This Privacy Policy is an initial technical compliance document provided by RK SOLUTIONS.

Legal

Privacy Policy

Last updated: 28 September 2026

Phsyo Care helps physiotherapy and dental clinics manage patients, appointments, treatment, exercise programmes and billing, and gives their patients and staff a single mobile app. Because that involves health information, we collect only what the service needs, never sell it, and never use it for advertising. This policy explains what we collect, why, who we share it with, how long we keep it, and how you can delete it.

1. Who we are and what this policy covers

Phsyo Care is a product of RK SOLUTIONS (“we”, “us”), 24A Umrav Vihar, Jhotwara, Jaipur, Rajasthan 302012, India. This policy covers the Phsyo Care mobile app for Android and iOS, the website at app.phsyo.com, clinic online-booking pages, shared prescription and exercise links, and the in-clinic QR station and TV displays.

This policy is issued under the Information Technology Act, 2000 and the rules made under it (including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011), and the Digital Personal Data Protection Act, 2023 (“DPDP Act”).

Clinics and Phsyo Care have different roles

Each clinic decides what to record about its patients and is responsible for those records as the “data fiduciary” under the DPDP Act. We process patient records on the clinic’s behalf and under its instructions. We are directly responsible for app account data — logins, devices and security records.

If you are a patient and have a question about what your clinic records about you, you can contact your clinic or us; we will help the clinic respond.

2. Information we collect

Account information (patients and staff)

  • Name, mobile number and (optionally) email address.
  • Password for clinic staff and admins — stored only as a one-way hash, never in readable form. Patients sign in with a one-time passcode (OTP) sent by SMS.
  • Your role (patient, staff or organization admin), the clinics you belong to, staff designation and the permissions your organization grants you.

Patient health and treatment records (entered by your clinic)

  • Profile: name, mobile number, gender, date of birth, city and state (older records may hold a street address), and the clinic’s patient code.
  • Clinical information: medical notes, diagnosis, treatment plans and details, referring doctor, visit records and notes, clinical notes, and appointment history.
  • Dental information: procedures, tooth number and surface, sittings, and prescriptions (medicines and instructions).
  • Documents uploaded by clinic staff: prescriptions, X-rays, MRI scans, lab reports and before/after photos.

Exercise and rehabilitation data

  • Exercise programmes (routines and protocols) your physiotherapist assigns you.
  • Your progress: which exercises and sets you complete, when, and whether a session was done at home, with staff, or at an in-clinic QR station or TV.
  • Exercise videos and images are uploaded by clinic staff for their exercise library. Patients do not upload videos.

Billing information

  • Invoices, packages, dues, and payments: amount, date, payment mode (cash, UPI, card, bank transfer or other), reference number and receipt number.
  • We record only that a payment was made and how; we do not collect or store card numbers or bank-account details. Payments are made directly to the clinic.

Online booking and enquiry forms

When you request an appointment on a clinic’s booking page we collect your name, mobile number, gender, date of birth, condition type, how long you have had the injury, notes, your preferred appointment time, and any files you choose to attach: a payment screenshot, a discharge summary or an MRI report.

Device and technical information

  • Device platform (Android or iOS) and records of your signed-in sessions.
  • Server logs: IP address, browser/app user agent, and the page or API address requested (with secret tokens removed). IP addresses are also used for rate limiting and recorded in some security audit entries.

Communications

  • One-time passcodes (stored only as a hash), and dispatch records for SMS we send (mobile number, purpose and delivery status).
  • In-app notifications, such as appointment reminders.
  • Emails we send you about your account, and any privacy or account-deletion requests you make.

App permissions

PermissionWhy we ask
CameraTo scan clinic QR codes and start an exercise session; for staff, to photograph patient documents for upload.
Photos / mediaFor staff to choose patient documents or exercise videos to upload.
NotificationsTo show appointment reminders and clinic updates.

We do not access your location, contacts, microphone or calendar. Spoken exercise guidance uses your device’s built-in text-to-speech; no audio is recorded.

What we don’t do

We do not use analytics or advertising SDKs, do not track you across other apps or websites, do not use advertising cookies, and do not sell or rent personal information. The admin website stores your sign-in token in your browser’s local storage only while you are signed in.

3. How we use information

  • To provide the service to your clinic: patient records, appointments, visits, treatment and exercise plans, billing and reports.
  • To sign you in and keep your account secure — OTP and password verification, one active device per login, and detection of stolen sessions.
  • To send appointment reminders, account verification codes and clinic updates.
  • To share information you or your clinic ask us to share — for example a prescription sent to your mobile as a secure, expiring link, or an exercise programme shared by link.
  • During an in-clinic session, to show your name on the clinic’s QR station or TV display so you can find your station.
  • To prevent abuse and fraud (rate limiting, audit logs) and to keep the service reliable.
  • To respond to support, privacy and deletion requests, and to meet legal obligations.

We do not use your health information for marketing, advertising, profiling, or training AI models, and we make no automated decisions about you that have legal or similarly significant effects.

4. Sharing and third-party processing

Within your clinic

Patient records are visible to staff of the clinic branch you are registered with, according to the permissions that clinic’s organization admin grants, and to the organization’s admins across its branches. Organization admins can export their data to spreadsheets. Clinics cannot see each other’s records.

Service providers

We use the following providers to run the service. They may only process data to provide their service to us.

ProviderPurposeData involved
DigitalOcean (Mumbai region, India)Hosts our servers, databases and file storage.All data held by the service, including uploaded documents, exercise media, data exports and backups.
GoogleDelivers transactional and system emails.Email address and message content.
SMS service providersAccount verification (OTP) and appointment alerts, and secure prescription links where your clinic uses them.Mobile number and message content.

Other disclosures

We disclose information when required by law, court order or a lawful request by a government authority; to protect the rights, safety or property of patients, clinics or us; or as part of a merger or acquisition, in which case this policy continues to apply. We do not sell personal information.

5. Data retention

We separate your app account, which you can delete at any time, from the clinical record your clinic keeps.

DataHow long we keep it
App account (login, contact details, sessions)Until you delete your account. Deletion of your login is immediate — see section 7.
Clinical and clinic dataFor as long as the clinic’s subscription is active. When a subscription ends, records are retained for 90 days, after which the clinic is notified and the data is permanently deleted.
Records a clinic removes during its subscription (visits, notes, documents, prescriptions, treatment plans)Hidden from the app immediately and kept in the clinic’s record history, so the medical record stays complete, until the clinic’s data is deleted as above.
Operational audit logs and SMS dispatch logsRetained indefinitely for security and compliance tracking.
Database backupsManaged according to each clinic’s or business’s requirements.
One-time passcodesDeleted after 30 days, and immediately when you delete your account.
Expired or revoked sign-in sessionsExpired sessions are deleted daily; revoked ones after 30 days.
Data exportsDownload files are deleted after 7 days.
Prescription links sent by SMS and shared exercise-programme linksExpire after 30 days by default (the clinic can change this).
Document download linksEach link works for 15 minutes.

6. How we protect your information

  • All data is encrypted in transit (TLS/SSL) and at rest (databases and file storage) using industry-standard encryption.
  • Passwords and one-time passcodes are stored only as one-way hashes; sign-in session tokens are hashed, short-lived, rotated on every use, and a whole session is revoked if a stolen token is reused.
  • One active device per login: signing in on a new device signs out the old one.
  • Role-based access and per-staff permissions, with strict separation between organizations and between clinic branches.
  • Uploaded documents are stored privately and served only through short-lived signed links; data exports are available only through an authenticated download.
  • Audit logs of sign-ins and sensitive actions, rate limiting of OTP requests, public forms and the API, and secret tokens removed from server logs.

These measures are designed to meet the reasonable security practices required under the IT Act and the DPDP Act. No system is perfectly secure; if a personal data breach occurs we will notify the affected clinics and, where required, you and the Data Protection Board of India, without undue delay.

7. Account and data deletion

You can request deletion of your Phsyo Care account at any time — inside the app, or online without installing the app. Full details are on our Account Deletion page.

In the app — patients

  1. Open Phsyo Care and sign in.
  2. Tap the More tab (your profile).
  3. Tap Delete Account.
  4. Type DELETE and confirm.

In the app — clinic staff & admins

  1. Go to More → Settings.
  2. Under Account, tap Delete Account.
  3. Enter your password.
  4. Type DELETE and confirm.

Online: use the web request form or email [email protected]. We verify online requests with the account owner before acting on them.

What happens: your login, password, the contact details on your account, all signed-in sessions, notifications and one-time passcodes, and any staff access and permissions are removed. Clinical and clinic records held for your clinic are subject to the mandatory retention and cleanup terms in section 5 — retained while the clinic’s subscription is active and for 90 days after it ends, then permanently deleted. If you are an organization’s only admin, our team will contact you to arrange the deletion.

8. Your rights

Under the DPDP Act and the IT Rules you have the right to:

  • Access a summary of the personal data held about you and how it is processed.
  • Correct inaccurate or incomplete data, or update it.
  • Request deletion of your personal data (see section 7).
  • Withdraw consent you have given, without affecting processing already carried out.
  • Nominate another person to exercise your rights in case of death or incapacity.
  • Raise a grievance with our Grievance Officer and, if you are not satisfied, with the Data Protection Board of India.

To exercise these rights, email [email protected]. We respond to and resolve valid data access and correction requests within 15 days. We may need to verify your identity first, and for clinical records we will coordinate with your clinic.

9. Minors and guardianship

Patients under 18 years of age may have an app login. For minors, account credentials and access are shared directly with, and controlled by, their verified parent or legal guardian, who acts on the minor’s behalf — including giving consent and making access, correction or deletion requests. We do not use minors’ data for tracking, behavioural monitoring or targeted advertising.

10. Where your data is stored

Our servers, databases and file storage are hosted in India, in DigitalOcean’s Mumbai region. Email delivery through Google may involve Google’s infrastructure. We comply with any restrictions on transfers the Government of India notifies under the DPDP Act.

11. Changes to this policy

We will update the “Last updated” date when this policy changes, and for significant changes we will notify you in the app or by email before they take effect.

12. Contact and Grievance Officer

Grievance Officer — RK SOLUTIONS Support

RK SOLUTIONS, 24A Umrav Vihar, Jhotwara, Jaipur, Rajasthan 302012, India

Email: [email protected]

Account deletion requests: online form