Privacy Policy
How we handle personal and health data under India's Digital Personal Data Protection (DPDP) Act, 2023 and DPDP Rules, 2025.
Last updated: 11 July 2026. This plain-language policy is subject to applicable law and any signed agreement with Prescr.
1. Who we are
Prescr ("Prescr", "we", "us") is a clinic operating system and payment technology platform made in India by RG INSYS. Depending on the activity, we may act as a Data Fiduciary for Prescr account, support, payment and platform operations, or as a Data Processor when we process clinic patient data on a clinic's documented instructions. Clinics remain responsible for the healthcare services they provide and may be independent or joint Data Fiduciaries for their patients' data.
2. What we collect
- Clinic & staff details: names, roles, contact numbers, email, city/state.
- Patient data entered by clinics: demographics, vitals, history, diagnoses, prescriptions, billing and, where used, consult audio for the scribe.
- Booking & payment data: appointment details, clinic/service selected, amount, taxes or fees, transaction ID, payment status, refund status and support communications.
- Usage data: basic, privacy-respecting analytics to run and improve the service.
3. How we use it
To provide the clinic OS (intake, queue, scribe, records, billing, pharmacy), to process bookings and payments, to settle clinic-service payments to the respective clinic, to link records to ABHA/ABDM where consented, to support and onboard your clinic, and to meet legal obligations. We do not sell patient or prescribing data, and we do not use your data to train third-party AI models.
4. Consent and lawful use
Where consent is required, we ask for clear, specific and informed consent, avoid bundling unrelated permissions, and provide a way to withdraw consent as easily as it was given. For children or persons who require a lawful guardian, we rely on guardian consent where required. Some processing may also occur where permitted or required by law, such as security, fraud prevention, accounting, legal compliance and clinic service fulfilment.
5. Storage & security
Patient data is stored in India. We encrypt data in transit and at rest, apply role-based access controls, log access, and follow a de-identify-first approach where AI processing is used. AI-generated clinical notes are reviewed and signed by a clinician before they are finalised.
6. Sharing
We share data only as needed to provide the service: with the selected clinic or provider for the booked service, India-resident infrastructure and processing sub-processors under contract, payment processors such as Razorpay for payment, settlement and refund processing, where you direct (e.g. ABDM sharing with patient consent), or where required by law. Prescr does not store full card numbers, UPI PINs or net-banking credentials.
7. Your rights
Under the DPDP framework you may access information about processing, correct or erase personal data where applicable, withdraw consent, nominate another person as permitted by law, and raise grievances. Patients should contact their clinic first for clinic-held medical records; you can also reach our Grievance Officer.
8. Retention
We retain data for as long as needed to provide the service and to meet medical-record retention and other legal obligations, then delete or de-identify it.
9. Changes
We'll update this policy as the product and law evolve, and note the date above.
10. Contact
Questions? Email [email protected] or see our Grievance Officer and DPDP Notice.