ड्राफ़्ट – भारतीय कानूनी सलाहकार की समीक्षा बाकी है। अभी लागू नहीं।
कानूनी दस्तावेज़ अभी अंग्रेज़ी में उपलब्ध हैं। अनुवाद जल्द आएँगे।
1. Data fiduciary
For account and website data, the data fiduciary is [Company legal name], [Registered office address, India]. For patient records in the SOTTO app, the clinic is the data fiduciary and SOTTO processes that data on the clinic's behalf (see the Data Processing Agreement).
2. What we collect on this website
- Account data: name, e-mail, mobile number, designation, medical registration number, clinic name and state.
- Security data: sign-in history, devices and sessions, approximate IP address.
- Billing data: plan, invoices. Card and UPI details are handled by our payment provider and never reach SOTTO.
- Messages you send us through the contact form.
This website never collects or displays patient records.
3. Why we use it
- To create and secure your account.
- To provide the trial and paid plans and issue GST invoices.
- To answer your questions.
- With your consent only: privacy-friendly analytics.
4. How long we keep it
Account data is kept while your account exists. If a trial ends without a purchase, data is kept so it can be restored when you buy a plan, for [maximum period – open question Q17], after which we notify you before deleting it. You can ask us to delete it earlier at any time.
5. Your rights
- Access a summary of your personal data.
- Correct or update it.
- Erase it (account deletion).
- Withdraw consent (e.g. analytics) at any time.
- Nominate another person to exercise your rights.
- Grievance redressal (below) and, afterwards, complaint to the Data Protection Board of India.
6. Grievance officer
[Grievance officer name] – grievance@sottohealth.com. We respond within [timeline to be confirmed].
7. Security and storage
Data is encrypted in transit and at rest and access is restricted by role. [Storage locations and any cross-border transfers to be listed.]
