Legal
How Healui handles your personal and health information across our EMR, marketplace, mobile app, AI clinical features and messages. Written to be read, not to be impenetrable.
Effective August 14, 2026
The short version
before the long version.
This summary is here to be useful, not to replace what follows. Where the two differ, the numbered sections below are what binds us.
When a clinic treats you, that clinic decides what happens to your record and Healui only processes it on their instructions. When you book through the Healui marketplace yourself, Healui is responsible directly.
Read the full sectionRecords, documents, recordings and backups are held in AWS Mumbai. The one exception is our AI features, which send clinical text and audio to providers outside India. We name that plainly rather than bury it.
Read the full sectionNot to insurers, not to pharma, not to advertisers. We do not use clinic patient lists to market the Healui marketplace.
Read the full sectionYou can delete your Healui account yourself, from the website, without signing in. Some clinical and billing records must be kept by law, so we anonymise those instead of destroying them.
Read the full sectionOn this page
Healui ("Healui", "we", "us", or "our") operates an AI-native electronic medical records (EMR) platform and marketplace built for physiotherapy clinics and practitioners. This Privacy Policy explains how we handle your information when you use the Healui Clinic mobile application, our websites and web applications (including app.healui.com), the patient care portal, our marketplace, and any communications we send you, including over WhatsApp.
By using Healui, you agree to the practices described in this Policy. If you do not agree, please do not use the platform.
This is the most important section in this Policy, because the answer changes depending on how you came to Healui. The Digital Personal Data Protection Act, 2023 ("DPDP Act") calls the party that decides why and how data is processed the Data Fiduciary, and the party that processes it on their behalf the Data Processor.
Your treating clinic is the Data Fiduciary for your clinical record. They decide what is recorded and how long it is kept. Healui is their Data Processor: we hold and process that record only on their instructions, to provide the service. Requests about your clinical record are routed to the clinic responsible for it.
Where you come to Healui directly, create your own account and consent to us, Healui is the Data Fiduciary for the account and booking data you give us. Marketplace patients are a separate population from clinic EMR patients; the two are never merged.
Practical consequence: if you are a clinic patient asking us to erase a clinical record, we cannot simply do it. We will route your request to your clinic, because the decision and the legal retention duty are theirs. Your account data with Healui is a different matter, and you can erase that yourself.
We collect the following categories of information:
We use your information to:
We process your personal data on the basis of your consent and, where applicable, to perform the services you or your clinic have requested, and to meet legal obligations. We do not use your clinical records to advertise to you, and we do not use a clinic’s patient list to market the Healui marketplace.
Healui includes AI features that assist physiotherapists, for example by suggesting differential diagnoses, drafting treatment plans, and helping convert voice notes into structured clinical documentation. These features are a clinical copilot: they assist the physiotherapist, who reviews, edits, and remains responsible for every clinical decision. The AI does not make decisions about your care on its own.
To provide these features, relevant clinical information is processed by third-party AI providers. Where this happens:
These AI providers operate servers outside India, primarily in the United States. This is named in the consent notice you are asked to agree to, and it is described in “Cross-border transfers” below. A clinic that would rather not use these features can tell us before onboarding.
With your consent, we use WhatsApp to send you appointment reminders, intake links, care-plan notifications, and follow-up prompts. WhatsApp messages are delivered through the WhatsApp/Meta platform, which processes message metadata under its own terms and operates outside India.
We are deliberate about what appears in a message. Sensitive clinical details are not placed in the message body. Instead, we send a secure link that opens your care plan only after you enter a one-time access code, and the link expires after a limited period. This keeps your health information behind an additional layer of verification rather than in the message itself.
You can ask us to stop sending WhatsApp messages at any time by contacting us using the details below. Transactional messages needed to deliver care you have booked, such as an appointment confirmation, may continue while that care is ongoing.
All patient data is stored and processed in AWS Mumbai (ap-south-1). Databases, file storage for documents and recordings, backups and encryption keys are all held within India. The DPDP Act does not currently require health data to remain in India; we keep it here anyway.
The exception is the AI processing described above, and the sign-in verification and messaging providers listed above, which operate outside India.
We apply technical and organisational measures designed to protect your information, including:
No method of transmission or storage is completely secure, but we work to protect your information and to continually improve our safeguards. Our full security document, including an honest list of what is still in development, is published at healui.com/data-security.
Certain service providers store or process information on servers located outside India: our AI providers (primarily in the United States), our sign-in verification provider, and WhatsApp/Meta for notifications. Where we transfer personal data internationally, we limit what is shared, select providers offering appropriate data-protection commitments, and contract them to use the data only for the purpose we engaged them for.
By consenting to the AI-assisted and communication features described above, you acknowledge that your information may be processed in this way. These purposes are named separately in the consent notice so you can see what you are agreeing to.
Subject to applicable law, including the DPDP Act, you have the right to:
You can delete your Healui account yourself at healui.com/delete-account, without signing in, which matters because most people asking have already removed the app. Enter your mobile number, confirm the one-time SMS code, and the account is erased. The page shows exactly what is removed and what is kept before anything happens.
Identifying data (your name, phone, email, date of birth, gender, address, and the medical history held on your account) is removed, and you can no longer be found by name or number. Appointment and treatment records your clinic must retain, invoices required for tax, the consent record proving your data was handled lawfully, and the access log that exists to protect you, are kept in anonymised form. Destroying those would erase the evidence that protects you, which is the opposite of what an erasure request is for.
To exercise any other right, contact us using the details below. We may need to verify your identity before acting on a request.
We process your information based on the consent you give when you sign up, receive care, or agree to our communications. Consent is requested through a link sent to your own phone, the notice is presented in plain language in English or Hindi before you agree, and each purpose is listed and explained separately. The exact notice you saw is stored with your consent record. Where care is provided to a minor, consent is given by a parent or lawful guardian.
You may withdraw consent at any time, in whole or for a single purpose, and the withdrawal is written to the same tamper-evident log as the original consent.
Withdrawal records your decision; it does not switch treatment off by itself. Acting on it, stopping treatment or stopping messages, is a decision for your treating clinic, and the record exists so that decision is documented. Self-service screens for this are still being built, so a withdrawal today goes through a person. The record it produces is the same either way. Withdrawing consent may limit or prevent our ability to provide some or all of the service.
Clinical records follow the statutory minimum of three years from the start of treatment, with ten years recommended in line with national health-record guidance. Consent and withdrawal evidence is retained separately, as proof of lawful processing. Invoices and payment records are retained for the periods tax law requires.
Access logs identifying a patient’s record, and records of refused access attempts, are retained for 13 months so that a report can always cover a full preceding year. Listing and dashboard views that identify no single patient are retained for 90 days. When information is no longer required, we delete or anonymise it.
Where care is provided to a child or a person who cannot provide consent on their own behalf, we process their information only with the consent of a parent or lawful guardian, and in connection with the care being delivered. If you believe a child’s information has been provided to us without appropriate consent, please contact us.
On becoming aware of a personal data breach we contain it, assess what was affected, and notify the affected parties without undue delay with what we know, what we are doing and what we recommend, alongside the reporting we owe CERT-In under the 2022 directions.
Where the affected records belong to a clinic, the DPDP Act places the duty to notify the Data Protection Board and affected patients on that clinic as Data Fiduciary. Our role is to give them the facts quickly enough to meet it. Our access log is what makes that possible: it lets the affected set be identified rather than estimated.
If you have any concern or complaint about how your personal data is handled, contact our Grievance Officer. We will acknowledge and address your concern within the timelines required by applicable law. If we do not resolve it to your satisfaction, you may escalate to the Data Protection Board of India.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the effective date above and, where appropriate, notify you. Your continued use of Healui after an update constitutes acceptance of the revised Policy.
For any question about this Policy or our data practices:
FAQ
It depends on how you came to us. If a clinic treats you using Healui, that clinic is the Data Fiduciary under the DPDP Act: they decide what is recorded and how long it is kept, and Healui only processes it on their instructions. If you booked physiotherapy through the Healui marketplace yourself, Healui is responsible directly for the account and booking data you gave us. It matters in practice, because a request to erase a clinical record has to go to the clinic that holds the duty to retain it.
In India. Records, documents, clinical photos, voice recordings, backups and encryption keys are all held in AWS Mumbai (ap-south-1). There is one exception we state plainly rather than bury: our AI features send clinical text and consultation audio to providers whose servers are outside India, primarily in the United States. That is named in the consent notice you agree to.
No. Not to insurers, not to pharma, not to advertisers, not to anyone. We also do not use a clinic’s patient list to market the Healui marketplace: marketplace patients are a separate population who consent to Healui directly, and the two are never merged.
They help your physiotherapist draft notes, suggest differential diagnoses and plan treatment. A qualified physiotherapist reviews everything before it is used in your care; the AI decides nothing on its own. Structured records are stripped of your name, phone and email before processing. Consultation audio is treated as identifiable, because a recording contains whatever was said aloud, and we would rather say that than call it anonymous. Providers are contracted not to train their models on it.
Not in the background. We use the addresses you save to price and schedule home visits. If you grant location permission, we use your device location to show physiotherapists near you and to pre-fill an address. You can decline that and type an address by hand instead.
Go to healui.com/delete-account. You do not need to sign in, which matters because most people asking have already removed the app. Enter your mobile number, confirm the SMS code, and the account is erased. Your identifying details go. Records your clinic must keep by law, invoices required for tax, and the consent and access records that prove your data was handled properly are kept in anonymised form, unlinked from you.
Yes, any time. Email grievance@healui.com and we will stop them. Messages needed to deliver care you have already booked, like an appointment confirmation, may continue while that care is ongoing.
Write to our Grievance Officer at grievance@healui.com or call +91 82829 89891. We will acknowledge and address it within the timelines the law requires. If we do not resolve it to your satisfaction, you have the right to escalate to the Data Protection Board of India.
Questions
Our Grievance Officer answers every question. For a data processing agreement, an access report, or an export of your records, write to support@healui.com.