Legal
Privacy Policy
How we handle the data your clinic puts into Cledge.
- Last updated
- 23 September 2026
- Data Fiduciary
- Inqmise Technologies India Pvt Limited ("Inqmise", "we", "us")
- Product
- Cledge, clinic management software available at cledge.in
- Registered address
- A-49, First Floor, Engine House, Mohan Cooperative, Badarpur, New Delhi 110044, India
1. Who we are and who this policy is for
Cledge is clinic management software provided by Inqmise Technologies India Pvt Limited. It helps clinics manage appointments, patient records, consultations, prescriptions and communication with their patients.
This policy explains how we handle personal data. It covers two groups:
- Clinics and their staff — our customers, who create accounts and use Cledge. For their data we are the data fiduciary (controller).
- Patients of those clinics — whose data clinics enter into Cledge. For patient data the clinic is the data fiduciary and Inqmise is a data processor acting only on the clinic's instructions. Patients should contact their clinic first about their data; we will assist the clinic in responding.
2. Information we collect
From clinic staff (account data)
- Name, email address, phone number, role and the branches they are assigned to.
- Login credentials. Passwords are stored only as salted hashes, never in readable form.
- The clinic's business details: legal name, branch addresses, working hours and specialities.
Entered by clinics about their patients
- Identity and contact details: name, age, gender, phone number, email address, postal address.
- Appointment and visit history.
- Clinical information entered by the treating doctor: complaints, notes, diagnosis, prescriptions and treatment packages. This is health data, which we treat as sensitive.
- Documents uploaded by the clinic, such as reports or scans.
- Consent status for receiving marketing messages.
Communication data
- Emails and WhatsApp messages sent through Cledge on behalf of the clinic, their delivery status, and replies patients send to the clinic's WhatsApp number.
Technical data
- IP address, browser type, device information, and logs of actions taken in the application, which we keep for security and audit purposes.
We do not collect payment card details. We do not knowingly collect data directly from children. Where a patient is a minor, the clinic is responsible for obtaining a guardian's consent.
3. How we use information
We use personal data only to:
- provide the Cledge service to the clinic: appointments, records, prescriptions, packages and reporting;
- send appointment confirmations, reminders and clinic communications on the clinic's instructions, by email and WhatsApp;
- send campaign or promotional messages only to patients who have consented to receive them from that clinic;
- authenticate users, enforce role-based access and keep audit logs;
- provide support, fix faults and keep the service secure;
- generate summaries of notes a doctor has already written, using an automated assistant. The assistant does not diagnose, prescribe or give medical advice, and a doctor reviews all output;
- comply with the law.
We do not sell personal data. We do not use patient data for advertising. We do not use patient data to train artificial intelligence models.
4. Legal basis
For clinics and their staff, we process data to perform our contract with the clinic and for our legitimate business interests. For patient data, the clinic obtains the consent or other lawful basis required under India's Digital Personal Data Protection Act, 2023, and we act only on the clinic's instructions.
5. WhatsApp and email messaging
Cledge uses the WhatsApp Business Platform provided by Meta and the email provider Resend to deliver messages on behalf of clinics.
- When a clinic connects its own WhatsApp Business Account to Cledge, we store the identifiers of that account and an access token issued by Meta. The token is stored encrypted and is used only to send and receive messages for that clinic.
- Message content and the patient's phone number are transmitted to Meta in order to deliver the message. Meta's handling of that data is governed by its own privacy policy and the WhatsApp Business Terms.
- Patients can stop receiving marketing messages at any time by replying STOP, by telling the clinic, or by contacting us.
- We use the access granted by Meta only to operate the clinic's messaging within Cledge. We do not use it for any other purpose, and we do not sell or transfer it to anyone else.
6. Sharing information
We share personal data only with:
- the clinic that owns the record, and its authorised staff;
- service providers who help us run Cledge, bound by contract to protect the data and to use it only on our instructions, namely: Meta Platforms (WhatsApp delivery), Resend (email delivery), our cloud hosting provider, and Anthropic (note summaries, which are not used to train models);
- authorities, where the law requires it;
- a successor, if Inqmise is merged or acquired, on the same terms as this policy.
We do not share data with advertisers or data brokers.
7. Where data is stored, and transfers
Data is stored on servers operated by our cloud hosting provider. Some service providers named above may process data outside India. Where that happens we rely on contractual protections and transfer only what is needed to deliver the service, in accordance with applicable Indian law.
8. How long we keep data
- Clinic account and patient records: for as long as the clinic's account is active. After an account closes we keep data for 90 days so the clinic can retrieve it, then delete or irreversibly anonymise it, unless a longer period is required by medical record-keeping or tax laws.
- Message and delivery logs: up to 24 months.
- Security and audit logs: up to 12 months.
- Backups: deleted data may remain in encrypted backups for up to 35 days before being overwritten.
9. Security
We protect data with encryption in transit (HTTPS/TLS), encryption of stored access tokens and credentials, salted password hashing, role-based access control restricting staff to their own clinic and branches, audit logging, access controls on our own systems, and regular backups. No system is perfectly secure, but we work to protect data, and we will notify affected clinics and the Data Protection Board of India of a personal data breach as required by law.
10. Your rights
Under the Digital Personal Data Protection Act, 2023, you may ask to:
- access the personal data we hold about you;
- correct or complete inaccurate data;
- erase data that is no longer needed;
- nominate another person to exercise your rights in the event of death or incapacity;
- raise a grievance about how your data is handled.
Patients: please contact your clinic, which controls your record. If you contact us directly, we will forward your request to the clinic and help them answer it.
Clinic staff: contact us at contact@inqmisetechnologies.com. We reply within 30 days.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
11. Deleting your data
See our Data Deletion page for how to have your data deleted.
12. Cookies
Cledge uses only cookies and browser storage that are necessary to keep you signed in and to remember your preferences. We do not use advertising or third-party tracking cookies.
13. Changes to this policy
We may update this policy. We will change the “Last updated” date and, for significant changes, notify clinic administrators by email or in the application.
14. Contact us
Inqmise Technologies India Pvt Limited
A-49, First Floor, Engine House, Mohan Cooperative, Badarpur, New Delhi 110044, India
Email: contact@inqmisetechnologies.com
