Privacy policy
Written to be read, not to be survived. It explains what we collect, why, who else touches it, and what you can ask us to do about it.
Last updated: 2 August 2026
1. Who we are
HomeoRep is operated by [your registered legal name], [entity type], at [registered postal address]. You can reach us at support@sabkacare.com.
2. Who is responsible for patient data
This is the part doctors ask about first, so it comes before everything else.
- For your patients' data, you are the Data Fiduciary. You decide what to record, you have the clinical relationship, and the duty to your patients under the Digital Personal Data Protection Act, 2023 is yours.
- HomeoRep is the Data Processor. We store and process that data on your instructions so the software works. We do not decide what goes into a patient file, we do not use patient data for our own purposes, and we do not sell it or share it for advertising — ever.
- For your own account data, we are the Data Fiduciary — your name, email, phone, registration number and billing details are ours to explain, and this policy does that.
3. What we collect, and why
Your account. Name, email address, password (stored only as a bcrypt hash — we cannot read it), clinic name, council registration number, phone number, and an optional profile photo. We need these to give you an account, to print a lawful prescription, and to contact you about the service.
Patient records you create. Patient demographics, case histories, symptoms, investigations and any files you attach, prescriptions, appointments and fees. These exist because you entered them; we process them solely to provide the service to you.
Access logs. Which account opened or changed which patient record, when, and the originating IP address and browser. This is required of us by DPDP Rules 2025, Rule 6 and is visible to you under Settings → Activity log.
Technical data. Standard server logs needed to keep the service running and secure.
We do not run advertising or third-party tracking, and we do not build profiles of you or your patients.
4. Who else touches the data
We use a small number of service providers, each for one narrow job:
- Hosting. Servers and database, where all records live.
- Transactional email. Sends password-reset links and account emails to you. Patient data is never emailed through it.
- Payments. Handles subscription payments and holds the card details — we never see or store a card number.
- AI assistance (optional, off unless enabled). When you use the symptom-to-rubric or follow-up assist, the text of the symptoms you are working on is sent to the model provider to generate repertory search phrases. The rubrics you are shown come from our database, never from the model. Leave the feature off and nothing is sent.
WhatsApp sharing is not an integration: it hands the message to the app already on your device, so the content travels under your own WhatsApp account, not ours.
5. Where data is stored, and for how long
Records are stored in our hosted database, with encrypted transport and daily backups. We keep your patient records for as long as your account is active, because they are clinical records you may be required to retain.
If you close your account we delete your data within 90 days, except where we must keep something longer to meet a legal obligation (billing records, for example) or to defend a legal claim. Access-log entries are retained even after the record they describe is deleted — an audit trail that could be erased would not be an audit trail.
6. Your rights
Under the DPDP Act you may ask us to:
- tell you what personal data of yours we hold and who we have shared it with;
- correct or complete anything inaccurate;
- erase data we no longer need for the purpose it was collected;
- nominate someone to exercise these rights if you die or become incapacitated.
You can withdraw consent at any time by closing your account — it is as easy to withdraw as it was to give. Withdrawal does not undo processing that already happened lawfully.
Write to support@sabkacare.com and we will respond within 30 days.
If you are a patient of a doctor who uses HomeoRep: your relationship is with your doctor, who decides what is recorded about you. Please raise requests with them. We will help them answer you, but we cannot release or change their records on our own.
7. Grievance redressal
If something about how we handle your data is wrong, tell us first — we would rather fix it than have you escalate.
Grievance Officer: [grievance officer name]
Email: [grievance email address]
Address: [registered postal address]
We acknowledge every grievance and complete redressal within 90 days, as DPDP Rules 2025, Rule 9 requires. If you are not satisfied, you may complain to the Data Protection Board of India.
8. How we protect it
Encrypted transport, passwords stored only as bcrypt hashes, database-level tenant isolation so one clinic's records cannot be reached from another's session, single-use password-reset links, and logged access. More detail is on the security page.
If a breach affects your data we will notify you and the Data Protection Board as the DPDP Rules require, with what happened and what to do about it.
9. Children
HomeoRep is for registered medical practitioners, so our own users are adults. Patient records you create may of course concern children — as their treating physician, obtaining any consent required from a parent or guardian is part of your role as Data Fiduciary.
11. Changes to this policy
If we change anything that materially affects you, we will email you before it takes effect, not merely edit this page and change the date.