Privacy Policy

1. Introduction

SarvaDoc is an AI-enabled healthcare technology platform designed to support healthcare professionals, frontline health workers, healthcare institutions, and patients with clinical documentation, assisted triage, health-record management, diagnostic-data capture, referral workflows, and continuity of care.

SarvaDoc is operated by Sarvadoc Technologies Pvt. Ltd. (“SarvaDoc”, “we”, “our”, or “us”).

Protecting the confidentiality, integrity, and privacy of health information is fundamental to the design and operation of SarvaDoc.

This Privacy Policy explains how personal data is collected, used, processed, shared, stored, and protected when individuals interact with:

  • the SarvaDoc website;
  • SarvaDoc Primary application;
  • SarvaDoc Capture application;
  • SarvaDoc Patient application;
  • SarvaDoc smart-glasses and connected-device workflows;
  • SarvaDoc Center of Excellence (“COE”) platform;
  • integrations with healthcare institutions and government health systems; and
  • related SarvaDoc services.

SarvaDoc is designed to align with applicable Indian privacy and digital-health requirements, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), applicable provisions of the Digital Personal Data Protection Rules, 2025 as they come into force, and applicable Ayushman Bharat Digital Mission (“ABDM”) requirements.

2. Our Role in Processing Health Data

SarvaDoc may operate in different roles depending on the service being provided.

2.1 Services Provided to Hospitals and Government Health Systems

Where SarvaDoc is deployed by a hospital, Primary Health Centre (“PHC”), Community Health Centre (“CHC”), government department, State Health Authority, or other healthcare institution, that institution may determine the purposes for which patient information is processed.

In such circumstances, the healthcare institution may act as the Data Fiduciary, and SarvaDoc may process data on its behalf as a Data Processor, subject to contractual and legal requirements.

Patients should also refer to the privacy notice issued by the relevant healthcare institution.

2.2 Direct SarvaDoc Services

Where SarvaDoc directly determines why and how personal data is processed, for example in connection with a SarvaDoc patient account, website account, support request, or other direct-to-user service, SarvaDoc may act as the Data Fiduciary.

3. Categories of Information We Process

Depending on the SarvaDoc service being used, we may process the following categories of information.

3.1 Identity and Demographic Information

This may include:

  • name;
  • age or date of birth;
  • gender;
  • mobile number;
  • email address;
  • address or geographic area;
  • patient or hospital identifier;
  • ABHA number or related ABDM identifier, where voluntarily provided or appropriately linked; and
  • healthcare facility or healthcare-worker identifiers.

3.2 Health and Clinical Information

SarvaDoc may process information including:

  • presenting complaints;
  • symptoms;
  • medical history;
  • previous diagnoses;
  • allergies;
  • current and past medications;
  • examination findings;
  • clinical observations;
  • provisional or confirmed diagnoses entered by healthcare professionals;
  • prescriptions;
  • referrals;
  • follow-up plans;
  • discharge information;
  • laboratory results;
  • diagnostic reports;
  • clinical notes; and
  • other information generated during healthcare delivery.

Health information is treated as highly sensitive information and is subject to enhanced technical and organizational safeguards.

3.3 Consultation Audio and Transcripts

SarvaDoc may capture and process audio during a clinical consultation through:

  • Meta or other supported smart glasses;
  • a mobile phone;
  • a tablet; or
  • another approved clinical device.

Audio may be processed to:

  • transcribe a clinical conversation;
  • identify relevant clinical information;
  • suggest appropriate follow-up or triage questions;
  • generate a structured consultation summary;
  • generate draft clinical documentation; and
  • support healthcare professionals during an encounter.

Whether raw audio is retained after processing will depend on the applicable deployment configuration, healthcare-institution policy, legal requirements, and patient consent where required.

The application or healthcare professional should provide appropriate notice when consultation audio is being captured.

3.4 Images and Video

Where enabled, SarvaDoc may process images or video captured through smart glasses, mobile devices, or other approved equipment.

This may include images of:

  • medical reports;
  • prescriptions;
  • wounds or clinically relevant physical findings;
  • diagnostic-device displays; and
  • other clinical documents or observations.

Live video may also be used in approved telemedicine, remote-supervision, or clinical-escalation workflows.

SarvaDoc should not intentionally capture unrelated individuals or areas where there is a reasonable expectation of privacy.

3.5 Diagnostic Device Data

SarvaDoc may receive information from approved connected medical or wellness devices, including:

  • blood pressure monitors;
  • glucometers;
  • pulse oximeters;
  • thermometers;
  • ECG devices;
  • digital stethoscopes; and
  • other compatible diagnostic devices.

Device data may be associated with the relevant patient encounter.

3.6 Uploaded Medical Documents

Users or healthcare professionals may upload:

  • laboratory reports;
  • prescriptions;
  • imaging reports;
  • previous medical records;
  • discharge summaries;
  • referral documents; and
  • other clinical documents.

SarvaDoc may use document-processing and artificial-intelligence services to extract structured information from these documents.

3.7 Technical and Security Information

We may collect limited technical information necessary to operate and secure the service, including:

  • device type;
  • application version;
  • operating system;
  • IP address;
  • login events;
  • timestamps;
  • security logs;
  • device identifiers;
  • authentication events;
  • API activity;
  • crash information; and
  • system-performance information.

3.8 Location Information

Where required for an approved healthcare workflow, SarvaDoc may process approximate or facility-level location information, for example to:

  • assign an ASHA or healthcare worker to a service area;
  • identify the facility providing care;
  • coordinate referral or emergency workflows; or
  • provide program-level analytics.

Precise device location will only be collected where necessary for an enabled feature and subject to appropriate permissions.

4. How We Collect Information

Information may be collected:

Directly from patients

For example, when a patient:

  • speaks during a consultation;
  • enters information into the SarvaDoc Patient application;
  • uploads a medical document;
  • provides consent;
  • links an ABHA account; or
  • contacts SarvaDoc support.

From healthcare professionals

Doctors, nurses, ASHA workers, ANMs, Community Health Officers, hospital staff, and other authorized healthcare professionals may enter or capture information during care delivery.

From connected healthcare devices

Diagnostic equipment may transmit measurements directly into an active patient encounter.

From healthcare institutions

Hospitals, PHCs, CHCs, government health programs, laboratories, and other healthcare entities may provide information as part of an authorized integration.

Through ABDM

Where SarvaDoc is integrated with ABDM, health information may be exchanged using applicable ABDM workflows, identifiers, and consent mechanisms.

5. How We Use Personal and Health Information

We process information only for legitimate and specified purposes connected with providing and securing SarvaDoc services.

These purposes may include:

5.1 Supporting Healthcare Delivery

To:

  • create and manage patient encounters;
  • assist healthcare professionals in collecting structured clinical information;
  • support triage;
  • identify missing clinical questions;
  • create clinical summaries;
  • support referrals;
  • support follow-up care; and
  • provide continuity between different levels of healthcare.

SarvaDoc provides clinical decision support. It does not replace the professional judgment of qualified healthcare practitioners.

5.2 Clinical Documentation

Information may be processed to generate draft:

  • consultation notes;
  • SOAP notes;
  • referral notes;
  • clinical summaries;
  • prescriptions where approved by the healthcare professional;
  • discharge documentation; and
  • longitudinal patient records.

Healthcare professionals remain responsible for reviewing and approving clinical documentation where required.

5.3 Artificial Intelligence-Assisted Triage

During supported consultations, SarvaDoc may analyze clinical context to suggest:

  • relevant follow-up questions;
  • missing history;
  • potential red flags;
  • escalation triggers; and
  • referral considerations.

AI-generated information is advisory and is intended to augment, not replace, human clinical judgment.

5.4 Processing Medical Reports

Artificial-intelligence and document-understanding systems may process medical documents to:

  • identify document type;
  • extract laboratory values;
  • identify medications;
  • identify diagnoses or clinical findings; and
  • convert unstructured documents into structured data for healthcare-professional review.

5.5 ABDM and Health-Record Interoperability

Where enabled, SarvaDoc may support:

  • ABHA identification;
  • creation or linking of care contexts;
  • consent-based exchange of health records;
  • health-information-provider or health-information-user workflows; and
  • other approved ABDM interoperability functions.

ABHA participation is voluntary except where otherwise lawfully required by an authorized government program.

5.6 Center of Excellence and Clinical Escalation

Authorized COE clinicians may review appropriately escalated cases for:

  • specialist support;
  • remote clinical guidance;
  • quality assurance;
  • referral management; and
  • continuity of care.

Access is restricted according to authorized roles and healthcare workflows.

5.7 Security and Fraud Prevention

We may process information to:

  • authenticate users and devices;
  • detect unauthorized access;
  • investigate security incidents;
  • prevent misuse or fraud;
  • maintain audit trails; and
  • protect patients, healthcare professionals, institutions, and the SarvaDoc platform.

5.8 Service Improvement

We may use appropriately protected, aggregated, anonymized, or de-identified information to:

  • assess system performance;
  • improve workflows;
  • identify technical errors;
  • evaluate AI quality;
  • monitor safety;
  • measure program outcomes; and
  • improve SarvaDoc services.

Identifiable patient health information will not be used for advertising.

6. Artificial Intelligence and Automated Processing

Artificial intelligence is an important component of SarvaDoc.

Depending on the feature and deployment, AI may be used for:

  • speech recognition;
  • translation;
  • consultation understanding;
  • triage-question generation;
  • clinical summarization;
  • document extraction;
  • OCR;
  • report interpretation support;
  • clinical-information structuring; and
  • operational analytics.

SarvaDoc currently may use specialized third-party AI providers as part of these workflows, including but not limited to:

  • Google / Gemini / Google Cloud for supported real-time consultation, language, transcription, reasoning, and summarization workflows; and
  • Anthropic / Claude for supported document understanding, OCR, and medical-report processing workflows.

Only information necessary for the applicable function should be transmitted to such providers.

Where SarvaDoc is deployed under an enterprise, hospital, or government agreement, use of external AI services may be restricted, replaced, locally hosted, or configured according to the institution’s approved deployment architecture.

SarvaDoc does not permit AI-generated clinical output to independently make final treatment decisions on behalf of healthcare professionals.

Where AI-generated information may materially affect clinical care, appropriate human review is required.

7. Use of Personal Data for AI Model Training

SarvaDoc does not sell identifiable patient health information for AI training or advertising.

SarvaDoc will not use identifiable patient consultation data to train a generalized commercial AI model unless:

  • such use is legally permitted;
  • the purpose has been clearly disclosed;
  • appropriate authorization or consent has been obtained where required; and
  • applicable contractual, institutional, ethical, and privacy safeguards have been satisfied.

Where data is used for quality evaluation, research, or improvement, SarvaDoc will apply appropriate safeguards such as de-identification, anonymization, aggregation, access restriction, or other privacy-preserving techniques depending on the purpose and risk.

8. Sharing of Information

We do not sell patient health information.

We may share personal data only where necessary for legitimate healthcare, operational, security, or legal purposes.

8.1 Healthcare Professionals and Institutions

Information may be shared with authorized:

  • doctors;
  • nurses;
  • ASHA workers;
  • ANMs;
  • Community Health Officers;
  • hospitals;
  • PHCs;
  • CHCs;
  • diagnostic facilities;
  • referral facilities; and
  • authorized COE personnel

where necessary to provide healthcare or support continuity of care.

8.2 Government Health Authorities

Where SarvaDoc is deployed as part of a government healthcare program, authorized data may be processed or made available to the relevant government healthcare authority according to applicable law, contractual arrangements, program requirements, and access controls.

8.3 ABDM

Where a patient chooses to participate in ABDM-enabled workflows, records may be exchanged through ABDM in accordance with applicable consent and interoperability mechanisms.

8.4 Technology Service Providers

We may engage service providers for functions such as:

  • infrastructure hosting;
  • communications;
  • AI processing;
  • document processing;
  • security;
  • monitoring;
  • analytics; and
  • technical support.

Such providers are permitted to process information only for authorized purposes and are expected to protect it through appropriate contractual and technical safeguards.

Depending on the deployment, these providers may include OpenAI / Google Cloud / Gemini, Anthropic / Claude, cloud-infrastructure providers, communication providers, monitoring providers, and other approved subprocessors.

8.5 Legal Requirements

Information may be disclosed when reasonably necessary to:

  • comply with applicable law;
  • comply with a lawful order from a court or competent authority;
  • protect the safety of an individual;
  • investigate fraud or security incidents; or
  • establish, exercise, or defend legal rights.

9. Cross-Border Processing

SarvaDoc deployments for Indian public-health programs are intended to follow the infrastructure, security, localization, and data-management requirements agreed with the relevant government authority or healthcare institution.

Certain third-party cloud or AI services may process information outside India depending on their service configuration.

Where cross-border processing occurs, SarvaDoc will apply applicable legal requirements and contractual safeguards and will limit such processing to what is necessary for the relevant service.

Enterprise and government deployments may be configured to restrict processing to approved infrastructure or jurisdictions.

10. ABDM and ABHA

SarvaDoc may integrate with the Ayushman Bharat Digital Mission.

Where such integration is enabled:

  • an ABHA number may be used to identify or link a patient;
  • health records may be linked to appropriate care contexts;
  • records may be exchanged using approved ABDM standards;
  • applicable patient consent mechanisms will be followed; and
  • access to health information will be controlled according to applicable ABDM requirements.

SarvaDoc does not treat possession of an ABHA number as unrestricted authorization to access a person’s health records.

11. Consent

Where consent is required, SarvaDoc or the relevant healthcare institution will provide appropriate notice describing:

  • what information is being collected;
  • the purpose of collection;
  • how the information will be used;
  • relevant data sharing; and
  • how consent may be withdrawn where applicable.

Consent may be obtained digitally, verbally where legally and operationally appropriate, through an ABDM consent workflow, or by another approved method.

Withdrawal of consent will not affect processing that was lawful before withdrawal or processing that is otherwise permitted or required under applicable law.

12. Recording Through Smart Glasses

Where Meta glasses or another wearable device is used during a consultation:

  • the wearable acts as a clinical data-capture interface for SarvaDoc;
  • audio, images, or video should only be captured for an approved healthcare purpose;
  • appropriate notice should be provided to the patient;
  • capture should be limited to information necessary for the clinical workflow; and
  • access to captured information is restricted to authorized users and systems.

Smart glasses must not be used through SarvaDoc for covert surveillance or unrelated recording.

13. Children’s Data

SarvaDoc may process children’s health data when the child is receiving healthcare.

Where applicable, processing of a child’s personal data will be undertaken through the child’s parent, lawful guardian, healthcare provider, or another mechanism permitted under applicable law.

SarvaDoc is not intended to allow children to independently create accounts or provide consent where parental or guardian authorization is legally required.

Additional safeguards may apply to pediatric data.

14. Security Measures

SarvaDoc applies technical and organizational safeguards appropriate to the sensitivity of healthcare information.

Depending on the deployment, these may include:

  • encryption in transit;
  • encryption at rest;
  • role-based access controls;
  • least-privilege access;
  • multi-factor authentication for privileged users;
  • secure API authentication;
  • device registration and access controls;
  • audit logging;
  • security monitoring;
  • vulnerability management;
  • secure backups;
  • incident-response procedures;
  • data-loss-prevention measures; and
  • business-continuity and disaster-recovery controls.

No information system can guarantee absolute security. We therefore continuously review and improve security controls based on system risk and applicable requirements.

15. Data Retention

SarvaDoc retains personal data only for as long as necessary for:

  • providing healthcare services;
  • maintaining legally required medical records;
  • fulfilling the requirements of the relevant healthcare institution or government health program;
  • security and audit purposes;
  • complying with law;
  • resolving disputes; or
  • another disclosed and lawful purpose.

Retention periods may differ according to:

  • type of information;
  • healthcare institution;
  • applicable medical-record requirements;
  • government-program requirements;
  • contractual terms; and
  • whether SarvaDoc acts as Data Fiduciary or Data Processor.

Where SarvaDoc processes information solely on behalf of a healthcare institution, deletion and retention may be controlled by that institution.

Raw audio, video, or images should not be retained longer than necessary for the approved purpose unless retention is required by the applicable healthcare workflow or institution.

Data that is securely anonymized such that it can no longer identify an individual may be retained for analytics, safety, statistical, research, or service-improvement purposes as permitted by law.

16. Data Accuracy

Healthcare professionals and patients should provide information that is accurate and complete to the best of their knowledge.

AI-generated transcriptions, document extraction, and summaries may occasionally contain errors.

Healthcare professionals are responsible for reviewing clinically material AI-generated information before relying upon it for care.

Users may request correction of inaccurate personal data in accordance with applicable law and healthcare-record requirements.

17. Individual Rights

Subject to applicable law and the role SarvaDoc performs in a particular deployment, individuals may have rights concerning their personal data, including the right to:

  • obtain information about personal data being processed;
  • request correction of inaccurate or incomplete personal data;
  • request erasure of personal data where legally permitted;
  • withdraw consent where processing is based on consent;
  • raise a grievance regarding processing of personal data; and
  • exercise other rights available under applicable law.

Where SarvaDoc processes information on behalf of a hospital, government health authority, or healthcare institution, we may direct the request to that organization as the responsible Data Fiduciary.

Identity verification may be required before fulfilling a privacy request.

18. Grievance Redressal

Questions, privacy requests, or grievances concerning SarvaDoc may be submitted to:

  • Grievance Officer / Data Protection Contact: Grievance Officer
  • Legal Entity: Sarvadoc Technologies Pvt. Ltd.
  • Address: Innov8 OKHLA, 3rd Floor, 211, OKHLA INDL. ESTATE PHASE -III NEW DELHI 110020
  • Email: privacy [at] sarvadoc.ai

We will acknowledge and process grievances in accordance with applicable law and contractual obligations.

Where a healthcare institution is the Data Fiduciary, users may also contact the grievance or privacy officer of that institution.

19. Website Analytics and Cookies

The SarvaDoc public website may use cookies and similar technologies for:

  • essential website functionality;
  • security;
  • performance measurement; and
  • analytics.

Non-essential analytics or advertising technologies will be used subject to applicable consent requirements.

Health information collected through SarvaDoc clinical services will not be used to create advertising profiles.

The clinical applications should not use third-party advertising trackers.

20. Marketing

SarvaDoc does not use patient clinical information for direct advertising.

Where users separately subscribe to product communications, newsletters, or other marketing material, contact information may be used for those communications in accordance with applicable law and user preferences.

Users may opt out of non-essential marketing communications at any time.

21. Research, Public Health and Analytics

Subject to applicable law, institutional approvals, contractual restrictions, and appropriate privacy safeguards, aggregated, anonymized, or de-identified data may be used to:

  • evaluate healthcare-program performance;
  • assess referral patterns;
  • assess access to healthcare;
  • improve clinical workflows;
  • identify population-level trends;
  • improve AI-system safety and performance; and
  • support approved research or public-health activities.

Such processing will be governed according to the purpose, nature of the data, and applicable legal and ethical requirements.

22. Security Incidents and Data Breaches

SarvaDoc maintains processes for identifying, investigating, containing, and responding to suspected information-security incidents.

Where a personal-data breach occurs, SarvaDoc will notify the relevant Data Fiduciary, affected individuals, governmental authority, regulator, or other party when required by applicable law or contract.

23. Third-Party Systems and Integrations

SarvaDoc may integrate with systems operated by:

  • healthcare institutions;
  • ABDM;
  • government health platforms;
  • laboratories;
  • diagnostic providers;
  • pharmacies;
  • telemedicine platforms; and
  • other authorized healthcare systems.

Information processed directly by those systems may also be governed by their respective privacy policies and legal obligations.

SarvaDoc is not responsible for independent processing carried out by third parties outside SarvaDoc’s control.

24. Changes to this Privacy Policy

We may update this Privacy Policy to reflect:

  • changes in SarvaDoc services;
  • changes in technology;
  • regulatory developments;
  • security requirements; or
  • changes to our data-processing practices.

Material changes will be communicated through appropriate channels.

The current version and its effective date will always be available on the SarvaDoc website.

25. Contact Us

For questions regarding this Privacy Policy or SarvaDoc’s privacy practices, contact:

  • Platform: SarvaDoc
  • Legal entity: Sarvadoc Technologies Pvt. Ltd.
  • Address: Innov8 OKHLA, 3rd Floor, 211, OKHLA INDL. ESTATE PHASE -III NEW DELHI 110020
  • Email: [email protected]

For clinical-record questions relating to care received at a hospital, PHC, CHC, or government health facility, patients should also contact the relevant healthcare institution.