Privacy Policy

Effective date: 15 July 2026 · Last updated: 16 July 2026

This Privacy Policy explains how RURINFRA TECHNOLOGIES PRIVATE LIMITED (“OPDesk”, “we”, “us”) collects, uses, and protects personal data when doctors and clinics (“Practices”) use the OPDesk appointment-booking service, and when patients book appointments through a Practice using OPDesk.

1. Who we are & our two roles

OPDesk is a booking tool that Practices use to manage their own appointments. Our role depends on whose data it is:

References to “personal data” and to the roles above follow India’s Digital Personal Data Protection Act, 2023 (DPDP Act).

2. Information we collect

CategoryExamplesFrom whom
Account dataOwner name, email address, mobile number, hashed password, practice nameThe Practice owner at sign-up
Practice configurationClinic names, addresses, doctors, specialties, working hours, availabilityThe Practice
Patient booking dataPatient name, mobile number, chosen clinic/doctor, appointment date & time, cancellation statusThe patient, at the time of booking
WhatsApp booking dataThe patient's WhatsApp phone number and the messages they send when booking with a Practice over WhatsAppThe patient, via WhatsApp (received from Meta Platforms)
Verification dataOne-time passwords (OTPs) and verification tokens used to confirm a phone or emailGenerated by OPDesk
Technical dataIP address, device/browser type, timestamps, and basic logs used for security and abuse-preventionAutomatically, on use

We do not intentionally collect medical records, diagnoses, or clinical notes through OPDesk. Patients should not send sensitive health details in the booking flow.

3. How we use personal data

4. Legal basis / consent

We process personal data on the basis of the consent obtained at sign-up or at booking, and for the legitimate uses permitted under the DPDP Act (for example, providing a service a person has asked for). Patients provide their number to a Practice in order to be booked; the Practice is responsible for obtaining any consent it needs from its patients.

5. Sharing & third-party processors

We do not sell personal data. We share it only with service providers who help us run OPDesk, under contractual confidentiality and data-protection terms:

Information we receive from the WhatsApp Business Platform (Meta) is used only to provide the booking service described in this policy, on behalf of the Practice, and is handled in line with Meta's Platform Terms. We do not use it for advertising, and we do not share it beyond the processors listed above and the Practice you booked with.

We may also disclose data where required by law, or to protect the rights, safety, and security of OPDesk, our users, and the public.

6. Government & law-enforcement requests

We sometimes receive requests from courts, police, regulators, or other public authorities asking us to disclose personal data, including data we receive from the WhatsApp Business Platform (Meta). We handle every such request under a documented internal policy, and we disclose data only where we are legally required to:

Because a Practice is the Data Fiduciary for its patients' booking data, where a request concerns patient data we will, where lawful and practicable, notify or defer to the relevant Practice.

7. Data retention

We keep personal data only as long as needed for the purposes above, or as required by law. Account and booking data is retained while the Practice’s account is active and for a reasonable period afterwards, unless a longer period is legally required. OTPs and verification tokens are short-lived and deleted or expired shortly after use.

8. Your rights

Subject to the DPDP Act, you may request to:

Patients: because a Practice controls your booking data, please contact that Practice first; we will assist the Practice in fulfilling your request.

9. Security

We use reasonable technical and organisational measures to protect personal data, including encryption in transit, hashed passwords, encrypted storage of API credentials, and restricted access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Cookies

The OPDesk owner dashboard uses a strictly necessary session cookie to keep you signed in. The public booking flow and this website do not use advertising or cross-site tracking cookies. If we add analytics in future, we will update this policy.

11. Children

OPDesk accounts are for medical professionals and are not directed at children. Where a patient is a minor, the booking is made by a parent or guardian, who is responsible for any consent required.

12. Grievance Officer & contact

For any privacy question, request, or complaint, contact our Grievance Officer:

We will acknowledge and respond to grievances within the timelines required by applicable law.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised “Last updated” date. Continued use of OPDesk after changes take effect means you accept the updated policy.


OPDesk is operated by RURINFRA TECHNOLOGIES PRIVATE LIMITED, Office No. 418, 4th Floor, Gangotri Icon, Opp. Gokul Party Plot, Vasna, Vadodara, Gujarat 390007, India. See also our Terms of Service.