← Back to Raydian Health
1. Introduction
Raydian Health ("we," "us," "our") is a product of Raydian Tech, a sole proprietorship firm registered in India, hereinafter referred to as the "Firm" (where such expression shall, unless repugnant to the context, be deemed to include the proprietor and the proprietor's legal heirs, representatives, administrators, and permitted successors and assigns). Raydian Health provides a cloud-based SaaS platform for Indian diagnostic laboratories and clinics. The platform combines a Laboratory Information System (LIS), real-time patient queue management, automated medical report delivery, and patient communication over WhatsApp.
This Privacy Policy explains how we collect, use, store, protect, share, and delete personal data in compliance with the Digital Personal Data Protection (DPDP) Act, 2023 of India and applicable healthcare regulations.
By using our platform, or by receiving WhatsApp communications sent through our platform on behalf of a diagnostic laboratory or clinic, you acknowledge the practices described in this policy.
2. Data Controller and Roles
Raydian Tech
Email: support@raydiantech.com
Website: health.raydiantech.com
Under the DPDP Act 2023:
- Diagnostic laboratories and clinics that use our platform act as Data Fiduciaries for their own patient relationships. They determine the purpose and means of processing their patients' personal data.
- Raydian Tech acts as a delegated processor on behalf of those laboratories and clinics, providing the technical infrastructure, software, and integrations needed to deliver the service.
- For data we collect about our own customers (lab administrators, billing contacts, employees of our customer organisations), Raydian Tech is the Data Fiduciary.
3. Data We Collect
3.1 Patient Phone Numbers — Three Collection Paths
Patient phone numbers are the primary identifier the platform uses to deliver report results, queue updates, and replies. We collect them through one of three paths, depending on which module a laboratory uses:
- Queue Management — When a clinic adds a patient to a doctor's queue, the receptionist enters the patient's mobile number directly into the system.
- Upload Service (legacy) — Some laboratories upload finished PDF reports to our platform; we extract the patient's phone number from the report text using OCR and AI. This collection path is scheduled for deprecation once the laboratory's LIS module is in full use, as the LIS path captures the same data more reliably at the source.
- LIS (primary, going forward) — When the laboratory registers a patient at intake in our LIS module, the receptionist or assistant enters the phone number as part of the patient record.
Regardless of collection path, phone numbers are encrypted at the application layer before storage and never displayed in full inside the admin interface (they are masked, e.g. +91 XXXX XX1234).
3.2 Patient Identity and Clinical Records (LIS)
For laboratories using the LIS module, we process the following on the laboratory's behalf:
- Patient name, date of birth, gender, address (where collected by the lab at registration)
- Patient case records — investigations ordered, sample collection times, test panels, modalities
- Laboratory results, reference ranges, sign-off status, and generated PDF reports
- Patient billing records — line items, discounts, payments, GST details
- Outsourcing records — when a test is sent to a partner laboratory, the partner-lab identifier and accession number are recorded
- Patient feedback ratings collected via WhatsApp after a visit
- Patient consent records — recorded with a timestamp and source, retained indefinitely under DPDP §6 as proof of consent
3.3 Report Processing Data (Upload Service / AI extraction)
- Original PDF reports uploaded by laboratories
- OCR-extracted text used to identify the patient phone number and to generate plain-language summaries
- AI-generated report summaries (with mandatory medical disclaimers)
- WhatsApp message logs — delivery status, timestamps, message identifiers
3.4 Q&A Chatbot Interactions
- Questions a patient sends to the laboratory's WhatsApp number, and the AI-generated reply
- The reply is grounded in knowledge-base documents uploaded by the laboratory itself
- No advertisements are sent in response to Q&A messages
3.5 Laboratory/Clinic Administrator Data
- Name, email address, mobile number of administrators, clinic admins, and receptionists
- Business information for the laboratory or clinic — legal name, addresses, business registration details, NABL accreditation status if applicable
- Authentication credentials, API keys, and integration tokens (stored only in hashed or encrypted form, never in plain text)
- Subscription and billing information for the platform itself
3.6 Laboratory Employee Data (LIS)
- Employee names, roles (technologist, pathologist, phlebotomist, etc.), contact phone numbers (encrypted), and sign-off authority for the LIS module
- Used by the LIS to attribute case ownership, result entry, and report sign-off to the responsible employee
3.7 Doctor / Referrer Data
- Doctor name, specialty, clinic, phone number — provided by laboratories for referrer tracking and (optional) referrer advertising features
- WhatsApp contact numbers for clickable "wa.me/" referral links
3.8 Automatically Collected Data
- IP addresses, device and browser information (User-Agent), and access logs for security monitoring, abuse detection, and new-device sign-in alerts
- API usage metrics, error logs, performance traces
- WhatsApp delivery-status webhook events received from Meta
- Application audit trail entries covering laboratory operations, messaging activity, and queue actions
4. How We Use Your Data
- Medical report delivery — Sending PDF reports and AI-generated plain-language summaries to patients over WhatsApp
- Queue management — Running real-time patient queues, sending appointment and near-turn notifications, providing public-display TV screens for waiting areas
- LIS operations — Patient registration, case management, result entry, report generation and printing, billing, outsourcing co-ordination
- Patient communication — Sending appointment reminders, recall and retest nudges, critical-result follow-ups, feedback prompts, and broadcast campaigns explicitly authorised by the laboratory
- Q&A chatbot — Answering patient queries about lab services, test preparation, pricing, and timings using the laboratory's own knowledge base
- Analytics for the laboratory — Patient segmentation (RFM), turnaround analytics, referrer scorecards, demand forecasting, revenue leakage detection — shown only to the laboratory whose data is being analysed
- Platform administration — Account management, subscription enforcement, AI cost monitoring, platform health checks
- Security and compliance — Maintaining audit trails, detecting fraud and abuse, verifying API authentication, demonstrating DPDP compliance to regulators
5. Legal Basis for Processing
We process personal data on one or more of the following bases recognised by the DPDP Act 2023:
- Consent — Recorded by the laboratory at patient registration or implied from the patient's act of approaching the lab for diagnostic services. Consent state changes are recorded in an immutable internal log and retained indefinitely as proof.
- Legitimate use — Processing necessary to deliver the diagnostic services the patient has approached the laboratory for, and to provide the technical services the laboratory has contracted us for.
- Legal obligation — Maintaining clinical records, audit trails, and consent proof for the periods required by Indian healthcare and data protection regulations (MCI Reg 1.3.1; DPDP §6, §8(7); NABL where applicable).
6. Data Storage and Security
All personal data is stored in India. Our application services and database are hosted on Indian cloud infrastructure in the Mumbai region. Supplementary services we use for file storage, asynchronous queues, and fallback OCR are also confined to the Mumbai region. No personal data is transferred outside India.
6.1 Encryption
- Patient phone numbers and other identifying contact data are encrypted with industry-standard symmetric encryption (AES-256) at the application layer before storage
- Decryption happens only when required to carry out a legitimate operation requested by the laboratory or by the patient (for example, delivering a message or looking up a record), and only for the duration of that operation
- Uploaded files and report attachments are encrypted at rest in object storage using server-side encryption
- All public traffic to the platform is served over HTTPS using modern TLS
- The database is not exposed to the public internet
- Authentication secrets and integration tokens are encrypted at rest
6.2 Access Controls
- Multi-tenant architecture with strict tenant isolation — laboratories cannot access each other's data through the product
- Authenticated sessions with role-based access control inside the admin application
- Programmatic API access uses signed requests with replay protection
- Passwords and credential secrets are stored using one-way hashing or encryption, never in plain text
6.3 Audit Trail
- Sensitive actions taken inside the platform are recorded in immutable audit records — covering laboratory operations, messaging activity, and queue actions
- Patient consent state changes are recorded in an immutable consent log
- Audit and consent records are retained indefinitely as required by DPDP §6 and §8(7) and are never automatically deleted
6.4 Limitations
We follow generally accepted industry practices to protect personal data and apply the controls described above. However, no security system is impenetrable. Despite our best efforts we cannot guarantee that personal data will never be accessed, intercepted, disclosed, or destroyed by an event outside our reasonable control. We acknowledge this honestly so that you can make informed decisions about what data you share with any online service, including ours.
7. Data Retention
We enforce retention by category. Purges are executed on a defined schedule by platform administrators, with each run recorded internally for compliance audit. Audit logs and patient consent logs are never automatically deleted.
Target retention windows for each category:
| Data Category |
Target Retention |
What happens at expiry |
| Patient phone numbers (Upload service path) | 30 days | Phone fields nullified; record stub preserved for audit |
| OCR-extracted text from report PDFs | 30 days | Permanently deleted |
| AI-generated report summaries | 90 days | Permanently deleted |
| WhatsApp message audit log | 180 days | Permanently deleted |
| Ad / referrer delivery log | 90 days | Permanently deleted |
| Q&A chatbot interaction log | 90 days | Permanently deleted |
| LIS patient identity (name, DOB, address) | Retained for the duration of the clinical record (per MCI Reg 1.3.1) | Anonymised when no longer required |
| LIS clinical record (cases, results, signed reports) | Per MCI / NABL retention requirements | Retained as a clinical record |
| Platform audit records and patient consent records | Never auto-deleted | Retained as DPDP proof of compliance and consent |
A patient may request earlier erasure of their personal data by contacting their laboratory directly or by writing to us at support@raydiantech.com. Erasure requests are handled in accordance with Section 9 below; clinical records that the laboratory is legally required to retain may remain in pseudonymised form for the regulatory retention period.
8. Data Sharing
We share personal data only with the following categories of recipients, and only as needed to deliver the service:
- Meta Platforms (WhatsApp Business Cloud API) — Phone numbers and template message content are transmitted to Meta for message delivery. See: WhatsApp Privacy Policy
- Oracle Cloud Infrastructure (OCI), Mumbai region — Hosts our application services. See: Oracle Privacy Policy
- Amazon Web Services (AWS), Mumbai region only — Used for file storage, asynchronous message queues, and fallback text recognition. See: AWS Privacy Policy
- Large-language-model providers — Report text and chatbot prompts are sent to third-party LLM providers (currently OpenAI, with the ability to route to Microsoft Azure OpenAI Service or Anthropic depending on configuration). No patient phone numbers or other direct identifiers are sent to LLM providers. See: OpenAI, Azure OpenAI, Anthropic
- Partner laboratories (LIS outsourcing) — When a laboratory outsources a test or modality to a partner lab, the relevant patient and test details are shared with the partner so that the test can be performed and the result returned. The originating laboratory remains the Data Fiduciary.
- The laboratory or clinic itself — A laboratory has full visibility of its own patients and operations through the admin interface.
We never sell personal data. We do not share patient data across laboratories. We do not use patient data for advertising on third-party platforms.
9. Your Rights Under DPDP Act 2023
As a Data Principal (the individual whose data is being processed), you have the following rights:
- Right to Access — Request information about what personal data we hold about you.
- Right to Correction — Request correction of inaccurate personal data.
- Right to Erasure — Request deletion of your personal data. Clinical records may be retained in pseudonymised form for the period the laboratory is legally required to keep them.
- Right to Grievance Redressal — Raise a complaint about how we process data. Contact: support@raydiantech.com.
- Right to Lodge a Complaint with the Supervisory Authority — If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India, the supervisory authority established under the DPDP Act 2023.
- Right to Information on Cross-Border Transfers — Request information on whether your personal data is transferred outside India. As stated in Section 6, we do not transfer personal data outside India.
- Right to Nominate — Nominate another individual to exercise your rights in the event of your death or incapacity, as provided under DPDP §14.
9.1 Identity Verification for Access and Erasure Requests
To prevent unauthorised access or accidental destruction of records, we verify the identity of the requester before acting on any access or erasure request.
- Patients are strongly encouraged to raise requests through the laboratory that holds their record. The laboratory verifies identity in person or against its visit records, and then raises the request with us from its authenticated admin session.
- Patients writing to us directly are asked to provide identifying details that only the actual patient would know — the laboratory's name, approximate visit date, and the last 4 digits of the registered phone number, which we match against the stored phone hash without decrypting. We may also confirm with the laboratory before acting.
- Laboratory administrators may raise requests for their own account either from within an authenticated admin session or by email from the registered email address on file, to which we reply for confirmation before acting.
- Requests on behalf of another person — for example, a guardian, a parent acting for a minor, or a legal heir under DPDP §14 — require documentary proof of authority.
We may decline to act where identity cannot reasonably be established. Clinical records that the laboratory is legally required to retain may remain in pseudonymised form for the regulatory retention period even after a successful erasure request.
To exercise any of these rights, write to us at support@raydiantech.com. We acknowledge requests within 48 hours and provide a substantive response within 30 days.
10. Automated Decision-Making and AI-Assisted Features
Our platform uses automated processing and AI-assisted features at several points in the workflow. We disclose these so you can make an informed decision about your data:
- AI report summarisation — Plain-language summaries of medical reports generated using a third-party large-language-model service. Every summary carries a mandatory disclaimer to consult a doctor.
- AI Lab Assistant — Allows authorised laboratory administrators to query their own lab's operational data in natural language, with answers grounded in the laboratory's own records.
- Q&A chatbot — Responds to patient queries over WhatsApp using the laboratory's uploaded knowledge base. Low-relevance queries return a fallback message with the laboratory's contact details.
- Phone number extraction — Extracts patient phone numbers from uploaded PDF reports using automated text recognition. Below a confidence threshold, the report is routed to email fallback instead of WhatsApp.
- Patient segmentation — Classifies patients into commercial segments (such as Champions, Loyal, At-Risk) based on the recency, frequency, and value of their visits. Used by the laboratory for marketing decisions.
- Demand forecasting — Statistical projections of future test demand, used by the laboratory for capacity planning.
- Next-best-test suggestions — Suggestions of related tests, shown to laboratory staff during order entry, based on patterns in the laboratory's own order history.
- Critical-result flagging — Automated flagging of out-of-range results that may warrant clinical follow-up.
No automated decision made by the platform constitutes a medical decision. Final clinical interpretation, diagnosis, and any decision affecting a patient's treatment rests with qualified clinical personnel — the laboratory's pathologist, the patient's referring doctor, or the patient's treating doctor. Our AI features are designed to support, not replace, human judgement.
You may request human review of any automated output that you believe materially affects you, by writing to us at support@raydiantech.com.
11. WhatsApp Business Platform
Raydian Health uses the Meta WhatsApp Business Cloud API to send and receive messages on behalf of laboratories. Specifically:
- We send medical report summaries and PDF download links to patients via pre-approved WhatsApp message templates
- We send queue status notifications (joined, near-turn, called, completed) to patients
- We send appointment reminders, retest reminders, recall nudges, critical-result follow-ups, and feedback prompts, where the laboratory has configured these
- We send broadcast campaign messages only when the laboratory has explicitly authored and sent the campaign
- We send optional doctor / referrer advertisement messages — only after a report delivery, never in response to a Q&A chatbot reply, and only where the laboratory has not opted out
- We receive inbound messages and route them to the Q&A chatbot, lab agent, or the laboratory's staff agent depending on the laboratory's configuration
All WhatsApp activity is recorded in our message audit log. A patient can stop receiving messages by replying STOP, or by contacting the laboratory directly.
12. Cookies and Tracking
Our admin web application uses essential cookies and browser storage for session management and authentication. We do not use advertising cookies. We do not run third-party tracking pixels. We do not track patients via cookies. Static assets (fonts) are served from third-party CDNs (Google Fonts) which may receive request metadata such as IP address; these are not used to personalise content.
13. Children's Data
The platform processes medical reports and clinical records that may relate to minors. The diagnostic laboratory is responsible for obtaining appropriate consent from the parent or guardian under DPDP §9 before recording a minor's personal data. We do not knowingly collect data directly from children under the age of 18 through the platform's patient-facing channels.
14. Account Security
If you access the platform with a registered account (as a laboratory administrator, clinic administrator, receptionist, or laboratory staff member), you are responsible for the confidentiality of your credentials:
- Choose a strong password, do not reuse it across other sites, and do not share it with anyone.
- Sign out of the admin application when you are done, particularly on shared or public devices.
- If you suspect that your password or session has been compromised, change your password immediately and notify us at support@raydiantech.com.
- You are responsible for all actions taken under your login, including any access to patient data. Audit-log entries are attributed to the logged-in user.
15. External Links
This Privacy Policy and the platform itself link to third-party websites and services — including WhatsApp, AWS, Oracle Cloud, OpenAI, Azure OpenAI, Anthropic, and Google Fonts. We provide these links for reference and do not control or endorse the content, products, or privacy practices of those third parties. When you follow an external link, the destination's own privacy policy applies. We recommend you review each external provider's privacy policy independently.
16. Severability
Each section of this Privacy Policy is independent and severable. If any provision is held to be invalid, unlawful, or unenforceable by a court or regulator of competent jurisdiction, that provision shall be deemed modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall continue in full force and effect.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We notify registered laboratory administrators by email of any material change. The "Last Updated" date at the top of this page indicates when the policy was last revised. Continued use of the platform after a change indicates acceptance of the updated policy.
18. Contact Us
For any privacy-related inquiries, data access requests, erasure requests, or complaints:
Raydian Tech
Email: support@raydiantech.com
General inquiries: info@raydiantech.com
Website: health.raydiantech.com
We acknowledge requests within 48 hours and provide a substantive response within 30 days.