We're in beta — first 50 clinics get 3 months free. Limited spots left.🚀 Early Access
Legal

Privacy Policy

CareNexa is committed to protecting the privacy of doctors, clinic staff, hospital administrators and patients.

Last updated: June 1, 2026

Important: CareNexa processes sensitive patient health data across ClinicOS, MediCore HIS and ClinicBot. We take privacy extremely seriously and comply with the IT Act 2000 and DPDP Act 2023.

1. Information We Collect

Clinic & Doctor data: Name, email, phone, clinic address, specialization, registration number and payment information.

Hospital data: Hospital name, branch details, staff profiles, department and bed configurations.

Patient data: Name, phone, medical history, prescriptions, visit notes, lab reports, documents and invoices — entered by authorised clinic or hospital staff.

Usage data: Login times, features used, pages visited, device and browser information for product improvement.

AI Bot conversations: WhatsApp and website chat messages processed by ClinicBot to provide bot responses and book appointments.

2. How We Use Your Data

We use your data solely to provide and improve CareNexa products — ClinicOS, MediCore HIS and ClinicBot. This includes patient management, appointment booking, billing and AI bot services.

We do not sell your data to any third party, use patient data for advertising, or share identifiable patient information without consent.

We may use anonymised, aggregated data for product analytics and platform improvement.

3. Data Storage & Security

All data is stored on encrypted servers hosted in India (MongoDB Atlas). Data is encrypted at rest (AES-256) and in transit (TLS 1.3).

Patient data is stored per clinic or hospital and is never accessible to other tenants on the platform. We perform regular security audits and maintain audit logs on all critical actions.

4. Third-Party Services

Razorpay: Payment processing. Razorpay's privacy policy applies to payment data.

Google Gemini AI: Powers the AI WhatsApp bot. Messages processed via Google's API as per Google's data policy.

Meta (WhatsApp): WhatsApp messages processed via the Meta Business API.

Twilio: SMS notifications for MediCore HIS lab results and alerts.

MongoDB Atlas: Database hosting with data stored in India regions (Mumbai).

5. Patient Rights

Patients have the right to access, correct or request deletion of their personal data. Requests should be made through the clinic or hospital that created the records, or by emailing privacy@carenexa.in.

Clinics and hospitals are responsible for obtaining appropriate patient consent for data collection and processing as required by applicable law.

6. Data Retention

Active account data is retained as long as the subscription is active. Upon cancellation, data is retained for 90 days for recovery purposes, then permanently deleted. Backup copies may be retained for up to 30 additional days.

7. ABHA / ABDM Data

MediCore HIS supports ABHA linking as part of ABDM M1 compliance. ABHA-linked data follows NHA guidelines. Field locking is enforced once ABHA is verified. Every ABHA action writes a consent audit record with timestamp, staff member and verification method.

8. Cookies

We use essential cookies for authentication and session management only. We do not use advertising or tracking cookies. Analytics are collected using privacy-friendly, aggregated methods.

9. Changes to This Policy

We will notify all account admins by email at least 14 days before making material changes to this policy.

10. Contact

For privacy queries, data deletion requests or to report a concern:
📧 privacy@carenexa.in
CareNexa Technologies, India