Under the DPDP Act, your clinic is the data fiduciary. Saaro is built to make that manageable.
Consent, notice, retention, erasure, breach reporting and grievance handling are obligations on the clinic. Here is what each one means for an OPD, and which parts the product does for you.
- Consent in the record
- Hosted in India
- Audit trail
The Act names three parties. The clinic is the one with the obligations.
The Digital Personal Data Protection Act 2023 uses three terms. The data principal is the person the data is about: your patient. The data fiduciary is whoever decides why and how that data is processed: your clinic. The data processor is whoever processes it on the fiduciary's behalf: Saaro Health, operated by Lumotis Digital Media. The obligations sit with the fiduciary, and the fiduciary stays responsible for what its processors do.
The Act asks for consent that is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and preceded by a notice in plain language stating what data is collected and why. Patients can withdraw consent as easily as they gave it. Processing without consent is allowed for certain legitimate uses, including medical emergencies, but those are exceptions and should be treated as such.
Patients have rights: to know what data you hold, to have it corrected or erased, to a grievance process, and to nominate someone to exercise these rights if they cannot. Children under eighteen need verifiable parental consent. Data must be erased once its purpose is served or consent is withdrawn, unless a law requires you to keep it, which for medical records the clinical establishment and medical council rules generally do for a minimum period.
If a personal data breach happens, the fiduciary must inform the Data Protection Board of India and each affected patient in the form and timeline set by the Rules. Penalties for non-compliance are structured in crores and scale with the seriousness of the failure. The DPDP Rules phase these obligations in over a period running through 2027, so a clinic that starts now has time, but not much of it.
One point of accuracy. The DPDP Act does not create a separate 'sensitive' category; it treats all personal data under one standard. Health information is, however, classed as sensitive personal data under the older IT Act rules, and regulators and courts treat it with heightened care. Practically, clinics should assume health data deserves the strictest handling the Act describes.
Every DPDP obligation for a clinic, with who owns it.
Product means Saaro provides the mechanism. Clinic means it is a decision, a document or a behaviour that is yours. Both means the product provides the tool and the clinic operates it.
- Shared
Give notice before or at collection
Patients must be told what is collected and why, in plain language. Saaro sends a notice on WhatsApp at registration from your clinic's number, in Hindi or English; the wording is yours to approve.
- Saaro handles it
Take and record consent
Consent is captured as a clear action by the patient, timestamped, and stored against the record with the notice version they saw. Withdrawal is one reply away and is recorded the same way.
- Shared
Limit processing to the stated purpose
Data collected for treatment is used for treatment, reminders and billing. Using it for anything else, such as marketing, needs a separate consent that the product asks for separately.
- Your clinic
Keep data accurate and complete
Patients can ask for corrections; the front desk edits the record and the change is logged with who made it and when.
- Shared
Respond to access, correction and erasure requests
Saaro exports a patient's full record on request and can erase it, subject to legal retention. The clinic decides what retention law applies and responds to the patient.
- Shared
Retain only as long as needed or required
Retention periods are set per record type in the workspace. Saaro flags records past the configured period; the clinic confirms deletion or documents the legal reason to keep them.
- Shared
Handle children's data with parental consent
Paediatric records carry a guardian field and consent is taken from the guardian. Verifying the guardian is the clinic's job at the desk.
- Shared
Report breaches to the Board and to patients
Lumotis notifies the clinic without undue delay if a breach touches its data, with the details the clinic needs to inform the Board and patients. Filing the report is the fiduciary's obligation.
- Your clinic
Publish a grievance contact
Patients need a way to complain. Saaro's notice template includes the clinic's grievance contact; the clinic names the person and responds within the period the Rules allow.
- Saaro handles it
Bind processors by contract
A data processing agreement between the clinic and Lumotis sets out purpose, security, sub-processors, breach notice and deletion on termination. It is part of every plan.
The consent lives with the record, so nobody has to go looking for it.
Notice and consent on WhatsApp
At registration the patient gets the notice from your clinic's number and replies to consent. No paper form, no app, and the reply is the timestamped record.
Learn moreConsent state on the record
Each patient record shows consent given, withdrawn, or pending, and for which purposes. Flows that need consent, like reminders or review requests, check it before sending.
Learn moreRole-based access
Front desk, doctor, pharmacy, lab and owner roles see only what their role needs. A receptionist can book and bill without opening clinical notes.
Learn moreAudit trail
Every view, edit, export and message is logged with user, time and what changed. The log is the evidence a fiduciary needs when a patient or the Board asks.
Learn moreExport and erase
One action exports a patient's complete record in a readable format. Another erases it, with a legal-hold option when retention rules apply and a log entry either way.
Hosted in India
Patient data is stored in hosting region with a named sub-processor list you can read. Nothing leaves the country except the WhatsApp message itself, which transits Meta's network.
Learn more
What a patient's consent history looks like on screen.
Consent is not a signed sheet in a file. It is a set of rows in the patient's timeline: the notice that was sent, the reply that gave consent, the purposes it covers, and any withdrawal.
When a patient asks what they agreed to, or a Board officer asks how you know, the answer is a screen the front desk can open in seconds.
- Notice version and language shown to the patient
- Consent reply with timestamp and channel
- Purposes covered, with marketing separate from care
- Withdrawal and erasure requests with outcome
- 09:41DPDP notice sent on WhatsApp (Hindi, v3)Delivered
- 09:43Consent given for care and remindersConsented
- 09:43Marketing consent not requestedSkipped
- Tue 2 SepRecord export requested by patientFulfilled
DPDP obligation against the Saaro control.
Obligations summarised from the DPDP Act 2023 and Rules. This is product documentation, not legal advice; counsel should confirm how each applies to your clinic.
| DPDP obligation | What it means for an OPD | Saaro control |
|---|---|---|
| Notice | Tell the patient what is collected and why, before or at collection | WhatsApp notice at registration, versioned, in Hindi or English |
| Consent | Free, specific, informed, unambiguous, by clear action | Reply-based consent stored with timestamp, channel and notice version |
| Withdrawal | As easy as giving consent | One-word reply stops non-care messaging; recorded on the timeline |
| Purpose limitation | Use data only for the purpose consented | Purposes tracked per patient; flows check consent before sending |
| Access and correction | Give patients their data; fix errors | Full record export; edits logged with user and time |
| Erasure | Delete when purpose ends unless law requires retention | Erase action with legal-hold option and retention flags |
| Children | Verifiable parental consent under eighteen | Guardian field on paediatric records; consent taken from guardian |
| Security safeguards | Reasonable measures to prevent breach | Encryption in transit and at rest, role-based access, audit trail, backups |
| Breach notification | Inform the Board and affected patients | Processor notifies clinic without undue delay with incident details |
| Processor contract | Bind processors in writing | Data processing agreement included in every plan |
| Grievance | Give patients a way to complain | Clinic contact in the notice; requests logged on the record |
| Data location | No statutory localisation, but sectoral care expected | Hosted in India, hosting region; sub-processor list published |
Swipe to see every tier
Your questions answered.
The things clinics ask first.
Yes, if you decide why and how patient data is processed, which any clinic keeping records does. Size does not exempt you. Saaro is your data processor and is bound to you by a data processing agreement.
No software can do that on its own. Saaro provides the mechanisms: notice, consent capture, purpose tracking, access controls, audit, export and erasure. The clinic still has to name a grievance contact, decide retention, and respond to patients. The checklist on this page shows which is which.
The front desk can record consent given verbally or on paper against the record, with the notice version and the staff member who took it. The audit trail shows it the same way.
Yes, and you must comply unless a law requires retention. Medical council and clinical establishment rules generally require records to be kept for a minimum period. Saaro lets you place a legal hold with the reason recorded, and erases once it lapses.
Lumotis notifies the clinic without undue delay with what happened, what data was affected and what has been done. The clinic, as fiduciary, reports to the Data Protection Board and affected patients in the form and timeline the Rules set. We help you draft it.
The Act is law; the Rules bring obligations into force in phases through 2027. Consent, notice and security expectations are the ones to be ready for first. Counsel can confirm the dates that apply to your clinic.
Keep reading.
- FeaturesPatient recordsA record built from every visit, not a spreadsheet row. Prescriptions, reports, notes and follow-ups sit in one timeline, linked to the patient's ABHA if they have one.
- FeaturesWhatsApp automationSaaro runs on SaroConnect, Lumotis's own WhatsApp Business infrastructure. Reminders, prescriptions, reports and refills go out from your number, patient replies come back to the desk, and messaging is included in every plan.
- FeaturesMulti-clinicSaaro runs a clinic chain as one system: a shared patient index, doctors who move between branches, billing that stays separate per location, and a single view for the owner.
- TrustSecurityPatient data is encrypted in transit and at rest, seen only by the roles that need it, logged every time it is touched, and backed up so it can be restored. Here is the detail behind each of those claims.
- TrustData residencySaaro Health is hosted in India, in hosting region. Databases, report files, backups and the WhatsApp messaging layer are all in-country. The one thing that crosses a border is the WhatsApp message itself, and we say so.
- TrustSub-processorsA sub-processor is any company Lumotis uses to process clinic data on your behalf. This page lists them, says what each does and where it runs, and explains how you are told before one is added.
See consent captured on a real registration.
Twenty minutes. Notice, consent, withdrawal and export, on your own patient flow.
