Privacy Policy

Last updated: 20 July 2026

Navino Health provides clinic-management software to healthcare providers in India. This policy explains what personal data we handle, why, where it is stored, and how it is protected.

1. Who is responsible for your data

This distinction matters, because it determines who you should contact about your data.

For patient data — your clinic is responsible. When a clinic uses Navino Health to record appointments, prescriptions, invoices, clinical notes or reports, the clinic decides what is collected and why. Navino Health stores and processes that data on the clinic's instructions and does not use it for its own purposes. If you are a patient, please direct requests about your medical records to your clinic in the first instance.

For clinic account data — we are responsible. Information about the clinic as our customer — staff logins, contact details, subscription and billing records, support correspondence — is handled by Navino Health directly.

2. What we process

Patient data, on behalf of clinics: name, age, gender, contact number, address, and the clinical record a clinic chooses to keep — appointments, vitals, clinical notes, prescriptions, test orders, invoices, and any reports or scans the clinic uploads.

Clinic and staff data: clinic name and address, staff names, usernames, optional contact email and phone, doctor qualifications and medical registration numbers, and authentication data including two-factor credentials.

Technical data: server and security logs necessary to operate the service, and an audit trail of actions taken inside a clinic's workspace.

We do not run third-party analytics or advertising trackers. There is no Google Analytics, no advertising pixel, and no session-replay tool on this platform. We do not sell personal data, and we never use patient data to train machine-learning models.

3. Where your data is stored

Patient and clinic data is stored in India. Our database and file storage run in the Mumbai region, and the application servers that process requests are also located in Mumbai.

Certain limited data leaves India where a service inherently requires it — most notably WhatsApp message delivery (see section 5). Where that happens we keep the data sent to the minimum necessary.

4. How we protect it

Clinic-level isolation is enforced by the database, not just the application. Every record carries its clinic's identity, and row-level security policies in PostgreSQL prevent one clinic's account from reading another's data — even if application code were to contain a bug.

Two-factor authentication is mandatory for every staff account, not optional.

Data is encrypted in transit (HTTPS/TLS) and at rest. Patient documents are held in private storage that is never publicly accessible. Signed prescriptions and issued invoices are locked against modification at the database level, and access to a clinic's workspace is recorded in an audit trail.

No system is perfectly secure. We do not claim certification under any security standard, and we will say so plainly if that changes.

5. Services we rely on

We use a small number of service providers to run the platform. Each receives only what it needs:

  • Supabase — database, authentication and file storage, hosted in Mumbai, India.
  • Vercel — application hosting, serving from Mumbai, India.
  • Meta (WhatsApp Business Platform) — used only when a clinic sends a patient an appointment confirmation or a link to their visit documents. We send the patient's name and phone number so the message can be addressed and delivered. We do not send clinical content, prescriptions or documents through WhatsApp. Documents are shared as a secure link that requires the patient to confirm their own phone number before anything is shown. Meta processes message delivery outside India under its own terms.
  • Google — used only if a clinic chooses to connect its public Google Business listing to display its own ratings and reviews. No patient data is sent to Google.

6. Patient document links

When a clinic shares a visit summary, the patient receives a link containing a long random token. Opening it is not enough to see anything: the patient must first confirm their own phone number, attempts are rate limited, the resulting session is short-lived, and the link covers only that single visit. Links expire, and a clinic can revoke access.

7. How long we keep data

Clinics decide how long to retain their patients' records, in keeping with medical record-keeping obligations. We retain data for as long as the clinic's account is active and it instructs us to.

Signed prescriptions and issued invoices are deliberately preserved as unalterable records, because they are legal and tax documents.

If a clinic closes its account, we will return or delete its data on request, subject to any period we are legally required to retain it. Backups are retained on a rolling basis and are overwritten in the ordinary course.

8. Your choices

Patients should contact their clinic to see, correct or delete their records — the clinic holds them and decides how they are handled. If you contact us directly about patient data, we will refer you to the clinic and assist it in responding.

Clinics can access, export, correct or delete their own account data at any time, either in the application or by writing to us.

9. Cookies

We use cookies only to keep you signed in and to secure your session. There are no advertising or tracking cookies on this platform, so there is nothing to opt out of.

10. Children

Clinics treat children as patients, and their records are handled with the same protections as any other patient record, under the supervision of the clinic and the child's parent or guardian. The Navino Health platform itself is not intended for use by children.

11. Changes to this policy

We will update this page when our practices change, and revise the date at the top. Material changes affecting clinics will be notified directly.

12. Contact

Questions or concerns about privacy? Write to hello@navinohealth.com. We aim to respond within three working days.