MedEase LogoMedEase
HomeFeaturesWhatsAppRolesPricingBlogFAQGet Started
menu
HomeFeaturesWhatsAppRolesPricingFAQGet Started
  • Terms & Conditions
  • Privacy Policy
  • Data Deletion
DPDP Act 2023 & Healthcare Privacy Standards

Privacy Policy

Version 3.2Operated by Aztreya Technologies Private Limited

Your privacy and the security of patient data are our highest priorities. This Privacy Policy details our practices in compliance with the Digital Personal Data Protection (DPDP) Act 2023 (India), local SPDI guidelines, and international data protection standards.

1. Data Segregation (The "Snapshot" Pattern)

To comply simultaneously with dynamic user profile updates and strict static accounting audits, we employ the "Snapshot" Data Pattern.

Transparent Auditing: All transactional data (including Invoice details, legal clinic names, and Tax/GSTIN numbers) are snapshotted and mathematically frozen at the exact moment of payment execution. This satisfies statutory tax audits and cannot be altered retrospectively, even if the user later updates their active organizational profile.

We distinctly separate current "Live" identity data (which you can edit at any time) from historical "Snapshot" billing data (which remains immutable).

2. Data Collected & Encryption Architecture

We classify collected data into distinct silos with varying levels of encryption and access control:

Identity & Authentications

  • Primary contact details: Email address and Name.
  • Network footprint: IP addresses and session timestamps.
  • Device signatures: Hardware persistent device IDs used strictly for security monitoring and fraud prevention.

Clinical Data

  • Patient demographic records.
  • EMR (Electronic Medical Record) notes and diagnostic files.
  • Digital prescriptions and clinic branch setups.

Encryption Architecture: For organizations using Zero-Knowledge encryption, supported clinical and patient data is encrypted locally on your client device before transmission so that MedEase cannot decrypt the protected content without authorized client-side access. Certain operational data required to provide enabled services, integrations, notifications, billing, and system functionality may be processed separately according to the organization's configuration and this Privacy Policy.

3. Meta and WhatsApp Business Platform

MedEase allows authorized organizations to connect their own WhatsApp Business Accounts using Meta authorization. When an organization enables this integration, MedEase may process Platform Data necessary to provide the requested WhatsApp integration, including:

  • Identifiers for the connected WhatsApp Business Account (WABA ID).
  • Business phone numbers and phone number IDs.
  • Approved message templates and template status metadata.
  • Messaging permissions, connection status, and transactional delivery metadata.

Usage & Ownership Principles:

  • Sole Purpose: MedEase uses Meta Platform Data only to provide the WhatsApp Business integration features explicitly requested by the organization (e.g. managing approved templates and sending operational notifications).
  • Clinic Ownership: Each organization retains full ownership and control of its own Meta Business Portfolio, WhatsApp Business Account, phone number, and templates. MedEase does not claim ownership of client Meta assets.
  • No Sale or Advertising: MedEase does not sell Meta Platform Data or use it for unrelated advertising, profiling, or third-party marketing purposes.
  • Restricted Access: Access to integration controls is restricted to authorized users within the organization according to assigned Role-Based Access Controls (RBAC) and the permissions granted through Meta.

4. Third-Party Sub-processors

To provide high-availability services, we partner with specialized, certified infrastructure providers:

  • Google Cloud & Amazon Web Services (AWS): Secure cloud hosting, application deployment, and isolated database storage infrastructure (India Regions).
  • Razorpay: PCI-DSS compliant, RBI-certified payment processor handling financial tokenization.
  • Meta Platforms, Inc. / WhatsApp Business Platform: Official API integration enabling clinic-authorized operational notifications, template management, and message delivery.
  • AWS SES / Msg91: High-deliverability dispatchers for transactional emails, SMS communications, and authentication OTPs.

5. Retention Periods & Disconnection

While we support modern privacy rights and user data deletion requests, certain data is subject to statutory retention laws:

  • Tax & Accounting Records: In adherence to Indian corporate and tax laws, historical legal invoices and financial transaction logs are retained securely for a period of 7 years.
  • WhatsApp & Meta Integration Data: When an organization disconnects the WhatsApp integration in application settings, MedEase immediately halts the use of Meta permissions and deletes stored authorization tokens and connection metadata according to our Data Deletion policy.

6. Contact Information & Data Protection Officer

For any privacy inquiries, data deletion requests, or compliance questions, please contact our data protection team:

Aztreya Technologies Private Limited
Product: MedEase
Address: KRF Square, Seaport and Airport Road, near BMC Thrikkakara, Kakkanad, Kochi, Kerala 682021, India
Email: support@aztreya.com | Phone: +91 7025 004 222

MedEase Logo

MedEase

The standard in medical practice management and healthcare SaaS.

lockHealthcare-Grade Security
verified_userDPDP Aligned
Aztreya Technologies Private Limited
KRF Square, Seaport and Airport Road,
near BMC Thrikkakara, Kakkanad,
Kochi, Kerala 682021, India
support@aztreya.com | +91 7025 004 222

© 2026 MedEase by Aztreya Technologies Private Limited. All rights reserved.

Product

FeaturesWhatsApp IntegrationRoles & AccessPricingSecurityBlogFAQ

Legal & Policy

Privacy PolicyTerms of ServiceData Deletion InstructionsSecurity Architecture

Solutions

Clinic SoftwarePatient ManagementEHR SystemsFor Hospitals

Connect

Aztreya TechnologiesLinkedInFacebookInstagram