Privacy Policy
How FAB Doctor handles personal data on this website and within the FAB Doctor platform.
Last updated: August 9, 2026
1. Introduction
This Privacy Policy ("Policy") describes how FAB Doctor ("Company", "we", "us" or "our"), the owner and operator of FAB Doctor (the "Platform" or "Service"), collects, uses, discloses, stores and protects personal data in connection with the website https://fabdoc.in (the "Website"), the web application, and our iOS and Android mobile applications (together, the "Platform"). By accessing the Website or using the Platform, you acknowledge that you have read and understood this Policy.
This Policy is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules"), and the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), each as applicable and amended from time to time.
2. Definitions
- Personal Data means any data about an individual who is identifiable by or in relation to such data.
- Sensitive Personal Data includes, among other categories, medical records and history and other health information, as defined under the SPDI Rules.
- Data Principal (or "data subject") means the individual to whom the Personal Data relates.
- Data Fiduciary (or "data controller") means the person who determines the purpose and means of processing Personal Data.
- Data Processor means a person who processes Personal Data on behalf of, and on the instructions of, a Data Fiduciary.
- Clinic (or "Customer") means a healthcare provider or organisation that subscribes to and uses the Platform.
3. Scope and Applicability
This Policy applies to: (a) visitors to the Website; (b) Clinics and their authorised users (such as practitioners, administrators and staff) who register for and use the Platform; and (c) patients and other individuals whose Personal Data is entered into the Platform by a Clinic.
4. Our Role as Data Fiduciary and Data Processor
Our role depends on the data in question:
- As a Data Fiduciary (controller): in respect of Website visitors and the account, contact and billing information of Clinics and their users, we determine the purpose and means of processing.
- As a Data Processor: in respect of patient data and other clinical information entered into the Platform, the Clinic is the Data Fiduciary and we process such data solely on the Clinic's documented instructions in order to provide the Service. Each Clinic is responsible for establishing a lawful basis for processing and for obtaining all consents and notices required from its patients.
5. Information We Collect
5.1 Information you provide to us
- Account and clinic data: name, email address, phone number, clinic or organisation name and address, professional details, and login credentials.
- Billing data: subscription plan and billing contact details. Payment-card details are collected and processed directly by our third-party payment providers and are not stored by us.
- Patient and clinical data (entered by Clinics): patient demographics and contact details, medical and dental history, clinical charts and treatment plans, prescriptions, consent forms, uploaded documents and radiographs, appointments and invoices.
- Communications: information submitted through our contact and demo-request forms (name, email, phone, clinic, message) and email addresses provided for newsletters.
5.2 Information collected automatically
- Technical and usage data such as IP address, device and browser type, log data, pages visited and timestamps.
- Cookies and similar technologies, as described in Section 12.
5.3 Mobile application data and device permissions
- Push notifications: with your permission, we register a device push token (via Google Firebase Cloud Messaging / Apple Push Notification service) to deliver appointment and workflow notifications. You can disable notifications in the app or your device settings.
- Camera and photo library: with your permission, the app accesses the camera and photo library only when you choose to capture or attach X-rays, documents or images to patient records. We do not access your camera or photos in the background.
- Device identifiers: a device/session identifier used for authentication, security and notification delivery.
6. How We Use Information
- To provide, operate, maintain and secure the Platform and the Website.
- To create and administer accounts and to process subscriptions and billing.
- To enable clinical workflows on behalf of Clinics, including scheduling, charting, prescriptions, invoicing, consent management and patient communications (such as appointment reminders sent via SMS or in-app notification).
- To respond to enquiries, arrange demonstrations and provide customer support.
- To send product updates and marketing communications where you have opted in; you may withdraw consent or unsubscribe at any time.
- To monitor, analyse and improve the Service, and to detect and prevent fraud, abuse and security incidents.
- To comply with applicable laws, regulations and lawful requests.
We process Personal Data on one or more of the following bases: your consent; the performance of a contract; our legitimate interests in operating the Service; and compliance with legal obligations.
7. Patient Data and Confidentiality
We process patient and clinical data strictly as a Data Processor, on the instructions of the relevant Clinic. We do not sell such data, do not use it for our own independent purposes, and access it only to the extent necessary to provide, maintain and support the Service. Responsibility for the accuracy and lawfulness of patient data, and for obtaining patient consent, rests with the Clinic that controls it.
8. Disclosure and Sub-processors
We do not sell Personal Data. We disclose Personal Data only in the following circumstances:
- Sub-processors: with service providers that support our infrastructure and operations under contractual confidentiality and security obligations, including cloud hosting and file storage (Amazon Web Services, India region), database hosting (MongoDB Atlas, India region), push-notification services (Google Firebase), SMS and messaging providers, and payment gateways for subscription billing.
- Professional advisers: with auditors, legal advisers and insurers, as required.
- Legal and safety: where required by law, regulation, court order or governmental authority, or to establish, exercise or defend legal claims, or to protect the rights, property or safety of any person.
- Business transfers: in connection with a merger, acquisition, reorganisation or sale of assets, subject to the recipient honouring this Policy and with notice where required.
9. Data Storage, Location and Security
- Data is hosted on secure cloud infrastructure located in India (Amazon Web Services, Mumbai region).
- Sensitive patient fields are encrypted at rest using AES-256-GCM with HMAC, and data in transit is protected using TLS/SSL.
- Access is governed by granular, role-based permissions; multi-factor authentication is available; and brute-force protection and configurable session timeouts are enforced.
- All material changes are recorded in tamper-evident audit logs, and uploaded documents are held in access-controlled storage served through time-limited, pre-signed links.
- Regular backups are maintained.
While we implement reasonable security practices and procedures consistent with the SPDI Rules, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Data Retention
We retain account and patient data for the duration of the Clinic's active subscription. Following termination, data is retained for a limited period (ordinarily up to 90 days) to enable export and retrieval, after which it is deleted or anonymised, unless a longer retention period is required or permitted by law (for example, medical-record retention, or tax and accounting obligations). Website enquiry and newsletter data is retained until you unsubscribe or request its deletion.
11. Your Rights
Subject to applicable law, including the DPDP Act, you may have the right to access a copy of your Personal Data, to correct or update inaccurate data, to request erasure, to withdraw consent, to request portability of your data, and to grievance redressal.
Requests concerning patient data should be directed to the relevant Clinic, which is the Data Fiduciary for that data; we will assist the Clinic in responding to such requests. For Website or account data for which we are the Data Fiduciary, you may contact us at [email protected].
Account deletion. You can delete your account at any time directly from within the app — go to Settings → Profile → Delete Account (or the equivalent in the web app), or email us at [email protected]. Deleting your account revokes your access and removes or anonymises your personal profile data (such as your name, phone number and login credentials). Clinical and financial records you created on behalf of a Clinic remain with that Clinic, which is the Data Fiduciary, and may be retained or anonymised as required by applicable medical‑record, tax and accounting laws. If you are the sole owner of a Clinic organisation, you will be asked to transfer ownership or close the organisation before your account can be deleted, so that patient records are not orphaned.
12. Cookies and Tracking
The Website uses cookies and similar technologies for essential functionality and, where enabled, analytics. You can control or disable cookies through your browser settings, although doing so may affect certain features of the Website.
13. Children's Data
The Platform is intended for use by healthcare professionals and is not directed at children. Where records of minors are maintained, they are entered and managed by a Clinic under the appropriate guardian consent and the Clinic's responsibility.
14. International Transfers
Personal Data is primarily stored and processed in India. Where any limited processing occurs outside India (for example, certain notification services), we take steps to ensure appropriate safeguards consistent with applicable law.
15. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the Website or by email, and the "Last updated" date above will be revised. Your continued use of the Website or the Platform after such changes constitutes acceptance of the updated Policy.
16. Grievance Officer
In accordance with the Information Technology Act, 2000 and the DPDP Act, the contact details of our Grievance Officer are set out below. We will acknowledge and address grievances within the timelines prescribed under applicable law.
- Entity: FAB Doctor
- Udyam Reg. No.: UDYAM-GA-01-0059750
- Email: [email protected]
- Address: D/01, Ground Floor, Block-D, Saldanha Business Tower, Mapusa, Bardez, Goa 403507, India
17. Governing Law and Jurisdiction
This Policy is governed by and construed in accordance with the laws of India. Subject to applicable law, the courts at Goa, India shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.
18. Contact Us
For any questions about this Policy or our data practices, contact us at [email protected], or write to FAB Doctor, D/01, Ground Floor, Block-D, Saldanha Business Tower, Mapusa, Bardez, Goa 403507, India.