Reason for consultation, reported symptoms, vital signs, clinical notes, past medical history uploaded by the patient, diagnostic reports, and digital e-prescriptions.
  • Queue and Appointment Records: Doctor selection, clinic location, appointment date and slot, generated token number, check-in status, and consultation timestamps.

3.3 Financial and Transactional Information

  • Billing Details: Clinic invoices, consultation fee breakdown, platform convenience fees, payment status, and Razorpay transaction/order identifiers.
  • Important: Docwo never collects or stores full credit/debit card numbers, CVVs, or Net Banking credentials on its servers. All card and banking transactions are processed directly by our PCI-DSS Level 1 certified payment partner, Razorpay.

3.4 Technical, Device, and Telemetry Data

  • Device & Connection: IP address, browser type and version, mobile operating system, device model, time zone, network carrier, and session duration.
  • Push Notification Tokens: Encrypted Firebase Cloud Messaging (FCM) device tokens utilized solely to deliver queue status updates and appointment alerts.

3.5 Security Controls

All collected data is safeguarded through multiple layers of protection:

  • AES-256-GCM Field Encryption — Applied to personal identifiers, health data, and financial records at rest.
  • TLS 1.3 In-Transit Encryption — All data in motion between your device and our servers is encrypted.
  • Blind HMAC Indexing — Phone numbers and emails are searched using hashed indexes, preventing plaintext exposure.

4. Legal Grounds and Purposes of Data Processing

We process your data only pursuant to lawful, specified grounds recognized under Section 4 and Section 6 of the DPDPA 2023 and Article 6 and 9 of the GDPR:

Purpose of Processing Category of Data Lawful Basis (DPDPA / GDPR)
Account Creation & Authentication Name, Phone, Email, OTP Performance of Contract (Terms of Service)
Appointment Booking & OPD Token Queueing Patient Name, Doctor ID, Slot Time, Token Performance of Contract
E-Prescriptions & Medical Records Storage Health Data, Symptoms, Prescriptions Explicit Consent & Facilitation of Healthcare
Payment Processing & Automated Invoicing Fee amounts, Razorpay Payment IDs Performance of Contract & Tax Legal Duty
Queue Alerts & Transactional Notifications Phone, Email, FCM Device Tokens Performance of Contract & Legitimate Service Purpose
Fraud Prevention & Security Auditing IP Address, User Agent, Activity Logs Legal Obligation & System Integrity
Marketing & Health Campaigns (Optional) Email, Phone (Strict Opt-in) Explicit Prior Consent (freely given)

5. Security Safeguards and Technical Measures

Docwo maintains enterprise-grade administrative, physical, and technical safeguards complying with Section 8(5) of DPDPA 2023, Rule 5(8) of the SPDI Rules 2011, and ISO/IEC 27001 standards:

  1. Field-Level Database Encryption: Sensitive medical and identifiable fields (such as patient names, contact numbers, symptoms, notes, and prescriptions) are encrypted at rest using AES-256-GCM.
  2. Key Management Hierarchy: Master Encryption Keys (MEK) are generated and stored in Hardware Security Modules (HSMs). Application servers utilize transient Data Encryption Keys (DEKs) that rotate regularly.
  3. Encryption in Transit: All communications between client devices, the API server, and backend services are enforced via TLS 1.3 with strict HTTPS and HSTS headers.
  4. Blind Indexing for Search: Phone numbers and email addresses are searched using salted SHA-256 blind indexes, preventing plaintext exposure during database queries.
  5. Role-Based Access Control (RBAC): Strict least-privilege access controls segregate clinic staff, doctors, and system administrators. Clinic receptionists cannot access external clinic records or unauthorized medical notes.
  6. Push Notification PHI-Free Policy: Push notifications displayed on device lock screens are strictly stripped of Protected Health Information (PHI). They display generic queue status (e.g., "Your token #14 has been called"), with specific medical details accessible only post-authentication inside the application.

6. Data Sharing and Third-Party Processors

Docwo never sells, rents, or monetizes your personal or medical data. We disclose data strictly to the following verified processors under binding Data Protection Agreements (DPAs):

  1. Independent Clinics and Consulting Doctors: The medical practitioner and clinic staff selected by you receive your patient profile, symptoms, and previous consultation history solely to facilitate your clinical examination and treatment.
  2. Payment Aggregators (Razorpay): Necessary transaction amounts and order metadata are transmitted securely to Razorpay to verify and capture payments and disburse automated refunds.
  3. Cloud Infrastructure (AWS / Microsoft Azure): Encrypted database storage, container hosting, and Key Vault services. Servers are physically located in secure enterprise data center regions in India.
  4. Communication & Messaging Gateways:
    • Postmark: For transactional emails and digital invoices.
    • Twilio: For high-priority SMS notifications, routed strictly through Telecom Regulatory Authority of India (TRAI) approved DLT headers.
    • Firebase Cloud Messaging (Google FCM): For real-time mobile push notifications.
  5. Law Enforcement & Statutory Mandates: We may disclose records if required to do so under a lawful court order, warrant, or statutory directive issued under Section 69A of the IT Act, 2000 or other applicable legislation.

7. Data Subject and Data Principal Rights

Under the DPDPA 2023 (Sections 11–14) and GDPR (Articles 15–22), you possess the following actionable rights:

  1. Right to Access and Summary: You have the right to obtain a summary of all personal data held by Docwo, including the processing activities undertaken and third parties with whom data has been shared.
  2. Right to Correction and Updating: You may correct, rectify, or update inaccurate, incomplete, or outdated personal information through your profile settings.
  3. Right to Erasure / Deletion: You may request the deletion of your account and personal data. Deletion is executed in accordance with our Account Deletion and Retention Policy, subject to mandatory statutory medical and tax retention exemptions.
  4. Right to Withdraw Consent: You may withdraw consent for optional data processing (such as marketing emails or health tips) at any time via the Preference Centre or one-click unsubscribe links. Revocation takes effect within 60 seconds.
  5. Right to Nominate: Under Section 14 of DPDPA 2023, you have the right to nominate an individual who, in the event of your death or incapacity, shall exercise your privacy rights on your behalf.
  6. Right of Grievance Redressal: You have the right to readily available grievance redressal through our designated Grievance Officer.

All rights requests are acknowledged within forty-eight (48) hours and resolved within fifteen (15) business days.


8. Children's Personal Data (Section 9 DPDPA)

  1. Docwo does not permit individuals below the age of eighteen (18) to register primary accounts or independently consent to data processing.
  2. Children's health information may only be processed when submitted by a verified parent or legal guardian under a Dependent Profile. The parent warrants that they possess lawful custody and parental authority.
  3. In strict compliance with Section 9(2) of the DPDPA 2023, Docwo never undertakes tracking, behavioral monitoring, or targeted advertising directed at children or using children's data.

9. Data Retention and Deletion Schedule

We retain data only as long as necessary to fulfill the purposes for which it was collected or to satisfy statutory legal, accounting, and healthcare retention requirements:

Data Classification Active System Period Cold Storage Archive Total Statutory Retention Deletion / Disposal Method
User Profile & Credentials Account Lifetime 30 Days (Soft-Delete) 30 Days post-request Cryptographic erasure & hard DB delete
Medical Records & Prescriptions 2 Years 8 Years 10 Years (Statutory IMC/NMC Mandate) Immutable encrypted cold storage
Invoices & Billing Transactions 2 Years 5 Years 7 Years (Income Tax & GST Act) Secure electronic archive
Security & Compliance Audit Logs 1 Year 6 Years 7 Years (DPDPA/IT Act Compliance) Automated permanent purge
Session Cache & Exported Files 7 Days None 7 Days Automated daily cleanup

10. Data Breach Notification Protocol

In the unlikely event of a security incident or personal data breach affecting your information:

  1. Docwo will immediately activate its Incident Response Plan to contain, isolate, and remediate the breach.
  2. Pursuant to Section 8(6) of the DPDPA 2023 and CERT-In directions under Section 70B of the IT Act, Docwo shall promptly report the breach to the Data Protection Board of India (DPBI), the Indian Computer Emergency Response Team (CERT-In), and affected data principals without undue delay, detailing the nature of the breach, affected data categories, and remedial steps taken.

11. Grievance Redressal Officer and DPO Contact

If you have any questions, concerns, objections, or complaints regarding this Privacy Policy or our data handling practices, please contact our designated Grievance Redressal Officer:

  • Officer: Grievance Redressal Officer & Data Protection Lead
  • Company: DOCWO SERVICES PRIVATE LIMITED
  • Office Address: Building No. 5/257A8, Suite No. 162 B, Heiley Offices, Basement Floor, Pallath Square, Kalamassery, Ernakulam, Kanayannur, Kerala, India, 683104
  • Direct Privacy Email: privacy@docwo.com
  • Official Grievance Email: grievance@docwo.com
  • Helpline: +91 99614 53665 (Mon–Sat, 10:00 AM – 6:00 PM IST)

Response Commitment:

  • Acknowledgment within forty-eight (48) hours.
  • Written resolution within fifteen (15) business days.