Privacy Policy
Clinizy Care, a product of Brynex Labs
Last updated: July 7, 2026 · Effective: July 7, 2026
“Your patients’ data belongs to your clinic, not to us. We are the custodian, never the owner.”
This Privacy Policy explains how Brynex Labs (“Brynex Labs”, “we”, “us”, “our”) collects, uses, discloses, stores and protects personal data through Clinizy Care, our Hospital Management Software (“Clinizy Care”, the “Service”), available at clinizy.in and app.clinizy.in. It is drafted in line with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the Digital Personal Data Protection Rules, 2025, and the Information Technology Act, 2000 read with the SPDI Rules, 2011. Please read it together with our Terms of Service and Cookie Policy.
1. Who We Are
Clinizy Care is a cloud-based Hospital Management Software for clinics and nursing homes in India, built and operated by Brynex Labs. Brynex Labs is the company; Clinizy Care is the product. We are based in and operate from India.
Privacy contact: privacy@clinizy.in
Grievance Officer: grievance@clinizy.in
Data Fiduciary and Data Processor
Under the DPDP Act, our role depends on the data in question:
- Data Processor for patient and clinical data. When a clinic uses Clinizy Care to record patient, clinical and billing information, the clinic is the Data Fiduciary and decides why and how that data is processed. We process it only on the clinic’s documented instructions, under a contract, on the clinic’s behalf.
- Data Fiduciary for our own account data. For data we collect to run our business — clinic owner and staff account details, subscription and billing records, website visitors and product analytics — we act as the Data Fiduciary and are directly responsible under the DPDP Act.
3. Personal Data We Collect
3a. Clinic / tenant data (from clinic owners)
- Clinic or facility name, GSTIN, and contact details
- Owner name, phone number, and email address
- Logo and branding assets
- Subscription and payment records (card details are handled by Razorpay — we do not store them)
3b. Staff data (from clinic staff who use Clinizy Care)
- Name, phone number, role, and speciality
- Login timestamps, device and browser information
- Actions performed within the system (audit logs)
3c. Patient data (entered by clinic staff)
- Name, phone, address, date of birth, and gender
- ABHA (Ayushman Bharat Health Account) number, where linked
- Medical history, diagnoses, prescriptions, and clinical notes
- Billing, payment, visit and admission records
Health condition and medical records are “sensitive personal data or information” under the SPDI Rules, 2011, and we treat them with heightened protection (see Section 7).
3d. Technical data (collected automatically)
- IP address, browser type, and device type
- Pages visited and features used (usage analytics)
- Error logs and performance data
4. Legal Basis and Consent
We process personal data on the following bases under the DPDP Act:
- Consent (Section 6). For account creation, communications and analytics, we rely on your consent, which is free, specific, informed and unambiguous, given through a clear affirmative action. You may withdraw consent at any time, as easily as it was given; withdrawal does not affect processing carried out before withdrawal.
- Legitimate uses (Section 7). For certain purposes the Act permits processing without separate consent — for example, to respond to a medical emergency or to comply with law.
- Contract and instruction. For patient and clinical data, we process on the clinic’s instructions under our services agreement; the clinic is responsible for obtaining patient consent.
5. How We Use Your Data
We use personal data to:
- Provide, operate, secure and support the Clinizy Care service
- Generate GST-compliant invoices, bills and receipts
- Send appointment reminders and service communications you have opted into
- Integrate with ABDM / ABHA systems where a clinic and patient authorise it
- Improve reliability and features using aggregated, de-identified analytics
- Comply with Indian law and regulatory requirements
We do NOT:
- Sell your data to third parties
- Use patient data for advertising or marketing profiling
- Process your data for any purpose beyond operating Clinizy Care and meeting legal obligations
6. Data Sharing and Sub-processors
We share data only with the processors below, each under a contract that limits use to the stated purpose. We do not sell data and we do not share it with advertisers.
| Recipient | Purpose | Data Shared |
|---|---|---|
| Amazon Web Services (Mumbai) | Cloud hosting & storage | All encrypted data |
| Razorpay | Payment processing | Billing information only |
| Meta (WhatsApp Business) | Message delivery | Phone number, message content |
| SMS gateways (Fast2SMS / MSG91) | SMS delivery | Phone numbers |
| NHA / ABDM | Health-record linkage | Only as authorised by the patient |
We may also disclose data where required by a valid legal order or to protect the rights, safety and security of users and the public.
7. Patient and Health Data
Patient health data is sensitive personal data. We handle it accordingly:
- Stored in India: Patient data is hosted on AWS Mumbai (ap-south-1) infrastructure.
- Encrypted at rest: AES-256 encryption for stored records.
- Encrypted in transit: TLS 1.2+ for all data in transit.
- Minimum collection: We process only the health data that clinic staff enter; we do not independently collect health information about patients.
- Clinic ownership: The clinic owns and controls patient data. For patient records, Clinizy Care acts as a Data Processor, not the Data Fiduciary.
- ABDM alignment: Where a clinic uses ABDM/ABHA features, health-record exchange follows the National Health Authority’s Health Data Management Policy and the consent-artefact model.
8. Data Storage and Security
We maintain reasonable security practices proportionate to the sensitivity of the data, aligned with the ISO/IEC 27001 framework referenced in the SPDI Rules:
- AWS ap-south-1 (Mumbai, India)
- AES-256 at rest, TLS 1.2+ in transit
- Access control: Role-based access with audit logging
- Automated daily backups with defined retention
- Each clinic’s data is logically separated by tenant
No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security.
9. Data Breach Notification
If a personal data breach occurs, we will:
- Notify each affected Data Principal (or, for patient data, the clinic as Data Fiduciary) without undue delay, in clear language describing the breach and steps to protect their interests;
- Give the Data Protection Board of India an initial intimation without delay and a detailed report within 72 hours, as required by the DPDP Rules, 2025; and
- Report cyber-security incidents to CERT-In within the applicable timelines under its directions.
10. Your Rights Under the DPDP Act 2023
As a Data Principal, you have the right to:
- a summary of your personal data being processed and the identities of those with whom it has been shared
- Correction & completion: correction, completion or updating of inaccurate or incomplete data
- deletion of your personal data, unless retention is required by law
- nominate a person to exercise your rights in the event of death or incapacity
- Grievance redressal: a readily available means to raise a grievance with us
- Withdraw consent: withdraw consent at any time
For patient records, please direct your request to the clinic that holds your data (the Data Fiduciary); we will assist the clinic in responding. For your own account data, write to privacy@clinizy.in. You may also complain to the Data Protection Board of India once its complaint channels are operational.
12. Children’s Data
Clinizy Care is a tool for healthcare professionals and is not directed at children. Under the DPDP Act, a “child” is a person under 18. Where a clinic records data of a patient who is a minor, the clinic is responsible for obtaining verifiable consent from a parent or lawful guardian. We do not knowingly use children’s data for tracking, behavioural monitoring or targeted advertising.
13. Cross-border Transfers
Patient and clinical data is stored in India. Some sub-processors that support communications or analytics may process limited data outside India in accordance with the DPDP Act’s transfer framework. We will not transfer personal data to any country restricted by the Central Government, and we disclose our processing locations on request.
14. Data Retention
We retain personal data only as long as needed for the purpose it was collected, or as required by law. Indicative periods:
| Data Type | Retention Period |
|---|---|
| Patient / clinical records | Minimum 3 years from commencement of treatment (MCI Regulations, 2002); 10 years for medico-legal cases — retained as directed by the clinic |
| Tax invoices & billing records | 6 years (GST law); up to 8 years where the Companies Act, 2013 applies |
| Account & audit logs | 2 years |
| In-app notifications | 90 days |
| Data after account closure | Available for export for 30 days, then deleted unless law requires retention |
15. Changes to This Policy
We may update this Policy to reflect changes in our practices or the law. We will post the revised version here with a new “Last updated” date and, for material changes, notify you by email or in-app notice before they take effect.
16. Grievance Redressal and Contact
If you have questions about this Policy or wish to exercise your rights, contact our Grievance Officer. We will acknowledge your request within 48 hours and resolve it within 30 days.
Grievance Officer: grievance@clinizy.in
Privacy / data-protection queries: privacy@clinizy.in
Brynex Labs (operator of Clinizy Care), India
To escalate, you may approach the Data Protection Board of India. The Board’s complaint channels will be published as it becomes operational under the DPDP Rules, 2025.
