Last Updated: 19 July 2026
[bracketed] placeholder below with your
actual registered entity details and have this reviewed by a lawyer familiar with India's DPDP Act,
2023 before relying on it. This draft is a starting point, not legal advice.
This Privacy Policy explains how Elysian IQ Hospital Management ("we", "our", "us", or the "Platform") collects, uses, protects, and shares personal data when you use our web and mobile services, or when a healthcare provider using our Platform communicates with you via SMS, WhatsApp, or email on their own behalf.
Legal Entity: [Registered legal name, e.g. "Elysian IQ Technologies Private Limited"], having its registered office at [registered address], India ([CIN / GST / other registration number, if applicable]).
Elysian IQ Hospital Management is a software platform used by independent hospitals and clinics ("Providers") to manage their own patients. Each Provider is independently responsible, as the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), for the personal data of its own patients. Elysian IQ acts as the Provider's data processor for that data — we host, secure, and transmit it on the Provider's instructions. If your query relates to a specific visit, appointment, prescription, or bill, please contact the Provider (clinic/hospital) you visited directly, as they control that data; we can assist them in fulfilling your request.
Where we determine the purpose and means of processing ourselves — for example, Provider account/billing data, or platform usage analytics — we act as the Data Fiduciary for that data.
We use three channels, each only with your consent (or your Provider's, on your behalf):
We do not sell your personal data. We share it only with:
[If any of the above process or store data outside India, list them here and confirm this is permitted under the DPDP Act's rules on cross-border transfer at the time of publishing.]
Sensitive fields such as patient name, phone number, and address are encrypted at rest using per-hospital envelope encryption, not stored in plain text. We use access controls, authentication, and secure transport (HTTPS) to protect data in transit and at rest, and we log access to sensitive records.
In the event of a personal data breach, we will notify the affected Provider(s) without undue delay so they can meet their own DPDP Act obligations, and, where the breach is one we control as Data Fiduciary, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Act.
Subject to the DPDP Act, you have the right to:
For data controlled by your Provider (your medical records, appointments, prescriptions), please contact the Provider directly, or contact us and we will route your request to them. For data we control directly, email: elysian.iq2025@gmail.com
In accordance with the DPDP Act, 2023, the Grievance Officer for data we control is:
[Full Name]
Elysian IQ Hospital Management
Email: [grievance officer email]
Address: [registered address]
We will acknowledge and respond to grievances within the timeframe required under the DPDP Act.
We (and Providers using our Platform) retain personal data only as long as necessary for the medical, legal, and operational purposes it was collected for, or as required by applicable law (including medical-record retention requirements). Data no longer needed for these purposes is deleted or anonymized.
Where a patient is under 18, we process their data only with the consent of, and on instructions from, their parent or lawful guardian, as required under the DPDP Act. We do not use children's personal data for behavioural monitoring or targeted advertising.
We may update this policy from time to time. Material changes will be posted here with an updated "Last Updated" date and, where appropriate, communicated via the app, email, SMS, or WhatsApp.
Elysian IQ Hospital Management
Email: elysian.iq2025@gmail.com
Website: www.elysian-iq.com