Privacy Policy

Last Updated: May 12, 2026

← Back to Raydian Health

1. Introduction

Raydian Health ("we," "us," "our") is a product of Raydian Tech, a sole proprietorship firm registered in India, hereinafter referred to as the "Firm" (where such expression shall, unless repugnant to the context, be deemed to include the proprietor and the proprietor's legal heirs, representatives, administrators, and permitted successors and assigns). Raydian Health provides a cloud-based SaaS platform for Indian diagnostic laboratories and clinics. The platform combines a Laboratory Information System (LIS), real-time patient queue management, automated medical report delivery, and patient communication over WhatsApp.

This Privacy Policy explains how we collect, use, store, protect, share, and delete personal data in compliance with the Digital Personal Data Protection (DPDP) Act, 2023 of India and applicable healthcare regulations.

By using our platform, or by receiving WhatsApp communications sent through our platform on behalf of a diagnostic laboratory or clinic, you acknowledge the practices described in this policy.

2. Data Controller and Roles

Raydian Tech
Email: support@raydiantech.com
Website: health.raydiantech.com

Under the DPDP Act 2023:

3. Data We Collect

3.1 Patient Phone Numbers — Three Collection Paths

Patient phone numbers are the primary identifier the platform uses to deliver report results, queue updates, and replies. We collect them through one of three paths, depending on which module a laboratory uses:

Regardless of collection path, phone numbers are encrypted at the application layer before storage and never displayed in full inside the admin interface (they are masked, e.g. +91 XXXX XX1234).

3.2 Patient Identity and Clinical Records (LIS)

For laboratories using the LIS module, we process the following on the laboratory's behalf:

3.3 Report Processing Data (Upload Service / AI extraction)

3.4 Q&A Chatbot Interactions

3.5 Laboratory/Clinic Administrator Data

3.6 Laboratory Employee Data (LIS)

3.7 Doctor / Referrer Data

3.8 Automatically Collected Data

4. How We Use Your Data

5. Legal Basis for Processing

We process personal data on one or more of the following bases recognised by the DPDP Act 2023:

6. Data Storage and Security

All personal data is stored in India. Our application services and database are hosted on Indian cloud infrastructure in the Mumbai region. Supplementary services we use for file storage, asynchronous queues, and fallback OCR are also confined to the Mumbai region. No personal data is transferred outside India.

6.1 Encryption

6.2 Access Controls

6.3 Audit Trail

6.4 Limitations

We follow generally accepted industry practices to protect personal data and apply the controls described above. However, no security system is impenetrable. Despite our best efforts we cannot guarantee that personal data will never be accessed, intercepted, disclosed, or destroyed by an event outside our reasonable control. We acknowledge this honestly so that you can make informed decisions about what data you share with any online service, including ours.

7. Data Retention

We enforce retention by category. Purges are executed on a defined schedule by platform administrators, with each run recorded internally for compliance audit. Audit logs and patient consent logs are never automatically deleted.

Target retention windows for each category:

Data Category Target Retention What happens at expiry
Patient phone numbers (Upload service path)30 daysPhone fields nullified; record stub preserved for audit
OCR-extracted text from report PDFs30 daysPermanently deleted
AI-generated report summaries90 daysPermanently deleted
WhatsApp message audit log180 daysPermanently deleted
Ad / referrer delivery log90 daysPermanently deleted
Q&A chatbot interaction log90 daysPermanently deleted
LIS patient identity (name, DOB, address)Retained for the duration of the clinical record (per MCI Reg 1.3.1)Anonymised when no longer required
LIS clinical record (cases, results, signed reports)Per MCI / NABL retention requirementsRetained as a clinical record
Platform audit records and patient consent recordsNever auto-deletedRetained as DPDP proof of compliance and consent

A patient may request earlier erasure of their personal data by contacting their laboratory directly or by writing to us at support@raydiantech.com. Erasure requests are handled in accordance with Section 9 below; clinical records that the laboratory is legally required to retain may remain in pseudonymised form for the regulatory retention period.

8. Data Sharing

We share personal data only with the following categories of recipients, and only as needed to deliver the service:

We never sell personal data. We do not share patient data across laboratories. We do not use patient data for advertising on third-party platforms.

9. Your Rights Under DPDP Act 2023

As a Data Principal (the individual whose data is being processed), you have the following rights:

9.1 Identity Verification for Access and Erasure Requests

To prevent unauthorised access or accidental destruction of records, we verify the identity of the requester before acting on any access or erasure request.

We may decline to act where identity cannot reasonably be established. Clinical records that the laboratory is legally required to retain may remain in pseudonymised form for the regulatory retention period even after a successful erasure request.

To exercise any of these rights, write to us at support@raydiantech.com. We acknowledge requests within 48 hours and provide a substantive response within 30 days.

10. Automated Decision-Making and AI-Assisted Features

Our platform uses automated processing and AI-assisted features at several points in the workflow. We disclose these so you can make an informed decision about your data:

No automated decision made by the platform constitutes a medical decision. Final clinical interpretation, diagnosis, and any decision affecting a patient's treatment rests with qualified clinical personnel — the laboratory's pathologist, the patient's referring doctor, or the patient's treating doctor. Our AI features are designed to support, not replace, human judgement.

You may request human review of any automated output that you believe materially affects you, by writing to us at support@raydiantech.com.

11. WhatsApp Business Platform

Raydian Health uses the Meta WhatsApp Business Cloud API to send and receive messages on behalf of laboratories. Specifically:

All WhatsApp activity is recorded in our message audit log. A patient can stop receiving messages by replying STOP, or by contacting the laboratory directly.

12. Cookies and Tracking

Our admin web application uses essential cookies and browser storage for session management and authentication. We do not use advertising cookies. We do not run third-party tracking pixels. We do not track patients via cookies. Static assets (fonts) are served from third-party CDNs (Google Fonts) which may receive request metadata such as IP address; these are not used to personalise content.

13. Children's Data

The platform processes medical reports and clinical records that may relate to minors. The diagnostic laboratory is responsible for obtaining appropriate consent from the parent or guardian under DPDP §9 before recording a minor's personal data. We do not knowingly collect data directly from children under the age of 18 through the platform's patient-facing channels.

14. Account Security

If you access the platform with a registered account (as a laboratory administrator, clinic administrator, receptionist, or laboratory staff member), you are responsible for the confidentiality of your credentials:

15. External Links

This Privacy Policy and the platform itself link to third-party websites and services — including WhatsApp, AWS, Oracle Cloud, OpenAI, Azure OpenAI, Anthropic, and Google Fonts. We provide these links for reference and do not control or endorse the content, products, or privacy practices of those third parties. When you follow an external link, the destination's own privacy policy applies. We recommend you review each external provider's privacy policy independently.

16. Severability

Each section of this Privacy Policy is independent and severable. If any provision is held to be invalid, unlawful, or unenforceable by a court or regulator of competent jurisdiction, that provision shall be deemed modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall continue in full force and effect.

17. Changes to This Policy

We may update this Privacy Policy from time to time. We notify registered laboratory administrators by email of any material change. The "Last Updated" date at the top of this page indicates when the policy was last revised. Continued use of the platform after a change indicates acceptance of the updated policy.

18. Contact Us

For any privacy-related inquiries, data access requests, erasure requests, or complaints:

Raydian Tech
Email: support@raydiantech.com
General inquiries: info@raydiantech.com
Website: health.raydiantech.com

We acknowledge requests within 48 hours and provide a substantive response within 30 days.