Privacy Policy
Last updated: 5 July 2026
1. Who we are
Ariqu (“Ariqu”, “we”, “us”) provides a cloud platform for clinics in India — clinic management for healthcare teams, a patient portal at patients.ariqu.com, and public clinic pages with online booking. This policy explains what personal data we handle across those services and the choices you have. It is designed to meet the requirements of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable Indian law.
Two roles matter here. For the medical records a clinic keeps about its patients, the clinic is the data fiduciary and Ariqu processes that data on the clinic’s instructions. For your Ariqu patient-portal account, staff accounts, and our websites, Ariqu is the data fiduciary.
2. Information we collect
- Clinic records about patients — entered by your clinic: demographics, contact details, vital signs, allergies, conditions, diagnoses, consultation summaries, prescriptions, lab reports and other documents, appointment and billing history.
- Patient portal account — your email address, name and phone number, documents you choose to upload, and sign-in activity. Sign-in uses one-time codes; we never store passwords.
- Staff accounts — name, email, phone, role, professional registration number and qualification.
- Bookings and communications — appointment requests from public clinic pages, reminders and notifications we send by email, SMS or WhatsApp, and — where a clinic enables an AI phone receptionist — call recordings, transcripts and call metadata.
- Technical data — device and browser information, IP address, and logs needed to keep the service secure and reliable.
3. How we use it
- Operating the platform: records, appointments, queues, prescriptions, billing and the patient portal.
- Sending service communications — appointment confirmations, reminders, one-time sign-in codes and prescription copies.
- Showing you your own records: the patient portal links records from any Ariqu clinic that has your verified email.
- Security: authentication, tenant isolation, fraud and abuse prevention, audit trails.
- Support and service improvement, using aggregated or de-identified information wherever possible.
We do not sell personal data, and we do not use patient records for advertising. Ever.
4. Sharing
Personal data is shared only with:
- Your clinic(s) — clinicians and authorised staff at the clinic that treats you see the records that clinic holds, plus documents you upload to your portal profile (that visibility is the portal’s purpose).
- Service providers — vetted processors who host and run the platform for us: cloud infrastructure in India (AWS, Mumbai region), transactional email, SMS/WhatsApp delivery and telephony providers. They act under contract, only on our instructions.
- Legal requirements — where Indian law, a court, or a competent authority requires disclosure.
5. Where your data lives, and how it's protected
Production data is stored in India (AWS Asia-Pacific, Mumbai). Data is encrypted in transit (TLS) and at rest. Every clinic’s data is logically isolated per tenant; access inside a clinic is role-based; administrative actions are audit-logged. Sign-in for the patient portal and staff accounts uses time-limited one-time codes with rate-limiting and lockouts.
6. Retention
Portal and staff account data is kept while the account is active and deleted on verified request. Clinical records are retained under the controlling clinic’s policy and applicable medical-record retention law; deletion of those records must be requested from your clinic, and we execute the clinic’s instruction. Backups roll off on a fixed schedule after deletion.
7. Your rights
Under the DPDP Act you can:
- Access a summary of the personal data we hold about you and how it is processed.
- Ask for correction of inaccurate or incomplete data, or updating of your details.
- Ask for erasure of data we no longer need to retain by law.
- Withdraw consent where processing rests on consent.
- Nominate a person to exercise your rights if you are unable to.
- Raise a grievance and, if unresolved, escalate to the Data Protection Board of India.
Write to hello@ariqu.com — our grievance contact — and we’ll respond within the timelines the law prescribes. For records controlled by your clinic we will route the request to them.
8. Cookies
We use only essential cookies and local storage needed to keep you signed in and the site working. No third-party advertising trackers.
9. Children
Clinics may maintain records for minors as part of care, with consent handled by a parent or guardian as the law requires. The patient portal is intended for adults; a parent or guardian may manage a minor’s records through the clinic.
10. Changes
When we change this policy we’ll update the date above; material changes will be announced on this page or by email. Continued use after a change means you accept the updated policy.
11. Contact
Ariqu · Gurugram, Haryana, India · hello@ariqu.com