Published under the IT (SPDI) Rules, 2011 · Last updated 21 July 2026

Privacy policy.

Parchi (for solo clinics) and ClinicOps (for hospitals) are clinic and hospital operating systems built by Logicues. Facilities use them to run bookings, prescriptions, patient records, billing and WhatsApp communication. This page explains — in plain language — what data lives on the platform, why, for how long, and what rights you have over it. It is published as required by Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

Who does what

Your clinic collects; Parchi processes

Your healthcare provider (the clinic you visit) collects your information to treat you and manage your visits. Parchi (operated by Logicues) provides the software the clinic uses and processes that information on the clinic's behalf. Each clinic's data is kept isolated from every other clinic's.

What we collect

Data in Parchi — including sensitive personal data

CategoryExamplesSPDI?
Patient demographicsName, phone number, age, sex, addressPartly (contact data)
Clinical recordsComplaints, diagnoses, prescriptions, vitals, allergies, lab results, uploaded reports and documentsYes — medical records and history are sensitive personal data under Rule 3
Appointment & communication dataBookings, queue numbers, reminder and WhatsApp message logsNo, but protected the same way
Clinic staff accountsStaff name, username, role, login activityNo

We do not collect financial information such as card numbers into patient records. Payments, where used, are handled by regulated payment providers.

Why we collect it

Purpose of collection

Information is used only for the purpose it was collected for, and only for as long as it is required. We never sell your data, and we do not share prescription data with pharmaceutical companies or advertisers.

Consent

Your consent, and your right to withdraw it

Your clinic obtains your consent when it registers you and records your visits. Consent for WhatsApp communication is taken as an explicit opt-in and is logged. You may decline to provide information or withdraw consent at any time by writing to your clinic; the clinic may then be unable to provide services that depend on that information. Consent records are kept in the platform's audit trail.

WhatsApp messages, specifically: we only send message types you've opted into — appointment confirmations and reminders, your prescription and bill, and (if enabled) recall messages — sent through WhatsApp Business Platform in the message categories Meta's Business Messaging Policy permits (utility and, where separately opted in, marketing templates). To stop WhatsApp messages at any time, reply STOP to any message from your clinic's WhatsApp number, or ask your clinic to turn off reminders for you — either way takes effect immediately and is logged the same as any other consent withdrawal.
Retention

How long records are kept

Clinical records are retained for a minimum of 3 years from the date of the last entry, supporting the record-keeping duty placed on physicians by the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002. Beyond the period required for the purpose (or by law), data is not retained. Patients may request erasure of their records; erasure is honoured except where the clinic is legally required to keep the record.

Disclosure

Who can see your data

No third party is given access to sensitive personal data for its own purposes without your consent.

Where your data lives

India data residency

Parchi's servers and databases are hosted in India, and patient data is stored at rest in India. Sensitive data is encrypted in storage and in transit — details are on our security practices page.

Your rights

Access, correction and erasure

Grievances

Grievance officer

First point of contact: your clinic's grievance officer

Each clinic on Parchi designates a grievance officer for its patients (named at the clinic and on its Parchi profile). Grievances are addressed within one month of receipt, as required by Rule 5(9).

Platform contact: Logicues

For grievances about the platform itself, write to [email protected]. Grievances are acknowledged and addressed within one month of receipt.

Grievance Officer: Logicues, Akola, Maharashtra, India · [email protected]

Looking ahead

DPDP Act readiness

The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 in three phases: the Data Protection Board provisions are already in force; Consent Manager registration rules commence 13 November 2026; and the substantive obligations that govern day-to-day processing — notice, consent standards, retention/deletion, security safeguards, and data-principal rights — commence 13 May 2027. Until then, the SPDI Rules, 2011 (this policy) govern. The platform already ships DPDP-supporting features — consent logging, audit trails, data export and erasure workflows — and this policy will be updated to reflect the May 2027 obligations before they take effect. ABDM (Ayushman Bharat Digital Mission) integration is on our roadmap; we do not currently make any ABDM claims.