← Back to RogiData
Privacy Policy
Last updated: 2026-10-06
RogiData ("we", "our") is a clinic/hospital management system used by small
healthcare practices to manage patient records, prescriptions, appointments, and
billing. This page explains what information we collect, how it's used, and how
it's protected.
Who this applies to
There are two kinds of people this policy covers: staff accounts
(doctors, receptionists, assistants, and administrators at a clinic using
RogiData) and patients whose records a clinic enters into the
system. We are a service provider to the clinic -- the clinic, not RogiData,
decides what patient information to collect and is responsible for having a
lawful basis to do so.
What we collect
- Staff account data: name, email address, mobile number, role, and the organization they belong to.
- Patient records, entered by clinic staff: name, mobile number, address, government ID (where a clinic chooses to record one), prescriptions, documents, and appointment/billing history.
- Usage and security logs: sign-in activity, and an audit trail of who accessed or changed a given record and when.
We do not buy, sell, or share any of this data with third parties for
marketing. We do not run advertising or tracking on this site.
How we protect it
- Sensitive patient fields (name, mobile number, address, government ID, clinical notes) are encrypted at the field level using AES-256-GCM, with keys managed by AWS Key Management Service -- not just encrypted storage, but unreadable in the database without going through that key.
- Uploaded documents are stored in a private AWS S3 bucket that is never publicly accessible.
- All traffic between your browser and our servers is encrypted (HTTPS/TLS), as is the connection between our application and its database.
- Each clinic's data is isolated from every other clinic's at the database level (row-level security), independently of the application code that also enforces this -- a bug in one layer doesn't expose data past the other.
- Every access to a patient record is written to an audit log.
- Our infrastructure runs in AWS's Asia Pacific (Mumbai) region, so patient data is hosted in India.
Emails we send
We only send transactional emails tied to an account action you took: an
email-verification code when you sign up, a password-reset link when you request
one, and an account-ready notice when a clinic admin creates a staff account for
you. We never send marketing email, and these emails never contain a password.
Your rights over your data
- Access & export: a clinic can export a patient's full record (demographics, documents, prescriptions, consents) as structured data at any time.
- Deletion: a clinic can submit an erasure request for a patient's record. We soft-delete the record immediately and run an anonymization process that scrubs identifying fields from both plaintext and encrypted columns.
- If you are a patient and want to exercise either right, please contact the clinic that holds your record directly -- they control it, and can act on your request through the system.
Data retention
We do not enforce a fixed retention period or automatically delete records by
age. Clinics are responsible for retaining or deleting patient data in line with
whatever regulations apply to their own practice.
RogiData is an actively developed product run by a small team. This policy
describes our actual current practices as accurately as we can, but it is not
a substitute for legal advice -- a clinic handling patient data should confirm
its own regulatory obligations (e.g. under India's DPDP Act) independently.
Contact
Questions about this policy or a request regarding your data can be sent to
gopalkalpande@gmail.com.