1. Who this policy is for
RevisitMD is software used by independent doctors and clinics ("Clinics") to manage patients and automatically stay in touch with them after a visit, primarily over WhatsApp. This policy covers two groups differently:
- Clinics: the doctors, receptionists, and clinic staff who create accounts and use RevisitMD directly. You are our customer, and this policy explains what account data we hold about you.
- Patients: the people a Clinic treats, whose information a Clinic enters into RevisitMD in order to provide care and follow-up. Patients don't create their own RevisitMD account or log in; they receive and can reply to WhatsApp messages sent by their Clinic through our platform.
2. What data we collect
From Clinics
- Doctor and staff name, email address, phone number, and login credentials
- Clinic name, specialty, and location details provided during setup
- Subscription and billing status
About patients (entered by the Clinic, not collected directly from patients by us)
- Name and phone number (used to send WhatsApp messages)
- Visit records: diagnoses, symptoms, procedures, chronic conditions, and prescribed medicines
- Visit notes and any consultation fee/billing details recorded for that visit
- Message history: the check-ins, reminders, and any replies exchanged over WhatsApp
Our public marketing website (the pages you're reading right now, at revisitmd.com) uses Google Tag Manager and Google Analytics to understand how visitors find and use the site: which pages get read, roughly how many visitors we get, and what device/browser they're on. These tools set cookies in your browser and may process your IP address and general location. None of this runs inside the RevisitMD product itself (the part doctors and receptionists log into); it only runs on the public marketing pages, and only after you actively accept the cookie banner shown on your first visit. If you decline or don't respond to that banner, none of this loads at all. We don't run any advertising trackers or ad-retargeting scripts. The only cookie the RevisitMD product itself sets is a strictly necessary session cookie that keeps a doctor, receptionist, or admin signed in. That one isn't optional, since the product can't keep you logged in without it.
3. How we use this data
- To run the Clinic's day-to-day operations inside RevisitMD: patient records, the visit queue, billing, and team accounts
- To send the automated WhatsApp messages a Clinic has configured (medicine and symptom check-ins, revisit reminders, chronic-care reminders, and feedback requests) on that Clinic's behalf and in that Clinic's name
- To maintain a patient's visit history so a Clinic can reference it on a future visit
- To provide customer support when a Clinic contacts us for help
We do not sell patient or Clinic data to anyone, for any purpose.
4. Where data is stored and how it's protected
RevisitMD runs on a single cloud server (Oracle Cloud Infrastructure), with all data held in a Postgres database on that server. We take the following measures to protect it:
- All traffic to and from RevisitMD is encrypted in transit (HTTPS/TLS)
- Access to Clinic accounts requires a password; admin, doctor, and receptionist accounts are kept in separate authentication systems with different permission levels
- The database itself is not reachable from the public internet; only the application server can query it
- Automated nightly backups are taken and stored separately in cloud object storage, so data can be recovered in the event of a server failure
We don't currently hold formal security certifications (such as ISO 27001 or a SOC 2 report). If your Clinic requires one of these for compliance reasons, please contact us directly to discuss.
5. Who we share data with
- Meta (WhatsApp Business Platform): messages a Clinic sends through RevisitMD are delivered via Meta's WhatsApp Cloud API. Meta processes the message content and phone number as required to deliver it, under Meta's own privacy policy.
- Oracle Cloud Infrastructure: our hosting provider, which stores the database and backups described above.
- Google Analytics: used only on our public marketing website (not inside the RevisitMD product) to understand site traffic, as described in Section 2. Google processes this data under its own privacy policy.
We don't share data with advertisers, data brokers, or any other third party.
6. How long we keep data
We retain Clinic and patient data for as long as a Clinic's account remains active, plus a reasonable period afterward in case the Clinic reactivates or needs to export records. A Clinic (or a patient, through their Clinic) can request deletion of specific patient records at any time by contacting us, subject to any legal obligation a Clinic may have to retain medical records for a minimum period under applicable healthcare regulations.
7. Your rights as a data principal
Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), both Clinics and patients ("data principals") have the right to:
- Access a summary of the personal data we (or, for patients, your Clinic) hold about you
- Correct inaccurate or outdated data
- Erase data that's no longer needed for the purpose it was collected for, subject to any legal record-keeping requirement a Clinic must follow
- Withdraw consent at any time, as easily as it was given, for any processing that relies on consent (for example, marketing analytics on this website)
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
- Lodge a grievance with us, and if unresolved, escalate it to the Data Protection Board of India
Because a Clinic (not RevisitMD) is the one treating a patient and entering their information, the fastest way for a patient to exercise these rights is through their Clinic directly. RevisitMD will also honor a request made directly to us, using the data rights request form, once we've verified it with the relevant Clinic. We aim to respond to any request within 2 working days.
8. Children's and minors' data
Some patients treated through RevisitMD are minors. In every case, it is the treating Clinic (not RevisitMD) that collects this information directly from the patient or their parent/guardian in the course of care, and enters it into RevisitMD. We do not collect information directly from minors ourselves.
9. Changes to this policy
If this policy changes in a way that meaningfully affects how data is handled, we'll update the date at the top of this page and, where appropriate, notify Clinics directly.
10. Grievance Officer
In accordance with the DPDP Act, the Grievance Officer for RevisitMD is:
- Name: Yogesh Rajendhiran, Founder
- Email: hello@revisitmd.com
- Phone: +91 8608080250
- Business name: RevisitMD Private Limited
- Registered address: 24H, Thilagar Street, Palani - 624601
Any complaint or grievance about how your data is handled can be sent to the Grievance Officer above, or submitted through our data rights request form. If you're not satisfied with our response, you may escalate the matter to the Data Protection Board of India.