Privacy Policy
Effective date: 15 July 2026 · Last updated: 16 July 2026
This Privacy Policy explains how RURINFRA TECHNOLOGIES PRIVATE LIMITED (“OPDesk”, “we”, “us”) collects, uses, and protects personal data when doctors and clinics (“Practices”) use the OPDesk appointment-booking service, and when patients book appointments through a Practice using OPDesk.
1. Who we are & our two roles
OPDesk is a booking tool that Practices use to manage their own appointments. Our role depends on whose data it is:
- Practice & account data — for the doctor/clinic that signs up (owner name, email, phone, practice details), we are the Data Fiduciary (controller).
- Patient data — for patients who book with a Practice (name, phone, appointment details), the Practice is the Data Fiduciary and OPDesk acts as a Data Processor handling that data on the Practice’s instructions. OPDesk does not use patient data for its own marketing and does not sell it.
References to “personal data” and to the roles above follow India’s Digital Personal Data Protection Act, 2023 (DPDP Act).
2. Information we collect
| Category | Examples | From whom |
|---|---|---|
| Account data | Owner name, email address, mobile number, hashed password, practice name | The Practice owner at sign-up |
| Practice configuration | Clinic names, addresses, doctors, specialties, working hours, availability | The Practice |
| Patient booking data | Patient name, mobile number, chosen clinic/doctor, appointment date & time, cancellation status | The patient, at the time of booking |
| WhatsApp booking data | The patient's WhatsApp phone number and the messages they send when booking with a Practice over WhatsApp | The patient, via WhatsApp (received from Meta Platforms) |
| Verification data | One-time passwords (OTPs) and verification tokens used to confirm a phone or email | Generated by OPDesk |
| Technical data | IP address, device/browser type, timestamps, and basic logs used for security and abuse-prevention | Automatically, on use |
We do not intentionally collect medical records, diagnoses, or clinical notes through OPDesk. Patients should not send sensitive health details in the booking flow.
3. How we use personal data
- To create and secure Practice accounts and authenticate logins.
- To show availability, take bookings, and send booking confirmations, reschedules, and cancellation links by SMS and/or WhatsApp.
- When a patient messages a Practice's WhatsApp number, to read those messages and use their WhatsApp number to identify them and to show availability, book, reschedule, or cancel appointments — no separate password or OTP is needed, because WhatsApp has already verified the number.
- To verify phone numbers and email addresses and to prevent fraud, spam, and OTP abuse.
- To operate, maintain, secure, and improve the service.
- To comply with legal obligations and respond to lawful requests.
4. Legal basis / consent
We process personal data on the basis of the consent obtained at sign-up or at booking, and for the legitimate uses permitted under the DPDP Act (for example, providing a service a person has asked for). Patients provide their number to a Practice in order to be booked; the Practice is responsible for obtaining any consent it needs from its patients.
5. Sharing & third-party processors
We do not sell personal data. We share it only with service providers who help us run OPDesk, under contractual confidentiality and data-protection terms:
- Hosting & database — Railway, Vercel, AWS, and GCP, to run the application and store data.
- Messaging — Pinnacle, MSG91, or Twilio and Meta Platforms (WhatsApp Business), to deliver OTPs, confirmations, and reminders.
- The Practice you booked with — patient booking data is made available to that Practice, which owns the patient relationship.
Information we receive from the WhatsApp Business Platform (Meta) is used only to provide the booking service described in this policy, on behalf of the Practice, and is handled in line with Meta's Platform Terms. We do not use it for advertising, and we do not share it beyond the processors listed above and the Practice you booked with.
We may also disclose data where required by law, or to protect the rights, safety, and security of OPDesk, our users, and the public.
6. Government & law-enforcement requests
We sometimes receive requests from courts, police, regulators, or other public authorities asking us to disclose personal data, including data we receive from the WhatsApp Business Platform (Meta). We handle every such request under a documented internal policy, and we disclose data only where we are legally required to:
- Legality review. Before responding, we review each request to confirm it is lawful and valid, comes from an authority with jurisdiction, and follows due legal process. Requests that are invalid on their face are refused or returned for correction.
- Challenging unlawful requests. Where we believe a request is unlawful, overbroad, or improper, we may challenge, narrow, or seek to set it aside, and we take legal advice before disclosing anything.
- Data minimisation. We disclose only the minimum personal data the lawful request actually requires — never our full records and never more than is strictly necessary.
- Documentation. We keep a record of each request, the data disclosed, the legal basis and reasoning, and the people involved.
Because a Practice is the Data Fiduciary for its patients' booking data, where a request concerns patient data we will, where lawful and practicable, notify or defer to the relevant Practice.
7. Data retention
We keep personal data only as long as needed for the purposes above, or as required by law. Account and booking data is retained while the Practice’s account is active and for a reasonable period afterwards, unless a longer period is legally required. OTPs and verification tokens are short-lived and deleted or expired shortly after use.
8. Your rights
Subject to the DPDP Act, you may request to:
- Access a summary of the personal data we hold about you;
- Correct or update inaccurate or incomplete data;
- Erase data where it is no longer needed;
- Withdraw consent (this may stop us from providing the service);
- Nominate another person to exercise your rights in the event of death or incapacity;
- Raise a grievance with our Grievance Officer (below).
Patients: because a Practice controls your booking data, please contact that Practice first; we will assist the Practice in fulfilling your request.
9. Security
We use reasonable technical and organisational measures to protect personal data, including encryption in transit, hashed passwords, encrypted storage of API credentials, and restricted access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Cookies
The OPDesk owner dashboard uses a strictly necessary session cookie to keep you signed in. The public booking flow and this website do not use advertising or cross-site tracking cookies. If we add analytics in future, we will update this policy.
11. Children
OPDesk accounts are for medical professionals and are not directed at children. Where a patient is a minor, the booking is made by a parent or guardian, who is responsible for any consent required.
12. Grievance Officer & contact
For any privacy question, request, or complaint, contact our Grievance Officer:
- Email: care@opdesk.in
- Phone: +91 99983 42512
- Address: Office No. 418, 4th Floor, Gangotri Icon, Opp. Gokul Party Plot, Vasna, Vadodara, Gujarat 390007
We will acknowledge and respond to grievances within the timelines required by applicable law.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised “Last updated” date. Continued use of OPDesk after changes take effect means you accept the updated policy.
OPDesk is operated by RURINFRA TECHNOLOGIES PRIVATE LIMITED, Office No. 418, 4th Floor, Gangotri Icon, Opp. Gokul Party Plot, Vasna, Vadodara, Gujarat 390007, India. See also our Terms of Service.