Legal

Privacy Policy

How Healui handles your personal and health information across our EMR, marketplace, mobile app, AI clinical features and messages. Written to be read, not to be impenetrable.

Effective August 14, 2026

The short version

Four things worth knowing,

before the long version.

This summary is here to be useful, not to replace what follows. Where the two differ, the numbered sections below are what binds us.

  1. 01

    Your clinic owns your record

    When a clinic treats you, that clinic decides what happens to your record and Healui only processes it on their instructions. When you book through the Healui marketplace yourself, Healui is responsible directly.

    Read the full section
  2. 02

    Your data is kept in India

    Records, documents, recordings and backups are held in AWS Mumbai. The one exception is our AI features, which send clinical text and audio to providers outside India. We name that plainly rather than bury it.

    Read the full section
  3. 03

    We never sell your data

    Not to insurers, not to pharma, not to advertisers. We do not use clinic patient lists to market the Healui marketplace.

    Read the full section
  4. 04

    You can leave, and take your data

    You can delete your Healui account yourself, from the website, without signing in. Some clinical and billing records must be kept by law, so we anonymise those instead of destroying them.

    Read the full section
01

Who we are

Healui ("Healui", "we", "us", or "our") operates an AI-native electronic medical records (EMR) platform and marketplace built for physiotherapy clinics and practitioners. This Privacy Policy explains how we handle your information when you use the Healui Clinic mobile application, our websites and web applications (including app.healui.com), the patient care portal, our marketplace, and any communications we send you, including over WhatsApp.

By using Healui, you agree to the practices described in this Policy. If you do not agree, please do not use the platform.

02

Who is responsible for your data

This is the most important section in this Policy, because the answer changes depending on how you came to Healui. The Digital Personal Data Protection Act, 2023 ("DPDP Act") calls the party that decides why and how data is processed the Data Fiduciary, and the party that processes it on their behalf the Data Processor.

If a clinic or physiotherapist treats you using Healui

Your treating clinic is the Data Fiduciary for your clinical record. They decide what is recorded and how long it is kept. Healui is their Data Processor: we hold and process that record only on their instructions, to provide the service. Requests about your clinical record are routed to the clinic responsible for it.

If you book physiotherapy through the Healui marketplace

Where you come to Healui directly, create your own account and consent to us, Healui is the Data Fiduciary for the account and booking data you give us. Marketplace patients are a separate population from clinic EMR patients; the two are never merged.

Practical consequence: if you are a clinic patient asking us to erase a clinical record, we cannot simply do it. We will route your request to your clinic, because the decision and the legal retention duty are theirs. Your account data with Healui is a different matter, and you can erase that yourself.

03

Information we collect

We collect the following categories of information:

Identity and contact information

  • Your name, mobile phone number, and (where provided) email address.
  • Address: your service or home address and billing address, where you provide them for home visits or invoicing.
  • Account and profile details, including your role (patient, physiotherapist, clinic staff, or administrator).

Health and clinical information

  • Clinical records created during your care, including symptoms, assessments, conditions, diagnoses, treatment plans, prescriptions, session notes, and outcome measures (PROMs).
  • Information you provide during screening or intake, including responses to questionnaires and body-map or pain inputs.
  • Voice recordings or dictation, where you or your physiotherapist use voice features to capture clinical notes.

Documents, images, and video consultations

  • Documents and images you or your clinic upload, such as imaging results, referrals, prescriptions, and profile photos.
  • Camera and microphone access during video consultations (teleconsultation), used to connect you with your physiotherapist in real time.

Location

  • The addresses you save, which we use to price and schedule home visits.
  • Your device location, only if you grant permission in the app or browser, and only to show you physiotherapists near you and pre-fill an address. You can decline and enter an address by hand instead; we do not track your location in the background.

Usage, device, and technical information

  • Device type, operating system, app version, and identifiers needed to operate the mobile app.
  • Log and usage data, such as features used and approximate activity times, used to keep the service secure and reliable.

Billing information

  • Invoices, payment status, and session-pack records associated with your care. Healui does not store full card or bank credentials; payments are handled by our payment partner, and payout details are shown only as the last four digits.
04

How we use your information

We use your information to:

  • Authenticate you and secure your account (we verify your identity using a one-time passcode sent to your phone).
  • Provide physiotherapy care, including scheduling, clinical documentation, treatment planning, and outcome tracking.
  • Enable video consultations (teleconsultation) and voice-assisted clinical documentation.
  • Generate and deliver your care plan, appointment reminders, and follow-up prompts.
  • Produce invoices and manage billing for the care you receive.
  • Operate, maintain, secure, and improve the platform.
  • Comply with legal, regulatory, and record-keeping obligations.

We process your personal data on the basis of your consent and, where applicable, to perform the services you or your clinic have requested, and to meet legal obligations. We do not use your clinical records to advertise to you, and we do not use a clinic’s patient list to market the Healui marketplace.

05

AI-assisted clinical features

Healui includes AI features that assist physiotherapists, for example by suggesting differential diagnoses, drafting treatment plans, and helping convert voice notes into structured clinical documentation. These features are a clinical copilot: they assist the physiotherapist, who reviews, edits, and remains responsible for every clinical decision. The AI does not make decisions about your care on its own.

To provide these features, relevant clinical information is processed by third-party AI providers. Where this happens:

  • Structured records are stripped of your name, phone number and email address before processing. Only the clinical picture needed for the task, such as age, symptoms and relevant history, is sent.
  • Consultation audio is different, because a recording contains whatever was said aloud. We treat those recordings as identifiable and protect them accordingly rather than describing them as anonymous.
  • Providers are engaged under contract to use the data only to return the requested result, not to train their general-purpose models, and not to retain it beyond what is needed to produce that result.
  • A qualified physiotherapist reviews AI-generated output before it is relied upon for your care.

These AI providers operate servers outside India, primarily in the United States. This is named in the consent notice you are asked to agree to, and it is described in “Cross-border transfers” below. A clinic that would rather not use these features can tell us before onboarding.

06

WhatsApp and other messages

With your consent, we use WhatsApp to send you appointment reminders, intake links, care-plan notifications, and follow-up prompts. WhatsApp messages are delivered through the WhatsApp/Meta platform, which processes message metadata under its own terms and operates outside India.

We are deliberate about what appears in a message. Sensitive clinical details are not placed in the message body. Instead, we send a secure link that opens your care plan only after you enter a one-time access code, and the link expires after a limited period. This keeps your health information behind an additional layer of verification rather than in the message itself.

You can ask us to stop sending WhatsApp messages at any time by contacting us using the details below. Transactional messages needed to deliver care you have booked, such as an appointment confirmation, may continue while that care is ongoing.

07

How we share information

We share your information only as needed to operate the service:

  • With your treating physiotherapist and clinic, so they can provide and manage your care.
  • With the service providers listed below, acting on our instructions under confidentiality obligations.
  • For legal reasons, where required to comply with applicable law, regulation, legal process, or enforceable governmental request, or to protect the rights, safety, and security of users and the public.
  • In connection with a business transfer, such as a merger or acquisition, subject to this Policy.

We do not sell your personal or health information, to anyone, for any purpose. Every request is authorised against the clinic that owns the record, so one clinic cannot reach another clinic’s patients.

Our service providers

  • Amazon Web Services: hosting, database, file storage and encryption keys. India (Mumbai).
  • Google Firebase: phone-number verification at sign-in. Outside India.
  • Meta (WhatsApp): appointment and care notifications. Outside India.
  • Razorpay: payment processing. India.
  • AI providers: transcription and clinical documentation support. Outside India.
08

Where your data is stored

All patient data is stored and processed in AWS Mumbai (ap-south-1). Databases, file storage for documents and recordings, backups and encryption keys are all held within India. The DPDP Act does not currently require health data to remain in India; we keep it here anyway.

The exception is the AI processing described above, and the sign-in verification and messaging providers listed above, which operate outside India.

09

How we protect it

We apply technical and organisational measures designed to protect your information, including:

  • TLS 1.3 encryption on every connection, including from our servers to the database.
  • AES-256 encryption at rest across database storage, backups and uploaded files.
  • Field-level encryption, applied individually to names, contact details, medical history, medications, assessments, transcripts and message content before they are written.
  • Encryption keys held in a hardware security module (AWS KMS), never stored alongside the data.
  • Phone-based one-time-passcode authentication, and care-plan links protected by an additional access code, automatic expiry, and lockout after repeated incorrect attempts.
  • Access controls that limit clinical records to the treating clinicians and authorised staff involved in your care, enforced on every request.
  • Per-record access logging, so it is recorded who viewed which record, when, and whether the request was allowed or refused.
  • Tamper-evident, hash-chained consent records that cannot be edited after the fact.

No method of transmission or storage is completely secure, but we work to protect your information and to continually improve our safeguards. Our full security document, including an honest list of what is still in development, is published at healui.com/data-security.

10

Cross-border transfers

Certain service providers store or process information on servers located outside India: our AI providers (primarily in the United States), our sign-in verification provider, and WhatsApp/Meta for notifications. Where we transfer personal data internationally, we limit what is shared, select providers offering appropriate data-protection commitments, and contract them to use the data only for the purpose we engaged them for.

By consenting to the AI-assisted and communication features described above, you acknowledge that your information may be processed in this way. These purposes are named separately in the consent notice so you can see what you are agreeing to.

11

Your rights and choices

Subject to applicable law, including the DPDP Act, you have the right to:

  • Access: request a summary of the personal data we process about you.
  • Correction: ask us to correct inaccurate or incomplete information.
  • Erasure: ask us to delete your personal data, subject to legal and clinical record-keeping requirements.
  • Withdraw consent: withdraw any consent you have given, in whole or for a single purpose, without affecting processing already carried out.
  • Grievance redressal: raise a concern about how your data is handled, and escalate to the Data Protection Board of India if we do not resolve it.
  • Nominate: nominate another individual to exercise your rights in the event of death or incapacity.

Deleting your account

You can delete your Healui account yourself at healui.com/delete-account, without signing in, which matters because most people asking have already removed the app. Enter your mobile number, confirm the one-time SMS code, and the account is erased. The page shows exactly what is removed and what is kept before anything happens.

Identifying data (your name, phone, email, date of birth, gender, address, and the medical history held on your account) is removed, and you can no longer be found by name or number. Appointment and treatment records your clinic must retain, invoices required for tax, the consent record proving your data was handled lawfully, and the access log that exists to protect you, are kept in anonymised form. Destroying those would erase the evidence that protects you, which is the opposite of what an erasure request is for.

To exercise any other right, contact us using the details below. We may need to verify your identity before acting on a request.

13

How long we keep it

Clinical records follow the statutory minimum of three years from the start of treatment, with ten years recommended in line with national health-record guidance. Consent and withdrawal evidence is retained separately, as proof of lawful processing. Invoices and payment records are retained for the periods tax law requires.

Access logs identifying a patient’s record, and records of refused access attempts, are retained for 13 months so that a report can always cover a full preceding year. Listing and dashboard views that identify no single patient are retained for 90 days. When information is no longer required, we delete or anonymise it.

14

Children’s privacy

Where care is provided to a child or a person who cannot provide consent on their own behalf, we process their information only with the consent of a parent or lawful guardian, and in connection with the care being delivered. If you believe a child’s information has been provided to us without appropriate consent, please contact us.

15

If something goes wrong

On becoming aware of a personal data breach we contain it, assess what was affected, and notify the affected parties without undue delay with what we know, what we are doing and what we recommend, alongside the reporting we owe CERT-In under the 2022 directions.

Where the affected records belong to a clinic, the DPDP Act places the duty to notify the Data Protection Board and affected patients on that clinic as Data Fiduciary. Our role is to give them the facts quickly enough to meet it. Our access log is what makes that possible: it lets the affected set be identified rather than estimated.

16

Grievance redressal

If you have any concern or complaint about how your personal data is handled, contact our Grievance Officer. We will acknowledge and address your concern within the timelines required by applicable law. If we do not resolve it to your satisfaction, you may escalate to the Data Protection Board of India.

  • Grievance Officer, Healui
  • Email: grievance@healui.com
  • Phone: +91 82829 89891
17

Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the effective date above and, where appropriate, notify you. Your continued use of Healui after an update constitutes acceptance of the revised Policy.

18

Contact us

For any question about this Policy or our data practices:

  • Privacy and grievances: grievance@healui.com
  • Data processing agreements, access reports, and record exports: support@healui.com
  • Website: https://www.healui.com

FAQ

Questions, answered.

It depends on how you came to us. If a clinic treats you using Healui, that clinic is the Data Fiduciary under the DPDP Act: they decide what is recorded and how long it is kept, and Healui only processes it on their instructions. If you booked physiotherapy through the Healui marketplace yourself, Healui is responsible directly for the account and booking data you gave us. It matters in practice, because a request to erase a clinical record has to go to the clinic that holds the duty to retain it.

In India. Records, documents, clinical photos, voice recordings, backups and encryption keys are all held in AWS Mumbai (ap-south-1). There is one exception we state plainly rather than bury: our AI features send clinical text and consultation audio to providers whose servers are outside India, primarily in the United States. That is named in the consent notice you agree to.

No. Not to insurers, not to pharma, not to advertisers, not to anyone. We also do not use a clinic’s patient list to market the Healui marketplace: marketplace patients are a separate population who consent to Healui directly, and the two are never merged.

They help your physiotherapist draft notes, suggest differential diagnoses and plan treatment. A qualified physiotherapist reviews everything before it is used in your care; the AI decides nothing on its own. Structured records are stripped of your name, phone and email before processing. Consultation audio is treated as identifiable, because a recording contains whatever was said aloud, and we would rather say that than call it anonymous. Providers are contracted not to train their models on it.

Not in the background. We use the addresses you save to price and schedule home visits. If you grant location permission, we use your device location to show physiotherapists near you and to pre-fill an address. You can decline that and type an address by hand instead.

Go to healui.com/delete-account. You do not need to sign in, which matters because most people asking have already removed the app. Enter your mobile number, confirm the SMS code, and the account is erased. Your identifying details go. Records your clinic must keep by law, invoices required for tax, and the consent and access records that prove your data was handled properly are kept in anonymised form, unlinked from you.

Yes, any time. Email grievance@healui.com and we will stop them. Messages needed to deliver care you have already booked, like an appointment confirmation, may continue while that care is ongoing.

Write to our Grievance Officer at grievance@healui.com or call +91 82829 89891. We will acknowledge and address it within the timelines the law requires. If we do not resolve it to your satisfaction, you have the right to escalate to the Data Protection Board of India.

Questions

Ask us anything about your data.

Our Grievance Officer answers every question. For a data processing agreement, an access report, or an export of your records, write to support@healui.com.