Privacy Policy
Klynea ("we", "us") builds an AI-first healthcare platform for India. This policy explains what personal data we collect, why, how we protect it, and the rights you have under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
Last updated: 15 July 2026
Language help · भाषा सहायता · மொழி உதவி · ভাষা সহায়তা
- This page is currently available in English. For help in your language, email privacy@klynea.in.
- यह पृष्ठ अभी अंग्रेज़ी में उपलब्ध है। हिन्दी में सहायता के लिए privacy@klynea.in पर ईमेल करें।
- এই পৃষ্ঠাটি বর্তমানে ইংরেজিতে উপলব্ধ। বাংলায় সাহায্যের জন্য privacy@klynea.in-এ ইমেল করুন।
- இந்தப் பக்கம் தற்போது ஆங்கிலத்தில் உள்ளது. தமிழில் உதவிக்கு privacy@klynea.in-க்கு மின்னஞ்சல் அனுப்பவும்.
- ఈ పేజీ ప్రస్తుతం ఇంగ్లీష్లో అందుబాటులో ఉంది. తెలుగులో సహాయం కోసం privacy@klynea.in కి ఇమెయిల్ చేయండి.
- ಈ ಪುಟ ಸದ್ಯಕ್ಕೆ ಇಂಗ್ಲಿಷ್ನಲ್ಲಿ ಲಭ್ಯವಿದೆ. ಕನ್ನಡದಲ್ಲಿ ಸಹಾಯಕ್ಕಾಗಿ privacy@klynea.in ಗೆ ಇಮೇಲ್ ಮಾಡಿ.
- ഈ പേജ് നിലവിൽ ഇംഗ്ലീഷിൽ ലഭ്യമാണ്. മലയാളത്തിൽ സഹായത്തിന് privacy@klynea.in-ലേക്ക് ഇമെയിൽ ചെയ്യുക.
- हे पृष्ठ सध्या इंग्रजीत उपलब्ध आहे. मराठीत मदतीसाठी privacy@klynea.in वर ईमेल करा.
- આ પૃષ્ઠ હાલમાં અંગ્રેજીમાં ઉપલબ્ધ છે. ગુજરાતીમાં મદદ માટે privacy@klynea.in પર ઇમેઇલ કરો.
- ਇਹ ਪੰਨਾ ਇਸ ਵੇਲੇ ਅੰਗਰੇਜ਼ੀ ਵਿੱਚ ਉਪਲਬਧ ਹੈ। ਪੰਜਾਬੀ ਵਿੱਚ ਮਦਦ ਲਈ privacy@klynea.in 'ਤੇ ਈਮੇਲ ਕਰੋ।
1. Who we are
Klynea (proprietor: Asiya Hashmi) is the data fiduciary responsible for the personal data processed through our patient app, clinician app, and websites. Klynea is a sole proprietorship registered in India (Udyam Reg. No. UDYAM-UP-50-0279489); our registered address is set out in the Grievance Officer section below (section 9).
2. Data we collect
We collect only what we need to provide care-related services:
- Identifiers — name, mobile number, email, date of birth, gender, and, where you choose to link it, your ABHA / Health ID.
- Health records — symptoms, diagnoses, prescriptions, lab reports, vitals, care notes, and other medical information you or your clinician add. Health data is treated as sensitive personal data.
- Account & usage data — login events, device and app version, and diagnostic logs used to keep the service secure and working.
3. Why we use your data (purpose)
We process your data to: deliver and operate the care platform; maintain your health record and share it with the clinicians you authorise; provide AI-assisted features that support (never replace) a clinician's judgement; secure your account; meet legal and regulatory obligations; and improve the service. We do not sell your personal data, and we do not use your health data for advertising.
4. Consent & withdrawal
We process your personal data on the basis of your consent, which we ask for in clear language at the point of collection. You may withdraw consent at any time from within the app or by writing to our grievance officer (see section 9). Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal, and may limit features that genuinely require that data.
5. Sharing your data
We share your data only with the clinicians and care teams you authorise, and with vetted processors (such as cloud hosting and messaging providers) who act on our instructions under contract. We may disclose data where required by law or a valid legal request. Any interoperability with India's Ayushman Bharat Digital Mission (ABDM) happens only with your explicit, per-request consent.
5a. Sub-processors & cross-border processing
To run the service we rely on a small set of vetted sub-processors, each engaged under contract and instructed to process data only for the purposes below. They fall into these categories:
- AI / large-language-model providers — to power AI-assisted features that support (never replace) a clinician's judgement. This includes OpenAI, whose processing takes place outside India.
- Payments — to process payments and refunds securely.
- Messaging & notifications — to send OTPs, transactional alerts, and service messages.
- Cloud hosting & storage — to host the platform and store your records (primarily in India, asia-south1, Mumbai).
While your health records are stored in India, some processing occurs outside India — in particular, text sent to AI providers such as OpenAI, and certain payment processing. Where data is processed outside India, we rely on contractual safeguards (including data-processing agreements, purpose limitation, confidentiality, and security obligations on the processor) and we transfer data only to the extent permitted under the DPDP Act and applicable rules. We will keep this list current as our providers change.
Our current sub-processors: OpenAI (AI features — processes consultation/record text outside India), Sarvam AI (speech recognition & translation for the AI scribe — outside India), Google (Firebase Cloud Messaging for notifications, and Google Cloud Storage in asia-south1/Mumbai for documents & recordings), Twilio SendGrid (transactional & OTP email — outside India), Sentry (error monitoring, no PHI — outside India), Cashfree (payments — in India), and MSG91 (SMS/OTP — in India). Our teleconsult/recording media server (LiveKit) is self-hosted on our own India infrastructure. We update this list as our providers change.
6. Where your data lives & how it is protected
Your records are stored in India (asia-south1, Mumbai). Some specific processing — such as certain AI features and payments — may be carried out by vetted providers outside India; see section 5a on sub-processors and cross-border processing. Data is stored onencrypted infrastructure in India and protected in transit with TLS. Selected sensitive identifiers and clinical artifacts receive an additional application-level encryption layer. Access is role-based and security-relevant activity is logged. We retain data only as long as needed for the purposes above or as required by law, after which it is deleted, de-identified, or irreversibly anonymised as appropriate.
7. Your rights as a data principal
Under the DPDP Act you have the right to:
- Access a summary of the personal data we hold about you.
- Correct or complete data that is inaccurate or out of date.
- Erase your data where it is no longer needed for the stated purpose.
- Nominate another person to exercise your rights in case of death or incapacity.
- Grievance redressal — raise a complaint and have it addressed (see section 9).
For full detail on how these rights are handled, see ourDPDP compliance notice.
8. Children's data
Where a patient is a child or a person with a disability, their account is managed by a verified parent or lawful guardian, whose consent we obtain before processing the child's data. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
9. Grievance officer
If you have any concern about how your data is handled, contact our Grievance Officer:
The Grievance Officer
Klynea — a sole proprietorship registered in India (Udyam Reg. No. UDYAM-UP-50-0279489), proprietor: Asiya Hashmi
474/9 Bari House, Kadam Rasool, Sitapur Road, Lucknow, Uttar Pradesh 226020, India
Email: grievance@klynea.in
We will acknowledge your grievance and respond within the timelines required under the DPDP Act and Rules. If unresolved, you may escalate to the Data Protection Board of India.
11. Changes to this policy
We may update this policy as the product and the law evolve. Material changes will be notified in the app or by email, and the "last updated" date above will change.
12. Contact
Questions about privacy? Write to us atprivacy@klynea.in.
