Back to Home
Digital Personal Data Protection (DPDP) Act, 2023 Compliant

Privacy Policy

Effective Date: September 1, 2026 • MedJot (Avinya Monorepo)

1. Architectural Foundation & Data Storage

MedJot is architected as an offline-first clinical assistant. By default, all patient personal data, consultation notes, diagnoses, prescriptions, and financial transactions are stored strictly within the client device's browser local database (IndexedDB via Dexie.js).

MedJot servers do not continuously ingest, process, or inspect clinical consultation notes in plaintext.

2. Client-Side Encryption & Cloud Backup

When you initiate an automated or manual cloud backup to Cloudflare R2, the entire database payload is:

  • Compressed on the client using Gzip to minimize transmission size.
  • Encrypted directly on the client using AES-GCM 256-bit encryption via the browser Web Crypto API.
  • Transferred over TLS 1.3 to Cloudflare R2 object storage.

3. Dual Audit Logging & Data Retention

In compliance with healthcare compliance standards and the DPDP Act 2023:

  • Client Audit Logs: Local operations (patient creation, visit editing, repeat Rx) are logged in IndexedDB.
  • Server Audit Logs: Authentication events and cloud backup operations are logged in Cloudflare D1.
  • Retention Period: Audit records are retained for a default period of 45 days, configurable up to 180 days (6 months), after which expired records are automatically pruned.

4. Rights of Data Principals

Under the DPDP Act 2023, doctors and clinics as Data Fiduciaries retain full control over patient records:

  • Right of Access & Portability: Export complete patient directories and visit records in open JSON or CSV formats at any time.
  • Right to Correction & Erasure: Edit or soft-delete/archive patient records with immediate effect.

5. Contact & Data Protection Inquiries

For data privacy inquiries or security concerns, contact our compliance desk at privacy@avinya.it.