Privacy Policy
- Legal entity
- DocFollow Technologies Private Limited
- CIN
- U62011AP2026PTC127506
- Registered office
- 4-1-105, R K Nagar, Nawabpeta, Nellore – 524002, Andhra Pradesh, India
- Website
- www.docfollow.in
- Privacy contact
- privacy@docfollow.in
- Last updated
- 23 September 2026
- Effective date
- [To be inserted on launch]
This Privacy Policy sets out how DocFollow Technologies Private Limited collects, uses, stores, shares and protects personal data, including health data, of the doctors and patients who use the DocFollow mobile applications (DocFollow Doctor and DocFollow Patient). It is framed in accordance with the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Telemedicine Practice Guidelines, 2020, and relevant amendments to the above Acts, Rules and Guidelines.
Definitions
In this Privacy Policy, unless the context requires otherwise:
- “Company” means DocFollow Technologies Private Limited, a company incorporated under the Companies Act, 2013, having its registered office at 4-1-105, R K Nagar, Nawabpeta, Nellore – 524002, Andhra Pradesh, India.
- “App” means the DocFollow Doctor and DocFollow Patient mobile applications operated by the Company.
- “User” means any person who registers on or uses the App, and includes a User-Doctor, a User-Patient and a Clinic Staff member.
- “User-Doctor” means a medical practitioner registered with a State Medical Council or the National Medical Commission who uses the App.
- “User-Patient” means a patient, or a parent or lawful guardian acting on behalf of a patient, who uses the App to communicate with a User-Doctor.
- “Clinic Staff” means a receptionist or assistant authorised by a User-Doctor to register patients and upload records on the User-Doctor’s behalf.
- “Treating Doctor” means the User-Doctor with whom a User-Patient has an established connection on the App.
About the Company and the App
The App is a doctor-patient communication platform that enables a User-Patient to message the User-Patient’s Treating Doctor, and enables the Treating Doctor to view the User-Patient’s medical context alongside those messages.
For the purposes of the DPDP Act, 2023, the Company acts as a Data Fiduciary, and determines the purpose and means of processing personal data on the App.
Every User-Doctor is an independent medical practitioner registered with a State Medical Council or the National Medical Commission. Clinical decisions, diagnoses and prescriptions are the sole responsibility of the Treating Doctor. The Company provides the communication channel and record-keeping tools, and does not itself provide medical advice, diagnosis or treatment.
The App is not a directory or marketplace. It does not list, recommend or refer User-Patients to other doctors.
Data Collected
The Company collects only such personal data as is necessary to provide the App, in accordance with the principle of data minimisation.
3.1 From User-Doctors
- Data
- Full name
- Purpose
- Identification and display in the patient app
- Required
- Yes
- Visible to User-Patients
- Yes
- Data
- Mobile number
- Purpose
- OTP login and authentication
- Required
- Yes
- Visible to User-Patients
- No
- Data
- Medical registration number and council
- Purpose
- Verification of registration; display as required under the Telemedicine Practice Guidelines, 2020
- Required
- Yes
- Visible to User-Patients
- Yes
- Data
- Qualifications and specialty
- Purpose
- Display in the patient app
- Required
- Yes
- Visible to User-Patients
- Yes
- Data
- Clinic name and address
- Purpose
- Display in the patient app
- Required
- Yes
- Visible to User-Patients
- Yes
- Data
- Profile photograph
- Purpose
- Display in the patient app
- Required
- No
- Visible to User-Patients
- Yes
| Data | Purpose | Required | Visible to User-Patients |
|---|---|---|---|
| Full name | Identification and display in the patient app | Yes | Yes |
| Mobile number | OTP login and authentication | Yes | No |
| Medical registration number and council | Verification of registration; display as required under the Telemedicine Practice Guidelines, 2020 | Yes | Yes |
| Qualifications and specialty | Display in the patient app | Yes | Yes |
| Clinic name and address | Display in the patient app | Yes | Yes |
| Profile photograph | Display in the patient app | No | Yes |
3.2 From User-Patients
- Data
- Full name
- Purpose
- Identification in the Treating Doctor’s registry
- Required
- Yes
- Visible to Treating Doctor
- Yes
- Data
- Mobile number
- Purpose
- OTP login and connection to the Treating Doctor
- Required
- Yes
- Visible to Treating Doctor
- Yes
- Data
- Age and sex
- Purpose
- Clinical context
- Required
- Yes
- Visible to Treating Doctor
- Yes
- Data
- Messages
- Purpose
- Communication with the Treating Doctor
- Required
- Yes
- Visible to Treating Doctor
- Yes
- Data
- Uploaded records
- Purpose
- Sharing with the Treating Doctor
- Required
- No
- Visible to Treating Doctor
- Yes
- Data
- Parent or guardian details
- Purpose
- Consent on behalf of a minor
- Required
- Where applicable
- Visible to Treating Doctor
- Yes
| Data | Purpose | Required | Visible to Treating Doctor |
|---|---|---|---|
| Full name | Identification in the Treating Doctor’s registry | Yes | Yes |
| Mobile number | OTP login and connection to the Treating Doctor | Yes | Yes |
| Age and sex | Clinical context | Yes | Yes |
| Messages | Communication with the Treating Doctor | Yes | Yes |
| Uploaded records | Sharing with the Treating Doctor | No | Yes |
| Parent or guardian details | Consent on behalf of a minor | Where applicable | Yes |
3.3 Health Data Recorded by User-Doctors
A Treating Doctor, or Clinic Staff authorised by the Treating Doctor, may record the following as part of clinical practice: medical history, current medications, allergies, diagnoses, prescriptions (including photographs of paper prescriptions), laboratory reports and private clinical notes.
Private clinical notes recorded by a User-Doctor are visible only to that User-Doctor and are never shown to the User-Patient.
Purposes of Processing
The Company processes personal data only for the following purposes:
- operating the messaging service between a User-Patient and the Treating Doctor;
- displaying the User-Patient’s medical context to the Treating Doctor alongside a conversation;
- storing and retrieving prescriptions and health records;
- authenticating Users through one-time passwords;
- sending notifications about new messages;
- verifying the registration of User-Doctors;
- detecting misuse, preventing fraud and maintaining the security of the App; and
- complying with legal obligations under Indian law.
The Company does not use health data for advertising, does not sell it, and does not share it with pharmaceutical companies, insurers, employers or data brokers.
Legal Basis for Processing
The Company processes personal data on the basis of the explicit, informed consent of the User, obtained separately for each distinct purpose as required by the DPDP Act, 2023 and the DPDP Rules, 2025. Where processing is necessary to comply with a legal obligation, including medical record-keeping obligations, the Company relies on that legal obligation.
Consent
A single consent to all terms is not treated as valid consent for health data. The Company therefore obtains separate and granular consent from each User for each distinct purpose.
6.1 Granular Consent at Registration
Consent is obtained as separate, individually selectable items. No item is pre-selected. Each item may be accepted or declined on its own, and declining an optional item does not prevent a User from using the core service.
- Consent item
- Account creation
- Purpose
- Storing name, mobile number and basic profile to create an account
- Status
- Required
- Consent item
- Health data storage
- Purpose
- Storing medical history, medications, allergies and diagnoses recorded by the Treating Doctor
- Status
- Required for User-Patients
- Consent item
- Prescription images
- Purpose
- Storing photographs of prescriptions and reading medicine names from them
- Status
- Optional
- Consent item
- Notifications
- Purpose
- Sending push notifications on receipt of a message
- Status
- Optional
- Consent item
- Service improvement
- Purpose
- Using anonymised, aggregated usage statistics to improve the App
- Status
- Optional
| Consent item | Purpose | Status |
|---|---|---|
| Account creation | Storing name, mobile number and basic profile to create an account | Required |
| Health data storage | Storing medical history, medications, allergies and diagnoses recorded by the Treating Doctor | Required for User-Patients |
| Prescription images | Storing photographs of prescriptions and reading medicine names from them | Optional |
| Notifications | Sending push notifications on receipt of a message | Optional |
| Service improvement | Using anonymised, aggregated usage statistics to improve the App | Optional |
Each consent is recorded individually for every User, with a timestamp, the version of this Privacy Policy in force at the time, and the exact wording shown to the User. A User may review and change optional consents at any time through Settings → Privacy → Manage Consent.
6.2 Withdrawal of Consent
A User may withdraw any consent at any time through Settings → Privacy → Manage Consent, or by writing to privacy@docfollow.in.
- Withdrawal of an optional consent disables only the corresponding feature; the rest of the App continues to function.
- Withdrawal of a required consent is treated as a request to close the account.
- On withdrawal, the Company stops the relevant processing and deletes the associated data, subject to the retention obligations set out in Section 11.
6.3 Connection Consent
Where a User-Patient’s mobile number matches a record created by a User-Doctor, the User-Patient is shown a confirmation screen identifying the User-Doctor and the clinic, and must expressly accept before any connection is established. Accounts are never connected automatically.
6.4 Secondary Use of Data
Data provided for communication between a User-Patient and the Treating Doctor is used solely for that purpose. The Company does not, directly or indirectly, use the identifiable data of User-Doctors or User-Patients for research, analytics, commercial insights or any other secondary purpose.
If the Company proposes to use anonymised or aggregated data for research or product development, it shall first obtain fresh, separate and explicit consent from the Users concerned. Declining such consent shall not affect a User’s use of the App. No such processing takes place until consent is given.
Data Storage and Security
7.1 Location of Data
- All personal and health data is stored on cloud servers located in India.
- The Company uses [cloud provider — to be confirmed] data centres located in India.
- No health data of User-Patients is stored outside India.
7.2 Security Safeguards
- All data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256.
- Authentication is by one-time password; no passwords are stored.
- Role-based access ensures that a User-Doctor can access only the User-Doctor’s own patients, and a User-Patient can access only the User-Patient’s own records.
- Clinic Staff have restricted access and cannot read conversations between a User-Doctor and a User-Patient.
- Messages cannot be edited or deleted after they are sent, so that the record of each consultation remains accurate.
- Access to backend systems is limited to authorised personnel of the Company, and every such access is logged.
- No health data is cached on a User’s device in plain text, and sessions time out after 30 minutes of inactivity.
- The Company conducts periodic security reviews of its infrastructure.
7.3 Data Protection Impact Assessment
Health data is treated as high-risk processing. The Company shall conduct a Data Protection Impact Assessment before introducing any feature that materially changes how health data is processed, and before the App reaches a scale at which the Company may be notified as a Significant Data Fiduciary.
7.4 Personal Data Breach
In the event of a personal data breach, the Company shall inform the Data Protection Board of India and every affected User without undue delay, and shall submit a detailed report to the Data Protection Board within 72 hours, in accordance with the DPDP Rules, 2025. The Company shall take immediate steps to contain and remediate the breach and shall document the incident.
Patient Confidentiality
The Company, its employees and any person engaged by the Company shall keep all medical records, personal information, diagnoses and communications relating to a User-Patient strictly confidential. Such information shall not be disclosed, published or released to any third party except:
- with the express consent of the User-Patient;
- as strictly required or permitted by applicable law, such as public health reporting obligations or an order of a court or competent authority; or
- to the User-Patient’s Treating Doctor on the App, for the purpose of the User-Patient’s care.
All details provided by User-Doctors shall likewise be kept confidential.
This obligation of confidentiality between the Users and the Company shall survive the closure of any account and the termination of any agreement between a User and the Company.
Rights of Users
- Right
- Access
- Description
- A summary of the personal data held by the Company
- How to exercise
- Settings → Privacy, or privacy@docfollow.in
- Right
- Correction
- Description
- Correction of inaccurate or incomplete data
- How to exercise
- Within the App, or privacy@docfollow.in
- Right
- Erasure
- Description
- Erasure of personal data, subject to Section 11
- How to exercise
- Settings → Delete Account, or privacy@docfollow.in
- Right
- Withdrawal of consent
- Description
- Withdrawal of any consent previously given
- How to exercise
- Settings → Privacy → Manage Consent
- Right
- Nomination
- Description
- Nomination of a person to exercise these rights in the event of death or incapacity
- How to exercise
- privacy@docfollow.in
- Right
- Grievance redressal
- Description
- A complaint about the handling of personal data
- How to exercise
- Grievance Officer (Section 16)
| Right | Description | How to exercise |
|---|---|---|
| Access | A summary of the personal data held by the Company | Settings → Privacy, or privacy@docfollow.in |
| Correction | Correction of inaccurate or incomplete data | Within the App, or privacy@docfollow.in |
| Erasure | Erasure of personal data, subject to Section 11 | Settings → Delete Account, or privacy@docfollow.in |
| Withdrawal of consent | Withdrawal of any consent previously given | Settings → Privacy → Manage Consent |
| Nomination | Nomination of a person to exercise these rights in the event of death or incapacity | privacy@docfollow.in |
| Grievance redressal | A complaint about the handling of personal data | Grievance Officer (Section 16) |
Data Retention
Messages, prescriptions and health records exchanged between a User-Patient and the Treating Doctor constitute medical records of the Treating Doctor. Such records are retained for the period required under applicable medical record-keeping laws and regulations, including the Telemedicine Practice Guidelines, 2020 and the professional conduct regulations applicable to registered medical practitioners, even where a User-Patient closes the account. On expiry of that period, the records are deleted.
- Data type
- Account and profile data
- Retained for
- While the account is active
- After an erasure request
- Sign-in is disabled at once, and every session ends. Profile data is retained, because it identifies the consultation records the Treating Doctor must keep, and is deleted with those records
- Data type
- Consultation records: messages, prescriptions and health records
- Retained for
- The period required under applicable medical record-keeping law (currently a minimum of three years from the last consultation)
- After an erasure request
- Retained for the legally required period, then deleted
- Data type
- Private clinical notes of a User-Doctor
- Retained for
- Until deleted by the User-Doctor, or the legally required period
- After an erasure request
- Deleted on expiry of the legally required period
- Data type
- Consent records
- Retained for
- Seven years after withdrawal
- After an erasure request
- Retained as proof of lawful processing
- Data type
- Analytics and crash logs
- Retained for
- 12 months
- After an erasure request
- Purged automatically
- Data type
- OTP logs
- Retained for
- 7 days
- After an erasure request
- Purged automatically
| Data type | Retained for | After an erasure request |
|---|---|---|
| Account and profile data | While the account is active | Sign-in is disabled at once, and every session ends. Profile data is retained, because it identifies the consultation records the Treating Doctor must keep, and is deleted with those records |
| Consultation records: messages, prescriptions and health records | The period required under applicable medical record-keeping law (currently a minimum of three years from the last consultation) | Retained for the legally required period, then deleted |
| Private clinical notes of a User-Doctor | Until deleted by the User-Doctor, or the legally required period | Deleted on expiry of the legally required period |
| Consent records | Seven years after withdrawal | Retained as proof of lawful processing |
| Analytics and crash logs | 12 months | Purged automatically |
| OTP logs | 7 days | Purged automatically |
A User-Doctor who closes an account may export the User-Doctor’s records before closure. A User-Patient who closes an account ceases to have access to the App; consultation records held on behalf of the Treating Doctor are retained only as set out above.
The Company shall address every erasure request within the period prescribed under the DPDP Rules, 2025, and shall inform the User where any data must be retained under law, and for how long.
Prescription Image Processing
Where a User has consented to prescription images, the following process applies:
- the User-Doctor or authorised Clinic Staff photographs a paper prescription;
- the image is uploaded over an encrypted connection to the Company’s servers in India;
- the image is processed by an optical character recognition (OCR) service to read medicine names and dosages;
- the extracted text is shown to the User-Doctor for review and correction, and nothing is saved until the User-Doctor confirms it; and
- the original photograph is always retained as the authoritative record.
The OCR service is provided by Google Cloud, processing [within India / outside India — to be confirmed]. The provider acts as a Data Processor on the Company’s instructions under a data processing agreement, and does not retain images after processing or use them for its own purposes.
Data of Children
The App may hold health records of patients below 18 years of age, recorded by the Treating Doctor as part of clinical care.
- A person below 18 years of age cannot create an independent account. The account is created and used by a parent or lawful guardian.
- Before processing the data of a child, the Company obtains verifiable consent of the parent or lawful guardian, using a method approved under the DPDP Rules, 2025, and records the relationship.
- The Company does not track, monitor or profile children, and does not direct any targeted advertising at children.
- The Company does not process the data of a child in any manner likely to have a detrimental effect on the well-being of the child.
Third-Party Service Providers
The Company relies on the following service providers. Each processes data on the Company’s instructions and not for its own purposes.
- Service
- Cloud hosting
- Provider
- [To be confirmed]
- Data shared
- All App data, encrypted
- Location
- India
- Service
- OCR processing
- Provider
- Google Cloud
- Data shared
- Prescription images
- Location
- [To be confirmed]
- Service
- Push notifications
- Provider
- Firebase Cloud Messaging
- Data shared
- Device tokens only
- Location
- —
- Service
- SMS / OTP
- Provider
- MSG91 (Walkover Web Solutions Pvt Ltd)
- Data shared
- Mobile number only
- Location
- India
- Service
- Analytics
- Provider
- [To be confirmed]
- Data shared
- Anonymised usage data
- Location
- [To be confirmed]
| Service | Provider | Data shared | Location |
|---|---|---|---|
| Cloud hosting | [To be confirmed] | All App data, encrypted | India |
| OCR processing | Google Cloud | Prescription images | [To be confirmed] |
| Push notifications | Firebase Cloud Messaging | Device tokens only | — |
| SMS / OTP | MSG91 (Walkover Web Solutions Pvt Ltd) | Mobile number only | India |
| Analytics | [To be confirmed] | Anonymised usage data | [To be confirmed] |
Grievance Officer
Any grievance, complaint or issue relating to personal data shall, in the first instance, be addressed to the Grievance Officer:
- Name: Dr. J. Sreeharsha
- Designation: Founder and Director, DocFollow Technologies Private Limited
- Address: 4-1-105, R K Nagar, Nawabpeta, Nellore – 524002, Andhra Pradesh, India
- Email: privacy@docfollow.in
- Response time: Within 15 days of receipt of a complaint
A User who is not satisfied with the response of the Grievance Officer may approach the Data Protection Board of India in accordance with the DPDP Act, 2023.
Changes to this Privacy Policy
- Users shall be notified within the App of any material change to this Privacy Policy.
- The “Last updated” date above shall be revised on every change.
- Where a change affects how health data is processed, the Company shall seek fresh consent rather than rely on continued use of the App.
Contact
- Company: DocFollow Technologies Private Limited
- CIN: U62011AP2026PTC127506
- Registered office: 4-1-105, R K Nagar, Nawabpeta, Nellore – 524002, Andhra Pradesh, India
- Email: privacy@docfollow.in
- Website: www.docfollow.in
This Website
Doctors can register on this website. The form asks for name, mobile number, email address, specialty, qualification, medical council and registration number, clinic name and address, a copy of the medical council registration certificate, and a copy of the doctor’s Aadhaar card as ID proof. Only our review team can open the certificate and the Aadhaar card.
This website is hosted by Cloudflare, which also checks that registration forms are sent by a person rather than a bot. Emails to doctors who register are sent through Resend.
This website does not use advertising or analytics cookies. It remembers whether you chose light or dark mode, in your own browser.
