CareNexa is committed to protecting the privacy of doctors, clinic staff, hospital administrators and patients.
Last updated: June 1, 2026
Clinic & Doctor data: Name, email, phone, clinic address, specialization, registration number and payment information.
Hospital data: Hospital name, branch details, staff profiles, department and bed configurations.
Patient data: Name, phone, medical history, prescriptions, visit notes, lab reports, documents and invoices — entered by authorised clinic or hospital staff.
Usage data: Login times, features used, pages visited, device and browser information for product improvement.
AI Bot conversations: WhatsApp and website chat messages processed by ClinicBot to provide bot responses and book appointments.
We use your data solely to provide and improve CareNexa products — ClinicOS, MediCore HIS and ClinicBot. This includes patient management, appointment booking, billing and AI bot services.
We do not sell your data to any third party, use patient data for advertising, or share identifiable patient information without consent.
We may use anonymised, aggregated data for product analytics and platform improvement.
All data is stored on encrypted servers hosted in India (MongoDB Atlas). Data is encrypted at rest (AES-256) and in transit (TLS 1.3).
Patient data is stored per clinic or hospital and is never accessible to other tenants on the platform. We perform regular security audits and maintain audit logs on all critical actions.
Razorpay: Payment processing. Razorpay's privacy policy applies to payment data.
Google Gemini AI: Powers the AI WhatsApp bot. Messages processed via Google's API as per Google's data policy.
Meta (WhatsApp): WhatsApp messages processed via the Meta Business API.
Twilio: SMS notifications for MediCore HIS lab results and alerts.
MongoDB Atlas: Database hosting with data stored in India regions (Mumbai).
Patients have the right to access, correct or request deletion of their personal data. Requests should be made through the clinic or hospital that created the records, or by emailing privacy@carenexa.in.
Clinics and hospitals are responsible for obtaining appropriate patient consent for data collection and processing as required by applicable law.
Active account data is retained as long as the subscription is active. Upon cancellation, data is retained for 90 days for recovery purposes, then permanently deleted. Backup copies may be retained for up to 30 additional days.
MediCore HIS supports ABHA linking as part of ABDM M1 compliance. ABHA-linked data follows NHA guidelines. Field locking is enforced once ABHA is verified. Every ABHA action writes a consent audit record with timestamp, staff member and verification method.
We use essential cookies for authentication and session management only. We do not use advertising or tracking cookies. Analytics are collected using privacy-friendly, aggregated methods.
We will notify all account admins by email at least 14 days before making material changes to this policy.
For privacy queries, data deletion requests or to report a concern:
📧 privacy@carenexa.in
CareNexa Technologies, India