Privacy Policy
Hospitals trust MedNote with the most sensitive category of personal data there is. This policy explains — in plain language — what we collect, why, how we protect it, and the rights you have over it.
Last updated: 8 July 2026
01Who we are & scope
MedNote (the "Platform") is a cloud-based Hospital Management System operated by Zyptr ("we", "us", "our") from Hyderabad, India. Hospitals and clinics ("Hospitals") subscribe to the Platform to run their operations — appointments, outpatient and inpatient care, pharmacy, laboratory, billing, insurance, human resources and analytics.
This Privacy Policy explains how we handle personal data across three contexts: (a) data of Hospital staff who use the Platform, (b) patient data that Hospitals record in the Platform, and (c) data of visitors to this website. It is written with reference to India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Ayushman Bharat Digital Mission ("ABDM") framework.
02Our role: processor for patient data
For patient records, the Hospital that treats the patient decides why and how data is collected — the Hospital is the Data Fiduciary under the DPDP Act. MedNote stores and processes that data strictly on the Hospital's instructions, as a Data Processor. If you are a patient, your primary privacy relationship is with your Hospital; please direct requests about your medical records to them first, and we will support the Hospital in fulfilling them.
For Hospital staff accounts, subscription and billing records, support tickets, and data submitted through this website (for example, the demo request form), Zyptr acts as the Data Fiduciary.
03Data we process
On behalf of Hospitals (as processor):
- Patient demographics and contact details, registration records and uploaded documents
- Clinical data: appointments, consultation notes, vitals and nursing notes, prescriptions, lab orders and results, admission and discharge records
- ABDM data where the Hospital enables it: ABHA numbers, consent artifacts and FHIR-format health records
- Pharmacy and billing data: dispenses, invoices, payments, insurance policies and claims
- Patient feedback, communication preferences and reminder delivery logs
As fiduciary (our own purposes):
- Staff account data: name, work email, phone, role, department/designation, hashed credentials
- Employment records the Hospital maintains in the HR module (attendance, leave, shifts, salary structure)
- Subscription, plan, invoice and payment records for the Hospital's account
- Technical logs: IP address, device and browser information, access timestamps and in-app activity logs kept for security and audit
- Website enquiries: the details you submit on our contact form
04How we use data
- To provide the Platform's modules and keep them running reliably
- To authenticate users and enforce role-based access controls
- To send operational notifications the Hospital configures — appointment confirmations, reminders, reschedules and cancellations over WhatsApp, SMS and email
- To process subscription payments and maintain billing records
- To generate the analytics and AI insights a Hospital sees about its own operations — these run only on that Hospital's own tenant data
- To maintain security: rate limiting, anomaly detection, audit trails and breach investigation
- To respond to support requests, including controlled and logged impersonation sessions when a Hospital asks us to troubleshoot
- To comply with applicable law and lawful requests from authorities
We do not sell personal data. We do not use patient data for advertising, and we do not train models on one Hospital's data to benefit another.
05MedNote mobile apps (iOS & Android)
MedNote also publishes mobile apps for two audiences: doctors (staff of a subscribing Hospital) and patients of Hospitals that switch on patient login. The apps are a mobile front-end to the same Platform described above — they do not introduce a separate controller of your data or any new advertising purpose.
What the apps access is scoped strictly to the person who is signed in:
- Doctors: their own appointments, the patients they treat, and the prescriptions they author
- Patients: their own profile, appointments, prescriptions and medical history at the Hospital they belong to
On your device:
- Login and refresh tokens are held in the operating system's secure store (iOS Keychain / Android Keystore) so you stay signed in; logging out removes that local session
- The apps request no access to your location, camera, microphone, contacts or photos, and contain no advertising or third-party tracking/analytics SDKs
- All communication with our servers is encrypted in transit over HTTPS/TLS
Accounts are issued by the Hospital — there is no public self-registration in the apps. Patient sign-in (phone number + password) is available only where the Hospital has enabled it. To delete your account or the data held about you, contact your Hospital directly, or email support@zyptr.com and we will route the request to the responsible Hospital and act on it as processor.
06ABDM, ABHA & health data exchange
Where a Hospital enables ABDM features, the Platform creates or links ABHA numbers via OTP, registers facilities (HFR) and professionals (HPR), and exchanges FHIR-format health records (prescriptions, lab reports, discharge summaries) with the ABDM network — including pushes to a patient's Health Locker.
Every such exchange is gated on a consent artifact obtained and recorded per the ABDM consent framework, and every ABDM transaction is written to a dedicated audit log. Patients can manage or withdraw ABDM consents through the mechanisms the ABDM ecosystem provides, or through their Hospital.
07How we protect data
- Tenant isolation: each Hospital's data lives in its own dedicated PostgreSQL schema — physically separated tables, not a shared table with a hospital-ID column
- Encryption in transit (HTTPS/TLS) for all traffic between your browser and the Platform
- Credentials stored only as bcrypt hashes; JWT-based sessions with short-lived access tokens and refresh rotation
- Granular role-based access control — 80+ module-level permissions across configurable roles — so staff see only what their role requires
- Security hardening at the API layer: security headers, CORS policy, request validation and rate limiting with stricter limits on authentication endpoints
- Comprehensive activity logs at both Hospital and platform level, retained for audit
- Support access to a Hospital tenant happens only through a controlled, logged impersonation flow — never shared passwords
No system is perfectly secure. If we become aware of a personal data breach affecting your data, we will notify the affected Hospitals and, where required, the Data Protection Board of India and affected individuals, as the DPDP Act prescribes.
08Third-party services we rely on
We share data with a small set of service providers, only to the extent needed to run the Platform:
- Razorpay — to process online payments; payment card details are handled by Razorpay, not stored by us. Webhooks confirm payment status back to the Platform
- Gupshup — to deliver WhatsApp and SMS notifications and reminders (recipient number and message content)
- Email delivery providers — to send transactional email such as reminders and account notifications
- Cloud hosting and storage providers — to run the Platform's infrastructure and store uploaded files
Each provider processes data under its own contractual and legal obligations. We do not permit them to use this data for their own purposes.
09Data retention & deletion
Patient and operational records are retained for as long as the Hospital's subscription is active, because Hospitals are typically required by Indian medical-records regulations to preserve clinical records for prescribed periods. Retention within the Platform is therefore controlled by the Hospital.
When a Hospital's subscription ends, we provide a window for the Hospital to export its data, after which the tenant schema and its backups are deleted from our systems in the normal backup rotation. Website enquiry data is kept only as long as needed to handle the enquiry and reasonable follow-up.
10Your rights
Under the DPDP Act you may have the right to access, correct, update or request erasure of your personal data, to nominate a person to exercise rights on your behalf, and to grieve to the Data Protection Board of India.
- Patients: contact your Hospital (the Data Fiduciary for your medical records); we will assist the Hospital in honouring your request
- Hospital staff: your Hospital administrator can correct most account records in-app; for anything else, contact us
- Website visitors: write to support@zyptr.com to access or delete your enquiry data
We will respond to requests within the timelines required by applicable law. Our grievance contact is support@zyptr.com.
12Children's data
Hospitals treat patients of all ages, so the Platform necessarily processes minors' health records — always under the direction of the treating Hospital, which is responsible for obtaining verifiable parental or guardian consent as the DPDP Act requires. Our website and Platform accounts are intended for adults acting in a professional capacity.
13Changes to this policy
We may update this policy as the Platform, law or our practices evolve. Material changes will be announced to Hospitals in-app and the "Last updated" date above will always reflect the current version. Continued use of the Platform after changes take effect constitutes acceptance of the revised policy.
Questions about this document?
Write to us and we'll respond within a reasonable time. For anything urgent, mention it in the subject line.