Privacy Policy
Last updated 29 September 2026
How personal information is collected, used, and protected across Soefer’s outpatient scheduling and clinic management platform in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act).
On this page
01Our Governance & Compliance Role
Soefer™ is a healthcare technology service engineered by Jackie Crafts Private Limited ("Soefer", "we", "us", or "our"). We operate as a Data Fiduciary regarding user account management, authentication, and platform infrastructure, and as a Data Processor on behalf of clinics and doctors for clinic-directed outpatient queue management.
We adhere strictly to the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
02Information We Collect
We collect only the personal information strictly necessary to facilitate outpatient scheduling, clinic discovery, and queue coordination:
Patient Profile Details: Full name, age or date of birth, gender, and registered email address or Google authentication profile.
Dependent Family Profiles: Name, age/DOB, and gender of family members or dependents added by the primary account holder to manage outpatient tokens on their behalf.
Device Location Data: Precise or approximate GPS coordinates, collected only when you grant explicit permission in your device settings. Location data is used strictly to display nearby clinics, calculate travel time, estimate queue arrival, and verify physical arrival at the clinic counter. We never track your location in the background when the application is closed.
Appointment & Live Queue Data: Clinic identifier, consulting doctor, booked OPD shift or slot time, sequential token number, live queue status (queued, arrived, called, on hold, completed, cancelled, or no-show), and a secure 4-digit Visit PIN for front-desk verification.
Billing & Transaction Metadata: Payment gateway order identifiers, token fee paid, platform Booking Fee, GST tax invoice details, and refund settlement status. We never collect, store, or process raw credit/debit card numbers, CVVs, net banking credentials, or UPI PINs. All online payments are processed through RBI-authorized, PCI-DSS Level 1 compliant payment aggregators.
Doctor & Clinic Information: Full legal name, professional email address, National Medical Commission (NMC) or State Medical Council registration certificate and registration number, medical qualifications, clinic branch address, geo-coordinates, OPD operating hours, and verified bank account credentials (account number and IFSC) for automated payout settlements.
03How Information Is Used
Personal data is processed strictly for legitimate healthcare administrative purposes:
Service Delivery: Authenticating account logins via secure Google Sign-In and verified email links, allocating sequential OPD queue tokens, calculating live estimated wait times, and dispatching real-time queue status notifications via in-app push alerts.
Clinic Check-In & Verification: Verifying patient identity at the clinic counter via QR code scanning or 4-digit Visit PIN.
Financial Settlement & Taxation: Reconciling consultation fee collections and automated payouts to doctor linked accounts in compliance with Section 194-O of the Income Tax Act and GST regulations.
Customer Support: Investigating booking issues, resolving cancellation requests, and facilitating automated refunds.
Strict Non-Commercialization Guarantee: We never sell, rent, license, trade, or monetize patient personal data to pharmaceutical companies, medical device manufacturers, insurance brokers, or third-party advertisers.
04Data Sharing & Third-Party Processors
We disclose personal data only to verified service providers under contractual Data Processing Agreements necessary to operate platform infrastructure:
Cloud Infrastructure: Central databases and synchronization services are hosted exclusively in secure domestic data centres located within India in compliance with the DPDP Act, 2023.
Payment Gateway: RBI-authorized payment aggregator partners for secure transaction processing and automated settlement routing.
Real-time Push Notifications: Certified push notification services strictly for transmitting transactional queue updates and token turn alerts to patient devices.
Statutory & Law Enforcement: Disclosures are made only when legally mandated under applicable Indian law, court order, or formal summons by authorized statutory bodies.
05Data Residency & Technical Safeguards
Domestic Data Residency: All central application databases, transaction ledgers, and queue coordination services are hosted strictly within data centres located in India. Data is never transferred offshore.
Technical Safeguards: Strict TLS 1.3 encryption for data in transit, AES-256 transparent encryption at rest, automated security audit logging, and granular database access controls.
Staff & Front-Desk Permissions: Clinic receptionists operating kiosk mode can only issue tokens and announce turns. Front-desk staff are restricted from accessing doctor earnings, bank details, or sensitive credentials.
06Data Retention & Mandatory KYC Purge
Account Data: Retained for as long as your account remains active.
Doctor KYC Document Purge: In strict compliance with UIDAI regulations, doctor Aadhaar document scans uploaded during professional verification are permanently purged within 30 days of verification approval. PAN card details are retained for statutory tax compliance.
Statutory Financial Records: Transaction ledgers, GST invoices, and Section 194-O TDS records are retained for a minimum period of 7 years as mandated by Indian tax and accounting statutes.
Security Audit Logs: Operational and access audit logs are retained for 5 years pursuant to Section 67C of the Information Technology Act, 2000.
07Your Statutory Rights Under the DPDP Act, 2023
Under the Digital Personal Data Protection Act, 2023, you hold the following rights regarding your personal data:
Right to Access: You may view and review your personal profile data and outpatient booking history directly through the application.
Right to Correction & Updating: You may update, rectify, or complete inaccurate personal information (such as name, gender, or date of birth) directly within your profile settings.
Right to Erasure (Account Deletion): You may withdraw consent and request complete account deletion at any time via Profile → Settings → Delete Account. Upon confirmation, your profile and active records are permanently erased within 72 hours, excluding statutory tax and audit ledgers required by law.
Right to Nominate: In the event of death or incapacity, you have the right to nominate an individual to exercise your data rights in accordance with the DPDP Act.
08Privacy Questions & Grievance Redressal
In accordance with the DPDP Act, 2023 and the Information Technology Act, 2000, Soefer has designated a formal Grievance & Data Protection Officer.
To exercise your statutory privacy rights, withdraw consent, or raise a concern regarding personal data processing, email grievance@soefer.com. Please include your registered account details and a clear description of your request (never include passwords or authentication credentials).
Statutory grievances are acknowledged within 24 hours and addressed within statutory timelines (not exceeding 30 days).