Privacy Policy
This Privacy Policy explains how NBALL TECHNOLOGIES INDIA PRIVATE LIMITED (“Cynaps”, “we”, “us”), a private company incorporated under the Companies Act, 2013 (CIN: U62099TS2025PTC196111) with its registered office at 2-4-821/1, 19/7, Road No. 1, New Nagole, Alkapuri, Saroornagar, Hyderabad – 500035, Telangana, India, collects, uses, discloses, and protects personal data when you access the Cynaps platform, mobile applications, APIs, and related services (the “Service”). It applies to all users of the Service in India and is to be read together with our Terms of Service and Refund & Cancellation Policy.
The shorter notice required by section 5 of the DPDP Act — what we process, why, and how to exercise your rights — is published separately and is available in English and in each of the twenty-two languages of the Eighth Schedule: read the Privacy Notice in your language.
1.Our Roles Under the DPDP Act, 2023
Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”):
- For data you provide about yourself (account, profile, billing, usage telemetry), Cynaps is the Data Fiduciary and you are the Data Principal.
- For data you upload about your patients (clinical notes, attachments, transcripts), you are the Data Fiduciary and Cynaps is the Data Processor, processing patient data only on your documented instructions.
2.Personal Data We Collect
We collect the following categories of personal data:
- Account & identity: name, email address, phone number, professional registration number and the medical council that issued it, HPR ID, specialty, designation, profile image.
- Authentication: hashed credentials, OTP records, device identifiers, IP address, user-agent.
- Billing: plan, payment status, GSTIN (if provided), and tokenised payment instrument references. We do not store full card or bank-account numbers; these are handled directly by our payment processor, Razorpay.
- Usage & telemetry: pages visited, features used, queries, error logs, latency measurements, session timings.
- User Content: clinical notes, voice transcripts, attachments (PDFs, images), and any other content you upload. May include patient personal data.
- Consultation recordings: where you use Cynaps Scribe to capture a consultation, the audio recording of that consultation and the transcript derived from it. Recorded only after the clinician confirms the patient was told and agreed. See Section 7 for how long these are kept and Section 8 for how to have them deleted.
- Dictation audio: where you dictate into a note or a form — the medical certificate, the referral letter, case notes — the short recording is transcribed to text and then deleted as soon as transcription finishes, whether or not it succeeded; only the resulting text is kept. Clinical Journal dictation is the exception: the recording is kept for a short window — up to 30 days so we can help if you report a problem with a transcription, or up to 90 days if you opt in to improving speech recognition — and then deleted automatically (Section 7). In every case a metadata record (duration, size and a content hash — never the audio itself) is kept in the audio ledger.
- Patient signatures: where a document requires the patient's signature or thumb impression — a medical certificate must, under the IMC Professional Conduct Regulations — the mark drawn on screen is stored with that document. It is held encrypted, and for a patient under 18 it is the guardian's signature that is taken and recorded as such.
- Support communications: email and message logs when you contact us.
3.Lawful Basis for Processing
We process personal data on the following lawful bases under the DPDP Act:
- Consent (Section 6) — obtained at registration and renewed for specific processing (e.g. marketing, optional analytics).
- Legitimate use (Section 7) — for service delivery, billing, fraud prevention, security incident response.
- Compliance with law — e.g. tax invoicing under the GST Act, intermediary compliance under IT Rules 2021, CERT-In reporting.
4.How We Use Personal Data
- To create and operate your account, authenticate you, and deliver the Service.
- To process subscriptions, charge payments through Razorpay, and issue tax invoices.
- To provide customer support and respond to your queries.
- To maintain security, prevent abuse, detect fraud, and investigate incidents.
- To comply with legal obligations, including tax and regulatory reporting.
- To send service-related notifications (downtime, policy changes, security alerts).
- To improve the Service through aggregated, de-identified analytics.
- To evaluate and improve our speech-to-text — but only your dictation recordings, and only if you opt in (“Keep my dictation recordings to improve speech recognition” in Settings → Privacy, off by default). You can withdraw at any time; see Section 7 for how long recordings are kept.
We do not use your User Content (including patient data) to train or fine-tune foundational AI models. AI inference happens for your session and is not retained for model improvement. The one exception is speech recognition: where you opt in, we keep your dictation recordings (Section 7) to measure and improve our own speech-to-text — this is off by default, involves the recordings only (never a patient record), and never trains a foundational model. Separately, a limited internal quality-review programme may surface individual AI question-and-answer pairs (not patient records) to authorised reviewers to assess and correct answer quality; these review records are access-controlled and are likewise not used to train foundational models.
5.Sharing and Sub-Processors
We do not sell personal data. We share data only with the following categories of recipients, under contractual obligations binding them to confidentiality and data-protection standards consistent with the DPDP Act:
- Razorpay Software Private Limited — payment processing, subscription management, eMandate / autopay registration.
- Cloud infrastructure providers hosting compute and storage within India (MeitY-empanelled where applicable).
- Communications providers for transactional email, SMS / WhatsApp OTP, and customer support tooling — including Meta Platforms (WhatsApp Business API) when you or your patients opt in to WhatsApp delivery.
- AI model providers — currently Google (Gemini), Anthropic (Claude) and Groq — for AI inference, including transcription of dictated and recorded audio and interpretation of uploaded reports and imaging. Each is engaged under data-processing terms that prohibit training on your content; retention at the provider is governed by those terms and by the provider's own policy for the API tier in use, and we do not control processing once content is transmitted. Identifiers in medical imaging are scrubbed before transmission. Referral letters are de-identified before transmission — the patient's name is replaced by a placeholder and restored only after the draft returns, and the clinical text you type is stripped of names, phone numbers, email addresses, Aadhaar/ABHA numbers, record numbers, dates of birth and street addresses; age and sex are sent, because the letter cannot be written without them. Medical certificates are de-identified the same way — the patient's name is replaced by a placeholder and restored after the draft returns, the condition, purpose, travel mode and advice you type are stripped of names, phone numbers, email addresses, Aadhaar/ABHA numbers, record numbers, dates of birth and street addresses, and the free notes you add are never transmitted at all. Age, sex and the certificate dates are sent, because the certificate cannot be phrased without them; the diagnosis is sent only if you choose to name it on the certificate, and not otherwise. Audio is not redacted before transmission — speech must be transcribed before anything in it can be identified, so a consultation recording reaches the transcription provider complete, including names spoken aloud and the patient's voice; redaction is applied to the resulting transcript. Where a dictated note is then structured by a model — as in the Clinical Journal — direct identifiers in the transcript (names, phone numbers, e-mail addresses, record numbers and dates) are replaced with neutral placeholders before the text is transmitted and restored only after the model responds, so that model never receives them. Patient education leaflets are written from the condition, not from the patient — the topic and the reading level are transmitted, the patient's name and age are never transmitted at all (the name is printed onto the leaflet after it comes back), and the free-text context you add is stripped of names, phone numbers, email addresses, Aadhaar/ABHA numbers, record numbers, dates of birth and street addresses before it is sent. The Drug Interaction Checker transmits only generic drug names — the molecules in the medicines you enter — and never any patient data; its results are not stored against a patient record. Some inference may be processed on servers outside India in accordance with Section 16 of the DPDP Act (see Section 6 below).
- LiveKit — real-time video infrastructure for teleconsultations. Calls are relayed, not recorded.
- Authorities and law-enforcement on receipt of a valid legal order under Indian law.
A current list of named sub-processors can be requested at grievance@cynaps.co.
Patient education leaflets shared by link. A leaflet your doctor prepares for you can be sent to you by email or WhatsApp as a link that opens a public page requiring no login — the point of it is that you can read it on your phone without an account. That is a disclosure to whoever holds the link, and it is listed here for the same reason the certificate page is. The page shows the leaflet and, where the doctor personalised it, the name it was prepared for. It shows nothing else about you: no contact details, no record identifier, no clinical history.
The link does not stay open. It stops working 90 days after the leaflet is made, and the clinician can revoke it at any time before that, after which the page says the leaflet is no longer available. Each time the page or its PDF is opened is recorded against the leaflet — the date and time, the IP address and the browser — so the clinician can account for who saw it; the page itself says so. Requests are rate-limited per link and per address so a leaked link cannot be scraped.
Public verification of medical certificates. A medical certificate is written to be given to someone else — an employer, a school, an airline, an insurer — so every issued certificate carries a QR code and a reference number that resolve on a public page requiring no login. This is a disclosure to whoever holds the certificate, not a transfer to a sub-processor, and it is listed separately for that reason. We ask for no account, password or one-time code from the person checking: that would identify a reader rather than the right one, and would mean collecting contact details for someone we otherwise hold nothing about.
That page shows only what confirms the certificate is genuine and belongs to the person presenting it: the certificate type, its reference, the patient's given name and the initial of their surname, the issuing clinician, clinic and registration, the date of issue and the period covered, together with a document identifier and the result of a digital signature check. It does not show the full name, any internal patient identifier, the diagnosis, contact details, or the text of the certificate.
The link on its own reveals none of that. Scanning the QR confirms only that a certificate with that reference exists; the details above appear once the reader enters the document identifier printed on the certificate, which is deliberately not carried in the link. Access is therefore tied to holding the document rather than to holding a forwarded URL. Attempts are limited both per address and per certificate, and verification pages are served so that they cannot be indexed by search engines, leak through a referrer header, or be retained by a shared cache.
A bare scan is not recorded, because it discloses nothing. What is recorded against the certificate is each occasion the details were actually revealed — and, separately, failed attempts, so that a link being probed is visible. That record is available to the clinician and forms part of the data we return on a request under Section 8.
Online checking is not open indefinitely: it closes one year after the later of the date of issue and the end of the period the certificate covers, after which the page says the check has closed and that the clinic still holds the certificate — never that it is unknown. A patient may also ask for online checking to be switched off entirely, and the practice can do so at any time; the page then says so in those terms. Neither withdraws the certificate nor calls it invalid. Where a patient has asked for erasure (Section 8), the page states that the certificate was erased at their request and shows nothing further.
6.Cross-Border Data Transfers
Primary storage of personal data (including User Content) is located within India. Limited transfers outside India may occur for the purpose of AI inference and certain cloud services, in accordance with notifications issued by the Central Government under Section 16 of the DPDP Act. Where data is transferred outside India, we ensure equivalent contractual safeguards.
7.Data Retention
We retain personal data only as long as necessary for the purposes described:
- Account data — for the life of the account plus 90 days after deletion request (for grace-period reactivation and to honour pending billing obligations).
- Billing and tax records — eight (8) years from the end of the relevant financial year, as required under Indian tax law.
- User Content (clinical) — until you delete it or close your account, except where a specific rule below applies; backups are purged within 30 days.
- Consultation recordings — Cynaps Scribe — retained indefinitely where the recording is linked to a patient record, so the notes drawn from it can be checked against what was said. They are not deleted when the note is written. They are deleted when the recording is deleted from the patient's Audio files tab, when the patient withdraws ambient-recording consent (which erases the audio automatically), or on account closure. A recording captured for a walk-in and never linked to a patient record is deleted automatically after 90 days. Deleting a recording removes the audio only — the clinical note it produced is part of the medical record and is retained.
- Dictation audio — on the clinical-form microphones (referral letters, medical certificates and case notes) the recording is deleted immediately after the dictation is transcribed, including when transcription fails; only the resulting text is retained. Clinical Journal dictation is kept for a bounded window and then deleted automatically by a daily sweep: up to 30 days for every dictation, so support can investigate a transcription problem you report, and up to 90 days where you have opted in to improving speech recognition (Settings → Privacy, off by default). Withdrawing that opt-in returns your recordings to the 30-day window; a data-erasure request deletes them outright. Dictation audio is never kept for later playback the way a Cynaps Scribe consultation recording is, there is no surface to replay it, and it is encrypted at rest. A metadata record (duration, size and a content hash — never the audio itself) is kept in the audio ledger so every recording a clinician has made remains accountable.
- Antibiotic Advisor assessments — the patient attributes entered for an advisory (age, weight, pregnancy, kidney function, allergies, current medications) are de-identified automatically after 90 days; the remaining de-identified recommendation is deleted after three (3) years, unless a specific assessment is under a legal hold. A record of every emailed advisory is kept as a disclosure log.
- Referral letters — a saved referral letter is disposed of automatically three (3) years after it is written, following the outpatient-record norm. Disposal erases the letter, the intake it was drafted from, the patient's name, the specialist's email address and the link to the patient record; what remains is a de-identified record that a referral was made, to which specialty, and when. Deleting a letter yourself is a withdrawal, not an erasure — it is retracted from use and the record is kept, and it is disposed of on the same three-year clock. A letter under a legal hold (for a complaint or inquiry) is exempt until the hold is lifted. A record of every letter emailed or shared is kept as a disclosure log, which outlives the letter itself. The patient's phone number is dropped from the letter's intake as soon as the letter is saved — it is carried only so that saving can file the letter against a patient record, and the number is held on that record instead. Erasure at a patient's request is a separate action, described in Section 8: it removes the intake, the patient's name and the link to the patient record, and strikes the name out of the letter itself, leaving the clinical narrative with no one named in it, sealed so it can no longer be opened, downloaded or sent.
- Medical certificates — an issued certificate is deleted automatically three (3) years after the date of issue, following the clinical-records norm, together with the log of who opened, downloaded, sent or verified it. A certificate that was drafted but never issued is deleted after 90 days from the last time it was edited; editing it starts that period again. Deleting a certificate yourself is a withdrawal, not an erasure — it is retracted from your list and the record is kept, because a withdrawn certificate is the one most likely to be queried later, and it is deleted on the same three-year clock. Erasure at a patient's request is a separate action, described in Section 8.
- Patient education leaflets — a leaflet prepared for a named patient is disposed of automatically three (3) years after it is made, following the outpatient-record norm. Disposal erases the patient's name, their age and the context the clinician typed, and closes the share link; what remains is the leaflet itself with no one named in it. The clinician can do the same at any time from the tool (Erase patient data), and can revoke the share link on its own without erasing anything. A generic leaflet — one made for no particular patient — is library content, holds no personal data, and is kept and reused. The record of who opened the link, and of every leaflet emailed or sent on WhatsApp, is kept as a disclosure log and outlives the leaflet it refers to.
- Clinical calculators — not retained at all. The values you enter into a calculator (age, observations, laboratory results) are computed in memory and returned to you; they are never written to storage, never linked to a patient record, and never sent to an AI provider. Closing the page is the deletion, and there is nothing left in the calculator to erase on request. A record that a calculator was used — which calculator, by whom, when, never the values and never the score — is kept with server logs under the 180-day rule below. Where you use the Copy control to put a result into a patient's record, what you paste becomes part of that record and is kept under the rules for your clinical notes rather than this one; the calculator still keeps nothing, and the copy travels no further than your own clipboard.
- Server logs and telemetry — up to 180 days, then purged or de-identified.
- Security / incident records — up to 180 days, subject to CERT-In retention directions.
8.Your Rights as a Data Principal
Under Sections 11–14 of the DPDP Act, you have the right to:
- Access a summary of personal data we process about you.
- Correct inaccurate or incomplete data.
- Erase personal data when no longer required for the original purpose, subject to legal-retention obligations.
- Withdraw consent at any time, where processing relies on consent.
- Nominate another individual to exercise these rights in case of your death or incapacity. You can record a nominee — name, relationship and contact — under Settings → Privacy. A nominee is a record only: they gain the right to ask, and are given no account, login or access of any kind.
- Grievance redressal — first to our Grievance Officer (see Section 13), and thereafter to the Data Protection Board of India.
Consultation recordings. A patient's recordings can be played back and deleted directly by their clinician, from the Audio files tab on the patient's record — individually or all at once. Every deletion is written to that patient's consent ledger, so when a recording was deleted and on whose authority stays answerable. Every time a recording is played back it is logged — who listened, when, and from where — and that log is retained after the audio itself is deleted, so “who has heard my consultation?” remains answerable. This logging currently covers consultation recordings and medical certificates; other clinical records are not access-logged.
Medical certificates. A patient may ask for their details to be erased from a certificate, and their clinician can do this directly. Erasure deletes the phone number, email address, age, sex and the condition entered for the certificate; removes the patient's name and internal identifier; deletes the addresses the certificate was sent to from its disclosure log; and closes the certificate so it can no longer be opened, downloaded, sent or verified by its QR code. It cannot be reversed, and the clinician records who asked for it and when.
Referral letters. A patient may ask for their details to be erased from a referral letter, and their clinician can do this directly — including from a letter already withdrawn from their list, because a patient's right does not wait. Erasure deletes the intake the letter was drafted from (name, age, sex and phone number as typed, and the referral target), removes the patient's name and the link to their patient record, removes the patient's phone number from the letter's disclosure log, and strikes the patient's name out of the letter itself. The letter is then closed, so it can no longer be opened, downloaded, edited or sent. It cannot be reversed, and the clinician records who asked for it and when.
What erasure cannot remove, and why. The patient's signature on the certificate is kept, and so is the text of an issued certificate — sealed and unreadable through the Service — until the three-year retention period in Section 7 ends, after which it is deleted with everything else. An issued certificate is a clinical record the practice is required by law to hold for that period, and Section 17(1) of the DPDP Act preserves processing that another law requires. The same rule keeps the signature: the Regulations require the retained copy to carry it, so a copy without it is one the rules call incomplete. Both are sealed rather than readable — an erased certificate cannot be opened, downloaded, sent or verified by anyone. Erasure therefore removes everything the law does not require us to keep, and stops the certificate being used or disclosed for anything at all. It also cannot reach a copy already handed over or emailed to a patient, an employer or an authority; it covers the copy the clinic holds.
To exercise these rights, write to grievance@cynaps.co from your registered email address. We will respond within the timeline prescribed by the DPDP Act (currently 30 days, extendable on notice).
10.Children
Accounts. The Service is not intended for individuals under 18, and we do not knowingly allow a minor to register. If you believe a minor has registered, please write to grievance@cynaps.co and we will close the account and erase the associated data.
Patients. A clinician using Cynaps may, however, treat and document care for a child, so patient data held in the Service may relate to someone under 18. Where it does, Section 9 of the DPDP Act applies and the consent of a parent or lawful guardian is required. The clinic obtains that consent as the Data Fiduciary; Cynaps records it.
In practice this means an ambient recording (Cynaps Scribe) cannot be started for a patient under 18 unless the parent or guardian who agreed is named on the record — the request is refused otherwise, and a child's consent can never be stored as self-given. That guardian is then carried onto every later consent, withdrawal and deletion for the patient, so those acts are attributed to the person entitled to make them.
We do not carry out tracking, behavioural monitoring or targeted advertising directed at children, as prohibited by Section 9(3).
11.Security Safeguards
We implement reasonable security practices proportionate to the risk, including:
- Encryption of data at rest (AES-256) and in transit (TLS 1.2 or higher). Stored files — consultation recordings, patient documents and attachments — are individually encrypted with an authenticated cipher, so a modified file fails to open rather than returning altered content. Clinical records held in the database are encrypted the same way, field by field: this currently covers referral letters and medical certificates — the document text, the details entered to produce it, and any patient signature — with each value carrying the identifier of the key that sealed it so keys can be rotated without a single mass re-encryption.
- Least-privilege access controls and audit logging for production systems.
- Hashed passwords (bcrypt) — we never store credentials in clear text.
- Multi-factor authentication for administrative access.
- Periodic vulnerability testing and timely application of security patches.
- Tokenisation of payment instruments via Razorpay; PAN/CVV are never stored on Cynaps systems.
No system is perfectly secure. You are responsible for keeping your credentials confidential and reporting any suspected unauthorised access at support@cynaps.co.
12.Breach Notification
In the event of a personal data breach likely to result in harm to you, we will notify you and the Data Protection Board of India in accordance with the DPDP Act and applicable CERT-In directions. Where Cynaps acts as Data Processor for patient data uploaded by you, we will notify the affected Data Fiduciary (i.e. you) without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach.
13.Grievance Officer
In accordance with the IT Rules, 2021 and Section 8(10) of the DPDP Act, our designated Grievance Officer is:
the Authorised Signatory of NBALL Technologies India Private Limited
For and on behalf of NBALL TECHNOLOGIES INDIA PRIVATE LIMITED
Email: grievance@cynaps.co
Phone: +91 91210 61239
Address: 2-4-821/1, 19/7, Road No. 1, New Nagole, Alkapuri, Saroornagar, Hyderabad – 500035, Telangana, India
Grievances are acknowledged within 24 hours and resolved within 15 days. If you are not satisfied with the resolution, you may approach the Data Protection Board of India under Section 13 of the DPDP Act.
14.Changes to This Policy
We may amend this Policy from time to time. Material changes will be notified by email and/or in-product banner at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.
15.Contact Us
For any privacy-related question, complaint, or request, please write to grievance@cynaps.co or contact our Grievance Officer (Section 13).
Privacy queries: grievance@cynaps.co · General support: support@cynaps.co
