DPDP Compliance Policy
How PRA complies with India's Digital Personal Data Protection (DPDP) Act, 2023 — and how we help your clinic stay compliant.
Last updated: 18 June 2026
What is DPDP Compliance?
DPDP compliance refers to the legal requirement for organisations to adhere to India's Digital Personal Data Protection (DPDP) Act, 2023. It dictates how businesses must collect, store, and process the personal data of individuals — ensuring user privacy, robust data security, and heavy penalties for violations.
Under this Act, PRA operates as a Data Fiduciary (we determine the purpose of processing) and as a Data Processor on behalf of clinics (who are themselves Data Fiduciaries for their patients).
Consent & Notice
Before collecting any personal data, we ensure:
- Patients receive a clear, itemised notice via WhatsApp explaining what data is being collected and why
- Consent is obtained freely, specifically, and unambiguously — patients must affirmatively respond to proceed
- No data is collected beyond what is necessary for the stated purpose (data minimisation)
- Withdrawal of consent is as easy as providing it — patients can text 'STOP' at any time
User Rights Management
Under the DPDP Act, every Data Principal (patient) has enforceable rights:
- Right to Access — patients can request a summary of all data PRA holds about them
- Right to Correction — inaccurate or incomplete data must be corrected promptly upon request
- Right to Erasure — if consent is withdrawn, data is deleted once the original purpose is fulfilled
- Right to Grievance — every complaint must receive a timely, documented response
- Right to Nominate — patients may nominate a representative to exercise their rights on their behalf
To exercise any of these rights, patients or clinic administrators may contact: support@parroconnect.com
Grievance Redressal
PRA has appointed a Data Protection Officer (DPO) responsible for overseeing compliance and handling grievances.
- Complaints must be acknowledged within 48 hours
- Resolution must be provided within 30 days of receipt
- Unresolved complaints may be escalated to the Data Protection Board of India (DPBI)
DPO Contact: support@parroconnect.com
Data Security Safeguards
PRA implements the following technical and organisational measures as legally mandated:
- AES-256 encryption for all patient data stored at rest
- TLS 1.3 encryption for all data in transit
- Role-based access controls — clinic staff see only the data relevant to their role
- Multi-factor authentication for all dashboard logins
- Regular third-party security audits and penetration testing
- Access logs retained for 12 months for audit purposes
- Vendor agreements with all sub-processors require equivalent security standards
Breach Notification
In the event of a personal data breach, PRA will:
- Contain and assess the breach within 24 hours of discovery
- Notify the Data Protection Board of India (DPBI) within 72 hours
- Notify affected patients and clinics without undue delay
- Provide a detailed incident report including nature of breach, data affected, and remediation steps
Retention & Erasure
Personal data is retained only as long as necessary for its original purpose:
- Active patient records: retained for the duration of the clinic subscription + 3 years (per MCI guidelines)
- Appointment logs: 3 years from date of appointment
- WhatsApp message logs: 12 months rolling window
- Deleted clinic data: anonymised within 90 days, permanently erased within 12 months of account closure
How PRA Helps Your Clinic Stay Compliant
Clinics using PRA benefit from built-in DPDP compliance infrastructure:
- Consent collection and audit trail — automatically logged at the WhatsApp layer
- Patient data export tool — allows you to respond to access/portability requests in minutes
- One-click data deletion — trigger erasure for any patient from the dashboard
- Grievance log — track and respond to patient complaints within the PRA dashboard
- DPA (Data Processing Agreement) — available on request for enterprise subscribers
Contact the Data Protection Officer
DPO: Data Protection Officer, ParroConnect
Email: support@parroconnect.com
Address: Chennai, Tamil Nadu, India — 600 001
Response SLA: 48 hours acknowledgement · 30 days resolution