Privacy Policy

Clinizy Care, a product of Brynex Labs

Last updated: July 7, 2026  ·  Effective: July 7, 2026

“Your patients’ data belongs to your clinic, not to us. We are the custodian, never the owner.”

This Privacy Policy explains how Brynex Labs (“Brynex Labs”, “we”, “us”, “our”) collects, uses, discloses, stores and protects personal data through Clinizy Care, our Hospital Management Software (“Clinizy Care”, the “Service”), available at clinizy.in and app.clinizy.in. It is drafted in line with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the Digital Personal Data Protection Rules, 2025, and the Information Technology Act, 2000 read with the SPDI Rules, 2011. Please read it together with our Terms of Service and Cookie Policy.

1. Who We Are

Clinizy Care is a cloud-based Hospital Management Software for clinics and nursing homes in India, built and operated by Brynex Labs. Brynex Labs is the company; Clinizy Care is the product. We are based in and operate from India.

Privacy contact: privacy@clinizy.in
Grievance Officer: grievance@clinizy.in


Data Fiduciary and Data Processor

Under the DPDP Act, our role depends on the data in question:

  • Data Processor for patient and clinical data. When a clinic uses Clinizy Care to record patient, clinical and billing information, the clinic is the Data Fiduciary and decides why and how that data is processed. We process it only on the clinic’s documented instructions, under a contract, on the clinic’s behalf.
  • Data Fiduciary for our own account data. For data we collect to run our business — clinic owner and staff account details, subscription and billing records, website visitors and product analytics — we act as the Data Fiduciary and are directly responsible under the DPDP Act.

3. Personal Data We Collect

3a. Clinic / tenant data (from clinic owners)

  • Clinic or facility name, GSTIN, and contact details
  • Owner name, phone number, and email address
  • Logo and branding assets
  • Subscription and payment records (card details are handled by Razorpay — we do not store them)

3b. Staff data (from clinic staff who use Clinizy Care)

  • Name, phone number, role, and speciality
  • Login timestamps, device and browser information
  • Actions performed within the system (audit logs)

3c. Patient data (entered by clinic staff)

  • Name, phone, address, date of birth, and gender
  • ABHA (Ayushman Bharat Health Account) number, where linked
  • Medical history, diagnoses, prescriptions, and clinical notes
  • Billing, payment, visit and admission records

Health condition and medical records are “sensitive personal data or information” under the SPDI Rules, 2011, and we treat them with heightened protection (see Section 7).

3d. Technical data (collected automatically)

  • IP address, browser type, and device type
  • Pages visited and features used (usage analytics)
  • Error logs and performance data


5. How We Use Your Data

We use personal data to:

  • Provide, operate, secure and support the Clinizy Care service
  • Generate GST-compliant invoices, bills and receipts
  • Send appointment reminders and service communications you have opted into
  • Integrate with ABDM / ABHA systems where a clinic and patient authorise it
  • Improve reliability and features using aggregated, de-identified analytics
  • Comply with Indian law and regulatory requirements

We do NOT:

  • Sell your data to third parties
  • Use patient data for advertising or marketing profiling
  • Process your data for any purpose beyond operating Clinizy Care and meeting legal obligations

6. Data Sharing and Sub-processors

We share data only with the processors below, each under a contract that limits use to the stated purpose. We do not sell data and we do not share it with advertisers.

RecipientPurposeData Shared
Amazon Web Services (Mumbai)Cloud hosting & storageAll encrypted data
RazorpayPayment processingBilling information only
Meta (WhatsApp Business)Message deliveryPhone number, message content
SMS gateways (Fast2SMS / MSG91)SMS deliveryPhone numbers
NHA / ABDMHealth-record linkageOnly as authorised by the patient

We may also disclose data where required by a valid legal order or to protect the rights, safety and security of users and the public.


7. Patient and Health Data

Patient health data is sensitive personal data. We handle it accordingly:

  • Stored in India: Patient data is hosted on AWS Mumbai (ap-south-1) infrastructure.
  • Encrypted at rest: AES-256 encryption for stored records.
  • Encrypted in transit: TLS 1.2+ for all data in transit.
  • Minimum collection: We process only the health data that clinic staff enter; we do not independently collect health information about patients.
  • Clinic ownership: The clinic owns and controls patient data. For patient records, Clinizy Care acts as a Data Processor, not the Data Fiduciary.
  • ABDM alignment: Where a clinic uses ABDM/ABHA features, health-record exchange follows the National Health Authority’s Health Data Management Policy and the consent-artefact model.

8. Data Storage and Security

We maintain reasonable security practices proportionate to the sensitivity of the data, aligned with the ISO/IEC 27001 framework referenced in the SPDI Rules:

  • AWS ap-south-1 (Mumbai, India)
  • AES-256 at rest, TLS 1.2+ in transit
  • Access control: Role-based access with audit logging
  • Automated daily backups with defined retention
  • Each clinic’s data is logically separated by tenant

No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security.


9. Data Breach Notification

If a personal data breach occurs, we will:

  • Notify each affected Data Principal (or, for patient data, the clinic as Data Fiduciary) without undue delay, in clear language describing the breach and steps to protect their interests;
  • Give the Data Protection Board of India an initial intimation without delay and a detailed report within 72 hours, as required by the DPDP Rules, 2025; and
  • Report cyber-security incidents to CERT-In within the applicable timelines under its directions.

10. Your Rights Under the DPDP Act 2023

As a Data Principal, you have the right to:

  • a summary of your personal data being processed and the identities of those with whom it has been shared
  • Correction & completion: correction, completion or updating of inaccurate or incomplete data
  • deletion of your personal data, unless retention is required by law
  • nominate a person to exercise your rights in the event of death or incapacity
  • Grievance redressal: a readily available means to raise a grievance with us
  • Withdraw consent: withdraw consent at any time

For patient records, please direct your request to the clinic that holds your data (the Data Fiduciary); we will assist the clinic in responding. For your own account data, write to privacy@clinizy.in. You may also complain to the Data Protection Board of India once its complaint channels are operational.


11. Cookies and Tracking

We use strictly necessary cookies to keep you signed in and secure, a preference cookie for language, and analytics cookies only with your consent. You can manage your choices at any time. Full details are in our Cookie Policy.


12. Children’s Data

Clinizy Care is a tool for healthcare professionals and is not directed at children. Under the DPDP Act, a “child” is a person under 18. Where a clinic records data of a patient who is a minor, the clinic is responsible for obtaining verifiable consent from a parent or lawful guardian. We do not knowingly use children’s data for tracking, behavioural monitoring or targeted advertising.


13. Cross-border Transfers

Patient and clinical data is stored in India. Some sub-processors that support communications or analytics may process limited data outside India in accordance with the DPDP Act’s transfer framework. We will not transfer personal data to any country restricted by the Central Government, and we disclose our processing locations on request.


14. Data Retention

We retain personal data only as long as needed for the purpose it was collected, or as required by law. Indicative periods:

Data TypeRetention Period
Patient / clinical recordsMinimum 3 years from commencement of treatment (MCI Regulations, 2002); 10 years for medico-legal cases — retained as directed by the clinic
Tax invoices & billing records6 years (GST law); up to 8 years where the Companies Act, 2013 applies
Account & audit logs2 years
In-app notifications90 days
Data after account closureAvailable for export for 30 days, then deleted unless law requires retention

15. Changes to This Policy

We may update this Policy to reflect changes in our practices or the law. We will post the revised version here with a new “Last updated” date and, for material changes, notify you by email or in-app notice before they take effect.


16. Grievance Redressal and Contact

If you have questions about this Policy or wish to exercise your rights, contact our Grievance Officer. We will acknowledge your request within 48 hours and resolve it within 30 days.

Grievance Officer: grievance@clinizy.in
Privacy / data-protection queries: privacy@clinizy.in
Brynex Labs (operator of Clinizy Care), India

To escalate, you may approach the Data Protection Board of India. The Board’s complaint channels will be published as it becomes operational under the DPDP Rules, 2025.