Legal
Data Processing Overview
How clinic customer data is processed when you use VaitalCare as a service provider.
Last updated: 5 August 2026
This page is a product-facing overview for clinics and partners. It is not a signed Data Processing Agreement (DPA). Enterprise customers may request a formal DPA via vaitalcare.bnglr@gmail.com.
1. Roles
- Clinic (customer): typically the data fiduciary / controller for patient personal data collected in the course of care and operations.
- VaitalCare: processes such data on the clinic’s instructions to provide the product (data processor / service provider role for that dataset).
2. Subject matter and purpose
Processing enables QR intake, queue and visit context, digital prescription delivery, automated WhatsApp retention messages, delivery logging, and clinic analytics surfaces configured for the tenant.
3. Categories of data
- Identity and contact (e.g. name, phone) as entered by staff or patients via intake.
- Visit and prescription-related content required for messaging and history features.
- Technical metadata (message IDs, delivery status, timestamps, clinic IDs).
- Staff authentication identifiers for authorised users of the dashboard.
Clinics should minimise sensitive data in free-text fields where not required for the workflow.
4. Instructions and ownership
Patient records remain the clinic’s. VaitalCare does not use clinic patient data for advertising, resale, or training public models for unrelated third parties. Access by VaitalCare personnel is limited to support, security, and operations under need-to-know controls.
5. Subprocessors
Hosting, database, authentication, and official WhatsApp API providers (e.g. cloud hosting / Supabase stack, Twilio WhatsApp as configured) process data to deliver the service. An up-to-date subprocessor list can be provided on request for contracted customers.
6. Security measures (summary)
- HTTPS/TLS for data in transit
- Role-based access and clinic-scoped data isolation
- Credentials and secrets kept out of client-side code for privileged operations
- Operational logging for abuse detection and reliability
7. International transfers
Infrastructure region depends on the active environment. If processing occurs outside India, we will disclose that to contracted customers and use appropriate contractual protections where required.
8. Retention and deletion
Data is retained while the subscription is active and for a limited period thereafter for backups/legal needs, unless a signed agreement specifies otherwise. Clinics may request export or deletion subject to law and retention required for dispute or regulatory purposes.
9. Breach notification
We investigate suspected personal data breaches affecting the service and notify affected contracted customers without undue delay where required by applicable law or agreement.
10. Related documents
Curious how this works in your clinic?
Book a short demo or email us — we respond within one business day.