[ LEGAL ]Privacy

Privacy Policy

Updated 22 Aug 2026 · Vaidra

Vaidra AI (“Vaidra”, “we”, “us”) builds the intelligence layer for hospitals. This policy explains how we collect, use, and share information when you visit vaidra.care, book a demo, or use the Vaidra Platform (including platform.vaidra.care). It is written for India’s Digital Personal Data Protection Act, 2023 (DPDP). It is not a HIPAA notice and does not claim HIPAA, SOC 2, or ISO 27001 certification.

01

Who we are and what this covers

In the consult, Vaidra captures ambient audio, drafts a working differential, structured notes, prescriptions, patient summaries, and encounter chat. The clinician reviews before anything commits. The same patient context is where a broader hospital layer is heading; this policy describes what is live today.

This policy covers (1) the marketing site at vaidra.care and demo booking, and (2) the Platform used to run live encounters. Related documents: Terms of Service, Cookie Policy, Subprocessors, and Security.

02

Roles under DPDP

For information about clinicians, invited staff, and people who browse the site or request a demo, Vaidra is a Data Fiduciary: we decide why that account and marketing data is processed.

For patient health information that a practice enters or captures in an encounter — identity, clinical history, audio, transcripts, notes, vitals, prescriptions, and attachments — the practice (the clinician or their hospital/clinic) is the Data Fiduciary. Vaidra processes that information as a Data Processor on the practice’s instructions, to provide the Service.

Patients do not create Vaidra accounts. Family members or others in the room may be recorded if they speak during a captured consult. The practice is responsible for telling those people that recording and transcription are in use.

03

Information we collect

Depending on how you use Vaidra, we may process:

  • Site visitors: technical logs (IP address, user agent, timestamps) needed to operate and secure the site.
  • Demo requests: name, email, and scheduling details you give Calendly when you book a walkthrough on Calendly’s site.
  • Clinician accounts: Google account email, name, profile image, and a Google subject identifier, stored as a FHIR Practitioner. Invited teammates contribute an email address. The workspace may store a care-system setting (for example allopathy, ayurveda, or homeopathy).
  • Patients (entered by the practice): name, date of birth or age, sex/gender, phone, email, and clinical history as FHIR resources.
  • Encounter content: notes, differentials, conditions, medications, allergies, vitals and other observations, care plans, prescriptions, chat threads, and attachments (images, PDFs, sketches). Audio and attachments are stored in object storage; clinical records sit in our database.
  • Audio and transcripts: microphone audio for the consult; stored session audio; diarized transcript text tied to the encounter.
  • AI outputs and traces: model-generated drafts (notes, hypotheses, orders, chat replies) that remain suggestions until a clinician accepts them. We may store LLM traces (prompts and outputs) to operate and debug the agents; those payloads are encrypted at rest when the trace key is configured.
  • Reliability: optional browser fatal-error reports may include the route, an encounter identifier, and error text.
  • Usage and billing: plan, consult quotas, seats, and related operational records. Payments, when collected, are arranged with us directly — we do not currently run a card checkout.
04

How we use it

We use this information to:

  • Operate the site, schedule demos, and follow up about pilots.
  • Create and authenticate clinician accounts, organisations, and invites.
  • Run ambient capture, transcription, clinical intelligence in the visit, documentation, and encounter chat.
  • Store and display the chart the practice creates, including patient-ready summaries and printable prescriptions the clinician chooses to generate.
  • Meter usage, apply plan limits, and communicate about the Service.
  • Secure the Service, debug failures (including traces and error reports), and understand aggregate product use.
  • Comply with law and respond to lawful requests.

We do not sell personal information. We do not use patient encounter content to train our own foundation models. Speech and language vendors process audio and text under their own terms; we do not claim they never use data to improve their services.

05

Recording and transcription

When a clinician starts capture, audio from the consult is streamed for speech-to-text. A transcript is built (with speaker labels where the selected engine supports diarization). Session audio may be stored and linked to the encounter so the practice can replay or recover the visit.

The clinician must inform the patient — and anyone else in the room — that the consult is being recorded and transcribed, and must obtain whatever consent their professional, hospital, and legal duties require. Vaidra does not obtain that consent from patients.

Transcription is performed by the speech engine configured for that session. Those vendors are listed on our Subprocessors page. Audio may be sent to them in real time, including, in some configurations, directly from the browser.

06

AI processing and third parties

Transcripts, notes, attachments, and other encounter context are sent to language-model providers so Vaidra can draft a working differential, documentation, treatment suggestions, and chat replies. Outputs are assistance for the clinician. They are not a diagnosis, prescription, or device output. See the Terms of Service.

Vendors that may process this content are named on the Subprocessors page. Some models or speech engines are optional and only run if enabled for a workspace.

07

Cookies and analytics

The marketing site may load Google Analytics 4 and Microsoft Clarity when those products are configured. The Platform sets a first-party session cookie to keep a clinician signed in, and may load Clarity. Details, including how to control these technologies, are in the Cookie Policy.

08

Sharing and international transfers

We share personal data with: the practice that owns the workspace; infrastructure and AI vendors acting on our instructions; Calendly when you book a demo on Calendly’s site; and authorities when the law requires it. We may share information to prevent harm, fraud, or abuse of the Service.

Several vendors operate outside India (including the United States). Encounter audio, transcripts, and clinical text may be processed in those regions to provide speech-to-text and AI features. We do not claim that patient data stays in India. The current list is on Subprocessors.

09

Retention

Demo inquiries are kept as long as needed to run the sales conversation and ordinary business records, then deleted or anonymised.

Clinician accounts and workspace data (including patient records, audio, transcripts, traces, and attachments) are retained while the account or organisation is active and for a reasonable period afterward so we can close the workspace, unless a shorter period is agreed in writing. We do not currently offer self-serve export of a workspace. If a practice needs a copy of records we hold, email hello@vaidra.care. We may keep limited logs and legal records longer where required.

Practices that need a specific hospital retention schedule should agree it with us before a pilot or production deployment.

10

Children and pediatric patients

The Platform is for clinicians, not for children as end users. A practice may still document pediatric patients, including recording a consult where a child is present.

The practice is responsible for any notice or guardian consent required for that child’s data and for recording. If you believe we have collected a child’s information other than through a clinician’s lawful use of the Platform, write to us and we will work with the practice to address it.

11

Your rights

If you are a clinician or a site visitor whose data we hold as Data Fiduciary, you may request access, correction, erasure, or a description of the processing, and you may withdraw consent where processing is consent-based, subject to DPDP and records we must keep.

If you are a patient, contact the clinician or hospital that used Vaidra for your visit first. They are the Data Fiduciary for your health record. We will assist that practice with verified requests.

hello@vaidra.care is the grievance and rights contact for Vaidra’s own fiduciary processing (clinician and marketing data). We will acknowledge and work to resolve it. You may also have the right to approach the Data Protection Board of India.

12

Security

We use TLS in transit, database encryption at rest, and per-workspace access isolation for clinical records. These measures reduce risk; they do not eliminate it. More detail is on the Security page.

13

Changes and contact

We may update this policy as the product or the law changes. The date at the top is the latest revision. Material changes will be posted on this page.

Questions: hello@vaidra.care.