This policy is being finalized. Some contact details below are not yet published. If you have a privacy concern, reach us at support@bgadibs.com in the meantime.
1. Who We Are
BGadi Health Technologies Private Limited ("BGadi Health", "we", "us", "our") operates a multi-vertical healthcare technology platform connecting hospitals, clinics, diagnostic labs, pharmacies, and other healthcare organizations with the tools they need to manage patients, appointments, billing, and operations.
2. What Data We Collect
Depending on how you use our platform, we may collect:
- Account data — name, email, phone number, role, and organization details for staff, doctors, and administrators using the platform
- Patient data — collected and controlled by the healthcare organization using our platform (the "Organization"), including medical records, appointment history, prescriptions, lab results, and billing information. We process this data on the Organization's behalf as a data processor
- Payment data — transaction records for subscription billing and patient billing; card/UPI details themselves are handled directly by our payment partners (Razorpay) and are never stored on our servers
- Usage data — how you interact with the platform, for the purpose of improving reliability and features
3. How We Use Your Data
- To provide, operate, and maintain the platform's core functionality
- To process appointments, bills, and payments as directed by the Organization
- To send appointment confirmations, billing notifications, and service updates via email/SMS/WhatsApp
- To improve platform reliability, security, and features
- To comply with legal obligations under Indian law, including the Digital Personal Data Protection Act, 2023
4. Who We Share Data With
We share data only where necessary to operate the platform:
- Payment processors (Razorpay) — to process subscription and patient billing payments
- Communication providers — for sending SMS, email, and WhatsApp notifications you or the Organization have opted into
- The healthcare Organization itself — patient data is fundamentally the Organization's data; we act as their technology processor, not an independent controller of patient records
We do not sell personal data to third parties, ever.
5. Data Retention
We retain data for as long as an Organization's account remains active, plus any additional period required by Indian healthcare record-keeping regulations or tax law (e.g., GST invoice retention requirements). Organizations may request deletion of their data subject to these legal retention obligations.
6. Your Rights
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request erasure of your data, subject to legal retention requirements
- Withdraw consent for data processing where consent is the basis for processing
- Lodge a complaint with our Grievance Officer, and subsequently with the Data Protection Board of India
7. Data Security
We use industry-standard security measures including encrypted connections (HTTPS), encrypted storage of sensitive credentials, and role-based access controls to protect data on our platform. No system is completely immune to risk, and we continuously work to improve our security posture.
8. Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023, the following person is designated to address privacy-related grievances:
9. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the platform after changes constitutes acceptance of the updated policy.
10. Governing Law
This policy is governed by the laws of India.
This is a working policy document. For legal advice specific to your situation, please consult a qualified professional.