Privacy
Last updated 7 September 2026
Who holds the data
When a clinic uses Aariva, the clinic decides what patient information is collected and why. Under India’s Digital Personal Data Protection Act, that makes the clinic the Data Fiduciary and Aariva its Data Processor: we hold and process records on the clinic’s instructions. Patients should direct requests about their records to their clinic in the first instance.
We cannot and do not claim to be “DPDP compliant” as a property of the software — compliance is a status the clinic holds. What we can say is that the product is built to help a clinic meet those obligations, and that the substantive DPDP Rules take effect in May 2027.
What we store
- Clinic and staff account details: name, email address, role.
- Patient records the clinic enters: demographics, contact details, visit notes, prescriptions, observations, invoices and payments.
- Files uploaded by the clinic or a patient, held in private storage and served only through authenticated, expiring links.
- An audit trail of who did what, and delivery records for messages we send.
Where it is stored
During this pilot the database is hosted in Singapore and uploaded files sit in Cloudflare R2’s network. India does not require health records to be stored in India, so this is lawful — but we are stating it plainly rather than implying local storage. Moving to India-region hosting is a decision we expect to take before any real patient data is handled.
Who can see a record
Access is checked on the server for every request. Clinic staff see only their own clinic’s records. A patient sees only their own chart, and only after accepting an invitation sent to a verified address — never because a name, phone number or email happened to match. Platform administrators see account and operational information; they have no route into a patient chart.
Messages
We send appointment and follow-up email where a patient has opted in, and we record that consent with the wording shown at the time. Opting out stops it. Message content is kept deliberately sparse and links are authenticated.
Retention and deletion
Each clinic sets a retention period, defaulting to three years. Indian medical ethics regulations set three years for in-patient records and do not fix a period for outpatient records, so this is a practice judgement rather than a statutory figure. Clinics can export their records at any time.
Contact
Questions about this notice: hello@supernetrix.com.