Effective Date: 18 Aug 2025
Last Updated: 12 June 2026

Executive Summary

At Doxmate, protecting the privacy, confidentiality, and security of healthcare information is a core commitment. Doxmate is an AI-powered healthcare operations platform developed and operated by Brainox Tech, providing digital solutions for hospitals, clinics, healthcare professionals, and patients. Our platform includes appointment scheduling, patient communication, WhatsApp automation, Electronic Medical Records (EMR), Queue Management, billing, analytics, and integrations with third-party services such as Google Workspace.

This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices available to our users. It applies to all Doxmate services, including our website, web and mobile applications, APIs, dashboards, embedded signup flows, WhatsApp integrations, and connected third-party services.

In summary:

  • We collect only the information necessary to provide, maintain, and improve our healthcare management services.

  • Healthcare organizations using Doxmate remain the Data Controllers of patient information, while Doxmate generally acts as a Data Processor, processing data only on behalf of and under the instructions of the healthcare organization.

  • We implement industry-standard administrative, technical, and organizational safeguards to protect personal and healthcare information from unauthorized access, disclosure, alteration, or destruction.

  • We never sell personal information or patient medical records.

  • We do not use Google Workspace or Google API data for advertising, marketing, user profiling, or training generalized artificial intelligence or machine learning models.

  • When users choose to connect Google services such as Google Calendar, Google Sheets, or Google Sign-In, Doxmate accesses only the information necessary to provide the requested functionality and only after explicit user authorization.

  • Users maintain control over their connected accounts and may revoke Google access at any time through their Google Account settings.

  • Our AI-powered features are designed to assist with administrative and operational workflows such as appointment scheduling, queue management, reminders, and patient communication. Doxmate does not provide medical diagnoses, treatment recommendations, or clinical decision-making services.

  • We comply with applicable privacy and data protection laws, including the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (GDPR) where applicable, and the Google API Services User Data Policy for integrations with Google services.

  • We regularly review and update our privacy and security practices to maintain compliance with evolving legal, regulatory, and industry requirements.

By using Doxmate, creating an account, or accessing our services, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, processing, and disclosure of information as described herein.

Definitions

For the purposes of this Privacy Policy, the following terms shall have the meanings set forth below:

“Doxmate”

“Doxmate”, “we”, “our”, or “us” refers to Doxmate, an AI-powered healthcare operations platform developed and operated by Brainox Tech, including all associated websites, applications, APIs, software, dashboards, services, and products.

“Brainox Tech”

Brainox Tech is the legal entity that owns, develops, operates, and maintains the Doxmate platform and related services.

“Platform”

The “Platform” refers collectively to Doxmate’s websites, web applications, mobile applications, dashboards, APIs, embedded signup flows, WhatsApp integrations, Electronic Medical Records (EMR), Queue Management System, appointment management modules, AI-powered services, and any related software or services.

“User”

A “User” is any individual or organization that accesses or uses the Platform, including but not limited to healthcare providers, hospitals, clinics, doctors, administrators, staff members, patients, caregivers, and authorized representatives.

“Healthcare Organization”

A “Healthcare Organization” means any hospital, clinic, medical practice, diagnostic center, laboratory, pharmacy, or other healthcare provider that subscribes to or uses Doxmate’s services.

“Patient”

A “Patient” refers to any individual whose appointment, healthcare, queue, or medical information is processed through the Platform by a Healthcare Organization.

“Personal Data”

“Personal Data” means any information relating to an identified or identifiable natural person, including but not limited to names, email addresses, phone numbers, identification numbers, location data, online identifiers, or any information that can reasonably be used to identify an individual.

“Health Data” or “Medical Information”

“Health Data” includes any information relating to an individual’s physical or mental health, medical history, diagnoses, prescriptions, laboratory reports, treatment plans, allergies, immunizations, clinical notes, vital signs, or other healthcare-related information processed through Doxmate’s Electronic Medical Records (EMR) module.

“Electronic Medical Records (EMR)”

The EMR module refers to Doxmate’s electronic medical record management system used by healthcare organizations to securely create, store, manage, and retrieve patient medical records and clinical information.

“Queue Management System”

The Queue Management System refers to Doxmate’s patient queue management features, including digital token generation, patient check-in, waiting list management, consultation tracking, doctor assignment, and estimated waiting time calculations.

“Appointment Data”

Appointment Data includes scheduling information such as appointment date and time, healthcare provider details, patient information, appointment status, reminders, cancellations, rescheduling information, and related administrative records.

“Google Services”

Google Services include Google Calendar, Google Sheets, Google Sign-In, Google Identity Services, and other Google APIs that users may choose to connect with Doxmate through Google’s OAuth authorization process.

“Google User Data”

Google User Data means any information obtained from Google APIs after a user grants authorization, including calendar events, spreadsheet data, Google account profile information, email address, and other data explicitly permitted by the user through Google’s OAuth consent process.

“WhatsApp Services”

WhatsApp Services refer to integrations provided through the Meta WhatsApp Cloud API, enabling appointment booking, reminders, confirmations, cancellations, patient communication, and administrative messaging.

“AI Services”

AI Services refer to artificial intelligence and machine learning features used by Doxmate to automate administrative workflows such as appointment scheduling, patient communication, queue optimization, reminders, operational assistance, and workflow automation. AI Services do not provide medical diagnoses, treatment recommendations, or clinical decision-making.

“Data Controller”

“Data Controller” means the natural or legal person, healthcare organization, or other entity that determines the purposes and means of processing Personal Data. In most cases, the Healthcare Organization using Doxmate acts as the Data Controller for patient information.

“Data Processor”

“Data Processor” means an entity that processes Personal Data on behalf of the Data Controller. Doxmate generally acts as a Data Processor when processing patient information for healthcare organizations.

“Processing”

“Processing” means any operation performed on Personal Data, whether automated or manual, including collection, recording, organization, storage, retrieval, consultation, use, transmission, disclosure, updating, modification, deletion, restriction, or destruction.

“Third-Party Services”

Third-Party Services include external products, platforms, APIs, payment processors, cloud infrastructure providers, analytics services, messaging platforms, identity providers, and other technologies that integrate with or support Doxmate’s services.

“Google OAuth”

Google OAuth refers to Google’s secure authorization framework that enables users to grant Doxmate limited access to specific Google services, such as Google Calendar or Google Sheets, without sharing their passwords.

“Cookies”

Cookies are small text files and similar technologies placed on a user’s device to enable authentication, remember preferences, analyze usage, enhance security, and improve the functionality of the Platform.

“Applicable Laws”

Applicable Laws include all relevant privacy, healthcare, consumer protection, cybersecurity, and data protection laws and regulations, including but not limited to the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (GDPR), and other laws applicable to the jurisdictions in which Doxmate operates.

“Business Day”

A Business Day means any day other than a Saturday, Sunday, or public holiday observed in the jurisdiction where Brainox Tech conducts its principal business operations.

1. Scope

This Privacy Policy describes how Doxmate, an AI-powered healthcare operations platform developed and operated by Brainox Tech (“Doxmate”, “we”, “our”, or “us”), collects, uses, processes, stores, protects, and shares Personal Data when individuals and organizations use our products and services.

This Privacy Policy applies to all Doxmate products, services, websites, applications, APIs, and integrations, including but not limited to:

  • The Doxmate website (https://www.doxmate.in)

  • Web and mobile applications

  • Administrator and healthcare provider dashboards

  • Patient portals (where available)

  • Embedded signup and onboarding flows

  • Appointment Scheduling System

  • Electronic Medical Records (EMR)

  • Queue Management System

  • Patient Registration and Check-in

  • WhatsApp-based appointment automation through the Meta WhatsApp Cloud API

  • AI-powered administrative automation features

  • Google Workspace integrations, including Google Calendar, Google Sheets, and Google Sign-In

  • APIs, SDKs, webhooks, and developer integrations

  • Customer support channels

  • Billing and subscription management services

  • Any future products or services that reference or link to this Privacy Policy

This Privacy Policy applies to information collected from or about:

  • Healthcare organizations, including hospitals, clinics, medical practices, diagnostic centers, laboratories, pharmacies, and other healthcare providers

  • Doctors, physicians, consultants, nurses, receptionists, and other authorized healthcare staff

  • Practice administrators and organization owners

  • Patients whose information is processed by healthcare organizations using Doxmate

  • Individuals communicating with Doxmate through our website, customer support, WhatsApp, email, or other communication channels

  • Visitors browsing our websites and digital properties

  • Developers and business partners integrating with our APIs or services

Data Controller and Data Processor Roles

The role of Doxmate with respect to Personal Data depends on the nature of the information being processed.

Healthcare Organizations as Data Controllers

For patient information, medical records, appointment details, prescriptions, diagnoses, laboratory reports, queue information, and other healthcare-related data entered into the Platform, the healthcare organization using Doxmate generally acts as the Data Controller. The healthcare organization determines the purposes and means of processing such information and is responsible for obtaining any required patient consents and complying with applicable healthcare and privacy laws.

Doxmate as Data Processor

When processing patient or healthcare information on behalf of a healthcare organization, Doxmate acts as a Data Processor and processes such information only in accordance with the documented instructions of the applicable healthcare organization, applicable contractual agreements, and relevant legal obligations.

Doxmate as Data Controller

Doxmate acts as the Data Controller for information we collect directly for our own business operations, including but not limited to:

  • User account registration and authentication

  • Subscription and billing information

  • Customer support communications

  • Website analytics

  • Marketing communications (where permitted)

  • Platform security and fraud prevention

  • Compliance with legal and regulatory obligations

  • Service improvement and operational analytics

Google Services

When users voluntarily connect their Google Account, this Privacy Policy also applies to information obtained through Google APIs, including Google Calendar, Google Sheets, and Google Identity Services. Such information is accessed only after explicit user authorization and solely for providing the features requested by the user.

Doxmate’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Third-Party Services

Certain features of the Platform rely on trusted third-party providers, including cloud infrastructure providers, payment processors, messaging services, authentication providers, analytics platforms, and healthcare communication services. The collection and processing of information by those providers may also be governed by their respective privacy policies.

Geographic Scope

Doxmate provides services to healthcare organizations and users located in multiple jurisdictions. Personal Data may be processed, transferred, or stored in countries where Doxmate or its authorized service providers operate, subject to appropriate contractual, technical, and organizational safeguards and applicable legal requirements.

Exclusions

This Privacy Policy does not apply to:

  • Third-party websites, products, or services that are not owned or controlled by Doxmate, even if they are linked from our Platform.

  • Healthcare services, diagnoses, treatments, or medical advice provided directly by healthcare professionals using Doxmate.

  • Data processing activities conducted independently by healthcare organizations outside the Doxmate Platform.

  • Third-party applications or integrations unless expressly stated in this Privacy Policy.

Users should review the privacy policies of any third-party services they choose to access through or alongside the Platform.

Acceptance of this Privacy Policy

By accessing or using Doxmate, creating an account, connecting third-party services, integrating Google services, or otherwise interacting with the Platform, you acknowledge that you have read, understood, and agree to the collection, use, processing, storage, and disclosure of your information as described in this Privacy Policy.

If you do not agree with this Privacy Policy, you should discontinue use of the Platform and any associated services.

2. Information We Collect

Doxmate collects information necessary to provide, operate, maintain, secure, and improve our healthcare operations platform. The information we collect depends on how you interact with our Platform, the services you use, and the permissions you grant.

We collect information directly from users, healthcare organizations, connected third-party services, and automatically through our Platform.


A. Information You Provide

Account Information

When you create or manage a Doxmate account, we may collect:

  • Full name

  • Email address

  • Mobile phone number

  • Password (stored securely in encrypted or hashed form)

  • Profile photograph (optional)

  • Organization name

  • Job title or designation

  • User role and permissions

  • Account preferences


Healthcare Organization Information

When a hospital, clinic, or healthcare provider registers with Doxmate, we may collect:

  • Organization name

  • Registration details

  • Address

  • Contact information

  • Website

  • Tax identification numbers (where applicable)

  • GST information (if applicable)

  • Operating hours

  • Departments

  • Healthcare specialties

  • Doctor and practitioner information

  • Branch locations

  • Subscription details


Patient Information

Healthcare organizations using Doxmate may collect and manage patient information including:

  • Patient name

  • Mobile number

  • Email address

  • Date of birth

  • Gender

  • Address

  • Emergency contact information

  • Unique patient identifiers

  • Appointment history

  • Communication preferences

Patient information is collected and processed on behalf of the healthcare organization.


B. Appointment & Scheduling Information

To facilitate appointment management, we may process:

  • Appointment date and time

  • Doctor assignment

  • Department

  • Appointment status

  • Consultation type

  • Follow-up schedules

  • Appointment notes

  • Cancellation details

  • Rescheduling history

  • Reminder preferences

  • Booking source

  • Check-in status

This information enables scheduling, confirmations, reminders, rescheduling, and operational reporting.


C. Electronic Medical Records (EMR)

When healthcare organizations enable the EMR module, Doxmate may process medical information including:

  • Medical history

  • Clinical notes

  • Diagnoses

  • Symptoms

  • Treatment plans

  • Prescriptions

  • Laboratory reports

  • Imaging reports

  • Allergies

  • Vital signs

  • Immunization records

  • Medications

  • Surgical history

  • Family medical history

  • Uploaded medical documents

  • Clinical attachments

Healthcare organizations remain the Data Controllers for all patient medical information processed through the EMR module.


D. Queue Management Information

For organizations using Doxmate’s Queue Management System, we may process:

  • Digital queue tokens

  • Check-in time

  • Waiting time

  • Consultation status

  • Doctor availability

  • Queue priority

  • Queue position

  • Estimated consultation time

  • Service completion status

  • Walk-in registrations

This information is used solely to facilitate patient flow and operational efficiency.


E. Billing and Payment Information

To manage subscriptions and payments, we may collect:

  • Billing name

  • Billing address

  • GST information

  • Subscription plan

  • Invoice history

  • Payment status

  • Transaction identifiers

  • Payment gateway references

Payment card information is processed directly by PCI-DSS compliant payment processors. Doxmate does not store complete payment card details.


F. WhatsApp Cloud API Information

When healthcare organizations use WhatsApp integration, Doxmate may process:

  • WhatsApp phone numbers

  • Administrative message content

  • Appointment confirmations

  • Appointment reminders

  • Appointment cancellations

  • Appointment rescheduling requests

  • Message delivery status

  • Read receipts

  • Template usage

  • Conversation timestamps

We process WhatsApp communications solely to provide appointment automation and patient communication services.

We do not use WhatsApp message content for advertising or unrelated purposes.


G. Google Account and Google API Information

When users voluntarily connect their Google Account, Doxmate may access Google services only after obtaining explicit authorization through Google’s OAuth consent process.

Depending on the permissions granted, we may collect or access:

Google Sign-In

  • Name

  • Email address

  • Google Account identifier

  • Profile picture (if available)

  • Authentication information

This information is used solely for authentication, account creation, and user identification.

Google Calendar

With your permission, Doxmate may:

  • Create calendar events

  • Read calendar availability where necessary

  • Update appointment events

  • Delete cancelled appointments

  • Synchronize appointment schedules

Calendar information is used exclusively for appointment scheduling and synchronization.

Google Sheets

With your authorization, Doxmate may:

  • Create spreadsheets

  • Export appointment reports

  • Update reporting spreadsheets

  • Synchronize operational reports

Spreadsheet access is limited to providing reporting and data export features requested by the user.

Google data is never used for advertising or unrelated purposes.


H. AI Services

To provide AI-powered administrative assistance, Doxmate may process information necessary to:

  • Schedule appointments

  • Route patient requests

  • Generate reminders

  • Assist healthcare staff

  • Optimize queue management

  • Improve operational workflows

AI features are designed exclusively for administrative automation.

Doxmate AI does not provide medical diagnoses, treatment recommendations, or clinical decision-making.

Google Workspace data is not used to train generalized artificial intelligence or machine learning models.


I. Customer Support Information

When you contact us, we may collect:

  • Name

  • Contact information

  • Support requests

  • Chat transcripts

  • Email correspondence

  • Call recordings (where permitted)

  • Screenshots

  • Diagnostic information

  • Feedback

This information helps us investigate issues and improve customer support.


J. Information Collected Automatically

When you access our Platform, we automatically collect certain technical information, including:

  • IP address

  • Browser type

  • Device type

  • Operating system

  • Language preferences

  • Login timestamps

  • Session identifiers

  • Referring URLs

  • Device identifiers

  • Crash reports

  • Performance metrics

  • Network information

  • Geographic region (approximate)

This information is used to improve security, monitor performance, and maintain platform reliability.


K. Cookies and Similar Technologies

We use cookies, local storage, and similar technologies to:

  • Authenticate users

  • Maintain secure sessions

  • Remember preferences

  • Improve performance

  • Analyze usage patterns

  • Prevent fraud

  • Enhance security

Users may manage cookie preferences through their browser settings, although disabling certain cookies may affect Platform functionality.


L. Analytics and Usage Information

We collect usage information to understand how our Platform is used, including:

  • Feature usage

  • Navigation patterns

  • Session duration

  • Page views

  • Click events

  • API usage

  • Error reports

  • Performance diagnostics

Analytics information is generally aggregated and used to improve our products and services.


M. Information from Third-Party Services

We may receive information from trusted third-party services that users choose to integrate with Doxmate, including:

  • Google Workspace services

  • Meta WhatsApp Cloud API

  • Payment processors

  • Identity providers

  • Cloud infrastructure providers

  • Analytics providers

Information received from third-party services is processed only for the purposes authorized by the user or necessary to provide requested services.


N. Information We Do Not Intentionally Collect

Unless explicitly required by a healthcare organization for the EMR module, Doxmate does not intentionally collect:

  • Biometric information

  • Government-issued identity documents

  • Financial account credentials

  • Passwords for third-party services

  • Highly sensitive personal information unrelated to healthcare operations

Users and healthcare organizations should avoid uploading information that is unnecessary for the intended use of the Platform.


O. Data Minimization

We are committed to collecting only the information that is reasonably necessary to provide our services, comply with legal obligations, maintain platform security, and improve user experience.

We regularly review our data collection practices to ensure they remain appropriate, proportionate, and consistent with applicable privacy and healthcare regulations.

3. Google OAuth & Google Workspace APIs

Doxmate provides optional integrations with Google Workspace services to enhance appointment scheduling, reporting, and user authentication. These integrations are entirely optional and are activated only after a user explicitly authorizes access through Google’s secure OAuth 2.0 authorization process.

We access only the Google data necessary to provide the specific features requested by the user. Users may revoke access at any time through their Google Account settings or by disconnecting the integration within Doxmate.


Google Services We Support

Depending on the features enabled, Doxmate may integrate with:

  • Google Calendar

  • Google Sheets

  • Google Sign-In (Google Identity Services)

No Google Workspace service is connected or accessed without the user’s explicit consent.


Google Calendar Integration

When a healthcare provider or authorized user connects their Google Calendar, Doxmate may access Google Calendar solely to support appointment scheduling and synchronization.

With your authorization, Doxmate may:

  • Create appointment events

  • Update existing appointment events

  • Delete cancelled appointments

  • Synchronize appointment schedules

  • Read calendar availability to prevent scheduling conflicts (only when required)

Typical use cases include:

  • Automatically creating calendar events when patients book appointments

  • Updating calendar events when appointments are rescheduled

  • Removing events when appointments are cancelled

  • Helping prevent double-booking of healthcare providers

Calendar information is never accessed or processed for advertising, marketing, profiling, or any unrelated purpose.


Google Sheets Integration

Users may choose to connect Google Sheets for reporting and operational data export.

With your permission, Doxmate may:

  • Create spreadsheets

  • Export appointment records

  • Update operational reports

  • Generate scheduling reports

  • Synchronize selected business data with spreadsheets

Google Sheets access is used exclusively to provide reporting and export functionality requested by the user.


Google Sign-In

Users may choose to authenticate using Google Sign-In instead of creating a traditional username and password.

When you sign in using Google, Doxmate may receive:

  • Full name

  • Email address

  • Google Account unique identifier

  • Profile picture (if available)

This information is used only for:

  • User authentication

  • Account creation

  • Secure login

  • Account identification

  • Preventing duplicate accounts

We do not access Gmail messages, Google Drive files, Google Contacts, or any other Google services unless separately authorized by the user.


Permissions We Request

Depending on the features used, Doxmate may request the following Google permissions:

Google Calendar

  • Create calendar events

  • Modify calendar events

  • Delete appointment events

  • Read calendar availability where necessary for scheduling

Google Sheets

  • Create spreadsheets

  • Read and update spreadsheets used by Doxmate

  • Export appointment and operational reports

Google Identity

  • Basic profile information

  • Email address

  • Authentication information

Permissions requested are limited to those necessary for providing the functionality selected by the user.


How We Use Google User Data

Google user data is used solely to provide user-requested features, including:

  • Appointment synchronization

  • Calendar management

  • Report generation

  • Spreadsheet exports

  • Secure authentication

  • Account management

Google user data is not used for:

  • Advertising

  • Personalized marketing

  • User profiling

  • Selling data

  • Data brokerage

  • General analytics unrelated to requested functionality


AI and Google User Data

Doxmate uses artificial intelligence to assist with administrative healthcare workflows, such as appointment scheduling, reminders, queue management, and operational automation.

Google Workspace data obtained through Google APIs is never used to develop, improve, or train generalized artificial intelligence or machine learning models.

Any processing of Google data is limited strictly to providing the user-facing functionality requested by the authorized user.


Google API Services User Data Policy

Doxmate’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use Requirements.

Specifically:

  • We access only the minimum Google data necessary to provide requested features.

  • We do not sell Google user data.

  • We do not share Google user data with advertisers or data brokers.

  • We do not use Google user data for advertising or marketing purposes.

  • We do not use Google Workspace data to train generalized AI or machine learning models.

  • We do not transfer Google user data to third parties except as necessary to provide the requested service or where required by applicable law.


Storage and Security of Google Data

Google OAuth access tokens and refresh tokens are stored securely using industry-standard encryption and access controls.

Only authorized backend services may use these credentials to perform synchronization operations requested by the user.

We implement technical and organizational safeguards including:

  • TLS encryption during transmission

  • Encrypted storage

  • Role-based access controls

  • Secure authentication

  • Audit logging

  • Regular security monitoring

Google credentials are never shared with unauthorized parties.


Revoking Google Access

Users may disconnect Google services at any time.

Google permissions can be managed by visiting:

https://myaccount.google.com/permissions

Users may also disconnect Google integrations from within their Doxmate account settings.

Once access is revoked, Doxmate will no longer be able to access the associated Google services unless the user grants authorization again.


Changes to Google Integrations

If Doxmate introduces new Google integrations or requests additional Google permissions in the future, users will be informed and asked to provide authorization before any additional Google data is accessed.

Google Calendar

Doxmate offers an optional integration with Google Calendar to help healthcare organizations efficiently manage appointments and reduce scheduling conflicts. This integration is available only to authorized users who explicitly choose to connect their Google Account through Google’s secure OAuth 2.0 authorization process.

Purpose of the Integration

The Google Calendar integration enables Doxmate to synchronize appointment schedules between the Platform and a user’s Google Calendar, ensuring that appointments booked through Doxmate are accurately reflected in the user’s calendar.

This feature helps healthcare providers:

  • Automatically create calendar events for newly booked appointments.

  • Update calendar events when appointments are rescheduled.

  • Delete calendar events when appointments are cancelled.

  • Prevent scheduling conflicts and double-bookings.

  • Maintain an up-to-date schedule across Doxmate and Google Calendar.

Information We Access

With your explicit authorization, Doxmate may access only the Google Calendar information necessary to provide the requested functionality, including:

  • Calendar identifiers

  • Appointment event details created or managed by Doxmate

  • Event date and time

  • Event title and description

  • Event location (if applicable)

  • Event attendees (when added by the user)

  • Calendar availability, where required to prevent scheduling conflicts

We do not access or process unrelated calendar information beyond what is necessary to deliver the requested features.

How We Use Google Calendar Data

Google Calendar data is used solely to:

  • Synchronize appointments between Doxmate and Google Calendar.

  • Create new calendar events when appointments are booked.

  • Update existing events when appointments change.

  • Delete events for cancelled appointments.

  • Display appointment schedules to authorized users.

  • Detect scheduling conflicts when requested by the user.

Google Calendar data is never used for:

  • Advertising or personalized marketing.

  • User profiling.

  • Selling or licensing data.

  • Unrelated analytics.

  • Training generalized artificial intelligence or machine learning models.

User Control

The Google Calendar integration is entirely optional.

Users may:

  • Connect or disconnect their Google Calendar at any time.

  • Revoke Google Calendar permissions through their Google Account settings.

  • Disable synchronization from within Doxmate.

  • Delete synchronized calendar events manually if desired.

Google permissions can be managed at:

https://myaccount.google.com/permissions

Once access is revoked, Doxmate will no longer be able to create, update, read, or delete calendar events until authorization is granted again.

Data Security

Google Calendar data and OAuth credentials are protected using industry-standard security measures, including:

  • Secure OAuth 2.0 authentication.

  • Encrypted transmission using TLS.

  • Encrypted storage of OAuth tokens.

  • Role-based access controls.

  • Secure backend processing.

  • Audit logging and monitoring.

  • Restricted access to authorized systems and personnel.

Doxmate does not store your Google Account password at any time.

Compliance with Google’s Policies

Doxmate’s access to Google Calendar is limited strictly to providing the functionality requested by the user.

Our use and transfer of information received from Google Calendar APIs complies with the Google API Services User Data Policy, including the Limited Use Requirements.

Specifically:

  • We access only the minimum calendar information necessary to provide appointment synchronization.

  • We do not sell Google Calendar data.

  • We do not share Google Calendar data with advertisers or data brokers.

  • We do not use Google Calendar data for advertising or marketing purposes.

  • We do not use Google Calendar data to develop, improve, or train generalized artificial intelligence or machine learning models.

  • We do not transfer Google Calendar data to third parties except where necessary to provide the requested service or as required by applicable law.

Google Sheets

Doxmate offers an optional integration with Google Sheets to enable healthcare organizations to export, synchronize, and manage operational data for reporting, analytics, and administrative workflows. This integration is available only to authorized users who explicitly connect their Google Account through Google’s secure OAuth 2.0 authorization process.

Purpose of the Integration

The Google Sheets integration allows Doxmate to securely create and update spreadsheets containing operational information generated within the Platform.

This feature helps healthcare organizations:

  • Export appointment records.

  • Generate daily, weekly, and monthly reports.

  • Maintain administrative logs.

  • Create operational dashboards.

  • Share authorized reports with clinic administrators.

  • Backup selected operational data to Google Sheets.

  • Automate reporting workflows.

Google Sheets integration is intended solely for administrative and operational purposes and is not required to use Doxmate’s core services.

Information We Access

With your explicit authorization, Doxmate may access only the Google Sheets information necessary to provide the requested functionality, including:

  • Spreadsheet identifiers.

  • Worksheet names.

  • Spreadsheet metadata.

  • Spreadsheet content created or managed by Doxmate.

  • Cell values required for synchronization.

  • Spreadsheet structure required for report generation.

Doxmate only accesses spreadsheets that are created, selected, or explicitly authorized by the user for use with the Platform.

How We Use Google Sheets Data

Google Sheets data is used solely to:

  • Create spreadsheets requested by authorized users.

  • Export appointment records.

  • Generate operational reports.

  • Update spreadsheets when appointment information changes.

  • Synchronize administrative data.

  • Produce business reports and analytics requested by the healthcare organization.

Google Sheets data is not used for:

  • Advertising or personalized marketing.

  • User profiling.

  • Selling or licensing data.

  • Data brokerage.

  • Unrelated analytics.

  • Training generalized artificial intelligence or machine learning models.

User Control

The Google Sheets integration is completely optional.

Users may:

  • Connect or disconnect Google Sheets at any time.

  • Select which spreadsheets are used with Doxmate.

  • Stop synchronization whenever desired.

  • Revoke Google Sheets permissions through their Google Account settings.

Google permissions can be managed at:

https://myaccount.google.com/permissions

After access is revoked, Doxmate will no longer be able to create, read, update, or synchronize spreadsheets until authorization is granted again.

Data Security

Google Sheets data and OAuth credentials are protected using industry-standard security measures, including:

  • Secure OAuth 2.0 authentication.

  • TLS encryption during data transmission.

  • Encrypted storage of OAuth access and refresh tokens.

  • Role-based access controls.

  • Secure backend processing.

  • Audit logging.

  • Continuous security monitoring.

  • Restricted access to authorized systems and personnel.

Doxmate never stores your Google Account password.

Compliance with Google’s Policies

Doxmate’s access to Google Sheets is limited strictly to providing the functionality requested by the user.

Our use and transfer of information received from Google Sheets APIs complies with the Google API Services User Data Policy, including the Limited Use Requirements.

Specifically:

  • We access only the minimum spreadsheet information necessary to provide reporting and synchronization features.

  • We do not sell Google Sheets data.

  • We do not share Google Sheets data with advertisers, marketing platforms, or data brokers.

  • We do not use Google Sheets data for advertising or personalized marketing.

  • We do not use Google Sheets data to develop, improve, or train generalized artificial intelligence or machine learning models.

  • We do not transfer Google Sheets data to third parties except where necessary to provide the requested services, comply with applicable laws, or at the explicit direction of the authorized user.

Google Sign-In

Doxmate offers Google Sign-In as an optional authentication method, allowing users to securely access their accounts using their Google Account without creating a separate password. Google Sign-In is provided through Google Identity Services and is available only after the user explicitly authorizes the authentication request.

Purpose of Google Sign-In

Google Sign-In simplifies account creation and authentication while enhancing account security. It enables users to:

  • Create a Doxmate account using their Google Account.

  • Sign in securely without managing an additional password.

  • Recover account access more easily.

  • Associate their Google Account with existing Doxmate services.

  • Enable seamless access to other authorized Google Workspace integrations within Doxmate.

Using Google Sign-In is entirely optional. Users may instead register using an email address and password, where available.

Information We Receive

When you choose to sign in with Google, Doxmate may receive the following information from your Google Account, subject to the permissions you grant:

  • Full name

  • Email address

  • Google Account unique identifier (User ID)

  • Profile picture (if available)

  • Email verification status

  • Authentication tokens necessary to complete the login process

We only request the minimum information required to authenticate your identity and manage your Doxmate account.

How We Use Google Sign-In Information

Information obtained through Google Sign-In is used solely to:

  • Authenticate your identity.

  • Create your Doxmate account (if you are a new user).

  • Link your Google Account to your existing Doxmate account.

  • Prevent duplicate accounts.

  • Improve account security.

  • Maintain secure login sessions.

  • Provide customer support when necessary.

Your Google account information is not used for:

  • Advertising.

  • Personalized marketing.

  • User profiling.

  • Selling personal information.

  • Data brokerage.

  • Training generalized artificial intelligence or machine learning models.

Data We Do Not Access

Google Sign-In does not provide Doxmate with access to your:

  • Gmail messages

  • Google Drive files

  • Google Photos

  • Google Contacts

  • Google Meet data

  • Google Docs

  • Google Calendar

  • Google Sheets

  • Other Google Workspace services

Access to any additional Google service requires your separate and explicit authorization through Google’s OAuth consent process.

User Control

Users remain in control of their Google Account and may:

  • Choose whether to use Google Sign-In.

  • Disconnect their Google Account from Doxmate.

  • Revoke Doxmate’s access through their Google Account settings.

  • Switch to another supported authentication method where available.

Google permissions may be managed at:

https://myaccount.google.com/permissions

Once access is revoked, Google Sign-In will no longer function until authorization is granted again.

Security

We protect Google Sign-In information using industry-standard security practices, including:

  • Google OAuth 2.0 authentication.

  • TLS encryption during data transmission.

  • Secure storage of authentication tokens.

  • Role-based access controls.

  • Session management and authentication safeguards.

  • Audit logging and security monitoring.

Doxmate never receives or stores your Google Account password.

Compliance with Google’s Policies

Doxmate uses Google Sign-In solely for secure authentication and account management.

Our use and transfer of information received from Google Identity Services complies with the Google API Services User Data Policy, including the Limited Use Requirements.

Specifically:

  • We request only the minimum user information necessary for authentication.

  • We do not sell Google account information.

  • We do not use Google account information for advertising or marketing purposes.

  • We do not share Google account information with advertisers or data brokers.

  • We do not use Google account information to develop, improve, or train generalized artificial intelligence or machine learning models.

  • We do not transfer Google account information to third parties except where necessary to provide the requested services, comply with applicable laws, or at the explicit direction of the user.

Google API Services User Data Policy (Limited Use)

Doxmate is committed to protecting the privacy, security, and confidentiality of information accessed through Google APIs. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use Requirements.

Limited Use Commitment

Information obtained through Google APIs is used solely to provide, maintain, and improve the user-facing features explicitly requested by the authorized user.

We access only the minimum Google user data necessary to deliver the requested functionality and process such information only in accordance with the permissions granted by the user.

Permitted Uses of Google User Data

Depending on the Google services connected by the user, Doxmate may use Google user data to:

  • Authenticate users through Google Sign-In.

  • Create, update, and delete Google Calendar events for appointment scheduling.

  • Synchronize appointment information with Google Calendar.

  • Export operational reports and appointment data to Google Sheets.

  • Maintain secure user sessions.

  • Troubleshoot technical issues.

  • Protect the security and integrity of the Platform.

  • Comply with applicable legal obligations.

Google user data is processed only for the specific features requested and authorized by the user.

Prohibited Uses

Doxmate does not use Google user data for any of the following purposes:

  • Advertising or targeted advertising.

  • Personalized marketing.

  • Building advertising profiles.

  • Selling, renting, or licensing Google user data.

  • Data brokerage.

  • Creditworthiness evaluation.

  • Employment screening.

  • Insurance underwriting.

  • Profiling unrelated to the requested functionality.

  • Any purpose prohibited by Google’s policies or applicable law.

Artificial Intelligence and Machine Learning

Doxmate provides AI-powered administrative tools to assist healthcare organizations with appointment scheduling, patient communication, workflow automation, queue management, and operational efficiency.

Google Workspace data accessed through Google APIs is never used to develop, improve, or train generalized artificial intelligence or machine learning models.

Any processing of Google user data by AI is strictly limited to providing the specific user-facing functionality requested by the authorized user, such as creating calendar events, generating appointment reminders, exporting reports, or automating administrative workflows.

Data Sharing

We do not sell or disclose Google user data to third parties except in the following limited circumstances:

  • To trusted service providers acting on our behalf under appropriate confidentiality and data protection obligations, where necessary to provide the requested services.

  • When required to comply with applicable laws, regulations, legal processes, or lawful requests from public authorities.

  • To protect the rights, security, safety, or property of Doxmate, our users, healthcare organizations, or others.

  • With the explicit direction or consent of the authorized user.

Any third-party service provider receiving Google user data is required to maintain appropriate security measures and may process such data only for the purposes authorized by Doxmate and the user.

Data Minimization

Doxmate follows the principle of data minimization.

We request and process only those Google API permissions that are reasonably necessary to provide the functionality selected by the user.

If a feature does not require access to a particular Google service, Doxmate will not request the corresponding permission.

Security

Google user data is protected using industry-standard administrative, technical, and organizational safeguards, including:

  • OAuth 2.0 authorization.

  • TLS encryption during transmission.

  • Encrypted storage of OAuth credentials and tokens.

  • Role-based access controls.

  • Principle of least privilege.

  • Secure backend processing.

  • Audit logging.

  • Continuous security monitoring.

  • Periodic security reviews.

Access to Google user data is restricted to authorized systems and personnel who require such access to provide the requested services.

User Control

Users remain in control of their Google Account and may:

  • Grant or deny Google API permissions.

  • Disconnect Google services at any time.

  • Revoke Doxmate’s access through their Google Account settings.

  • Delete or modify synchronized data where supported.

Google permissions can be managed at:

https://myaccount.google.com/permissions

Revoking access will prevent Doxmate from accessing the associated Google services until authorization is granted again.

Data Retention

Google user data is retained only for as long as necessary to provide the requested functionality, comply with applicable legal obligations, resolve disputes, enforce agreements, or meet legitimate business requirements.

OAuth access tokens and refresh tokens are securely stored only while the integration remains active and are deleted or invalidated when the user disconnects the integration or revokes authorization, subject to reasonable backup and security retention practices.

Policy Compliance

Doxmate regularly reviews its products, services, and internal processes to ensure ongoing compliance with:

  • Google API Services User Data Policy

  • Google OAuth 2.0 requirements

  • Google Identity Services policies

  • Applicable privacy and data protection laws

  • Internal security and privacy standards

If our use of Google APIs changes in a manner that requires additional permissions or user consent, we will update this Privacy Policy and request authorization before accessing any additional Google user data.

Electronic Medical Records (EMR)

Doxmate provides an optional Electronic Medical Records (EMR) module that enables healthcare organizations to securely create, manage, store, retrieve, and maintain digital patient medical records. The EMR module is intended exclusively for use by authorized healthcare professionals and healthcare organizations in connection with the delivery of healthcare services.

Purpose of the EMR Module

The EMR module is designed to assist healthcare organizations in maintaining accurate, secure, and accessible patient medical records while improving clinical workflows, continuity of care, and operational efficiency.

Depending on the services subscribed to by a healthcare organization, the EMR module may be used to:

  • Register and manage patient records.

  • Maintain patient demographics.

  • Record medical history.

  • Document consultations and clinical notes.

  • Record diagnoses and treatment plans.

  • Issue prescriptions.

  • Manage laboratory and diagnostic reports.

  • Store medical documents and attachments.

  • Track allergies and immunizations.

  • Record vital signs.

  • Maintain visit history.

  • Support follow-up consultations.

  • Generate medical summaries and reports.

Information Processed Through the EMR Module

Healthcare organizations using the EMR module may choose to store and process information including:

Patient Identification Information

  • Full name

  • Date of birth

  • Gender

  • Contact information

  • Address

  • Emergency contacts

  • Patient identification numbers

  • Insurance information (where applicable)

Clinical Information

  • Medical history

  • Consultation records

  • Clinical notes

  • Symptoms

  • Diagnoses

  • Treatment plans

  • Prescriptions

  • Medications

  • Allergies

  • Immunization records

  • Vital signs

  • Laboratory reports

  • Radiology and imaging reports

  • Surgical history

  • Family medical history

  • Uploaded medical documents

  • Clinical attachments

Administrative Information

  • Appointment history

  • Visit history

  • Queue information

  • Doctor assignments

  • Billing references

  • Referral information

  • Discharge summaries (where applicable)

The exact information processed depends on the features enabled by the healthcare organization and the information entered by authorized users.

Data Controller and Data Processor Roles

Healthcare organizations remain the Data Controllers of all patient medical information stored within the EMR module.

Doxmate acts as a Data Processor, processing patient medical information solely on behalf of and under the documented instructions of the applicable healthcare organization.

Healthcare organizations are responsible for:

  • Determining the purposes of processing patient information.

  • Obtaining any required patient consent.

  • Ensuring the accuracy of medical records.

  • Managing access permissions for authorized personnel.

  • Complying with applicable healthcare, privacy, and data protection laws.

Access to Medical Records

Access to EMR information is restricted to authorized users designated by the healthcare organization.

Healthcare organizations may configure role-based access controls to limit access according to professional responsibilities, including:

  • Physicians

  • Specialists

  • Nurses

  • Reception staff

  • Laboratory personnel

  • Pharmacists

  • Administrators

  • Authorized support personnel

Users are responsible for maintaining the confidentiality of their login credentials and ensuring that unauthorized individuals cannot access patient information.

Security of Medical Information

Doxmate implements industry-standard administrative, technical, and organizational safeguards to protect medical information, including:

  • TLS encryption during transmission.

  • Encryption of stored data where applicable.

  • Secure authentication mechanisms.

  • Role-based access controls.

  • Multi-factor authentication for privileged accounts (where enabled).

  • Audit logging of user activities.

  • Continuous security monitoring.

  • Secure cloud infrastructure.

  • Routine backups and disaster recovery procedures.

  • Vulnerability assessments and security testing.

Access to patient medical records is limited to authorized personnel who require access to perform their professional responsibilities.

Use of Medical Information

Medical information processed through the EMR module is used solely to:

  • Provide healthcare services.

  • Maintain patient medical records.

  • Support clinical documentation.

  • Manage appointments and follow-up care.

  • Facilitate healthcare operations.

  • Generate authorized clinical reports.

  • Meet regulatory and legal obligations.

  • Improve healthcare delivery requested by the healthcare organization.

Doxmate does not use patient medical records for advertising, marketing, or unrelated commercial purposes.

Artificial Intelligence and EMR Data

Where AI-powered administrative features are enabled, Doxmate may assist healthcare organizations with administrative tasks such as documentation support, appointment coordination, workflow automation, and operational efficiency.

Unless explicitly requested and authorized by the healthcare organization, Doxmate’s AI features do not make clinical decisions, diagnose medical conditions, prescribe treatments, or replace the professional judgment of qualified healthcare providers.

Patient medical records are not used to develop, improve, or train generalized artificial intelligence or machine learning models without the explicit consent of the healthcare organization and where required, the applicable legal basis.

Data Sharing

Doxmate does not sell or disclose patient medical records.

Medical information may be shared only:

  • With authorized users within the healthcare organization.

  • With third-party service providers acting on behalf of Doxmate under strict confidentiality and security obligations, where necessary to provide the services.

  • When required by applicable law, regulation, court order, or lawful government request.

  • With the explicit direction or authorization of the healthcare organization or the patient, where applicable.

Data Retention

Medical records are retained according to the retention policies established by the healthcare organization and applicable legal or regulatory requirements.

Upon termination of services, healthcare organizations may request export or deletion of their data, subject to applicable legal obligations, contractual commitments, backup retention schedules, and regulatory record-keeping requirements.

Patient Rights

Depending on applicable law and the policies of the healthcare organization, patients may have rights to:

  • Access their medical information.

  • Request correction of inaccurate information.

  • Request deletion where legally permitted.

  • Obtain copies of their records.

  • Restrict certain processing activities.

  • Withdraw consent where processing is based on consent.

Requests relating to patient medical records should generally be directed to the healthcare organization acting as the Data Controller. Where appropriate, Doxmate will assist healthcare organizations in fulfilling such requests in accordance with applicable law and contractual obligations.

Compliance

Doxmate is committed to processing medical information in accordance with applicable healthcare and privacy laws, industry standards, and contractual obligations.

We continuously review and improve our privacy, security, and compliance practices to help healthcare organizations protect patient information while delivering secure, reliable, and efficient digital healthcare services.

Queue Management System

Doxmate provides an optional Queue Management System (QMS) that enables healthcare organizations to efficiently manage patient flow, reduce waiting times, and improve the overall patient experience. The Queue Management System is designed for use by authorized healthcare organizations and their staff to coordinate patient check-ins, consultations, and service delivery.

Purpose of the Queue Management System

The Queue Management System helps healthcare organizations organize patient visits by digitally managing queues and tracking patient progress throughout their visit.

Depending on the services enabled by the healthcare organization, the Queue Management System may be used to:

  • Generate digital queue tokens.

  • Register walk-in patients.

  • Manage scheduled and unscheduled appointments.

  • Monitor patient waiting times.

  • Assign patients to doctors, departments, or service counters.

  • Prioritize emergency or high-priority cases.

  • Display live queue status.

  • Notify patients of their queue position.

  • Track consultation progress.

  • Generate operational reports and queue analytics.

The Queue Management System is intended solely to improve healthcare operations and administrative efficiency.


Information Processed Through the Queue Management System

To provide queue management services, Doxmate may process the following information:

Patient Information

  • Patient name

  • Patient identification number (if assigned)

  • Contact number

  • Appointment reference

  • Department

  • Assigned healthcare provider

Queue Information

  • Queue token number

  • Queue position

  • Queue category

  • Priority level

  • Check-in time

  • Waiting time

  • Estimated consultation time

  • Consultation start time

  • Consultation completion time

  • Service status

  • Queue history

Operational Information

  • Department assignment

  • Doctor availability

  • Counter or room allocation

  • Staff assignments

  • Service completion status

  • Queue performance metrics

  • Daily operational statistics

The exact information processed depends on the configuration selected by the healthcare organization.


How Queue Information Is Used

Queue information is processed solely for healthcare operations and administrative purposes, including:

  • Managing patient flow.

  • Reducing waiting times.

  • Assigning patients to healthcare providers.

  • Tracking consultation progress.

  • Providing real-time queue updates.

  • Displaying queue status on digital displays or patient portals.

  • Sending queue-related notifications.

  • Generating operational reports.

  • Improving workflow efficiency.

  • Supporting appointment scheduling and follow-up services.

Queue information is not used for advertising, profiling, or unrelated commercial purposes.


Notifications and Communication

Where enabled by the healthcare organization, Doxmate may send queue-related notifications through supported communication channels, including:

  • WhatsApp

  • SMS

  • Email

  • Push notifications

  • In-app notifications

These notifications may include:

  • Queue token confirmation

  • Check-in confirmation

  • Queue position updates

  • Estimated waiting time

  • Consultation readiness

  • Service completion notifications

These communications are operational in nature and are intended solely to facilitate healthcare service delivery.


Data Controller and Data Processor Roles

Healthcare organizations remain the Data Controllers of all queue-related information processed through the Queue Management System.

Doxmate acts as a Data Processor, processing queue information only on behalf of and under the documented instructions of the applicable healthcare organization.

Healthcare organizations are responsible for:

  • Determining how queue information is collected and used.

  • Managing staff access permissions.

  • Obtaining any required patient consents.

  • Ensuring compliance with applicable healthcare and privacy laws.


Access Controls

Queue information is accessible only to authorized users designated by the healthcare organization.

Role-based permissions may be configured for users such as:

  • Reception staff

  • Front desk personnel

  • Doctors

  • Nurses

  • Department coordinators

  • Administrators

  • Queue managers

Access is granted based on operational responsibilities and the principle of least privilege.


Security

Queue-related information is protected using industry-standard administrative, technical, and organizational safeguards, including:

  • Secure user authentication.

  • TLS encryption during data transmission.

  • Encrypted data storage where applicable.

  • Role-based access controls.

  • Audit logging.

  • Session management.

  • Infrastructure monitoring.

  • Routine backups.

  • Security testing and vulnerability assessments.

Only authorized systems and personnel may access queue information.


Queue Analytics

Doxmate may generate aggregated and anonymized operational analytics to assist healthcare organizations in improving service efficiency.

Examples include:

  • Average waiting times.

  • Daily patient volume.

  • Consultation duration.

  • Department performance.

  • Queue utilization.

  • Appointment adherence.

  • Peak operating hours.

Where possible, analytics are aggregated or anonymized and are not intended to identify individual patients.


Integration with Other Doxmate Services

The Queue Management System may integrate with other Doxmate modules, including:

  • Appointment Scheduling

  • Electronic Medical Records (EMR)

  • WhatsApp Cloud API

  • Billing and Invoicing

  • Doctor Management

  • Patient Registration

  • Google Calendar (where enabled)

  • Reporting and Analytics

Such integrations are performed solely to provide a seamless healthcare workflow and improve operational efficiency.


Data Retention

Queue records are retained according to the retention policies established by the healthcare organization and applicable legal requirements.

Historical queue information may be retained for reporting, auditing, operational analysis, and regulatory compliance, after which it may be securely deleted or anonymized in accordance with applicable retention policies.


Compliance

Doxmate processes queue-related information in accordance with applicable privacy and data protection laws and implements reasonable administrative, technical, and organizational safeguards to protect such information.

We continuously review and improve our Queue Management System to ensure secure, reliable, and efficient operation while respecting the privacy of patients, healthcare professionals, and healthcare organizations.

Appointment Management

Doxmate provides an integrated Appointment Management System that enables healthcare organizations to efficiently schedule, manage, modify, and track patient appointments across multiple departments, practitioners, and locations. The Appointment Management System is designed to streamline healthcare operations, improve patient experience, and reduce administrative workload through automation and intelligent scheduling.

Purpose of the Appointment Management System

The Appointment Management System helps healthcare organizations efficiently manage the complete appointment lifecycle, from booking to consultation completion and follow-up.

Depending on the services enabled by the healthcare organization, the system may be used to:

  • Schedule new appointments.

  • Manage follow-up appointments.

  • Reschedule appointments.

  • Cancel appointments.

  • Assign appointments to healthcare providers.

  • Manage doctor availability.

  • Prevent scheduling conflicts.

  • Send appointment confirmations and reminders.

  • Track patient attendance.

  • Manage walk-in patients.

  • Integrate appointments with Queue Management.

  • Synchronize appointments with Google Calendar (where authorized).

  • Generate appointment reports and analytics.

The Appointment Management System is intended solely to facilitate healthcare administration and does not replace the professional judgment of healthcare providers.


Information Processed

To provide appointment management services, Doxmate may process information including:

Patient Information

  • Patient name

  • Contact number

  • Email address (where provided)

  • Patient identification number

  • Date of birth (where applicable)

  • Gender (where applicable)

Appointment Information

  • Appointment date and time

  • Appointment status

  • Appointment type

  • Consultation mode (in-person or virtual, where supported)

  • Department

  • Assigned doctor or healthcare provider

  • Clinic or branch location

  • Follow-up information

  • Referral information

  • Appointment notes entered by authorized users

  • Booking source (website, WhatsApp, phone, reception, API, etc.)

Operational Information

  • Appointment creation timestamp

  • Appointment modification history

  • Cancellation details

  • Rescheduling history

  • Check-in time

  • Consultation status

  • Queue status

  • Attendance records

  • Reminder delivery status

The exact information processed depends on the configuration selected by the healthcare organization.


Appointment Booking

Appointments may be booked through one or more supported channels, including:

  • Reception or front desk staff.

  • Doxmate Web Dashboard.

  • Patient Portal (where available).

  • Mobile applications.

  • WhatsApp Cloud API.

  • Website booking widgets.

  • APIs and third-party integrations.

  • AI-powered appointment assistants.

Each appointment is recorded and managed according to the configuration established by the healthcare organization.


Appointment Automation

To improve operational efficiency, Doxmate may automate administrative appointment workflows, including:

  • Appointment confirmation messages.

  • Appointment reminders.

  • Follow-up reminders.

  • Appointment rescheduling.

  • Appointment cancellation notifications.

  • Waiting list management.

  • Queue synchronization.

  • Calendar synchronization.

  • Missed appointment notifications.

These automations are intended solely to assist healthcare organizations in managing appointments and improving patient communication.


Notifications and Patient Communication

Where enabled by the healthcare organization, Doxmate may send appointment-related communications through supported channels, including:

  • WhatsApp

  • SMS

  • Email

  • Push notifications

  • In-app notifications

Communications may include:

  • Appointment confirmation.

  • Appointment reminders.

  • Rescheduling notifications.

  • Cancellation confirmations.

  • Check-in instructions.

  • Queue updates.

  • Follow-up reminders.

  • Administrative announcements related to scheduled appointments.

These communications are operational in nature and are not intended for promotional or marketing purposes unless the recipient has separately provided consent where required by applicable law.


Google Calendar Synchronization

Authorized users may choose to connect their Google Calendar to synchronize appointments.

When this feature is enabled, Doxmate may:

  • Create calendar events for new appointments.

  • Update calendar events when appointments are modified.

  • Delete calendar events when appointments are cancelled.

  • Read limited calendar availability where necessary to help prevent scheduling conflicts.

Google Calendar integration is optional and is available only after explicit authorization through Google’s OAuth consent process.


AI-Assisted Scheduling

Doxmate may use artificial intelligence to assist with administrative scheduling activities, including:

  • Appointment booking assistance.

  • Appointment routing.

  • Intelligent scheduling suggestions.

  • Reminder generation.

  • Workflow automation.

  • Queue optimization.

  • Administrative communication.

AI-generated recommendations are intended solely to support administrative operations.

Doxmate does not provide medical advice, clinical diagnoses, treatment recommendations, or emergency healthcare services.


Data Controller and Data Processor Roles

Healthcare organizations remain the Data Controllers of appointment information processed through the Appointment Management System.

Doxmate acts as a Data Processor, processing appointment information only on behalf of and under the documented instructions of the applicable healthcare organization.

Healthcare organizations are responsible for:

  • Determining appointment scheduling policies.

  • Managing user permissions.

  • Obtaining any required patient consent.

  • Ensuring compliance with applicable healthcare and privacy laws.

  • Maintaining the accuracy of appointment information.


Data Security

Appointment information is protected using industry-standard administrative, technical, and organizational safeguards, including:

  • Secure authentication.

  • TLS encryption during data transmission.

  • Encryption of stored data where applicable.

  • Role-based access controls.

  • Audit logging.

  • Session management.

  • Secure cloud infrastructure.

  • Routine backups.

  • Continuous security monitoring.

  • Regular vulnerability assessments.

Access to appointment information is restricted to authorized users with a legitimate business or clinical need.


Data Sharing

Appointment information is not sold or disclosed to third parties for advertising or marketing purposes.

Appointment information may be shared only:

  • With authorized personnel within the healthcare organization.

  • With integrated third-party services explicitly enabled by the healthcare organization (such as Google Calendar or WhatsApp Cloud API).

  • With trusted service providers acting on Doxmate’s behalf under appropriate contractual confidentiality and security obligations.

  • When required by applicable law, legal process, or regulatory authority.

  • With the explicit authorization or direction of the healthcare organization or the patient, where applicable.


Data Retention

Appointment records are retained according to the retention policies established by the healthcare organization and applicable legal or regulatory requirements.

Historical appointment information may be retained for reporting, auditing, operational analysis, billing, dispute resolution, and legal compliance, after which it may be securely deleted or anonymized in accordance with applicable retention policies.


Compliance

Doxmate processes appointment information in accordance with applicable privacy, healthcare, and data protection laws. We regularly review and enhance our administrative, technical, and organizational safeguards to ensure that appointment information remains secure, confidential, and available only to authorized users.

The Appointment Management System is designed to support healthcare operations while protecting the privacy and confidentiality of patients, healthcare professionals, and healthcare organizations.

AI Features

Doxmate incorporates Artificial Intelligence (“AI”) technologies to assist healthcare organizations in automating administrative workflows, improving operational efficiency, and enhancing the user experience. Our AI features are designed to support healthcare professionals and administrative staff and are not intended to replace professional medical judgment, diagnosis, or treatment decisions.

AI functionality is available only as part of the services enabled by the healthcare organization and is used in accordance with this Privacy Policy and applicable data protection laws.


Purpose of AI Features

Doxmate’s AI capabilities are intended to assist healthcare organizations with administrative and operational tasks, including:

  • Appointment scheduling and rescheduling

  • Appointment confirmations and reminders

  • Queue management and patient flow optimization

  • WhatsApp-based patient communication

  • Patient registration assistance

  • Administrative workflow automation

  • Smart form completion and data entry assistance

  • Medical documentation assistance (where enabled)

  • Report generation and summarization

  • Operational analytics and insights

  • Customer support assistance

  • Knowledge base search and information retrieval

  • Notification and communication automation

The specific AI features available depend on the subscription plan and modules enabled by the healthcare organization.


Information Processed by AI

Depending on the enabled features and user interactions, AI may process information including:

Administrative Information

  • Appointment details

  • Queue information

  • Department information

  • Doctor availability

  • Clinic schedules

  • Communication preferences

  • User requests

  • Operational workflows

Patient Information

Where authorized by the healthcare organization, AI may process:

  • Patient name

  • Appointment history

  • Registration information

  • Queue status

  • Communication history

  • Follow-up schedules

EMR Information (When Enabled)

If the EMR module is enabled and the healthcare organization authorizes AI-assisted features, AI may process selected medical information solely to support administrative or documentation-related tasks, such as:

  • Clinical notes

  • Visit summaries

  • Diagnoses

  • Prescriptions

  • Laboratory reports

  • Medical history

  • Treatment plans

AI processes only the information necessary to provide the requested functionality.


How AI Is Used

AI may assist with:

  • Scheduling appointments.

  • Identifying available appointment slots.

  • Managing waiting lists.

  • Generating appointment reminders.

  • Answering administrative questions.

  • Assisting patient registration.

  • Organizing healthcare workflows.

  • Preparing draft documentation for review.

  • Generating operational reports.

  • Improving workflow efficiency.

  • Assisting authorized users with routine administrative tasks.

All AI-generated outputs should be reviewed by authorized users before being relied upon for operational or clinical purposes.


AI Does Not Provide Medical Advice

Doxmate’s AI features are not designed or intended to:

  • Diagnose medical conditions.

  • Prescribe medications.

  • Recommend treatments.

  • Replace licensed healthcare professionals.

  • Make independent clinical decisions.

  • Provide emergency medical advice.

  • Interpret laboratory results without professional review.

  • Replace physician judgment.

Healthcare providers remain solely responsible for all clinical decisions, diagnoses, prescriptions, treatment plans, and patient care.

Patients should not rely on AI-generated content as medical advice and should always consult qualified healthcare professionals regarding medical concerns.


Human Oversight

AI-generated content is intended to assist—not replace—human decision-making.

Healthcare organizations and their authorized personnel are responsible for reviewing, validating, and approving AI-generated outputs before they are used in patient care, documentation, communications, or operational workflows.

Where applicable, users may modify, reject, or regenerate AI-generated content.


AI Models and Third-Party Providers

Certain AI features may utilize models or services provided by trusted third-party AI providers acting on Doxmate’s behalf.

Where third-party AI services are used:

  • Data is shared only to the extent necessary to provide the requested AI functionality.

  • Appropriate contractual, technical, and organizational safeguards are implemented.

  • Third-party providers are required to protect the confidentiality and security of processed information.

  • Data is processed in accordance with applicable privacy laws and contractual obligations.


Use of Healthcare Data

Healthcare information processed through AI features is used solely for providing the requested functionality to the healthcare organization.

Unless expressly authorized by the healthcare organization and permitted by applicable law:

  • Patient medical records are not used for advertising.

  • Patient information is not sold or licensed.

  • Patient information is not used to build marketing profiles.

  • Patient information is not disclosed except as described in this Privacy Policy.

Healthcare organizations remain the Data Controllers of patient information processed through AI-enabled features.


Google Workspace Data and AI

Where users connect Google services such as Google Calendar, Google Sheets, or Google Sign-In, Doxmate may process Google data only to provide the authorized functionality.

Google Workspace data obtained through Google APIs is never used to develop, improve, or train generalized artificial intelligence or machine learning models.

Our use of Google API data complies with the Google API Services User Data Policy, including the Limited Use Requirements.


AI Security

Information processed through AI features is protected using industry-standard administrative, technical, and organizational safeguards, including:

  • Secure authentication

  • TLS encryption during transmission

  • Encrypted storage where applicable

  • Role-based access controls

  • Audit logging

  • Secure cloud infrastructure

  • Continuous monitoring

  • Access restrictions based on the principle of least privilege

Access to AI-processed information is limited to authorized systems and personnel with a legitimate operational need.


Data Retention

Information processed by AI features is retained only for as long as necessary to:

  • Provide the requested services.

  • Improve operational performance.

  • Maintain system security.

  • Comply with applicable legal and regulatory obligations.

  • Resolve disputes and enforce agreements.

Retention periods may vary depending on the type of information, contractual obligations, and applicable law.


User Controls

Healthcare organizations determine whether AI features are enabled for their users.

Authorized users may:

  • Enable or disable supported AI features.

  • Review AI-generated outputs.

  • Edit or reject AI-generated content.

  • Control access through role-based permissions, where available.

Patients may contact their healthcare provider regarding information processed through AI-enabled administrative workflows.


Continuous Improvement

Doxmate continuously evaluates and improves its AI-powered features to enhance administrative efficiency, security, reliability, and user experience.

As AI technologies evolve, we may introduce new capabilities. If such capabilities require additional categories of personal information or materially change how information is processed, we will update this Privacy Policy and, where required by applicable law, obtain appropriate consent before implementing those changes.

WhatsApp Cloud API

Doxmate integrates with the Meta WhatsApp Cloud API to enable secure, automated, and efficient communication between healthcare organizations and their patients. This integration helps healthcare providers manage appointment-related communications, improve patient engagement, and streamline administrative workflows through WhatsApp.

The WhatsApp integration is optional and is available only to healthcare organizations that choose to connect their WhatsApp Business Account through Meta’s official WhatsApp Cloud API.


Purpose of the WhatsApp Integration

The WhatsApp Cloud API integration enables healthcare organizations to communicate with patients through WhatsApp for operational and healthcare administration purposes.

Depending on the services enabled, Doxmate may use WhatsApp to:

  • Confirm appointments.

  • Send appointment reminders.

  • Schedule appointments.

  • Reschedule appointments.

  • Cancel appointments.

  • Send queue updates and token information.

  • Notify patients of consultation status.

  • Share appointment confirmations.

  • Collect appointment preferences.

  • Send follow-up reminders.

  • Respond to administrative patient inquiries.

  • Provide AI-assisted appointment booking and support.

  • Deliver other healthcare administrative communications authorized by the healthcare organization.

The WhatsApp integration is intended solely to facilitate healthcare operations and patient communication.


Information Processed

To provide WhatsApp-based services, Doxmate may process:

Patient Information

  • Name

  • Mobile phone number

  • Preferred language (where available)

  • Communication preferences

Appointment Information

  • Appointment date and time

  • Assigned doctor

  • Department

  • Appointment status

  • Queue token

  • Queue position

  • Appointment reference number

  • Clinic location

  • Follow-up information

WhatsApp Communication Data

  • Message content

  • Message templates

  • Delivery status

  • Read receipts

  • Message timestamps

  • Conversation identifiers

  • Conversation category

  • User responses

  • Interactive button selections

  • Media attachments (where supported)

  • Error logs related to message delivery

Only the information necessary to deliver the requested functionality is processed.


AI-Powered WhatsApp Assistant

Healthcare organizations may enable Doxmate’s AI-powered WhatsApp assistant to automate administrative conversations.

The AI assistant may help patients:

  • Book appointments.

  • Reschedule appointments.

  • Cancel appointments.

  • Check appointment status.

  • Obtain clinic timings.

  • View doctor availability.

  • Receive queue updates.

  • Receive appointment reminders.

  • Ask administrative questions.

  • Connect with clinic staff when appropriate.

The AI assistant is designed solely for administrative assistance.

It does not provide:

  • Medical advice.

  • Clinical diagnosis.

  • Treatment recommendations.

  • Emergency medical assistance.

  • Prescription decisions.

Patients requiring medical advice should consult a qualified healthcare professional.


Message Templates

Doxmate may use WhatsApp Business message templates approved by Meta for communications such as:

  • Appointment confirmations.

  • Appointment reminders.

  • Appointment cancellations.

  • Appointment rescheduling.

  • Queue notifications.

  • Follow-up reminders.

  • Administrative service updates.

Template messages are used in accordance with Meta’s WhatsApp Business policies.


Automated Messaging

Where enabled by the healthcare organization, Doxmate may automatically send operational messages based on predefined workflows, including:

  • Appointment booked.

  • Appointment confirmed.

  • Appointment reminder.

  • Appointment cancelled.

  • Appointment rescheduled.

  • Patient checked in.

  • Queue token assigned.

  • Consultation ready.

  • Follow-up reminder.

  • Feedback request after consultation.

These communications are operational in nature and are not promotional unless the recipient has separately opted in where required by applicable law.


How We Use WhatsApp Data

WhatsApp-related information is used solely to:

  • Deliver messages requested by healthcare organizations.

  • Facilitate appointment scheduling.

  • Manage patient communications.

  • Improve operational efficiency.

  • Track message delivery.

  • Monitor service reliability.

  • Resolve communication issues.

  • Maintain audit records.

  • Comply with legal obligations.

WhatsApp message content is not used for advertising, behavioral profiling, or unrelated commercial purposes.


Data Controller and Data Processor Roles

Healthcare organizations remain the Data Controllers of patient communication processed through WhatsApp.

Doxmate acts as a Data Processor, processing WhatsApp communications only on behalf of and under the documented instructions of the applicable healthcare organization.

Healthcare organizations are responsible for:

  • Obtaining any required patient consent.

  • Configuring communication preferences.

  • Managing message templates.

  • Ensuring compliance with applicable healthcare and privacy laws.

  • Complying with Meta’s WhatsApp Business policies.


Third-Party Processing

WhatsApp communications are delivered through the Meta WhatsApp Cloud API.

Accordingly, certain information required to deliver messages is processed by Meta in accordance with its own privacy policies and applicable terms.

Users are encouraged to review Meta’s privacy documentation to understand how Meta processes WhatsApp data.


Security

Doxmate implements industry-standard administrative, technical, and organizational safeguards to protect WhatsApp-related information, including:

  • Secure API authentication.

  • TLS encryption during transmission.

  • Encrypted storage where applicable.

  • Role-based access controls.

  • Audit logging.

  • Secure backend infrastructure.

  • Continuous monitoring.

  • Access restrictions based on the principle of least privilege.

Only authorized systems and personnel may access WhatsApp communication data where necessary to provide the requested services.


Data Retention

WhatsApp communication records may be retained only for as long as necessary to:

  • Deliver healthcare services.

  • Maintain communication history.

  • Resolve disputes.

  • Support customer service.

  • Meet legal, contractual, and regulatory obligations.

  • Maintain operational audit trails.

Retention periods may vary depending on the healthcare organization’s configuration, applicable laws, and Meta’s platform policies.


User Rights

Patients may exercise applicable privacy rights regarding WhatsApp communications through the healthcare organization acting as the Data Controller.

Where required by applicable law, patients may have the right to:

  • Access communication records.

  • Correct inaccurate information.

  • Request deletion of personal information.

  • Object to certain processing activities.

  • Withdraw consent for non-essential communications.

Operational messages necessary for delivering healthcare services may continue where permitted by applicable law.


Compliance

Doxmate’s WhatsApp integration is designed to comply with:

  • Meta WhatsApp Business Platform Terms.

  • Meta WhatsApp Business Messaging Policies.

  • Applicable privacy and data protection laws.

  • Healthcare confidentiality obligations.

  • This Privacy Policy.

We continuously review and improve our WhatsApp integration to ensure secure, reliable, and compliant communication between healthcare organizations and their patients while protecting the confidentiality and integrity of personal information.

Billing & Payments

Doxmate offers subscription-based software and related healthcare technology services. This section explains how billing information is collected, processed, and protected when healthcare organizations purchase or subscribe to our services.

Purpose

Billing and payment information is processed solely to:

  • Create and manage customer subscriptions.

  • Process payments.

  • Generate invoices and receipts.

  • Calculate applicable taxes.

  • Manage renewals and upgrades.

  • Process refunds where applicable.

  • Detect fraudulent transactions.

  • Comply with financial, accounting, and legal obligations.


Information We Collect

Depending on the services purchased, we may collect:

Customer Information

  • Organization name

  • Billing contact name

  • Email address

  • Phone number

  • Billing address

  • Country and state

  • Tax identification numbers (such as GSTIN, VAT, or similar identifiers)

  • Business registration information (where applicable)

Subscription Information

  • Subscription plan

  • Purchased modules

  • Number of users

  • Number of practitioners

  • Subscription period

  • Renewal preferences

  • License information

  • Service usage relevant to billing

Payment Information

Payments are processed through authorized third-party payment service providers.

Depending on the selected payment method, payment processors may collect:

  • Payment method

  • Card details

  • UPI information

  • Net banking information

  • Wallet information

  • Bank account information

  • Transaction identifiers

  • Payment authorization details

Doxmate does not store your complete debit card, credit card, CVV, or banking credentials on its own servers.

Sensitive payment information is processed directly by certified payment providers.


Payment Service Providers

We may use trusted third-party payment processors to securely process transactions, including:

  • Razorpay

  • Stripe

  • Other PCI DSS-compliant payment providers, where available

These providers process payment information in accordance with their own privacy policies and security standards.

Users are encouraged to review the privacy policies of their selected payment provider.


Subscription Billing

Depending on the selected plan, subscriptions may be:

  • Monthly

  • Quarterly

  • Semi-Annual

  • Annual

  • Multi-year

  • Usage-based

  • Enterprise custom plans

Subscriptions may automatically renew unless cancelled in accordance with the applicable subscription agreement or Terms of Service.


Invoices and Taxation

Doxmate may generate invoices containing information such as:

  • Customer details

  • Organization information

  • Subscription details

  • Billing period

  • Taxes

  • Discounts

  • Payment status

  • Invoice reference numbers

Applicable taxes, including GST, VAT, sales tax, or similar indirect taxes, may be charged as required by applicable law.

Customers are responsible for providing accurate billing and tax information.


Refunds

Refund requests are handled in accordance with Doxmate’s Refund Policy and applicable law.

Approved refunds, where applicable, may be processed through the original payment method or another method determined by the payment processor.

Certain subscription fees, implementation fees, onboarding services, professional services, and third-party charges may be non-refundable unless otherwise required by law.


Failed Payments

If a payment cannot be successfully processed, Doxmate may:

  • Retry the payment.

  • Notify the billing contact.

  • Suspend access to paid features.

  • Restrict certain services.

  • Cancel subscriptions after reasonable notice where permitted by applicable agreements.

Healthcare organizations remain responsible for all outstanding charges incurred prior to suspension or termination.


Billing Communications

We may send billing-related communications, including:

  • Payment confirmations

  • Invoice notifications

  • Subscription renewal reminders

  • Payment failure notifications

  • Tax invoices

  • Credit notes

  • Refund confirmations

  • Subscription upgrade or downgrade confirmations

These communications are considered service-related and may be sent regardless of marketing communication preferences.


Security of Payment Information

Doxmate implements industry-standard administrative, technical, and organizational safeguards to protect billing information.

Security measures include:

  • TLS encryption during transmission.

  • Secure authentication.

  • Role-based access controls.

  • Audit logging.

  • Continuous monitoring.

  • Fraud detection mechanisms.

  • Secure cloud infrastructure.

Where payment information is processed by third-party payment providers, those providers are responsible for protecting payment credentials in accordance with applicable security standards, including the Payment Card Industry Data Security Standard (PCI DSS) where applicable.


Data Retention

Billing records may be retained for as long as necessary to:

  • Comply with tax and accounting laws.

  • Resolve disputes.

  • Process refunds.

  • Detect fraud.

  • Maintain financial records.

  • Enforce contractual rights.

  • Meet legal and regulatory obligations.

Retention periods may vary depending on applicable laws and accounting requirements.


International Payments

For customers located outside India, payments may be processed in supported currencies through authorized payment providers.

Additional taxes, foreign exchange charges, banking fees, or payment processing fees may be imposed by financial institutions or payment providers and are the responsibility of the customer unless otherwise stated.


Data Sharing

Billing information is shared only as necessary to:

  • Process payments.

  • Generate invoices.

  • Comply with tax obligations.

  • Detect fraudulent activity.

  • Provide customer support.

  • Meet legal or regulatory requirements.

Doxmate does not sell billing information or payment-related personal data to advertisers, marketers, or data brokers.


Compliance

Doxmate processes billing information in accordance with applicable financial, taxation, privacy, and data protection laws.

We work only with trusted payment providers that maintain appropriate security and compliance standards to protect customer payment information and ensure secure financial transactions.

Cookies & Similar Technologies

Doxmate uses cookies and similar technologies to provide, secure, improve, and personalize our Platform. This section explains what cookies are, how we use them, and the choices available to users.

By continuing to use our Platform, you consent to our use of cookies and similar technologies as described in this Privacy Policy, except where applicable law requires separate consent.


What Are Cookies?

Cookies are small text files that are stored on your computer, mobile device, or other internet-enabled device when you visit a website or use certain online services.

Cookies help websites recognize returning users, remember preferences, maintain secure sessions, improve performance, and analyze how services are used.

In addition to cookies, Doxmate may use similar technologies such as:

  • Local Storage

  • Session Storage

  • Web Beacons

  • Pixels

  • Software Development Kits (SDKs)

  • Device Identifiers

  • Authentication Tokens

  • Server-side session identifiers

For simplicity, all of these technologies are referred to collectively as “Cookies” in this Privacy Policy unless otherwise stated.


Types of Cookies We Use

1. Essential Cookies

Essential cookies are required for the operation of the Platform and cannot be disabled through our services.

These cookies help us:

  • Authenticate users.

  • Maintain secure login sessions.

  • Prevent unauthorized access.

  • Protect against fraud.

  • Remember security settings.

  • Enable core application functionality.

  • Process user requests.

  • Maintain session continuity.

Without these cookies, many features of Doxmate would not function properly.


2. Functional Cookies

Functional cookies allow the Platform to remember user preferences and improve the overall experience.

These cookies may remember:

  • Preferred language.

  • Time zone.

  • Dashboard preferences.

  • Notification settings.

  • User interface customization.

  • Accessibility preferences.

  • Recently used features.


3. Performance and Analytics Cookies

Performance cookies help us understand how users interact with the Platform so that we can improve reliability and usability.

These cookies may collect information such as:

  • Pages visited.

  • Feature usage.

  • Session duration.

  • Navigation paths.

  • Device type.

  • Browser information.

  • Performance metrics.

  • Error reports.

  • Crash diagnostics.

Where possible, analytics information is aggregated or pseudonymized.


4. Security Cookies

Security cookies help protect both users and the Platform.

They may be used to:

  • Detect suspicious activity.

  • Prevent fraudulent logins.

  • Protect against cross-site request forgery (CSRF).

  • Prevent session hijacking.

  • Monitor authentication status.

  • Secure administrative access.

  • Enforce rate limiting.


5. Preference Cookies

Preference cookies remember user choices to improve usability.

Examples include:

  • Theme preferences.

  • Language selection.

  • Region settings.

  • Dashboard layout.

  • Notification preferences.


How We Use Cookies

We use cookies and similar technologies to:

  • Authenticate users.

  • Maintain secure login sessions.

  • Remember user preferences.

  • Improve Platform performance.

  • Analyze usage patterns.

  • Diagnose technical issues.

  • Detect security incidents.

  • Prevent fraud and abuse.

  • Support customer service.

  • Improve accessibility.

  • Enhance user experience.

  • Measure system reliability.

Cookies are not used to collect information beyond what is reasonably necessary to operate and improve our services.


Third-Party Cookies

Some cookies may be placed by trusted third-party service providers that support the operation of Doxmate.

These providers may include:

  • Analytics providers.

  • Cloud infrastructure providers.

  • Payment service providers.

  • Authentication providers.

  • Customer support platforms.

  • Security monitoring services.

Third-party providers process information in accordance with their own privacy policies and applicable laws.


Google Services

If users choose to authenticate using Google Sign-In or connect Google Calendar or Google Sheets, Google may set cookies or similar technologies necessary to provide authentication and authorized Google services.

These cookies are governed by Google’s own privacy policies and are not controlled by Doxmate.


WhatsApp Integration

Where WhatsApp Cloud API features are enabled, Meta may use cookies or similar technologies in connection with authentication, service delivery, or security.

Such technologies are governed by Meta’s own privacy policies.


Managing Cookies

Most web browsers allow users to:

  • View stored cookies.

  • Delete cookies.

  • Block cookies.

  • Restrict third-party cookies.

  • Configure cookie preferences.

  • Receive notifications before cookies are stored.

Browser settings vary by browser and device.

Please note that disabling certain cookies may affect the availability or functionality of some Doxmate services.


Do Not Track

Some browsers support “Do Not Track” (“DNT”) signals.

Because there is currently no universally accepted standard for responding to DNT signals, Doxmate does not currently respond differently to such signals. We will continue to monitor developments in browser standards and applicable laws.


Cookie Retention

Some cookies expire automatically when you close your browser (session cookies), while others remain on your device until they expire or are manually deleted (persistent cookies).

Retention periods vary depending on the purpose of the cookie and applicable legal or operational requirements.


Consent

Where required by applicable law, Doxmate will request your consent before placing non-essential cookies on your device.

You may withdraw or modify your cookie preferences at any time through your browser settings or any cookie preference tools that we make available.

Essential cookies required for security, authentication, and core Platform functionality cannot be disabled through our services because they are necessary for the operation of the Platform.


Changes to Our Cookie Practices

We may update our use of cookies and similar technologies from time to time to improve our services, introduce new features, comply with legal requirements, or enhance security.

Any material changes will be reflected in this Privacy Policy or communicated through appropriate notices where required by applicable law.

Security

Protecting the confidentiality, integrity, availability, and privacy of our users’ information is a fundamental priority for Doxmate. We implement industry-standard administrative, technical, and organizational safeguards designed to protect Personal Data, healthcare information, and other confidential information against unauthorized access, disclosure, alteration, destruction, misuse, or loss.

While no method of electronic transmission or storage is completely secure, Doxmate continuously evaluates and enhances its security practices to reduce risks and maintain a secure platform.


Security Program

Doxmate maintains a comprehensive information security program designed to:

  • Protect personal and healthcare information.

  • Maintain the confidentiality of customer data.

  • Ensure data integrity.

  • Support service availability and reliability.

  • Prevent unauthorized access.

  • Detect and respond to security incidents.

  • Comply with applicable legal and contractual obligations.

Security measures are regularly reviewed and updated to address evolving threats and industry best practices.


Administrative Safeguards

We implement administrative controls including:

  • Information security policies and procedures.

  • Role-based access management.

  • Employee confidentiality obligations.

  • Security awareness and training.

  • Background verification where appropriate.

  • Access approval and review processes.

  • Vendor and third-party security assessments.

  • Incident response planning.

  • Business continuity planning.

  • Disaster recovery planning.

  • Periodic security reviews.

Access to customer information is granted only to authorized personnel with a legitimate business need.


Technical Safeguards

Doxmate employs multiple technical safeguards, including:

  • Secure authentication mechanisms.

  • Multi-Factor Authentication (MFA) for privileged accounts, where supported.

  • Role-Based Access Control (RBAC).

  • Least-privilege access principles.

  • TLS encryption for data in transit.

  • Encryption of sensitive data at rest where applicable.

  • Secure password hashing using industry-standard algorithms.

  • Session management and timeout controls.

  • API authentication and authorization.

  • Network security controls.

  • Secure cloud infrastructure.

  • Firewalls and network segmentation.

  • Continuous monitoring and alerting.

  • Security logging and audit trails.

  • Vulnerability scanning and remediation.

  • Regular software updates and security patches.


Encryption

Where appropriate, Doxmate protects data using strong encryption technologies.

These protections include:

  • HTTPS/TLS encryption for communications between users and the Platform.

  • Encryption of sensitive information stored within our infrastructure where applicable.

  • Secure management of encryption keys.

  • Encrypted backups where supported.

Passwords are never stored in plain text.


Access Controls

Access to customer information is controlled using the principle of least privilege.

Depending on the services used, Doxmate supports:

  • User authentication.

  • Role-based permissions.

  • Department-level access restrictions.

  • Organization-level isolation.

  • Administrative approval workflows.

  • Session expiration.

  • Login monitoring.

  • Device and IP restrictions where available.

Healthcare organizations are responsible for assigning appropriate permissions to their authorized users.


Infrastructure Security

Doxmate is hosted using secure cloud infrastructure operated by trusted service providers.

Infrastructure protections include:

  • Redundant systems.

  • Secure network architecture.

  • Continuous monitoring.

  • Infrastructure logging.

  • Backup and recovery mechanisms.

  • Physical security controls provided by cloud providers.

  • Availability monitoring.

  • Disaster recovery capabilities.


Application Security

Security is integrated throughout the software development lifecycle.

We implement practices including:

  • Secure software development practices.

  • Code reviews.

  • Security testing.

  • Dependency management.

  • Vulnerability remediation.

  • Access control validation.

  • Input validation.

  • Protection against common web application vulnerabilities.

  • Logging and monitoring of security events.

Security updates are deployed as appropriate to address identified risks.


Electronic Medical Records (EMR) Security

For healthcare organizations using the EMR module, Doxmate applies additional safeguards designed to protect medical information.

These may include:

  • Restricted access to medical records.

  • Clinical audit trails.

  • User activity logging.

  • Record modification history.

  • Role-based clinical permissions.

  • Secure document storage.

  • Access monitoring.

  • Controlled export capabilities.

Healthcare organizations remain responsible for configuring appropriate user permissions and complying with applicable healthcare regulations.


Google API Security

Where users authorize Google integrations such as Google Calendar, Google Sheets, or Google Sign-In, Doxmate protects Google OAuth credentials using appropriate security controls.

These include:

  • Secure OAuth 2.0 authorization.

  • Encrypted storage of OAuth access and refresh tokens.

  • Token lifecycle management.

  • Access restrictions.

  • Secure backend processing.

  • Continuous monitoring.

Doxmate never stores users’ Google Account passwords.

Our use of Google API data complies with the Google API Services User Data Policy, including the Limited Use Requirements.


WhatsApp Security

Communications through the Meta WhatsApp Cloud API are processed using secure authenticated connections.

Doxmate protects WhatsApp-related information through:

  • Secure API authentication.

  • Encrypted communications.

  • Role-based access controls.

  • Operational monitoring.

  • Secure infrastructure.

Healthcare organizations remain responsible for configuring authorized WhatsApp Business Accounts and message templates.


Payment Security

Payments are processed through trusted third-party payment providers.

Doxmate does not store complete payment card numbers, CVV values, or online banking credentials.

Payment processors are responsible for securing payment information in accordance with applicable industry standards, including PCI DSS where applicable.


Monitoring and Incident Detection

We continuously monitor our Platform to identify potential security events.

Monitoring activities may include:

  • Authentication monitoring.

  • Infrastructure monitoring.

  • Performance monitoring.

  • Error detection.

  • Security event logging.

  • Suspicious activity detection.

  • Automated alerting.

  • Service availability monitoring.

Monitoring helps us maintain the security, reliability, and availability of our services.


Security Incident Response

Doxmate maintains procedures for responding to suspected or confirmed security incidents.

Depending on the nature of the incident, we may:

  • Investigate the incident.

  • Contain affected systems.

  • Restore services.

  • Notify affected customers where required by applicable law.

  • Cooperate with regulatory authorities where legally required.

  • Implement corrective and preventive measures.


Data Backups and Business Continuity

To support service continuity, Doxmate maintains backup and recovery procedures.

These may include:

  • Automated backups.

  • Disaster recovery planning.

  • Service redundancy.

  • Infrastructure resilience.

  • Recovery testing.

Backup retention periods are managed according to operational and legal requirements.


Customer Responsibilities

Healthcare organizations and users also play an important role in protecting information.

Users are responsible for:

  • Maintaining the confidentiality of account credentials.

  • Choosing strong passwords.

  • Enabling Multi-Factor Authentication where available.

  • Managing user permissions appropriately.

  • Logging out of shared devices.

  • Keeping devices and browsers updated.

  • Reporting suspected security incidents promptly.

  • Protecting patient confidentiality in accordance with applicable laws.


International Security Standards

Doxmate designs its security program with reference to widely accepted industry security principles and continuously evaluates its practices to align with evolving security, privacy, and healthcare requirements.

While we strive to maintain a high level of security, no system can guarantee absolute protection against every potential threat.


Continuous Improvement

Security is an ongoing process.

We regularly review and enhance our administrative, technical, and organizational safeguards to address emerging threats, improve resilience, strengthen our infrastructure, and maintain the trust of healthcare organizations, patients, and users.

We encourage users who discover a potential security vulnerability to report it promptly by contacting us at security@doxmate.in or privacy@doxmate.in so that we can investigate and address the issue responsibly.

Data Retention

Doxmate retains Personal Data only for as long as necessary to provide our services, fulfill contractual obligations, comply with applicable legal, regulatory, accounting, and healthcare requirements, resolve disputes, enforce agreements, and maintain the security and integrity of our Platform.

Retention periods vary depending on the type of information, the services used, the instructions of the healthcare organization, and applicable legal requirements.


Retention Principles

We retain information based on the following principles:

  • Data is retained only for legitimate business and legal purposes.

  • Information is retained only as long as necessary for the purposes for which it was collected.

  • Healthcare organizations determine the retention period for patient records where they act as the Data Controller.

  • Information that is no longer required is securely deleted, anonymized, or de-identified where appropriate.

  • Certain information may be retained for longer periods where required by applicable law or regulatory obligations.


Categories of Data and Retention

Account Information

Account information, including user profiles, authentication records, and organization details, is retained for as long as the account remains active and for a reasonable period thereafter to:

  • Maintain account integrity.

  • Resolve disputes.

  • Detect fraud.

  • Comply with legal obligations.

  • Restore accounts when requested.

Inactive accounts may be deleted or anonymized after applicable retention periods unless legal obligations require longer retention.


Appointment Records

Appointment information, including booking history, reminders, confirmations, cancellations, and rescheduling records, is retained according to:

  • The healthcare organization’s retention policies.

  • Applicable healthcare regulations.

  • Contractual obligations.

  • Operational requirements.

  • Legal and audit requirements.

Historical appointment records may be retained to support reporting, analytics, dispute resolution, and regulatory compliance.


Electronic Medical Records (EMR)

Patient medical records are retained according to:

  • The healthcare organization’s instructions.

  • Applicable healthcare regulations.

  • Medical record retention laws.

  • Professional recordkeeping obligations.

Healthcare organizations remain responsible for determining appropriate retention periods for patient medical information.

Upon termination of services, healthcare organizations may request export or deletion of EMR data, subject to applicable legal and regulatory requirements.


Queue Management Data

Queue-related information, including digital tokens, waiting times, consultation status, and operational metrics, may be retained for:

  • Operational reporting.

  • Service improvement.

  • Performance analytics.

  • Audit purposes.

  • Regulatory compliance.

Where practical, historical queue information may be aggregated or anonymized after operational use.


WhatsApp Communication Records

WhatsApp communication data, including message logs, delivery status, and conversation metadata, may be retained for:

  • Appointment history.

  • Customer support.

  • Operational troubleshooting.

  • Audit requirements.

  • Legal compliance.

Retention periods may also be subject to Meta’s platform policies and the healthcare organization’s configuration.


Google API Data

Where users connect Google services such as Google Calendar, Google Sheets, or Google Sign-In:

  • OAuth access tokens and refresh tokens are retained only while the integration remains active.

  • Tokens are securely deleted or invalidated when a user disconnects the integration or revokes authorization, subject to reasonable backup and security retention practices.

  • Calendar and spreadsheet data synchronized by Doxmate are retained only as necessary to provide the requested functionality or as instructed by the healthcare organization.

Google Workspace data is not retained longer than necessary for the purposes for which it was authorized.


Billing and Financial Records

Invoices, payment records, subscription information, and related financial documents are retained for the periods required under applicable tax, accounting, financial reporting, and legal requirements.

These records may be retained even after account closure where required by law.


Customer Support Records

Support requests, emails, chat transcripts, call recordings (where applicable), and related communications may be retained to:

  • Resolve support issues.

  • Improve customer service.

  • Investigate complaints.

  • Maintain service history.

  • Comply with legal obligations.


System Logs and Security Records

Security logs, authentication logs, audit trails, and operational logs may be retained for purposes including:

  • Security monitoring.

  • Fraud detection.

  • Incident investigation.

  • System troubleshooting.

  • Performance monitoring.

  • Regulatory compliance.

Retention periods are determined based on operational requirements and applicable legal obligations.


Analytics Information

Analytics and usage information may be retained for product improvement, service optimization, and business reporting.

Where possible, analytics data is aggregated, anonymized, or pseudonymized to reduce the identification of individual users.


Data Deletion

Users and healthcare organizations may request deletion of Personal Data where permitted by applicable law.

Upon receiving a valid request, Doxmate may:

  • Delete the requested information.

  • Anonymize or de-identify information.

  • Restrict further processing.

  • Return data to the healthcare organization where contractually required.

Deletion requests may be limited where retention is necessary to:

  • Comply with legal obligations.

  • Resolve disputes.

  • Enforce agreements.

  • Protect the rights, safety, or security of users or third parties.

  • Maintain backup integrity.

  • Prevent fraud or abuse.


Account Closure

When an account is closed:

  • User access is disabled.

  • Active services are terminated.

  • Information is retained according to this Privacy Policy and applicable legal obligations.

  • Certain operational records may be retained for audit, financial, legal, and security purposes.

Healthcare organizations may request data export before account termination, subject to applicable contractual terms.


Backups and Disaster Recovery

To maintain service continuity and disaster recovery capabilities, Doxmate maintains secure backups.

Backup data:

  • Is protected using appropriate security controls.

  • May continue to exist for a limited period after deletion from active systems.

  • Is automatically overwritten or securely deleted according to backup retention schedules.

Backups are not routinely accessed except for disaster recovery, security investigations, or legal compliance.


Anonymization and Aggregation

Where appropriate, Doxmate may anonymize or aggregate information so that it can no longer reasonably identify an individual.

Anonymized or aggregated information may be retained for:

  • Statistical analysis.

  • Service improvement.

  • Performance monitoring.

  • Capacity planning.

  • Research and product development.

Such information is no longer considered Personal Data under applicable law.


International Data Retention

Where information is processed in multiple jurisdictions, Doxmate retains information in accordance with applicable local legal requirements and contractual commitments.

Cross-border data transfers are protected using appropriate technical, contractual, and organizational safeguards.


Changes to Retention Practices

We may update our data retention practices from time to time to reflect:

  • Changes in legal or regulatory requirements.

  • New product features.

  • Operational improvements.

  • Security enhancements.

  • Business needs.

Any material changes will be reflected in this Privacy Policy.


Contact Regarding Data Retention

Questions or requests regarding data retention, deletion, export, or data lifecycle management may be directed to:

Privacy Team
📧 privacy@brainoxai.com
📧 support@doxmate.in

We will respond to requests in accordance with applicable law and our contractual obligations with healthcare organizations.

GDPR Rights

If you are located in the European Economic Area (EEA), the United Kingdom (UK), or another jurisdiction where the General Data Protection Regulation (GDPR) or equivalent data protection laws apply, you may have certain rights regarding your Personal Data.

Where Doxmate processes Personal Data as a Data Processor on behalf of a healthcare organization, requests relating to patient information should generally be directed to the applicable healthcare organization, which acts as the Data Controller. Doxmate will assist healthcare organizations in responding to such requests where required by applicable law and contractual obligations.


Your Rights Under GDPR

Subject to applicable law and certain legal exceptions, you may have the following rights:

1. Right to Access

You have the right to request confirmation as to whether we process your Personal Data and, where applicable, obtain access to that information.

This may include information about:

  • The categories of Personal Data processed.

  • The purposes of processing.

  • The recipients or categories of recipients.

  • The expected retention period.

  • The source of the information, where applicable.

  • Your applicable rights under data protection laws.


2. Right to Rectification

You have the right to request correction of inaccurate or incomplete Personal Data.

We encourage users and healthcare organizations to keep account and patient information accurate and up to date.


3. Right to Erasure (“Right to be Forgotten”)

You may request deletion of your Personal Data where:

  • The information is no longer necessary for the purposes for which it was collected.

  • You withdraw consent where processing is based on consent.

  • You successfully object to processing.

  • Processing is unlawful.

  • Deletion is required to comply with applicable law.

This right is subject to legal, regulatory, contractual, healthcare record retention, and other legitimate business obligations.


4. Right to Restrict Processing

You may request that we temporarily restrict the processing of your Personal Data where:

  • You contest the accuracy of the information.

  • Processing is unlawful but you prefer restriction rather than deletion.

  • The information is required for legal claims.

  • An objection to processing is under consideration.

During restricted processing, we will continue to securely store your information but will limit its use where required by law.


5. Right to Data Portability

Where technically feasible and applicable, you may request a copy of your Personal Data in a structured, commonly used, and machine-readable format.

Where appropriate, you may also request that your information be transmitted to another service provider.


6. Right to Object

You may object to the processing of your Personal Data where processing is based on:

  • Legitimate interests.

  • Direct marketing.

  • Certain public interest activities.

We will evaluate such objections in accordance with applicable legal requirements.


7. Right to Withdraw Consent

Where processing is based on your consent, you may withdraw that consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Certain services may no longer be available after consent is withdrawn.


8. Right Not to Be Subject to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, where such processing produces legal or similarly significant effects, except where permitted by applicable law.

Doxmate’s AI features are intended to assist with administrative workflows and do not make independent clinical decisions or automated decisions that produce legal or similarly significant effects without appropriate human oversight.


Exercising Your Rights

To exercise your GDPR rights, you may contact us using the contact details provided in this Privacy Policy.

Please include sufficient information to allow us to verify your identity and process your request.

We may request additional information where reasonably necessary to:

  • Confirm your identity.

  • Prevent unauthorized access.

  • Protect the privacy of other individuals.

  • Comply with legal obligations.

We will respond within the timeframes required by applicable law.


Healthcare Organizations

Where Doxmate processes patient information on behalf of a healthcare organization, that healthcare organization acts as the Data Controller.

Requests relating to:

  • Medical records

  • Appointment information

  • EMR data

  • Queue information

  • Clinical documentation

  • Healthcare communications

should generally be submitted directly to the relevant healthcare organization.

Doxmate will assist healthcare organizations in fulfilling data subject requests where required by applicable law and contractual agreements.


International Data Transfers

Where Personal Data is transferred outside the European Economic Area (EEA), the United Kingdom (UK), or other jurisdictions with cross-border data transfer restrictions, Doxmate implements appropriate safeguards, which may include:

  • Standard Contractual Clauses (SCCs).

  • Contractual data protection commitments.

  • Technical and organizational security measures.

  • Other legally recognized transfer mechanisms where applicable.


Right to Lodge a Complaint

If you believe that your Personal Data has been processed in violation of applicable data protection laws, you have the right to lodge a complaint with your local data protection authority.

We encourage you to contact us first so that we may have the opportunity to address your concerns promptly and effectively.


Contact Us

If you have questions about your GDPR rights or wish to exercise any of your rights, please contact:

Privacy Team – Brainox Tech (Doxmate)

📧 privacy@brainoxai.com
📧 support@doxmate.in

We are committed to handling all privacy requests fairly, transparently, and in accordance with applicable data protection laws.

Rights Under India’s Digital Personal Data Protection Act, 2023 (DPDP Act)

If you are a resident of India, your Personal Data is protected under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), subject to its applicability and any exemptions provided under the law.

Doxmate is committed to respecting your privacy rights and processing your Personal Data in a lawful, fair, transparent, and secure manner.

Where Doxmate processes Personal Data on behalf of a healthcare organization, the healthcare organization generally acts as the Data Fiduciary (or Data Controller, where applicable), while Doxmate acts as a Data Processor (Data Processor/Data Processor equivalent under applicable law). Requests relating to patient medical records or healthcare information should generally be directed to the applicable healthcare organization.


Your Rights Under the DPDP Act

Subject to applicable law, contractual obligations, healthcare regulations, and legal exceptions, you may have the following rights.

1. Right to Access Information

You have the right to obtain information regarding the Personal Data processed about you, including:

  • The categories of Personal Data being processed.

  • The purposes for which your Personal Data is being processed.

  • The identities or categories of entities with whom your Personal Data has been shared, where required by law.

  • Information about your rights under applicable law.


2. Right to Correction and Completion

You may request correction, updating, or completion of inaccurate, incomplete, or outdated Personal Data.

Healthcare organizations remain responsible for maintaining the accuracy of patient medical records processed through Doxmate.


3. Right to Erasure

You may request the deletion of your Personal Data where:

  • The purpose for which the information was collected has been fulfilled.

  • You withdraw consent where consent is the legal basis for processing.

  • Retention is no longer required under applicable law.

  • Deletion is otherwise required by applicable law.

Certain information may continue to be retained where necessary to:

  • Comply with legal obligations.

  • Meet healthcare record retention requirements.

  • Resolve disputes.

  • Prevent fraud.

  • Enforce contractual rights.

  • Protect public health or safety where permitted by law.


4. Right to Withdraw Consent

Where processing is based on your consent, you may withdraw that consent at any time.

Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.

Please note that withdrawing consent may affect our ability, or the healthcare organization’s ability, to provide certain services.


5. Right to Grievance Redressal

If you have concerns regarding the processing of your Personal Data, you have the right to submit a grievance to Doxmate.

We will acknowledge and address grievances within a reasonable time in accordance with applicable legal requirements.

If you are not satisfied with our response, you may have the right to pursue remedies available under the DPDP Act before the appropriate authority.


6. Right to Nominate

Where provided under the DPDP Act, you may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.

Such requests may require appropriate verification and supporting documentation.


Consent

Where required by applicable law, Doxmate or the applicable healthcare organization will obtain your consent before collecting or processing your Personal Data.

Consent requests will be:

  • Clear and understandable.

  • Specific to the intended purpose.

  • Provided in plain language where reasonably practicable.

  • Capable of being withdrawn by the individual.

Where processing is permitted under another lawful basis recognized by applicable law, separate consent may not be required.


Processing on Behalf of Healthcare Organizations

Healthcare organizations using Doxmate determine the purposes and means of processing patient information.

Accordingly:

  • Healthcare organizations are generally responsible for obtaining patient consent where required.

  • Healthcare organizations determine retention periods for patient records.

  • Healthcare organizations determine who may access patient information.

  • Doxmate processes patient information only on behalf of and under the documented instructions of the healthcare organization.

Requests relating to:

  • Electronic Medical Records (EMR)

  • Appointment history

  • Clinical documentation

  • Prescriptions

  • Laboratory reports

  • Queue information

  • Patient communications

should generally be directed to the relevant healthcare organization.

Doxmate will provide reasonable assistance to healthcare organizations in responding to such requests where required by applicable law and contractual obligations.


Verification of Requests

To protect the privacy and security of Personal Data, Doxmate may require reasonable verification of identity before fulfilling requests.

We may request additional information where necessary to:

  • Confirm identity.

  • Prevent unauthorized access.

  • Protect the rights of other individuals.

  • Comply with legal obligations.


Response Time

We aim to respond to privacy requests and grievances within the timeframes required under applicable law.

Complex requests or requests involving healthcare organizations may require additional time where permitted by law.


Contact for Privacy Requests

If you wish to exercise your rights under the Digital Personal Data Protection Act, 2023, or have questions regarding the processing of your Personal Data, you may contact:

Privacy Team – Brainox Tech (Doxmate)

📧 privacy@brainoxai.com
📧 support@doxmate.in

We are committed to addressing privacy requests promptly, transparently, and in accordance with applicable laws.


Updates to This Section

As privacy laws and regulatory guidance evolve, Doxmate may update this section to reflect changes in the Digital Personal Data Protection Act, 2023, related rules, or other applicable legal requirements. Any material updates will be reflected in the “Last Updated” date of this Privacy Policy.

International Data Transfers

Doxmate is a cloud-based healthcare operations platform that may process, store, and transfer Personal Data across different jurisdictions in order to provide our services, maintain platform availability, support healthcare organizations, and comply with applicable legal and regulatory requirements.

We are committed to ensuring that any international transfer of Personal Data is conducted securely and in accordance with applicable data protection laws.


Global Operations

Depending on the location of our users, healthcare organizations, cloud infrastructure providers, or authorized service providers, Personal Data may be processed or stored in countries other than the country in which it was originally collected.

Such transfers may occur for purposes including:

  • Hosting and cloud infrastructure.

  • Disaster recovery and backups.

  • Customer support.

  • Platform operations.

  • Data synchronization.

  • Security monitoring.

  • Performance optimization.

  • Integration with authorized third-party services.


Cloud Infrastructure

Doxmate utilizes trusted cloud infrastructure providers to host and operate its Platform.

Personal Data may be processed within one or more geographically distributed data centers depending on:

  • Service availability.

  • Infrastructure redundancy.

  • Disaster recovery requirements.

  • Customer configuration.

  • Regulatory requirements.

Where possible, we select data hosting locations that support the operational and compliance requirements of our customers.


Third-Party Service Providers

Certain trusted third-party providers supporting Doxmate may process Personal Data in different jurisdictions.

These providers may include:

  • Cloud hosting providers.

  • Payment processors.

  • Messaging providers (including Meta WhatsApp Cloud API).

  • Google Workspace services (where authorized by users).

  • Authentication providers.

  • Analytics providers.

  • Customer support platforms.

  • Infrastructure monitoring providers.

Each provider is selected based on appropriate security, privacy, and operational standards.


Transfer Safeguards

Where Personal Data is transferred internationally, Doxmate implements appropriate technical, contractual, and organizational safeguards designed to protect Personal Data.

Depending on the applicable jurisdiction and legal requirements, these safeguards may include:

  • Standard Contractual Clauses (SCCs) or equivalent contractual protections.

  • Data Processing Agreements (DPAs).

  • Encryption during transmission.

  • Encryption at rest where appropriate.

  • Role-based access controls.

  • Least-privilege access principles.

  • Security monitoring and logging.

  • Confidentiality obligations for personnel and service providers.

  • Vendor security assessments.

  • Other legally recognized transfer mechanisms where applicable.


Transfers from the European Economic Area (EEA), United Kingdom, and Switzerland

Where Personal Data originating from the European Economic Area (EEA), the United Kingdom (UK), or Switzerland is transferred to countries that may not provide an equivalent level of data protection, Doxmate implements appropriate safeguards as required by applicable law.

Such safeguards may include:

  • Standard Contractual Clauses approved by the European Commission.

  • UK International Data Transfer Addendum or equivalent mechanisms where applicable.

  • Appropriate contractual obligations with service providers.

  • Additional technical and organizational security measures where appropriate.


Transfers from India

Where Personal Data is processed in connection with users located in India, Doxmate processes such information in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and any applicable rules or regulations.

Where cross-border transfers occur, Doxmate will implement reasonable safeguards and comply with any restrictions or requirements prescribed under applicable Indian law.


Google Services

Where users voluntarily connect Google services, including Google Calendar, Google Sheets, or Google Sign-In, certain information may be processed by Google in accordance with the user’s authorization and Google’s own infrastructure.

Doxmate accesses Google user data only to provide the functionality requested by the user and processes such data in accordance with the Google API Services User Data Policy, including the Limited Use Requirements.


Meta WhatsApp Cloud API

Where healthcare organizations enable WhatsApp integrations, certain communications are transmitted through the Meta WhatsApp Cloud API.

Accordingly, message-related information may be processed by Meta in accordance with its applicable terms, infrastructure, and privacy policies.

Healthcare organizations should review Meta’s privacy documentation for additional information regarding Meta’s processing activities.


Security of International Transfers

Regardless of where Personal Data is processed, Doxmate applies appropriate security measures designed to protect the confidentiality, integrity, and availability of information.

These measures include:

  • Secure HTTPS/TLS communications.

  • Encryption of sensitive information where appropriate.

  • Secure authentication mechanisms.

  • Role-based access controls.

  • Audit logging.

  • Continuous security monitoring.

  • Secure cloud infrastructure.

  • Access restrictions based on the principle of least privilege.

We regularly review our security practices to help ensure that transferred information remains protected throughout its lifecycle.


Healthcare Organizations

Healthcare organizations remain responsible for determining whether international transfers of patient information are appropriate under applicable healthcare, privacy, and regulatory requirements.

Where Doxmate acts as a Data Processor, international transfers are performed only in accordance with:

  • The documented instructions of the healthcare organization.

  • Applicable contractual agreements.

  • Applicable legal and regulatory requirements.


User Rights

Where required by applicable law, users may request additional information regarding the safeguards applied to international transfers of their Personal Data.

Requests relating to international transfers may be submitted using the contact information provided in this Privacy Policy.


Changes to International Transfer Practices

As our services, infrastructure, or legal obligations evolve, Doxmate may update its international data transfer practices.

Any material changes affecting the international processing or transfer of Personal Data will be reflected in this Privacy Policy, and where required by applicable law, users will be notified through appropriate communication channels.

Healthcare Data Processing

Doxmate is designed to support healthcare organizations in the secure management of appointments, patient communications, Electronic Medical Records (EMR), Queue Management, billing, and other healthcare operations.

This section explains how healthcare information is processed through the Doxmate Platform and clarifies the respective responsibilities of Doxmate and healthcare organizations.


Roles and Responsibilities

The responsibilities of Doxmate and healthcare organizations differ depending on the type of information being processed.

Healthcare Organization as Data Controller

Healthcare organizations, including hospitals, clinics, medical practices, diagnostic centers, and other healthcare providers, generally act as the Data Controller (or Data Fiduciary, where applicable under local law) for patient information processed through Doxmate.

Healthcare organizations determine:

  • The purposes for which patient information is collected.

  • The categories of information collected.

  • The lawful basis for processing.

  • The retention period for patient records.

  • Which users may access patient information.

  • Whether third-party integrations are enabled.

  • Whether AI-powered features are enabled.

  • Compliance with applicable healthcare and privacy laws.

Healthcare organizations are responsible for obtaining any patient consents required under applicable law.


Doxmate as Data Processor

Doxmate generally acts as a Data Processor (or equivalent service provider under applicable law) when processing healthcare information on behalf of healthcare organizations.

As a Data Processor, Doxmate processes healthcare information only:

  • On behalf of the healthcare organization.

  • In accordance with documented instructions from the healthcare organization.

  • As necessary to provide the subscribed services.

  • To maintain platform security.

  • To comply with applicable legal obligations.

Doxmate does not determine the purposes for which patient medical information is processed.


Categories of Healthcare Information Processed

Depending on the services enabled by the healthcare organization, Doxmate may process:

Patient Registration Information

  • Patient name

  • Contact information

  • Date of birth

  • Gender

  • Address

  • Emergency contact information

  • Patient identification numbers

Appointment Information

  • Appointment schedules

  • Doctor assignments

  • Consultation history

  • Follow-up appointments

  • Appointment reminders

  • Cancellation history

  • Rescheduling information

Queue Management Information

  • Queue tokens

  • Queue position

  • Check-in time

  • Waiting time

  • Consultation status

  • Department assignments

Electronic Medical Records (EMR)

Where enabled, healthcare organizations may store:

  • Medical history

  • Clinical notes

  • Diagnoses

  • Prescriptions

  • Laboratory reports

  • Imaging reports

  • Allergies

  • Vital signs

  • Immunization records

  • Treatment plans

  • Uploaded medical documents

Billing Information

  • Consultation charges

  • Payment status

  • Invoices

  • Billing references

  • Insurance-related administrative information (where applicable)

Communication Records

  • WhatsApp communications

  • Email notifications

  • SMS notifications

  • Appointment reminders

  • Support communications


Purpose of Processing

Healthcare information is processed solely for legitimate healthcare and administrative purposes, including:

  • Managing patient registrations.

  • Scheduling appointments.

  • Maintaining Electronic Medical Records.

  • Managing patient queues.

  • Facilitating patient communications.

  • Processing billing and invoicing.

  • Generating operational reports.

  • Supporting healthcare delivery.

  • Maintaining audit records.

  • Complying with legal obligations.

Healthcare information is processed only to the extent necessary to provide the services requested by the healthcare organization.


Confidentiality

Doxmate recognizes that healthcare information is highly confidential.

Accordingly:

  • Access to healthcare information is restricted to authorized personnel.

  • Personnel are subject to confidentiality obligations.

  • Access is granted only where necessary to perform assigned responsibilities.

  • Administrative and technical safeguards are implemented to protect confidentiality.


Security Measures

Healthcare information is protected using industry-standard administrative, technical, and organizational safeguards, including:

  • Secure authentication.

  • TLS encryption during transmission.

  • Encryption of stored data where applicable.

  • Role-Based Access Control (RBAC).

  • Audit logging.

  • Session management.

  • Secure cloud infrastructure.

  • Continuous monitoring.

  • Vulnerability management.

  • Backup and disaster recovery procedures.

Healthcare organizations remain responsible for configuring user permissions and maintaining secure access to their own accounts.


AI Processing

Where AI-powered administrative features are enabled by the healthcare organization, healthcare information may be processed to support:

  • Appointment scheduling.

  • Queue optimization.

  • Administrative documentation.

  • Workflow automation.

  • Patient communication.

  • Operational reporting.

AI is used solely to assist administrative workflows.

Doxmate’s AI does not independently diagnose medical conditions, prescribe treatments, replace healthcare professionals, or make clinical decisions.

Healthcare providers remain solely responsible for patient care and clinical decision-making.


Google and Third-Party Integrations

Healthcare organizations may choose to connect authorized third-party services, including:

  • Google Calendar

  • Google Sheets

  • Google Sign-In

  • Meta WhatsApp Cloud API

  • Payment providers

Only the minimum information necessary to provide the requested functionality is shared with these services.

Google Workspace data obtained through Google APIs is processed in accordance with the Google API Services User Data Policy, including the Limited Use Requirements, and is never used to develop, improve, or train generalized artificial intelligence or machine learning models.


Data Sharing

Doxmate does not sell patient information.

Healthcare information is shared only:

  • With authorized users designated by the healthcare organization.

  • With trusted service providers acting on Doxmate’s behalf under appropriate contractual confidentiality obligations.

  • Where required by applicable law or lawful governmental request.

  • At the direction of the healthcare organization.


Data Retention

Healthcare information is retained according to:

  • The healthcare organization’s retention policies.

  • Applicable healthcare regulations.

  • Contractual obligations.

  • Legal and regulatory requirements.

Healthcare organizations may request export or deletion of their data in accordance with applicable agreements and legal obligations.


Patient Rights

Patients generally exercise their privacy rights through the healthcare organization that collected their information.

These rights may include:

  • Access to personal information.

  • Correction of inaccurate information.

  • Deletion where legally permitted.

  • Restriction of processing.

  • Withdrawal of consent where applicable.

Doxmate will reasonably assist healthcare organizations in fulfilling such requests where required by law and contractual obligations.


Compliance

Doxmate is committed to processing healthcare information responsibly and securely.

Our Platform is designed to support healthcare organizations in meeting their privacy, security, and regulatory obligations while maintaining the confidentiality, integrity, and availability of healthcare information.

We regularly review and improve our privacy, security, and operational practices to reflect evolving legal requirements, industry standards, and technological advancements.

Third-Party Services & Subprocessors

To provide, operate, secure, and improve the Doxmate Platform, we rely on trusted third-party service providers (“Third-Party Services” or “Subprocessors”). These providers perform specific functions on our behalf and process Personal Data only as necessary to deliver the services requested by our customers.

We carefully evaluate third-party providers based on their security, privacy, reliability, and compliance practices. Where appropriate, we enter into contractual agreements requiring them to protect Personal Data and process it only for authorized purposes.


Categories of Third-Party Services

Depending on the features enabled by a healthcare organization or user, Doxmate may use one or more of the following categories of service providers.

Cloud Infrastructure & Hosting

We use trusted cloud infrastructure providers to host and operate our Platform.

These providers may process data necessary to:

  • Host applications.

  • Store encrypted data.

  • Provide disaster recovery.

  • Maintain backups.

  • Deliver content.

  • Monitor infrastructure availability.

Examples include:

  • Amazon Web Services (AWS)

  • Cloudflare (where applicable)

  • Other enterprise cloud infrastructure providers


Authentication & Identity Providers

To provide secure authentication and account management, Doxmate may integrate with identity providers.

These services may assist with:

  • User authentication.

  • Multi-factor authentication.

  • Single Sign-On (SSO).

  • Google Sign-In.

  • Session management.

Examples include:

  • Google Identity Services

  • Firebase Authentication (where applicable)

  • Microsoft Identity (where enabled)


Google Workspace Integrations

Where users authorize Google integrations, Doxmate may connect with:

  • Google Calendar

  • Google Sheets

  • Google Sign-In

  • Google OAuth 2.0

  • Other Google Workspace APIs authorized by the user

Google data is processed solely to provide user-requested functionality and in accordance with the Google API Services User Data Policy, including the Limited Use Requirements.


Messaging & Communication Services

Doxmate integrates with messaging platforms to facilitate operational communications.

These services may be used for:

  • Appointment confirmations.

  • Appointment reminders.

  • Queue notifications.

  • Patient communications.

  • Administrative alerts.

Examples include:

  • Meta WhatsApp Cloud API

  • SMS gateway providers

  • Email delivery providers

  • Push notification providers


Artificial Intelligence Providers

Certain AI-powered features may utilize trusted third-party AI service providers to assist with administrative workflows.

Depending on the enabled features, these providers may assist with:

  • Administrative automation.

  • Appointment scheduling.

  • Workflow assistance.

  • Document summarization.

  • Operational reporting.

  • Customer support assistance.

Examples may include:

  • OpenAI

  • Anthropic

  • Google AI services

  • Microsoft Azure AI services

  • Other enterprise AI providers approved by Doxmate

Where AI providers process Personal Data:

  • Processing is limited to providing the requested functionality.

  • Appropriate contractual safeguards are implemented.

  • Google Workspace data obtained through Google APIs is never used to develop, improve, or train generalized AI or machine learning models.


Payment Processors

Payments are securely processed by trusted payment service providers.

These providers may process:

  • Payment authorization.

  • Subscription billing.

  • Refunds.

  • Invoice payments.

  • Tax calculations.

Examples include:

  • Razorpay

  • Stripe

  • Other PCI DSS-compliant payment providers

Doxmate does not store complete payment card numbers or CVV information.


Analytics & Monitoring

To improve the reliability and performance of the Platform, Doxmate may use analytics and monitoring providers.

These services help us:

  • Monitor application performance.

  • Identify software errors.

  • Measure service availability.

  • Analyze feature usage.

  • Improve user experience.

Examples include:

  • Google Analytics

  • Google Tag Manager

  • Microsoft Clarity

  • Sentry

  • Datadog

  • New Relic

  • Other infrastructure monitoring services

Where possible, analytics information is aggregated, pseudonymized, or anonymized.


Customer Support Services

We may use third-party platforms to provide customer support.

These services may process:

  • Support requests.

  • Email correspondence.

  • Chat conversations.

  • Diagnostic information.

  • Attachments voluntarily provided by users.

Examples include:

  • Freshdesk

  • Zendesk

  • Intercom

  • Other customer support platforms


Email Delivery Services

We use email delivery providers to send:

  • Account verification emails.

  • Password reset emails.

  • Appointment notifications.

  • Billing notifications.

  • Service announcements.

  • Customer support communications.

Examples include:

  • Amazon SES

  • SendGrid

  • Mailgun

  • Other transactional email providers


SMS Providers

Where SMS notifications are enabled, Doxmate may use third-party SMS providers to deliver:

  • One-Time Passwords (OTPs).

  • Appointment reminders.

  • Queue notifications.

  • Operational alerts.

Only the information necessary to deliver the message is shared with the provider.


Maps & Location Services

Certain Platform features may integrate with mapping or geolocation providers to display clinic locations or assist users with navigation.

Examples may include:

  • Google Maps Platform

  • Other mapping providers


Data Shared with Third Parties

Depending on the services used, third-party providers may process limited categories of information, including:

  • User account information.

  • Contact information.

  • Appointment information.

  • Queue information.

  • Authentication information.

  • Device information.

  • Payment references.

  • Communication metadata.

  • Operational logs.

We share only the minimum amount of information necessary to provide the requested functionality.


Data Protection Obligations

Third-party providers processing Personal Data on behalf of Doxmate are expected to:

  • Maintain appropriate technical and organizational security measures.

  • Process Personal Data only for authorized purposes.

  • Protect the confidentiality of Personal Data.

  • Comply with applicable privacy and data protection laws.

  • Notify us of security incidents where contractually required.


International Processing

Some third-party providers may process information outside your country of residence.

Where international transfers occur, Doxmate implements appropriate contractual, technical, and organizational safeguards in accordance with applicable law.


Changes to Third-Party Providers

As our Platform evolves, we may add, replace, or discontinue third-party service providers.

The examples listed in this Privacy Policy are illustrative and may change over time without prior notice, provided such changes do not materially affect how Personal Data is processed.

Where required by applicable law, we will update this Privacy Policy or provide appropriate notice before material changes take effect.


Subprocessor Information

Healthcare organizations or enterprise customers may request additional information regarding Doxmate’s subprocessors, including the categories of services provided and applicable security measures, by contacting us at:

Privacy Team – Brainox Tech (Doxmate)

📧 privacy@brainoxai.com
📧 support@doxmate.in

We may maintain and provide an up-to-date list of significant subprocessors upon reasonable request or through our customer documentation, where applicable.

Children’s Privacy

Protecting the privacy of children is important to Doxmate. Our Platform is designed for use by healthcare organizations, healthcare professionals, clinic administrators, and authorized staff. It is not intended for direct use by children.

However, healthcare organizations using Doxmate may provide healthcare services to infants, children, and adolescents. As a result, Doxmate may process Personal Data relating to minors solely on behalf of and under the instructions of the applicable healthcare organization.


Services Are Not Directed to Children

Doxmate does not knowingly offer its Platform directly to children or permit children to independently create user accounts for administrative access to the Platform.

Administrative access is intended only for:

  • Healthcare organizations

  • Hospitals

  • Clinics

  • Licensed healthcare professionals

  • Authorized staff members

  • Organization administrators

  • Authorized representatives


Processing Information About Minors

Healthcare organizations may use Doxmate to manage healthcare services for pediatric patients.

Where authorized by the healthcare organization, Doxmate may process information relating to minors, including:

  • Patient identification information

  • Appointment records

  • Electronic Medical Records (EMR)

  • Queue information

  • Healthcare communications

  • Billing information

  • Parent or guardian contact information

  • Emergency contact information

Such information is processed solely for the purpose of providing healthcare services and administering the Platform.

Healthcare organizations remain responsible for ensuring that any required parental or guardian consent has been obtained in accordance with applicable law.


Responsibility of Healthcare Organizations

Healthcare organizations using Doxmate are responsible for:

  • Determining the lawful basis for processing children’s Personal Data.

  • Obtaining parental or guardian consent where required.

  • Verifying the identity of parents or legal guardians where applicable.

  • Complying with applicable healthcare, privacy, and child protection laws.

  • Managing access to pediatric patient records.

Doxmate processes children’s information only as instructed by the healthcare organization acting as the Data Controller (or Data Fiduciary, where applicable).


Parental and Guardian Rights

Where required by applicable law, parents or legal guardians may have rights regarding the Personal Data of minors, including the right to:

  • Request access to information.

  • Request correction of inaccurate information.

  • Request deletion where legally permitted.

  • Withdraw consent where applicable.

  • Submit privacy-related inquiries.

Requests relating to patient records should generally be directed to the healthcare organization responsible for providing healthcare services.

Doxmate will reasonably assist healthcare organizations in responding to such requests where required by law and contractual obligations.


Protection of Children’s Information

Doxmate applies the same administrative, technical, and organizational safeguards to children’s Personal Data as it does to all healthcare information, including:

  • Secure authentication.

  • TLS encryption during transmission.

  • Encryption of stored data where applicable.

  • Role-based access controls.

  • Audit logging.

  • Secure cloud infrastructure.

  • Continuous monitoring.

  • Restricted access based on the principle of least privilege.

Access to pediatric patient information is limited to authorized users with a legitimate healthcare or operational need.


AI and Children’s Information

Where AI-powered administrative features are enabled, information relating to minors may be processed only to support administrative functions such as:

  • Appointment scheduling.

  • Queue management.

  • Administrative documentation.

  • Patient communications.

  • Operational workflows.

Doxmate’s AI features do not independently diagnose medical conditions, provide treatment recommendations, or make clinical decisions regarding children or any other patients.

Patient information relating to minors is not used to develop, improve, or train generalized artificial intelligence or machine learning models.


Accidental Collection

If Doxmate becomes aware that Personal Data has been collected directly from a child in a manner inconsistent with this Privacy Policy or applicable law, we will take reasonable steps to investigate the matter and, where appropriate, delete or restrict the processing of such information unless retention is required by law or necessary to provide healthcare services through the applicable healthcare organization.


Contact Us

If you believe that a child’s Personal Data has been processed in a manner inconsistent with this Privacy Policy or applicable law, or if you have questions regarding our handling of children’s information, please contact:

Privacy Team – Brainox Tech (Doxmate)

📧 privacy@brainoxai.com
📧 support@doxmate.in

We are committed to protecting children’s privacy and working with healthcare organizations to ensure that pediatric information is handled responsibly, securely, and in accordance with applicable laws and regulations.

Data Breach Notification

Doxmate is committed to maintaining the confidentiality, integrity, and availability of Personal Data and healthcare information. While we implement industry-standard administrative, technical, and organizational safeguards to protect information, no system or method of electronic storage or transmission can guarantee absolute security.

In the event of a suspected or confirmed security incident involving Personal Data, Doxmate follows established incident response procedures to investigate, contain, mitigate, and remediate the incident in accordance with applicable laws, contractual obligations, and industry best practices.


Incident Detection and Response

Doxmate maintains security monitoring and incident response processes designed to detect, assess, and respond to potential security events.

Our incident response process may include:

  • Identification and verification of the incident.

  • Assessment of the nature and scope of the incident.

  • Containment of affected systems.

  • Investigation of the root cause.

  • Preservation of relevant evidence where appropriate.

  • Recovery and restoration of services.

  • Implementation of corrective and preventive measures.

  • Post-incident review and continuous improvement.


Assessment of Security Incidents

Upon becoming aware of a suspected or confirmed security incident, Doxmate will evaluate factors including:

  • The nature of the affected information.

  • The categories of individuals potentially affected.

  • The number of records involved.

  • Whether the information was encrypted or otherwise protected.

  • The likelihood of unauthorized access, disclosure, alteration, or loss.

  • The potential impact on affected individuals and healthcare organizations.

  • Applicable legal, contractual, and regulatory notification requirements.

Not every security event constitutes a reportable data breach.


Notification to Healthcare Organizations

Where Doxmate acts as a Data Processor on behalf of a healthcare organization and becomes aware of a confirmed Personal Data breach affecting customer data, we will notify the affected healthcare organization without undue delay, or within any timeframe required by applicable law or contractual agreement.

The notification may include, where reasonably available:

  • A description of the incident.

  • The categories of information affected.

  • The approximate number of affected individuals or records, where known.

  • The likely consequences of the incident.

  • Actions taken or proposed to contain and remediate the incident.

  • Recommended actions that the healthcare organization may take to mitigate potential risks.

  • Contact information for further assistance.

Healthcare organizations remain responsible for determining whether notification to patients, regulators, or other authorities is required under applicable law.


Notification to Individuals

Where Doxmate acts as the Data Controller and applicable law requires notification to affected individuals, we will provide notice without undue delay, taking into account:

  • The nature and severity of the incident.

  • The risk to affected individuals.

  • Applicable legal and regulatory requirements.

  • The availability of accurate information.

Notifications may be provided through one or more of the following methods:

  • Email.

  • In-application notifications.

  • Website announcements.

  • Telephone (where appropriate).

  • Other reasonable communication methods.


Regulatory Notifications

Where required by applicable law, Doxmate will cooperate with healthcare organizations and relevant authorities regarding reportable Personal Data breaches.

Where Doxmate acts as a Data Processor, the healthcare organization generally remains responsible for fulfilling any regulatory notification obligations unless otherwise required by law or agreed by contract.


Containment and Recovery

Following a confirmed security incident, Doxmate may implement measures including:

  • Isolating affected systems.

  • Revoking compromised credentials or access tokens.

  • Rotating encryption keys or credentials where appropriate.

  • Restoring services from secure backups.

  • Applying security patches and configuration updates.

  • Enhancing monitoring and detection capabilities.

  • Conducting additional security assessments.


Customer Responsibilities

Healthcare organizations and users also play an important role in protecting information.

Customers should:

  • Use strong, unique passwords.

  • Enable Multi-Factor Authentication (MFA) where available.

  • Protect account credentials.

  • Promptly report suspected unauthorized access.

  • Keep devices and software up to date.

  • Regularly review user permissions and access controls.

If you suspect that your Doxmate account has been compromised, please notify us immediately.


Cooperation with Authorities

Where legally required, Doxmate may cooperate with law enforcement agencies, regulatory authorities, healthcare organizations, and other authorized entities in investigating security incidents or complying with legal obligations.


Continuous Improvement

Following any significant security incident, Doxmate conducts a review of the incident response process to identify lessons learned and opportunities for improvement.

This may include:

  • Updating security controls.

  • Improving monitoring capabilities.

  • Enhancing incident response procedures.

  • Conducting additional employee training.

  • Reviewing third-party security controls.

  • Implementing additional technical or organizational safeguards.

Our goal is to continuously strengthen the security and resilience of the Doxmate Platform.


Reporting a Security Concern

If you believe you have identified a security vulnerability, unauthorized access, or a potential Personal Data breach involving Doxmate, please contact us immediately.

Security & Privacy Team – Brainox Tech (Doxmate)

📧 security@brainoxai.com
📧 privacy@brainoxai.com
📧 support@doxmate.in

Please include as much relevant information as possible, including:

  • A description of the issue.

  • The affected account or organization (if known).

  • The date and time the issue was discovered.

  • Any supporting screenshots, logs, or other evidence.

We will investigate all legitimate reports promptly and take appropriate action in accordance with our incident response procedures.

Appendix A – Google OAuth Verification & Google Workspace Integrations

This Appendix provides additional information regarding Doxmate’s integration with Google services and supplements the Privacy Policy. It is intended to help users understand how Doxmate requests, accesses, and protects Google user data when Google Workspace integrations are enabled.


Purpose of Google Workspace Integrations

Doxmate offers optional integrations with Google Workspace services to improve healthcare operations and administrative workflows.

These integrations are available only after a user explicitly authorizes access through Google’s OAuth 2.0 authorization framework.

Google integrations currently supported by Doxmate include:

  • Google Sign-In

  • Google Calendar

  • Google Sheets

These integrations are optional and are not required to use the core features of the Doxmate Platform.


Google API Scopes Requested

Depending on the features enabled by the user, Doxmate may request permission to access one or more Google API scopes.

Google Sign-In

Purpose:

  • Authenticate users.

  • Create or link Doxmate accounts.

  • Provide secure login.

Information accessed:

  • Name

  • Email address

  • Google Account identifier

  • Profile picture (if available)


Google Calendar

Purpose:

  • Create appointment events.

  • Update appointment events.

  • Delete cancelled appointments.

  • Synchronize appointment schedules.

  • Help prevent scheduling conflicts.

Information accessed:

  • Calendar identifiers.

  • Appointment events created or managed by Doxmate.

  • Event date and time.

  • Event title.

  • Event description.

  • Calendar availability where required.


Google Sheets

Purpose:

  • Export appointment reports.

  • Generate operational reports.

  • Create spreadsheets.

  • Update spreadsheets.

  • Synchronize authorized reporting data.

Information accessed:

  • Spreadsheet identifiers.

  • Worksheet names.

  • Spreadsheet content created or managed by Doxmate.

  • Spreadsheet metadata required for synchronization.


Why We Request Google Permissions

Doxmate requests only the permissions necessary to provide the features selected by the user.

Examples include:

Google ServicePurpose
Google Sign-InSecure authentication and account management
Google CalendarAppointment scheduling and synchronization
Google SheetsReporting and spreadsheet exports

We do not request unnecessary Google API permissions.


User Authorization

Google services are connected only after the user:

  • Chooses to enable the integration.

  • Reviews Google’s OAuth consent screen.

  • Grants the requested permissions.

  • Completes Google’s authentication process.

Users may refuse or revoke permissions at any time.


Limited Use of Google User Data

Doxmate’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use Requirements.

Specifically:

  • We access only the minimum Google user data required to provide the requested functionality.

  • We process Google user data only for user-facing features explicitly requested by the authorized user.

  • We do not sell Google user data.

  • We do not use Google user data for advertising or personalized marketing.

  • We do not share Google user data with advertisers or data brokers.

  • We do not build advertising profiles using Google user data.


Artificial Intelligence

Doxmate provides AI-powered administrative assistance for healthcare organizations.

Examples include:

  • Appointment scheduling.

  • Queue management.

  • Administrative workflow automation.

  • Patient communication assistance.

  • Operational reporting.

Google Workspace data obtained through Google APIs is never used to develop, improve, or train generalized artificial intelligence or machine learning models.

AI processes Google data only when necessary to perform the functionality explicitly requested by the user.


Security of Google Data

Google OAuth credentials and user data are protected using industry-standard security controls, including:

  • OAuth 2.0 authorization.

  • TLS encryption.

  • Encrypted storage of OAuth credentials.

  • Role-based access controls.

  • Audit logging.

  • Secure backend processing.

  • Continuous security monitoring.

  • Least-privilege access principles.

Doxmate never stores Google Account passwords.


Revoking Access

Users may revoke Google permissions at any time by:

  1. Disconnecting the integration from within Doxmate.

  2. Visiting their Google Account permissions page:

https://myaccount.google.com/permissions

After authorization is revoked, Doxmate will no longer be able to access the corresponding Google service unless the user grants permission again.


Data Retention

Google OAuth tokens are retained only while the integration remains active and only as long as necessary to provide the authorized functionality.

Upon revocation or disconnection:

  • OAuth tokens are invalidated or securely deleted, subject to reasonable backup and operational requirements.

  • Synchronization with Google services ceases.

  • Previously synchronized information stored within Doxmate remains subject to the healthcare organization’s retention policies and this Privacy Policy.


Google Workspace Services Covered

This Privacy Policy currently applies to the following Google Workspace integrations supported by Doxmate:

  • Google Identity Services (Google Sign-In)

  • Google Calendar API

  • Google Sheets API

If Doxmate introduces additional Google integrations in the future that require access to new categories of Google user data, we will:

  • Update this Privacy Policy.

  • Request any additional permissions through Google’s OAuth consent process.

  • Obtain user authorization before accessing new Google data.


Questions

If you have questions regarding Doxmate’s use of Google APIs or Google Workspace integrations, please contact:

Privacy Team – Brainox Tech (Doxmate)

📧 privacy@brainoxai.com
📧 support@doxmate.in

For more information about Google’s privacy and API policies, please visit the official Google documentation and privacy resources.

Contact Information

If you have any questions, concerns, requests, or complaints regarding this Privacy Policy or our privacy and data protection practices, please contact us using the information below.

We are committed to responding to privacy-related inquiries promptly, transparently, and in accordance with applicable laws.


Brainox Tech (Doxmate)

Doxmate is developed and operated by Brainox Tech.

Registered Business Name: Brainox Tech

Website:


Privacy & Data Protection

For questions regarding privacy, data protection, data processing, or this Privacy Policy, please contact:

Privacy Team
Brainox Tech (Doxmate)

📧 privacy@brainoxai.com


Customer Support

For technical support, product assistance, account-related issues, or general inquiries:

Customer Support

📧 support@doxmate.in


Security Reporting

If you believe you have discovered a security vulnerability, unauthorized access, suspected data breach, or other security concern relating to Doxmate, please notify our Security Team immediately.

Security Team

📧 security@brainoxai.com

Please include sufficient information to help us investigate your report, including:

  • A description of the issue.

  • Date and time of discovery.

  • Organization or account affected (if known).

  • Supporting screenshots or logs (where available).

We appreciate responsible disclosure and will investigate all legitimate security reports promptly.


Grievance Redressal (India)

In accordance with applicable provisions of the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable laws, users may submit privacy-related grievances to our Privacy Team.

Grievances may relate to:

  • Access to Personal Data.

  • Correction or updating of information.

  • Deletion requests.

  • Withdrawal of consent.

  • Data processing concerns.

  • Privacy complaints.

  • Security incidents.

  • Exercise of applicable privacy rights.

Please send all privacy-related grievances to:

📧 privacy@brainoxai.com

We will acknowledge and respond to grievances within the timelines required under applicable law.


Requests from Healthcare Organizations

Healthcare organizations requiring assistance regarding:

  • Electronic Medical Records (EMR)

  • Appointment Management

  • Queue Management

  • Google Workspace integrations

  • WhatsApp Cloud API

  • Data export

  • Data deletion

  • Data Processing Agreements (DPAs)

  • Security documentation

  • Enterprise compliance questionnaires

may contact:

📧 support@doxmate.in

or

📧 privacy@brainoxai.com


Enterprise & Compliance Requests

Enterprise customers requiring information regarding:

  • Security practices

  • Privacy documentation

  • Subprocessor information

  • Data Processing Agreements (DPAs)

  • Compliance documentation

  • Vendor security questionnaires

  • Google API compliance

  • International data transfers

may contact:

📧 privacy@brainoxai.com


Postal Address

Brainox Tech
Registered Office Address:

A43, New Mansarovar colony, Chittor Road, Bundi, Pin Code 323001, Rajsthan, India


Response Times

We aim to respond to inquiries within the following timeframes:

  • General support inquiries: 1–3 business days

  • Privacy requests: As required by applicable law

  • Security vulnerability reports: As soon as reasonably practicable

  • Enterprise compliance requests: Within a reasonable timeframe based on the complexity of the request

Response times may vary depending on the nature of the request, verification requirements, and applicable legal obligations.


Identity Verification

To protect the privacy and security of Personal Data, we may request reasonable information to verify the identity of individuals submitting privacy or data access requests before fulfilling such requests.

Verification requirements help prevent unauthorized access to Personal Data and protect the rights of our users and healthcare organizations.


Updates to Contact Information

We may update our contact information from time to time. Any changes will be published on our website and reflected in this Privacy Policy. We encourage users to review this section periodically to ensure they have the most current contact details.