Draft — last edited July 2026, not yet published
This policy describes how pAI ("we", "the assistant") handles information when a doctor uses the pAI widget embedded in a clinic's existing patient management system.
pAI does not hold a standing copy of a clinic's patient records. It does not store diagnoses, prescriptions, or clinical notes — it has no fields for them. Every patient lookup is a live, one-time request to the clinic's own system, not a mirrored database.
Most requests are resolved by pattern-matching and never reach an AI model at all. For the ones that do, the patient's name and phone number are automatically replaced with a generic reference before the request leaves our infrastructure — the AI providers never see real patient identity.
OpenAI is explicitly instructed not to retain or train on this data (store: false on every request). We do not yet have a signed Data Processing Agreement in place with either provider — this is a known gap, tracked internally, and worth confirming is resolved before relying on this policy for anything beyond a small pilot.
The pAI service runs on cloud infrastructure operated by us. The clinic's own patient and appointment system is a separate system the clinic already runs and controls — pAI only ever calls it over the network, it never takes it over.
If you're a clinic, doctor, or patient with a question about data handled through pAI, contact us at pankajagarwal8890@gmail.com.
(AI-drafted) Under India's Digital Personal Data Protection (DPDP) Act, 2023, where it applies to information handled through pAI, you may have the right to:
(AI-drafted) Grievance Officer: [Name and designated contact details to be published here, as required under the DPDP Act, once appointed.] Until then, direct any grievance to pankajagarwal8890@gmail.com, and we will respond within a reasonable time.
[This section is placeholder boilerplate reflecting the DPDP Act's general framework — it must be reviewed against the final Rules and completed by counsel before publication, including confirming which rights apply given pAI processes data as a processor on behalf of clinics rather than as the primary data fiduciary.]
This is an early draft and will change, likely substantially, once formally reviewed. Once published as final, updates will be dated on this page.