This Privacy Policy explains how SJ Soft Tech (“we”, “us”, “our”) collects, uses, shares, secures, retains and protects personal data in connection with CutiSpan, our clinic-management platform (the “Platform”, “Service”) available at https://cutispan.com, per-clinic subdomains (*.cutispan.com) and related applications.
Operator: SJ Soft Tech, a sole proprietorship, G-3, SKC Royal Sannidhi, Road No. 5, Praneeth Nagar Road, KVR Valley, Shambipur (VTC), Bowrampet (PO), Medchal-Malkajgiri, Telangana 500043, India.
This Policy is aligned to India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 together with the SPDI Rules, 2011. By using the Platform you acknowledge this Policy.
CutiSpan is software used by Clinics to run their practice — appointments, consultations, diagnoses, prescriptions, pharmacy, lab tests, billing, telemedicine and a patient portal.
Name, mobile number, email, date of birth or age, gender, address, blood group, emergency contact, referral source, insurance ID.
Skin type, allergies, medical history, symptoms, diagnoses (ICD-10 codes, severity, PASI/DLQI scores), examination findings and clinical notes, treatments and procedures, lab tests and results, prescriptions and dispensing history, vital signs, clinical photographs (before/after images), and signed consent forms (including a digital signature image).
Symptoms and photos submitted for review, the doctor’s notes/diagnosis, and — for live video — the audio/video of the consultation.
Invoices, bill items, GST details where applicable, payment method and status, refunds, and payment-gateway references. We do not store full card numbers; card/UPI details are handled by the payment gateway.
Ratings and comments patients submit about a visit or tele-review.
Clinic name, address, GSTIN/registration numbers, owner name; for staff users — name, role, medical registration number, phone, email, username, profile/signature image, and a securely hashed password.
IP address, device/browser information and timestamps recorded in audit logs for security and accountability.
We use only essential cookies / browser local storage that are necessary to operate the Service — chiefly to keep you signed in (authentication tokens) and remember basic preferences. We do not use advertising cookies, cross-site tracking, third-party analytics or social-media trackers, and we do not sell or share data for advertising. Because we use no advertising/tracking, there is no behavioural profiling to opt out of; you can clear cookies/local storage in your browser at any time (this will sign you out).
We process personal data to: provide and operate the Platform for the Clinic; enable appointments, clinical records, prescriptions, pharmacy, lab, billing and the patient portal; send the notifications a Clinic chooses to enable; process payments; provide security, audit, fraud-prevention and support; improve and maintain the Service; and comply with legal, tax and medical record-keeping obligations.
Lawful basis. We process patient health data on the basis of the Clinic’s instruction and the consent the Clinic obtains from the patient, and for the Clinic’s legitimate medical and legal record-keeping. We do not sell personal data and do not use patient data for advertising or to train AI/marketing models.
We do not sell or rent personal data. We share it only with the limited service providers needed to run the Service, each under data-protection obligations:
| Sub-processor | Purpose | Data shared | Location |
|---|---|---|---|
| Microsoft Azure | Cloud hosting & database (Azure SQL) | All Platform data (encrypted at rest) | India (Central India) |
| Meta (WhatsApp Cloud API) | WhatsApp notifications (only if the Clinic enables, with its own account) | Patient name, mobile, appointment/lab details; documents where sent | Processed by Meta (may be outside India) |
| Razorpay | Online payments & refunds | Patient name, email, mobile, amount, reference | India |
| VideoSDK.live | Private telemedicine video consultations | Consultation audio/video and room id | India |
We may also disclose data where required by law, court order, or a lawful government request, or to establish, exercise or defend legal claims, or to protect the rights, safety and security of users and the public.
Telemedicine note. Live video consultations use VideoSDK.live, which provides private, India-based video rooms; patients join securely from within the clinic’s patient portal (there is no public room link). Video is not recorded by the Platform unless a clinic separately enables and discloses such recording.
Platform data is hosted on Microsoft Azure in the Central India region, i.e. within India. Some sub-processed functions (e.g. WhatsApp messaging or the default video service) may involve processing outside India as disclosed above. We will comply with any cross-border transfer restrictions notified by the Government under the DPDP Act.
We implement reasonable technical and organisational measures, including: encryption of data at rest (Azure Transparent Data Encryption) and in transit (HTTPS/TLS); passwords stored only as bcrypt hashes with complexity rules and re-use history; role-based access control with strict per-Clinic data isolation; audit logging of sensitive actions with IP address; account lockout after repeated failed logins and login rate-limiting; configurable automatic idle sign-out; and managed-cloud backups with point-in-time restore. No method of transmission or storage is completely secure, but we work continuously to protect personal data.
If we become aware of a personal-data breach, we will act without undue delay to contain and assess it, notify the affected Clinic(s), support notification to affected individuals where required, and report to the Data Protection Board of India in the manner and within the timelines required by law.
We retain patient medical records for at least 3 years from the patient’s last visit (in line with medical record-keeping norms and applicable law), and financial/tax records for the period required by law. Records are generally deactivated (“soft-deleted”) rather than immediately erased so that medical and legal history is preserved. When a Clinic stops using CutiSpan, we make its data available for export and then delete it from active systems, except where law requires continued retention; routine backups cycle out on their normal schedule.
Subject to the DPDP Act and other applicable law, a Data Principal may:
How to exercise. Because Clinics control patient data, patients should make requests to their Clinic, which we will support through the Platform (e.g. data export and erasure tools). Clinic account holders and staff may contact us at admin@cutispan.com. We will verify your identity and respond within the timelines required by law. There is no fee for a reasonable request.
Where processing relies on consent, that consent is obtained by the Clinic from the patient and may be withdrawn at any time by contacting the Clinic. Withdrawing consent does not affect processing already carried out lawfully, and does not affect records the Clinic must retain by law. Some features may not function without the related data.
The Platform may hold data about minors when a Clinic treats them. For such data, the Clinic is responsible for obtaining verifiable consent from a parent or legal guardian, and we process it only on that basis. We do not knowingly use children’s data for tracking, profiling or targeted advertising.
The Platform or this site may link to third-party websites or services we do not control. This Policy does not apply to those third parties; please review their privacy policies. We are not responsible for their content or practices.
We may update this Policy from time to time. We will post the revised version here with a new “Last updated” date and, for material changes, take reasonable steps to notify Clinics. Continued use of the Platform after changes take effect constitutes acknowledgement of the updated Policy.
In line with the DPDP Act and the IT Rules, you can raise any privacy concern or grievance with our Grievance Officer:
We aim to acknowledge grievances promptly and resolve them within the timelines required by law. If you are not satisfied, you may escalate to the Data Protection Board of India.
SJ Soft Tech — admin@cutispan.com — address as above.
This Policy is governed by and construed in accordance with the laws of India. Subject to applicable law, the courts at Hyderabad, Telangana have exclusive jurisdiction.