πIntroduction
Welcome to DocDoor, operated by Divya Tech. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile application β whether you are a Patient, Doctor, or Hospital Admin.
By using DocDoor, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use of the app.
ποΈ1. Information We Collect
The information we collect depends on the role you use the app as. All roles share the items listed under All Users below, and each role has additional role-specific data.
All Users
- Full name
- Mobile number β used as your primary login ID
- Email address
- Profile picture β optional, only if you choose to upload one
- State and district of residence
- Account status flags (active / verified / role)
- Device and login information β device type, OS version, login timestamps
- App usage data β screens visited, features used (for support and debugging)
- Push notification device token β so we can send you appointment and system alerts
- Aadhaar verification status β we only store a yes/no flag. Your Aadhaar number and images are processed by the UIDAI-verified provider and discarded by us.
Patient
- Appointment history (dates, times, assigned doctor or hospital, status, your notes)
- Reviews and ratings you leave for doctors or hospitals
- Bookmarks (doctors / hospitals you save for later)
- Identity verification state (mobile OTP verification, email verification)
- No-show / cancellation history (used for the freeze-on-repeat-no-show policy)
Doctor
Medical / professional credentials:
- Medical council licence / registration number
- Specialisation (e.g. General Medicine, Cardiology) and specialisation ID
- Qualifications (e.g. MBBS, MD), years of experience, bio (optional), languages spoken
Practice location:
- State, district, and subdivision / taluk / block
- Clinic or hospital name and full street address (if you add practice details)
- Consultation fee, consultation type(s), working days and hours
Identity verification documents (mandatory):
- Aadhaar QR code image (used to confirm name and date of birth; stored for audit purposes)
- Medical council registration certificate (uploaded by you)
- Matching flags (name matched with Aadhaar, DOB matched, registration type, state council)
Availability and bookings:
- Availability slots, daily slots, follow-up slots, urgent-booking flags
- Appointments booked with you (patient name, phone, date/time, status, notes, review)
- Free-up / cancellation reasons, walk-in reservations, reviews and ratings from patients
- Aggregated statistics (average rating, total reviews, total appointments, verification badge)
Admin support: If a platform admin acts on your account for support, the action and reason are logged.
Hospital Admin
- Personal account data (same as All Users)
- Hospital profile: name, description, phone, email, logo, full address, state, district, pincode, latitude/longitude, verification status
- Hospitalβdoctor associations: invitations sent, per-doctor consultation fee overrides
- Hospital availability: day-wise and date-range availability, slot duration, capacity, booking counts
- Hospital appointments and operations: patient appointments, prescriptions, payments (amount, status, gateway, transaction ID, refund details), walk-in reservations, free-up actions
- Aggregated hospital statistics and admin / impersonation logs
βοΈ2. Why We Collect It
Your information is used solely for:
- Account creation, authentication, and role-based access control
- Identity validation (mobile OTP, email verification, Aadhaar-based identity verification for doctors, hospital verification for hospital admins)
- Helping patients find and book the right doctor or hospital
- Appointment booking, management, reminders (SMS, email, push), and follow-ups
- Processing payments, refunds, and consultation fees
- Detecting fraud, abuse, and repeat no-shows
- Customer and technical support
- Internal analytics in aggregate form to improve the service
π3. How We Protect It
We apply industry-standard security measures across all systems:
- All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
- Data stored at rest is protected with AES-256 encryption.
- Passwords are never stored in plain text β they are hashed using bcrypt with a unique salt.
- Access to authentication records is restricted to role-authorised internal services only.
- Identity verification images (Aadhaar QR, medical certificate) are stored encrypted and accessible only to the verification workflow and authorised reviewers.
- Regular security audits and vulnerability assessments are performed.
π€4. Who We Share It With
We share your data only where strictly necessary, and only with the parties relevant to your role:
All Users
- SMS / email / push notification providers β receive your phone number, email, or device token solely to deliver appointment reminders and important alerts on our behalf.
- Encrypted cloud infrastructure β data is stored in secure, encrypted cloud environments.
Patient
- Your assigned doctor or hospital β receives your appointment details (date, time, and any notes you provide).
- Other patients (anonymously) β see only anonymised statistics on doctor / hospital profiles (e.g. average rating, total reviews).
Doctor
- Patients searching for a doctor β see your public profile: name, specialisation, qualifications, years of experience, languages, bio (if public), state, district, consultation fee, working days/hours, average rating, and total reviews.
- The hospital admin you associate with β sees your professional details and per-doctor availability at that hospital.
- The patient who books with you β sees appointment details and can leave a review.
Hospital Admin
- Patients searching for hospitals β see your public hospital profile: name, description, logo, address, state, district, pincode, verification status, and associated doctors.
- Doctors you invite β see your invitation notes and hospital name.
- Patients who book at your hospital β see your hospital name, address, and the relevant doctor for their slot.
β 5. Your Rights
You have the following rights over your personal data at any time, regardless of your role (patient, doctor, or hospital admin):
- View β request a copy of the data we hold about you.
- Correct β request correction of inaccurate or incomplete data.
- Export β receive your data in a portable format.
- Freeze β your account may be temporarily frozen if repeated no-shows are detected (applies to patients booking appointments). During a freeze, you may view existing appointments but cannot book new ones. Strike history is tied to your phone number and persists across account deletion.
-
Delete β request deletion of your account.
- Appointments past the cancellation window will not be auto-cancelled and will proceed as scheduled (marked as no-show if you do not attend).
- Appointments outside the cancellation window are cancelled automatically.
- Re-registration with the same credentials is restricted for 30 days.
- Past appointment records (date, time, status, rating) are retained in anonymised form for the other party's reference.
- Personally identifying details (name, phone, email, profile picture, Aadhaar data) are removed within 30 days.
To exercise any of these rights, go to Settings β Privacy within the app, or contact us directly at support.docdoor@gmail.com. We will respond within 5 business days.
ποΈ6. Retention
Upon account deletion, the following applies for all roles β patient, doctor, and hospital admin:
- Future appointments are cancelled immediately and the account is deactivated.
- Personally identifying information (name, phone number, email, profile picture, Aadhaar data, identity verification images) is permanently erased within 30 days of deletion.
- Appointment history visible to the other party (doctor, patient, or hospital) is retained with the identity shown as "Deleted User" after 30 days.
- Review ratings are retained anonymously to preserve doctor rating integrity; review comments are removed after 30 days.
- Prescriptions, payment records, and audit logs are retained for up to 7 years as required by financial and medical regulations, with personal identifiers removed after 30 days.
- Hospital profiles created by a hospital admin are deactivated and personal contact details erased; anonymised aggregate statistics may be retained.
- System and access logs (including impersonation actions taken by platform admins) are purged after 12 months.
πThird-Party Services
DocDoor uses the following third-party services that have their own privacy policies:
- Firebase Cloud Messaging (Google) β for push notifications
- SMS / email notification providers β for appointment reminders
- UIDAI-verified Aadhaar provider β for identity verification (doctors); Aadhaar numbers and images are processed by the provider and discarded by us
- Encrypted cloud infrastructure β for secure data storage
- Google Play Services β for app distribution and device authentication
We encourage you to review the privacy policies of these services. DocDoor is not responsible for the data practices of third-party providers.
πΆChildren's Privacy
DocDoor is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
πChanges to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the Last Updated date at the top of this page. We encourage you to review this policy periodically. Continued use of DocDoor after changes constitutes acceptance of the updated policy.
βοΈContact Us
If you have any questions or concerns about this Privacy Policy, please reach out to us.
Divya Tech
support.docdoor@gmail.com