Privacy Policy

Our role

Under the Digital Personal Data Protection Act 2023, the doctor using Medveda EMR is the Data Fiduciary for their patients’ records. We are a Data Processor: we hold and process that data on the doctor’s instructions, and we do not decide the purposes it is used for.

For a doctor’s own account information — their name, registration details, contact and billing — we are the Data Fiduciary.

What we process on a doctor’s behalf

Patient identity: name, phonetic name, date of birth and how precisely it is known, and gender. Exactly one identifier — an ABHA number, a mobile number, or a clinic-issued UHID.

The clinical record: consultations, visits, vital signs, examination findings, diagnoses, clinical notes, recorded allergies, laboratory reports and results, prescriptions and the medicines on them, and documents issued such as prescriptions and certificates.

Also: consent records, family links between patients, corrections to records, and merges of duplicate records.

What we process for ourselves

The doctor’s name, contact details and professional registration; sign-in sessions; counts of prescriptions issued, for billing; and payments.

Consent

Consent is recorded per purpose, not as a single blanket grant. The exact wording shown to the patient is stored alongside the record, so what they agreed to can be read later rather than inferred.

Consent can be withdrawn at any time. The record of it is kept, because it is the evidence that processing was lawful up to the moment it was withdrawn.

Where the data is kept

In India, in the Mumbai region. This is enforced technically rather than merely intended: an organisation-wide rule denies our systems the ability to operate in any other region.

Who we share it with

Nobody. Medveda EMR sends no patient data to any third party. There is no messaging vendor, no email vendor and no artificial-intelligence service in the path. If this changes, this page will be updated before it changes, not after.

Our infrastructure is provided by Amazon Web Services, who host the data in India under a data-processing agreement.

Cookies

One cookie, which keeps you signed in. No analytics, no advertising, and no third-party trackers of any kind.

How long we keep it

For as long as the doctor’s account is active. When an account ends, records remain available for export for 90 days and are then permanently deleted.

Access transparency

Every read of a patient record is logged. A doctor can see who accessed a record and when.

Your rights

Because the doctor is the Data Fiduciary for patient records, a patient exercises their rights — access, correction and erasure — through their doctor. We assist the doctor in answering those requests.

Grievances

Amit Kumar Tiwari, Grievance Officer — support@medvedaemr.com

Changes to this policy

Changes are posted to this page with an effective date. Material changes take effect no sooner than 30 days after posting. Continued use of the service after the effective date constitutes acceptance.

Last updated 2026-08-30. Changes are posted to this page with an effective date, and material changes take effect no sooner than 30 days after posting.

Source: drafted by Claude, decisions and approval by the operator, 2026-08-30