Calculatorsहिहिन्दी
Privacy

Website and patient portal privacy notice

This notice explains the Phase 3 data flows. The clinic must review it before production launch and align it with applicable law, professional obligations and actual operating practices.

Information collected

Appointment requests may include name, age, phone, email, consultation preference, scheduling details, a short administrative note and an optional report. Patient feedback may include contact details, rating, experience, publication preference and an optional photo. The patient portal stores a verified email account, sign-in events, secure sessions, change requests and notification history.

Purpose

Information is used to review appointment requests, contact patients, provide administrative status updates, manage teleconsultation details, verify and moderate feedback, process reschedule or cancellation requests, protect the service from abuse and maintain an audit trail.

Passwordless sign-in and cookies

The portal uses a six-digit one-time code sent by email. Codes expire after 10 minutes, are stored as secret-derived hashes and cannot be reused. A successful sign-in creates a secure HTTP-only, Secure and SameSite=Strict session cookie. The cookie is required to keep the patient signed in and is not available to browser JavaScript.

Patient portal access boundaries

After email verification, the portal displays only administrative records connected to that verified email or account. It does not provide a complete medical record and is not a clinical messaging service. Private video-consultation links, when supplied by the clinic, are visible only to the authenticated patient and authorised administrators.

Public feedback

Feedback is never published automatically. Only submissions marked public, carrying explicit publication consent and approved by an authorised clinic administrator may appear. Email, phone and private names are never included in the public response.

Storage and access

When deployed as configured, structured data is stored in a private Cloudflare D1 database. Optional reports and photos are stored in a private Cloudflare R2 bucket. Administrative APIs require a secret administrator token. Patient APIs require a valid secure session. Uploaded files are not placed in the public website directory.

Email delivery

One-time sign-in codes and administrative updates may be sent through the configured email delivery provider. The provider receives the recipient address and the minimum message content needed to deliver the email. Clinical details and uploaded report contents are not included in notification emails.

Security and data minimisation

The service validates inputs, applies rate limits, uses expiring hashed login codes and sessions, restricts file types and sizes, and supports Cloudflare Turnstile with server-side verification. No internet system can guarantee absolute security. Patients should avoid unnecessary medical details, identity documents, financial information or information about other people.

Export, account closure, retention and deletion

Authenticated patients can export a JSON copy of their portal administrative data and close portal access. Account closure revokes sessions and removes the portal profile and account link. Existing appointment, feedback, audit or communication records may still be retained where operational, legal or professional requirements apply. Contact the clinic to request correction, withdrawal of publication consent or deletion review.

Emergency and clinical use

Forms and portal requests are not monitored continuously and are not suitable for emergencies. Submission or portal access does not confirm an appointment, establish a doctor–patient relationship or replace direct clinical consultation.

Third-party services

The site may use Cloudflare hosting, D1, R2 and Turnstile, a configured transactional email provider, web fonts, icons and external WhatsApp links. Each provider applies its own terms and privacy practices.

Preferences and privacy requests

Signed-in patients can choose update preferences and submit access, correction, deletion-review or restriction requests. A request is reviewed by the clinic and is not an automatic deletion command where retention may be required for operational, legal or professional reasons.

Operational exports and audit events

Authorised clinic users may export administrative records for legitimate clinic operations. Security-sensitive administrative actions are recorded in an audit trail. Exported files must be stored and shared according to the clinic’s approved privacy and retention procedures.

Offline use

The website may cache selected public educational pages on the patient’s device for resilience. Patient sign-in, dashboards, appointment forms, private documents and administrative pages are deliberately excluded from offline caching.

Last updated: 20 July 2026. Before launch, the clinic should confirm the final data-controller identity, patient contact route, lawful basis, retention schedule, breach process and applicable Indian healthcare and privacy requirements.