Data privacy

You decide where your patients’ records live.

Run CliniKite on our secure Indian cloud — encrypted and scoped to your clinic — or on-premise, where records never leave your building. On either plan, we never sell, share, or mine your patient data.

A clean desk with a laptop and smartphone, representing secure digital records
Patient data sold or mined
Never
What this means for your clinic

Four straightforward commitments.

Each commitment below is a direct outcome of how the product is designed. They are not optional settings or premium upgrades — they are the default behaviour of the platform.

01

Your data is never our business model

CliniKite earns revenue from software — clinic subscriptions, licences, and optional add-ons. On no plan do we sell aggregated data, derive analytics from your records, or engage in pharmaceutical-industry data partnerships.

02

Encrypted, and scoped to your clinic

On CliniKite Cloud, your data is encrypted at rest and in transit, and every request is strictly scoped to your clinic so staff only ever see their own patients. On-premise installations add full-disk encryption on hardware you control.

03

On-Premise keeps data on-site

Choose the On-Premise plan and every record stays on a machine at your clinic. Your team holds the database and backup credentials, and the system keeps working on the local network during internet outages.

04

AI sees only de-identified text

When AI assistance is used, a privacy filter removes names, dates of birth, phone numbers, addresses, and identity numbers before any request leaves your clinic.

Digital Personal Data Protection Act

Aligned with India’s data protection law.

India’s Digital Personal Data Protection Act (DPDP) comes into full effect in May 2027. The Act places clear obligations on any organisation that holds personal data, including the responsibilities of the data fiduciary, consent management, breach notification, and data-principal rights.

Your clinic is always the data fiduciary for its patients. On On-Premise, records never leave your clinic, so you are the sole fiduciary end to end. On Cloud, CliniKite acts as your data processor under a written agreement, with all data hosted in India — and data-principal requests are handled through the CliniKite interface either way.

CliniKiteTypical cloud EMRs
Patient data sold or sharedNeverCommonly allowed
Data hosted in IndiaAlwaysNot always
Encryption at restAlwaysVaries
Export of recordsOpen, documentedOften proprietary
On-premise optionAvailableRarely offered
Revenue from your dataNeverCommon
Common questions

The questions clinics ask most often.

Each answer covers the practical implication for your clinic. More detailed documentation is available on request, including a technical summary suitable for IT or security review.

01Where are my patient records stored?

It depends on the plan you choose. On CliniKite Cloud, records are hosted on our secure multi-tenant platform in an Indian data region (AWS Mumbai), encrypted and strictly scoped to your clinic. On On-Premise, records are stored only on a machine at your clinic and never leave the building.

02Can CliniKite read or sell my patient data?

We never sell, share, or mine your clinical data on any plan. On Cloud, we operate the hosting on your behalf as your data processor, with access limited to authorised support that you request and that is time-bound. On On-Premise, CliniKite has no administrative access to your database at all.

03What happens if CliniKite discontinues the product?

Each clinic can export its complete records in an open, documented format at any time. On-Premise clinics keep the application and database outright; Cloud clinics receive a full export and can migrate to On-Premise. Your practice is never stranded.

04How does the AI assistance protect patient privacy?

Every AI request passes through a privacy filter that removes patient identifiers before the request is sent. The AI provider receives clinical text without names, dates of birth, contact details, or identity numbers.

05How does CliniKite fit DPDP Act compliance?

On On-Premise, your clinic is the sole data fiduciary for its patient records, which keeps consent, access, correction, and erasure entirely in your hands. On Cloud, your clinic remains the data fiduciary and CliniKite acts as your data processor under a written agreement, with data hosted in India.

For technical review

How the On-Premise deployment keeps data on-site.

The diagram below shows the On-Premise model: what stays inside your clinic and what — only de-identified AI requests — ever leaves. Detailed technical documentation for both Cloud and On-Premise is available during the evaluation process.

YOUR CLINICCLINIC SYSTEMRuns on your hardwareCliniKite applicationWeb interface for staffSecure software updatesPATIENT RECORDSYour clinic's database· Records & prescriptions· Vitals & lab reports· Invoices & messagesCLINIC STAFFDRDoctorRCReceptionNRNurseBLBillingADAdminENCRYPTED BACKUPKept in your clinicNightly, encryptedYour encryption keyPRIVACY FILTERRemoves identifiersBefore any AI requestName, DOB, phone, IDCLINIKITE SERVICESAdministrative onlyWhich clinics are registeredLicence and connectivity statusSoftware update channelNo records or namesNo prescriptionsNo vitals or lab dataAI PROVIDERReceives de-identified text onlyRequest:"BP 138/86, trending up 3visits. Current medication telmisartan 40.Suggestions for combination therapy?"No name, date of birth, phone, Aadhaar, or addresslicence and updatesde-identified requestsuggestion returnedPatient information remains inside your clinicDe-identified requests are the only clinical data that leavesAdministrative signals only