01
Who we are
Nitya Aarogya is a product operated by Trinetra Technologies, a sole proprietorship of Shubham Desoria.
353, Trinetra Technologies, Ganj Bazaria, Near Old Bus Stand,Sehore, Madhya Pradesh – 466001, India.
Privacy and support contact: Shubham Desoria
business@nitya-aarogya.com
Clinics decide which patient information to enter, how it is used for care and clinic operations, and which staff may access it. We provide software and process clinic information to deliver the service under the clinic's instructions and our agreement with it. We also handle information for account administration, subscription billing, support and security.
A clinic may have its own privacy notice for its medical services. Patients should normally contact their clinic first about medical records; we can help coordinate a request received by us.
02
Information we process
The information depends on the features you or your clinic use. It may include:
- Clinic and staff names, contact details, professional information, roles, account credentials and activity.
- Patient names, contact details, age or date of birth, gender, address, photographs and patient identifiers. The application includes an Aadhaar information field; clinics should use it only where necessary and appropriately authorized.
- Appointments, consultation notes, medical histories, vital signs, prescriptions, reports, uploaded documents, pharmacy and laboratory records, and billing information.
- For connected messaging: phone and account identifiers, messages, attachment references, templates and delivery or read status.
- Subscription and payment references, transaction status, invoices and related customer details.
- Support messages, IP addresses, device or browser information, access and security logs, and notification tokens where the relevant service is enabled.
Information may be supplied by you, your clinic, authorized staff or a connected provider. Please provide only information necessary for the relevant service.
03
How we use information
We process information to provide accounts and clinic workflows; manage appointments, records, documents and billing; operate enabled communications and consultations; respond to support and privacy requests; protect the service; investigate errors or misuse; and meet applicable obligations.
Trinetra Technologies does not use customer or patient personal information for advertising or to train AI models. We do not sell that information or share it with marketing companies.
AI-assisted clinical summaries and translation are not configured in our production service as of 8 September 2026. Before enabling features that send information to an AI provider, we will update the relevant disclosures and establish the appropriate provider settings and permissions. Our statement about our own use of information is not a blanket claim about an independent provider's practices.
04
Providers and sharing
Google Cloud provides application hosting and file storage; MongoDB Atlas provides database hosting. The main website's hosting provider processes technical information needed to deliver the site. Razorpay supports subscription payment features; a payment provider may collect payment details directly through its checkout.
Where enabled, WhatsApp messaging involves Meta/WhatsApp, email delivery involves the configured email provider, and push notifications involve Google Firebase. We share information needed for the relevant function. Provider processing may also be governed by the provider's terms and privacy notice. Not every integration is enabled for every clinic or in every release.
Authorized clinic staff can access records according to their permissions. We may disclose information to comply with applicable law or a valid legal process, or as necessary to investigate misuse and protect rights or safety. Information may be processed outside India depending on the provider and service; we do not promise that every copy or every processing activity remains in India.
05
Connected features and browser storage
WhatsApp and other communications
Where messaging is enabled, clinics must obtain the appropriate messaging permission and honor opt-out requests. Tell the sending clinic if you want messages to stop, or contact us for help. Withdrawing messaging permission is separate from deleting medical records. Recipients and messaging providers may retain their own copies.
Website demo bookings
The website embeds a Google Calendar booking page for product demonstrations. When you book, Google Calendar and Trinetra Technologies receive your name, email address, phone number, clinic or organisation and city, appointment time, and any optional notes you provide. We use these details to arrange the demonstration, prepare for your questions and send the calendar invitation and related updates. Google Calendar creates the Google Meet link. Please do not enter patient information or medical records in the booking form.
Loading the booking page connects your browser to Google, which processes technical information and may use cookies or your signed-in Google account under its own privacy policy. You can use the invitation to cancel or reschedule. Cancellation does not automatically delete the booking or email records; contact us for a privacy or deletion request.
Browser storage
The applications store authentication tokens and preferences in your browser, including an optional remembered email address. Clearing this storage may sign you out; it does not delete server-side records. Website hosting and connected services may use technical cookies or similar storage needed to operate their features.
Video consultations
Our self-hosted MiroTalk service processes connection information to establish video consultations. Audio and video are transmitted between participants, with relay infrastructure when needed. The video software supports participant-initiated recording and download to the recording participant's device. Participants must obtain the necessary permissions before recording and protect any downloaded copies. Deletion from our systems does not remove recordings or other copies held independently by participants.
06
Retention and deletion
Patient records are the clinic's records. We keep a clinic's records online for 5 years from the date the clinic joined. After that, once a year, we hand over the oldest year of records to the clinic as a download and remind the head doctor 3 times. About 90 days after the download is ready, we delete that year of records from our systems. Our Terms of Service explain the full schedule.
- Legal hold. We do not delete records that the clinic has marked as under legal hold, or that a court, a regulator or the law requires us to keep.
- After hand-over. Keeping the handed-over records is the clinic's responsibility, for as long as the law requires. Some records, such as medico-legal records and records of children, must be kept for longer than 5 years.
- Our own records. Invoices we issue to the clinic and its WhatsApp credit history are our tax and accounting records. We keep them for 8 years and then delete them. Security and dispute-related information may be kept for as long as that purpose or obligation needs it.
Cancelling a subscription does not automatically erase clinic data. The patient removal action deactivates a record and cancels scheduled appointments; it is not complete erasure of the record or related data. Contact us for a separate, verified deletion request.
After verification and agreement on the scope, we aim to complete approved active-system deletion within the request-handling period below, except for records under legal hold or that the law requires us to keep. Backup copies are removed within 90 calendar days after a deletion, whether it follows a yearly hand-over or an approved request. If a provider restriction requires a different schedule for a particular backup, we will explain it.
We will explain information that must be retained and the reason, and coordinate relevant provider-held copies where possible. Copies held independently by clinics, recipients or other providers may require a request to those organizations. See data-deletion instructions.
07
Your requests and complaints
Email business@nitya-aarogya.com, addressed to Shubham Desoria, for privacy questions, complaints, or requests concerning access, correction, deletion or withdrawal of permission, as applicable.
Include your name, relevant clinic or account, a contact method and a description of your request. Do not send passwords, full identity-document numbers or medical attachments in your initial email. We may need to verify identity and authority and coordinate with your clinic before acting.
Our service targets are to acknowledge requests within 7 calendar days and aim to resolve them within 30 calendar days after necessary verification. We will explain delays, remaining steps or lawful retention. Applicable shorter legal deadlines take precedence. These service targets do not limit your rights under applicable law.
08
Security and children's information
We use safeguards such as HTTPS, authentication and clinic-scoped access controls. These measures reduce risk but cannot eliminate every risk. Users should protect their login details and use appropriate access permissions.
Clinics may treat children and enter their records. Clinics are responsible for establishing the necessary authority and parent or guardian involvement where required. A parent or guardian may contact the clinic or our privacy contact about a child's information, subject to verification and applicable requirements.
09
Changes to this policy
We may update this policy as our services or requirements change. This page shows the last updated date. Where required, we will provide additional notice or obtain the necessary permission for material changes.