This policy explains, in plain language, what personal and health data Medigent collects, how we use and protect it, and the rights you have over it.
MediGent Technologies LLP ("Medigent", "we", "us") operates the Medigent platform at medigent.in, app.medigent.in, me.medigent.in and the Medigent mobile apps. This policy explains, in plain language, what personal and health data we collect, how we use and protect it, and the rights you have over it. It follows India’s Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and the SPDI Rules, 2011, and applicable ABDM / MoHFW health-data standards.
Medigent handles data in two distinct roles:
We do not sell your personal data, and we do not use patient health data for advertising.
We process personal data with your consent and for the legitimate uses permitted under the DPDP Act — for example, to deliver a service you have asked for. For clinic patient records, the clinic obtains and manages the patient’s consent, and Medigent provides consent-capture tools (such as the in-app User Consent Policy) to help. You can withdraw consent at any time, though some features may then stop working.
Delivering the AI receptionist means voice and text are processed by AI service providers (for speech-to-text, text-to-speech and language understanding) and by our cloud provider. These providers act under contract and confidentiality obligations and process the data only to deliver the Medigent service. Medigent does not make final clinical decisions — a person at the clinic confirms bookings and reviews records.
We never sell personal data.
Data is hosted on Amazon Web Services on ISO 27001 / SOC 2 certified infrastructure in India (AWS Asia Pacific — Mumbai). It is encrypted in transit and at rest, isolated per clinic and per patient, and access is restricted and logged. Health data is handled to HIPAA safeguards under a Business Associate Addendum where applicable. Medical records are portable and exportable in the open FHIR R4 standard.
We keep personal data for as long as your account is active and as long as needed for the purposes above or to meet legal, tax and medical-record obligations. When data is no longer required we delete or anonymise it. Clinics control the retention and deletion of the patient records they own.
Under the DPDP Act you can:
To exercise any of these, email privacy@medigent.in. If your data sits inside a clinic’s records, we will route your request to that clinic and help fulfil it.
In line with the DPDP Act and the IT Rules, our Grievance Officer handles data complaints:
We acknowledge grievances promptly and respond within the timelines set by law.
We use essential cookies to keep you signed in and the site working, and limited analytics to understand usage and improve the product. You can control cookies through your browser settings; disabling essential cookies may break parts of the site.
Medigent is intended for clinics and adults. We do not knowingly collect data directly from children under 18 without verifiable parental or guardian consent. A minor’s medical record is created and managed by their clinic under the guardian’s consent.
We may update this policy as the product, our partners or the law change. We will post the new version here with a fresh “last updated” date and notify you of material changes where required.
Medigent organises information and sends reminders. It is not a medical device and does not provide medical advice, diagnosis, or treatment.