Privacy Policy
Last Updated: July 23, 2026
This Privacy Policy describes how Dapto (VISPL), operated by Vinfocom IT Services Private Limited ("VISPL", "Dapto (VISPL)", "we", "our", or "us"), collects, uses, discloses, stores, and safeguards your information when you use the Dapto mobile application, website, and related services.
1. Information We Collect
- Account and profile data, including your name, email, phone number, role, clinic details, profile photo, qualifications, medical registration number, and related profile information.
- Patient, appointment, and healthcare data, including patient details, appointment information, follow-ups, live queue data, booking history, and related healthcare records.
- Electronic Medical Record (EMR) data, including complaints, diagnosis, medical history, examination findings, vital signs, prescriptions, medicines, dosage instructions, tests, advice, follow-up notes, and other clinical records created by authorized healthcare professionals.
- Communication data, including in-app messages, announcements, emails, SMS notifications, OTP records, and related metadata such as timestamps and delivery status.
- Uploaded files, including profile images, prescription images, scanned prescriptions, medical documents, reports, clinic barcode images, and chat attachments.
- Notification data, including push notification tokens used for reminders, alerts, and announcements.
- Authentication and session data, including hashed passwords, authentication tokens, session identifiers, verification records, and security logs.
2. Device Permissions We Use
- Camera: To capture profile photos, prescription images, medical documents, reports, and chat attachments when you choose.
- Photos/Media Library: To select and upload images, prescriptions, reports, documents, and other files from your device.
- Notifications: To send appointment updates, announcements, and chat alerts (when enabled by you).
- Storage/Files Access (where applicable): To upload, export, download, print, or save prescriptions, reports, and other generated files.
3. How We Use Information
- Create and manage user accounts and provide secure authentication.
- Verify user identity through email or phone-based verification where applicable.
- Schedule, manage, and track appointments, follow-up visits, live queues, and clinic workflows.
- Create, store, retrieve, view, print, download, and manage Electronic Medical Records (EMRs) and digital prescriptions.
- Enable communication between doctors, patients, clinic staff, and administrators.
- Send appointment reminders, OTP verification, notifications, announcements, and other service communications.
- Record medical documents, scanned prescriptions, reports, and other files required for services.
- Maintain platform security, detect fraud or misuse, troubleshoot technical issues, and improve service reliability.
- Analyze aggregated or de-identified information to improve platform functionality, monitor performance, develop new features, and enhance user experience where permitted by applicable law.
4. Legal Basis and Necessity of Processing
We process personal information where necessary to provide our Services, fulfill contractual obligations, comply with applicable legal obligations, protect legitimate interests, and obtain consent where required by applicable law.
Personal information is processed only to the extent necessary to provide healthcare management services, account authentication, appointment management, Electronic Medical Records, communication services, customer support, security, and related platform functionality.
5. How Information Is Shared
We do not sell your personal information for any other illegal activities.
We may share information only in the following circumstances:
- With service providers and infrastructure partners that help us operate the Services, including cloud hosting, storage, communication, email, SMS, notification delivery, and other technical infrastructure providers.
- Within your authorized healthcare workflow, including doctors, patients, clinic staff, and administrators, strictly in accordance with role-based access controls and only where necessary to provide healthcare services.
- When required by applicable law, legal process, court order, governmental authority, or to protect the rights, safety, security, or property of users or Dapto (VISPL).
6. Data Retention
We retain personal information only for as long as necessary to provide our Services, comply with applicable legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate operational requirements.
Medical records, prescriptions, appointment records, and related healthcare information may be retained for periods required by applicable laws, healthcare regulations, professional record-keeping obligations, or legitimate operational needs.
Data may also be securely backed up for disaster recovery, business continuity, and system restoration purposes.
7. Data Security and Confidentiality
We implement reasonable technical, administrative, and organizational measures to protect personal information against unauthorized access, disclosure, alteration, misuse, or loss.
Sensitive healthcare information is handled as confidential information with role-based access controls, secure authentication mechanisms, and other appropriate safeguards.
Access to patient medical records is restricted based on user roles so that only authorized healthcare professionals, patients, clinic staff, and administrators can access information necessary for their responsibilities.
Uploaded files, including prescription images, reports, and medical documents, are stored using cloud infrastructure.
While we implement reasonable and industry-standard security measures, no method of electronic transmission or storage is completely secure. Accordingly, we cannot guarantee absolute security, and we shall not be liable for unauthorized access, disclosure, or data breaches resulting from circumstances beyond our reasonable control.
8. Your Choices and Rights
Subject to applicable law, you may have the right to access, correct, update, or request deletion of your personal information.
Account deletion requests may be submitted by contacting us using the contact information provided below. Upon verification, we will process such requests in accordance with applicable laws, operational requirements, and our data retention practices.
Where permitted or required by law, certain healthcare records, prescriptions, appointment records, audit logs, or other information may be retained for legal, regulatory, security, dispute resolution, or legitimate business purposes.
Parents, legal guardians, or authorized representatives may manage information relating to minor patients where permitted by applicable law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will become effective when the updated Privacy Policy is published. The "Last Updated" date at the top of this Privacy Policy will indicate the latest revision.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us:
Email: dapptosupport@gmail.com, operations@vinfocom.co.in
Dapto (VISPL)
Vinfocom IT Services Private Limited (VISPL)
11. Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of India.
Any dispute arising out of or relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts located in Delhi, India.