Legal
Privacy Policy
Last updated: 11 June 2026
1. Introduction
This Privacy Policy describes how VitalForce (“we”, “us”) collects, uses, shares, and protects personal data when registered homeopathic practitioners (“doctors”, “practitioners”) use our platform. It is written to serve as a notice under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) of India. It should be read together with our Terms of Service and Medical Disclaimer.
Two categories of personal data flow through VitalForce. For doctor account data, we act as the data fiduciary. For patient records entered by doctors, the doctor is the data fiduciary and we process that data on the doctor's behalf and instructions, as a data processor.
2. What data we collect
- Doctor account data: name, email address, password (stored only as a salted hash), optional profile photo, subscription and billing records, and acceptance of our Terms.
- Patient records entered by doctors: patient demographics (name, age, gender, contact details), case histories, symptom descriptions (text, and — where the doctor uses those features — voice recordings, images, and uploaded reports), consultations, prescriptions, appointments, and follow-up notes.
- Technical and usage data: authentication tokens, request logs, and feature-usage counts needed to operate, secure, and rate-limit the service. We do not log patient case text or media payloads in application logs.
3. Purposes of processing
- providing the practice management, record-keeping, and scheduling features of the platform;
- providing AI-assisted decision-support features (symptom extraction, repertory evidence retrieval, and remedy differential suggestions) when the doctor invokes them;
- account administration, subscription billing, and usage-cap enforcement;
- service security, abuse prevention, and troubleshooting;
- communicating with doctors about the service (e.g. password-reset codes, service notices);
- complying with legal obligations.
We do not sell personal data, and we do not use patient records for advertising.
4. Third-party AI processing and cross-border transfers
Please read this section carefully. When a doctor uses the AI features, the relevant patient symptom text and compact case context are transmitted to DeepSeek, a third-party large-language-model provider, for processing. DeepSeek may process this data on infrastructure located outside India (DeepSeek is headquartered in the People's Republic of China), which constitutes a cross-border transfer of personal data. We send only the case material needed for the specific AI request — not full patient histories or identifiers beyond what the doctor includes in the case text.
If a doctor enables the optional speech-to-text feature, audio recordings of dictated case notes are transmitted to the configured speech-to-text provider — Groq or OpenAI — for transcription. These features are disabled by default and only operate when configured and used.
Doctors are responsible for informing their patients of, and obtaining any required consent for, this third-party processing before entering patient data into VitalForce. Semantic search embeddings, where enabled, are computed on our own self-hosted infrastructure; symptom-derived text is never sent to a third-party embedding API.
5. Other service providers
We use infrastructure sub-processors to run the service, such as cloud hosting, managed databases and caches, and email delivery for transactional messages (e.g. password-reset codes). These providers process data only to provide their services to us and are bound by contractual confidentiality and security obligations.
6. Security safeguards
- encryption of data in transit (TLS) for all platform traffic;
- passwords stored only as salted cryptographic hashes; backend-managed token authentication;
- strict per-doctor data isolation: every patient, consultation, appointment, and statistics query is scoped to the authenticated doctor's account;
- rate limiting, request-size limits, and abuse monitoring;
- access to production systems restricted to authorised personnel on a need-to-know basis;
- no logging of API keys, tokens, patient case text, or media payloads.
7. Data retention
Doctor account data is retained while the account is active and for a reasonable period thereafter as required for legal, accounting, or dispute-resolution purposes. Patient records are retained while the controlling doctor's account remains active; doctors may delete patient records at any time, and may request export or deletion of their data on account closure.
8. Your rights under the DPDP Act, 2023
As a data principal under the DPDP Act, you have the right to:
- access a summary of your personal data and the processing activities applied to it;
- correction, completion, and updating of your personal data;
- erasure of your personal data where it is no longer necessary and retention is not required by law;
- grievance redressal through an accessible mechanism;
- nominate another individual to exercise your rights in the event of death or incapacity;
- withdraw consent where processing is based on consent, with prospective effect.
Patients whose records were entered by their doctor should direct rights requests to their doctor (the data fiduciary for those records); we will assist the doctor in fulfilling such requests.
9. Grievance officer
To exercise your rights or raise a grievance, contact our grievance officer at support@vitalforce.ai. We aim to acknowledge grievances promptly and resolve them within the timelines prescribed under applicable law. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
10. Personal data breach notification
In the event of a personal data breach affecting your data, we are committed to notifying the Data Protection Board of India and affected data principals in the form and manner prescribed under the DPDP Act, 2023, and to providing affected doctors with the information they need to meet their own obligations to their patients.
11. Children
VitalForce accounts are available only to adult practitioners. Where a doctor enters records of a minor patient, the doctor is responsible for obtaining verifiable parental or guardian consent as required by the DPDP Act.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or in-product notice, with the updated date shown at the top of this page.