Home › Privacy Policy
Privacy Policy
This explains what personal data Solace Health handles, why, who is responsible for it, and what you can require us to do about it. It is written to be read, not to be survived.
1. Who we are
Solace Health is a product of Renusoft LLP, a limited liability partnership registered in India (LLPIN ADB-0132), with its registered office at Behind Awadh Apartment, B. H. Colony, Kankarbagh, Sampatchak, Patna – 800026, Bihar, India. In this policy “we”, “us” and “Renusoft” mean Renusoft LLP.
This policy is written under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and uses its words: a Data Principal is the person the data is about, a Data Fiduciary decides why and how it is processed, and a Data Processor processes it on a Fiduciary's instructions.
2. Whose data it is, and who is responsible
This is the most important section, and most software policies blur it. Solace has two different situations, and our role is different in each.
2.1 Your clinic's patient records — the clinic is the Fiduciary, we are the Processor
When a clinic uses Solace to run its practice, the patient records belong to the clinic's relationship with its patients. The clinic is the Data Fiduciary; it decides what to record, obtains consent from its patients, and answers to them. Renusoft is the Data Processor: we hold and process those records only to provide the service the clinic has asked for, and only on the clinic's instructions.
In practice that means we do not decide what goes into a patient's chart, we do not use one clinic's records for another clinic's benefit, and we do not process them for our own purposes. If you are a patient and you want a record changed or erased, the clinic is the right place to ask — see §11.
2.2 The Solace patient app — we are the Fiduciary
The patient app is deliberately not a clinic's app. A patient signs in to Solace, not to a hospital, and the same account works at every clinic on Solace that they visit. For that account — the sign-in, the profile, the linked clinics, the reminders — Renusoft is the Data Fiduciary and answers to the patient directly.
The clinical records shown inside the app still belong to the clinic that created them. The app is showing them to the patient with the clinic's participation; it is not a second copy that we own.
2.3 Clinic staff and prospects
For the people who work at a clinic (names, roles, logins, credentials) and for people who enquire through this website, Renusoft is the Data Fiduciary.
3. What we collect
- Patient identity and contact details
- Name, phone number, age or date of birth, sex, address, and — if the patient chooses to link it — their ABHA number. The phone number matters more than most fields: it is how a clinic finds a patient and how reminders reach them.
- Clinical records
- Visits, symptoms and history, diagnoses recorded by the doctor, prescriptions, investigation orders and results, vitals, allergies, procedures, admissions and nursing records — whatever the clinic's own desks record. For eye care this includes per-eye measurements; for inpatients it includes bed and medication-administration records.
- Financial records
- Invoices, payments, outstanding balances and, where the clinic runs an insurance desk, claim and pre-authorisation details.
- Voice and audio
- Where a clinic has switched on dictation, the ambient scribe or the AI phone line, we process speech in order to transcribe it. See §7.
- Documents you upload
- Prescriptions, reports and scans that a patient or a clinic adds to a record, including text extracted from them.
- Account and technical data
- Login identifiers, authentication tokens, device and browser information, IP address, and audit logs recording which user took which action and when.
- Enquiries
- What you send us through the enquiry form on this website, by WhatsApp or by email.
4. Why we process it
- To run the clinic's service — appointments, records, prescribing, billing, pharmacy, laboratory, imaging and inpatient desks, as switched on by that clinic.
- To provide the patient app — booking, records, reminders, and the patient's own account.
- Clinical safety — drug-interaction, allergy and dose checks, and flagging results that are outside safe ranges.
- To send reminders and confirmations the patient or clinic has asked for.
- To secure the service — authentication, audit logging, fraud and abuse prevention, backups and disaster recovery.
- To support and improve the software — diagnosing faults reported to us, and understanding aggregate usage. Where we can do this without patient-identifying data, we do.
- To comply with law and to establish or defend legal claims.
We do not sell personal data, we do not share it with advertisers, and we do not use patient data to build marketing profiles.
5. Consent, and how to withdraw it
Under the DPDP Act, processing generally rests on the Data Principal's consent, given after a clear notice, or on a legitimate use the Act recognises.
- For clinic records, the clinic obtains consent from its patients as part of treating them, and is responsible for that notice. We process on the clinic's instructions.
- For the patient app, the patient consents when they create an account, and separately when they choose to link a clinic, link an ABHA number, or turn on reminders.
- Withdrawal is as easy as giving it. A patient can unlink a clinic, turn off reminders, or close their account from within the app, or write to us. Withdrawing consent stops future processing for that purpose; it does not undo processing already lawfully carried out, and it does not erase records the clinic is required by law to keep.
6. Who else sees it
We share personal data only in these circumstances:
- The clinic treating the patient
- Its own staff, each limited to what their role needs. A front-desk user does not see what a doctor sees.
- Other clinics — only when the patient links them
- A patient's record does not travel between clinics on its own. It moves when the patient links a clinic in the app, or asks for it.
- Infrastructure and service providers
- Cloud hosting, AI model providers, SMS and WhatsApp delivery, and telephony — each under contract, each limited to processing on our instructions, and each restricted to what the specific feature requires. A clinic that has not switched on the phone line has no data with a telephony provider.
- Where the law requires it
- A valid order from a court or a lawful authority. Where we are permitted to tell the clinic or the patient that this has happened, we will.
We do not pool one clinic's data with another's. Each clinic's records live in a separate database — the boundary is the database itself, not a filter in code that has to be written correctly every time.
7. How the AI uses your data
Solace uses AI to draft and to flag. Being exact about this matters more than sounding reassuring.
- The AI never diagnoses and never prescribes on its own. It drafts prescriptions and summaries, and raises red flags. A registered medical practitioner reviews and signs everything that reaches a patient. Solace is not a medical device and is not registered as one with CDSCO.
- We do not train models on your data. Your clinic's records are used to serve your clinic. They are not pooled into training data for anyone else's benefit, and we require the same of the model providers we use.
- Processing is scoped to India. The models that read clinical data are run in an Indian region. Where a capability is genuinely unavailable in India, we go without it rather than route your data elsewhere. See §8.
- Audio. Dictation, the ambient scribe and the AI phone line process speech to produce text. The resulting text is stored against the record; audio is retained only as long as needed to produce and verify the transcript, and a clinic can ask us not to retain it at all.
- Callers are told. Where a clinic runs the AI phone line, the caller is told they are speaking to an automated assistant.
8. Where it is stored
Personal data processed through Solace is stored and processed on infrastructure located in India, and the AI that reads clinical data is region-scoped to India.
The DPDP Act permits transfer outside India except to territories the Central Government restricts. We have designed the service so that clinical data does not leave India in ordinary operation. If that ever has to change for a specific feature, we will say so before the feature is switched on, not afterwards.
9. Children's data
Clinics using Solace treat children, so children's data is in the system by design. Under §9 of the DPDP Act, processing a child's personal data requires verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited. We do none of the latter, for anybody.
For clinical records, the clinic obtains that parental consent as part of treating the child, and records the guardian against the patient. The Solace patient app account is for adults — a parent or guardian holds the account and manages a child's records within it. If we learn that a child has created an account for themselves, we will close it.
10. How long we keep it
| What | How long |
|---|---|
| Clinic patient records | For as long as the clinic's subscription runs, and then as the clinic instructs. Clinics have their own record-keeping obligations under Indian medical regulations, so the retention period is the clinic's decision, not ours. |
| Patient app account | Until the patient closes it. On closure we delete the account and its profile. |
| Audio for dictation and phone calls | Only as long as needed to produce and verify the transcript, then deleted. |
| Audit and security logs | Retained for a limited period for security and accountability, then deleted. |
| Backups | Rotated on a fixed cycle. A deletion request is applied to live systems immediately and works through the backup cycle as backups age out. |
| Enquiries and business records | As long as needed for the enquiry, and thereafter as required by tax and company law. |
When a clinic leaves Solace, it can export all of its data as a standard FHIR bundle. We delete the clinic's database on its written instruction.
11. Your rights
Under the DPDP Act you may:
- Ask what we hold about you and how it has been processed and shared.
- Ask for it to be corrected if it is wrong, incomplete or out of date.
- Ask for it to be erased, where there is no legal reason to keep it.
- Nominate someone to exercise your rights if you die or become incapacitated.
- Complain — see §16.
Where to ask matters. If your request is about a clinical record, ask the clinic that created it — they are the Data Fiduciary and only they can decide what a medical record should say. If it is about your Solace patient app account, ask us. If you write to us about something that belongs to a clinic, we will tell you which clinic to approach and, where the clinic asks us to, help them act on it.
We respond within a reasonable period and in any case within the timeframe the law requires. We may need to verify your identity first — for health data, that check is a protection, not an obstruction.
12. Security
- Separation by database. Each clinic's records are in their own database.
- Encryption in transit over TLS for every connection.
- Role-based access. Doctors, front desk, nurses and owners see different screens; every change is logged against the person who made it, including anything an AI desk did on a staff member's behalf.
- Restricted internal access. Only the engineers who operate the platform can reach production systems, only for support and incident work, and that access is logged.
- Backups, with restores that are practised rather than assumed.
We do not currently hold ISO 27001 or SOC 2 certification and we will not imply that we do. If certification matters to your organisation, ask us where we are — we would rather answer honestly than win a deal on a claim that is not true.
13. If something goes wrong
If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal — through the relevant clinic, where the data is the clinic's — in the manner and within the time the DPDP Act requires. We will say what happened, what data was involved, and what we and you should do about it.
14. Calls, SMS and WhatsApp
Reminders and confirmations are sent only where the patient or the clinic has asked for them. SMS to Indian numbers is sent through registered DLT sender IDs and templates as required by TRAI, and WhatsApp messages use approved templates through the official Business API. Every messaging channel can be stopped, and stopping it actually stops it.
15. This website
solacehealth.in does not use tracking or advertising cookies, and does not run third-party analytics or advertising pixels. The site loads a web font from Google Fonts, which means your browser makes a request to Google's servers and Google will see your IP address for that request.
The enquiry form does not post to a server. It opens WhatsApp or your own email application with your message filled in, so nothing is transmitted until you press send in that app. What you then send reaches us at the number or address shown on the contact page.
The clinic software and the patient app use cookies and local storage strictly to keep you signed in and to remember your settings. They are necessary for the service to work and are not used for tracking.
16. Grievance officer
If you are unhappy with how we have handled your personal data, contact our Grievance Officer:
Grievance Officer, Renusoft LLP
Email: info@renusoftllp.com
Phone: +91 93111 40410
Behind Awadh Apartment, B. H. Colony, Kankarbagh, Sampatchak, Patna – 800026, Bihar, India
We will acknowledge your complaint and respond within the period the DPDP Act requires. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
17. Changes
If we change this policy we will update the effective date at the top, and we will tell clinics and patient-app users directly about any change that materially affects them — before it takes effect, not after. Previous versions are available on request.
See also our Terms of Service and the plain-language summary on Your data.