Legal
Privacy Policy
Effective date: 29 August 2026 · Last reviewed: 29 August 2026
This policy describes how HexaRadius Technologies (OPC) Private Limited (“HexaRadius”, “we”, “us”), the company behind CliniKite, processes personal data in connection with the CliniKite clinic management platform, the website at https://clinikite.in, enquiries, demonstrations, sales outreach, and related business communications.
- Company
- HexaRadius Technologies (OPC) Private Limited
- Operating as
- CliniKite
- CIN
- U62020TN2025OPC186873
- GSTIN
- 33AAICH3362F1ZT
- Registered office
- 1A Kayitha Millath Street, Bharathi Nagar, Nesapakkam, Chennai 600078
About HexaRadius and CliniKite
CliniKite is a clinic management platform developed, operated, and supported by HexaRadius Technologies (OPC) Private Limited (“HexaRadius”), a company registered in India under CIN U62020TN2025OPC186873. All references to “CliniKite” in this policy refer to the software platform; all references to the company behind the platform refer to HexaRadius.
The CliniKite platform provides appointment management, digital prescriptions, GST-compliant billing, and patient communication to clinics and independent medical practitioners across India.
Who is the data controller?
In all cases, the treating clinic is the data fiduciary (equivalent to the data controller) for the personal data of its patients.
Where a clinic chooses the On-Premise deployment, patient records are stored entirely on infrastructure the clinic controls, and HexaRadius has no access to them. Where a clinic chooses CliniKite Cloud, HexaRadius hosts that clinic’s data on its shared, multi-tenant cloud platform on the clinic’s behalf — with strict tenant isolation — and acts as the clinic’s data processor under a written agreement. HexaRadius is also a processor for the delivery of clinic-initiated WhatsApp messages.
For doctors, clinic representatives, and other business contacts who enquire about CliniKite, request a demonstration, submit a lead form, or opt in to CliniKite communications, HexaRadius is the data fiduciary for that business relationship.
What personal data we process
Outside of hosting, the personal data HexaRadius itself processes is intentionally minimal. On CliniKite Cloud we host patient records on a shared, multi-tenant platform as the clinic’s processor, with strict tenant isolation so each clinic’s data is accessible only to that clinic; on On-Premise we hold no patient records at all.
| Data element | Purpose | Retention |
|---|---|---|
| Clinic owner name and email | Account administration and billing | Duration of the relationship + 7 years for tax |
| GSTIN and invoicing details of the clinic | Issuing GST-compliant invoices | 7 years as required by Indian tax law |
| Patient name, mobile number, appointment slot | Dispatching WhatsApp reminders initiated by the clinic | Transient — not persisted after successful delivery |
| Website visitor IP and device information | Site reliability, product analytics, advertising measurement, and fraud prevention | According to configured provider retention and until browser storage is cleared or expires |
| Business contact name, role, clinic or organisation, mobile number, email, lead source, enquiry history, and consent status | Responding to enquiries, arranging demonstrations, relationship management, and sending CliniKite communications the contact requested | While needed for the enquiry or business relationship, followed by only the records needed for legal, security, dispute, audit, and opt-out suppression purposes |
Regardless of plan, HexaRadius never uses clinical data — medical records, prescriptions, diagnoses, or lab results — for any purpose of its own. On On-Premise this data never reaches us; on CliniKite Cloud it is hosted solely to operate the service for the clinic, and is never sold, shared, or mined.
How clinical data is stored
Where and how your patient records are stored depends on the plan:
- On-Premise — the database runs on hardware at the clinic, using full-disk encryption. The clinic holds all database credentials and encryption keys, and HexaRadius has no administrative access.
- CliniKite Cloud — HexaRadius hosts records on a shared, multi-tenant platform in the AWS Asia Pacific (Mumbai) region, encrypted at rest and in transit, with strict tenant isolation so each clinic’s data is accessible only to that clinic. HexaRadius operates the platform as the clinic’s processor, and access is limited to authorised support the clinic requests and that is time-bound.
On no plan does HexaRadius sell, share, mine, or derive analytics from clinical data.
Third-party processors
HexaRadius uses a small number of third-party service providers strictly for operational purposes. Each provider processes data under a written agreement and is bound by contractual confidentiality.
- Meta Platforms Ireland — delivery of clinic-initiated and expressly opted-in CliniKite WhatsApp messages, and website advertising measurement through Meta Pixel and the Conversions API. Depending on the interaction, Meta may receive a mobile number, profile name, message content and delivery metadata, or website IP address, browser and device data, page and event data, ad-click identifiers, and SHA-256-hashed contact identifiers.
- PostHog — website analytics and error monitoring. Processes page and interaction events, browser and device information, network information, and technical error details; no patient or clinical data is intentionally sent.
- Amazon Web Services India — cloud hosting for CliniKite Cloud clinics, the CliniKite control plane, and the internal business relationship system used for enquiries and demonstrations. All infrastructure is hosted in the Asia Pacific (Mumbai) region.
- Amazon Bedrock — AI inference used to power the optional AI Assistant add-on. Only de-identified text is sent to Bedrock; no patient identifiers are transmitted.
HexaRadius does not sell, licence, or otherwise disclose patient data to pharmaceutical companies, insurance providers, advertisers, data brokers, or any other third party not listed above.
Patient WhatsApp communication
When a clinic uses CliniKite’s WhatsApp integration to send appointment reminders or confirmations to its patients, the clinic is the data fiduciary for that communication. HexaRadius acts as the processor that dispatches the message via the WhatsApp Business Platform.
- The clinic is immediately notified of the preference.
- No further WhatsApp messages are sent to the number by that clinic through CliniKite.
- The opt-out does not affect medical appointments or the patient’s relationship with their doctor.
Patients may stop receiving WhatsApp messages from a clinic at any time by replying STOP to any message. On receipt of the opt-out:
CliniKite enquiries and WhatsApp outreach
When a doctor, clinic representative, or other business contact asks about CliniKite, submits a lead form, or otherwise gives HexaRadius permission to contact them, HexaRadius processes the contact and enquiry information needed to respond, arrange a demonstration, and manage that business relationship.
- Marketing and sales WhatsApp messages stop for that number, and the suppression status is checked before any later outreach.
- HexaRadius retains the minimum consent and suppression record needed to honour the request and demonstrate compliance.
- Business-initiated messages use approved templates where WhatsApp rules require them, and automated conversations provide a route to a person.
HexaRadius sends business-initiated WhatsApp messages only when the contact has provided their mobile number and opted in to receive the relevant category of messages from CliniKite. A Meta lead-form submission, agency qualification, referral, imported contact, or CRM entry is not by itself treated as WhatsApp permission unless the captured consent wording expressly covers WhatsApp messages from CliniKite.
A contact may withdraw permission at any time by replying STOP to a CliniKite WhatsApp message or by contacting [email protected]. On withdrawal:
Website analytics and cookies
This website uses PostHog for product analytics and technical error monitoring, and Meta Pixel together with Meta’s Conversions API to measure advertising and website events. These services may use cookies or browser storage and may process IP address, browser and device information, page URLs, interaction events, and advertising click identifiers.
If a person submits contact details through a CliniKite demonstration or enquiry flow, normalized contact identifiers may be SHA-256 hashed in the browser before being sent to Meta for advertising measurement and matching. Hashing is a security measure, not anonymisation; Meta may match those identifiers to an account according to its own terms and privacy policy.
Website analytics and advertising systems are kept separate from CliniKite clinic records. Patient records and clinical data are not intentionally sent to PostHog, Meta Pixel, or the Conversions API.
Your rights under Indian data protection law
Under the Digital Personal Data Protection Act 2023 (the “DPDP Act”) and applicable Indian law, you have the right to:
- Access — confirm whether your personal data is being processed and obtain a summary.
- Correction — request correction of inaccurate or incomplete personal data.
- Erasure — request deletion of your personal data, subject to applicable legal retention requirements.
- Withdrawal of consent — withdraw consent for CliniKite business WhatsApp communications by replying STOP or contacting HexaRadius, and for clinic-initiated patient messages by replying STOP or contacting the treating clinic.
- Grievance redressal — raise a complaint regarding the processing of your personal data with the grievance officer identified in section 13.
For patient records stored in a clinic’s CliniKite installation, these rights are exercised through the treating clinic as the data fiduciary. For data processed by HexaRadius directly, contact the privacy team at [email protected]. We will respond within thirty days.
Security measures
HexaRadius follows industry-standard practices for the limited data it processes. All data in transit is encrypted using TLS 1.2 or higher. Infrastructure access is restricted to authorised personnel and protected by multi-factor authentication.
On-premise installations use full-disk encryption with backup keys held exclusively by the clinic. CliniKite Cloud encrypts data at rest and in transit on its multi-tenant platform, with managed, encrypted backups and strict tenant isolation between clinics.
Data retention
HexaRadius retains only the data necessary for the purposes described in section 3 and according to the criteria stated there. Patient data processed only for clinic-initiated WhatsApp dispatch is not retained by the dispatch service after successful delivery. Business contact and conversation records are retained while needed for the enquiry or relationship; afterward, only records required for legal, security, dispute, audit, and opt-out suppression purposes are retained. Clinic-level billing data is retained for seven years as required by Indian tax law.
Changes to this policy
This policy may be revised to reflect changes in our practices, in applicable law, or in the CliniKite product. Material changes will be reflected on this page with an updated effective date, and — where appropriate — communicated to clinics by email.
Contact and grievance officer
For privacy-related enquiries, requests, or complaints, please contact:
Grievance Officer HexaRadius Technologies (OPC) Private Limited 1A Kayitha Millath Street, Bharathi Nagar, Nesapakkam, Chennai 600078 Privacy · [email protected] General · [email protected]
This policy is governed by the laws of India and any disputes are subject to the exclusive jurisdiction of courts in Chennai, Tamil Nadu, India.
See also our Terms of Service.