D+Doctor SOS
लॉगिनफ़्री डेमो बुक करें

Privacy Policy

Last updated: 23 September 2026

Doctor SOS is a hospital operations platform built and operated by Gariba IT Services Private Limited ("Gariba", "we", "us"). This policy explains what personal data the platform handles, why, who it is shared with, and the rights you have under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable Indian law.

1. Who is responsible for your data

  • Patients of a hospital or clinic. The hospital you visit decides why and how your health and appointment data is used. The hospital is the Data Fiduciary; Gariba processes that data on the hospital's behalf as its Data Processor. Requests about your medical records should first go to your hospital; we will help them respond.
  • Hospital staff accounts, hospital owners and website visitors (including people who request a demo). For this data Gariba is the Data Fiduciary.

2. What we collect

WhoData
PatientsName, mobile number, age/gender, optional email, appointments and tokens, visit notes, prescriptions, uploaded reports, payment records, language preference, and consent choices (for example, sharing updates with an attendant).
Hospital staffName, mobile number, email, role(s), and a log of actions taken in the platform.
Demo requestsName, hospital name, city, mobile number, optional email and message.
EveryoneTechnical data needed to run the service securely: IP address, device/browser type and request logs, kept for security and abuse prevention.

We do not sell personal data, and we do not use patient data for advertising.

3. Why we use it

  • To run the OPD: booking, tokens, live queue status, delay updates and reminders.
  • To keep and share medical records (prescriptions, reports) with the patient they belong to.
  • To record and receipt payments, and to process online payments you choose to make.
  • To sign staff in with one-time codes and to keep a tamper-evident audit trail of actions.
  • To respond to demo requests and support queries.
  • To keep the service secure, reliable and compliant with law.

Automated assistance: when hospital staff do not complete a routine task (such as an appointment reminder) within its time window, the platform may complete it automatically. Refunds, prescriptions and clinical decisions are always made by a person. Every automated action is recorded with its reason on the hospital's audit timeline.

4. Who we share it with

We share personal data only with the hospital you deal with and with the service providers below, each bound by contract to use it only to provide their service to us:

RecipientPurpose
HostingerServers that run the application (data centre in India)
Amazon Web Services (AWS)Encrypted storage of uploaded files and backups (India region)
RazorpayProcessing online payments, when you choose to pay online
ResendDelivering emails such as sign-in codes and notifications
MSG91 and Meta (WhatsApp)Delivering WhatsApp/SMS messages, where the hospital has enabled them

Some providers (for example, email delivery) may process data outside India. We use only providers that apply appropriate security safeguards, and we transfer only what is needed to deliver the message. We may also disclose data where required by law or a lawful order.

5. How long we keep it

Medical records are kept for as long as the hospital requires them under applicable medical record-keeping rules, and are then deleted or anonymised on the hospital's instruction. Staff account data is kept while the account is active and for a reasonable period after. Demo-request data is kept for up to 24 months unless you ask us to delete it sooner. Audit records are kept for their full legal retention period because they must not be altered.

6. Security

Access is role-based (owner, reception, doctor), sign-in uses one-time codes, data is encrypted in transit, stored files and backups are encrypted, and every action is recorded on a tamper-evident timeline. No system is perfectly secure; if a breach affecting your data occurs we will notify the hospital and the Data Protection Board as the law requires.

7. Your rights

Under the DPDP Act you may:

  • ask for a summary of your personal data and how it is processed;
  • ask for inaccurate or incomplete data to be corrected or updated;
  • withdraw consent and ask for data to be erased, subject to legal retention duties;
  • nominate another person to exercise your rights in case of death or incapacity;
  • raise a grievance with us, and then with the Data Protection Board of India.

Patients should contact their hospital first; you can also write to us and we will route the request. Staff, owners and visitors can write to us directly.

8. Children

Data about a child is provided by a parent or lawful guardian at the hospital. We do not knowingly collect children's data for any purpose other than their care.

9. Grievance Officer

Grievance Officer, Gariba IT Services Private Limited
Email: doctor.sos@garibaitservices.com
Registered office address available on request at doctor.sos@garibaitservices.com

We acknowledge grievances within 48 hours and aim to resolve them within 30 days.

10. Changes

We will post any change to this policy on this page with a new date, and notify hospitals of material changes. Questions: doctor.sos@garibaitservices.com.

D+Doctor SOS

आपके अस्पताल का ऑपरेटिंग सिस्टम

क्विक लिंक
  • फ़्री डेमो बुक करें
  • लाइव डेमो आज़माएँ
  • डेमो बुकिंग
  • स्टाफ़ लॉगिन
  • मरीज़ पोर्टल
नीतियाँ
  • प्राइवेसी पॉलिसी
  • सेवा की शर्तें
  • रिफ़ंड और कैंसलेशन
  • संपर्क करें
Gariba IT ServicesGariba IT Services

Doctor SOS is a product of Gariba IT Services Private Limited.

Developed & maintained by Gariba IT Services Pvt. Ltd.

© 2026 Gariba IT Services Private Limited · सर्वाधिकार सुरक्षित