India's Digital Personal Data Protection Act, 2023

DPDP Compliance Policy

How PRA complies with India's Digital Personal Data Protection (DPDP) Act, 2023 — and how we help your clinic stay compliant.

Last updated: 18 June 2026

What is DPDP Compliance?

DPDP compliance refers to the legal requirement for organisations to adhere to India's Digital Personal Data Protection (DPDP) Act, 2023. It dictates how businesses must collect, store, and process the personal data of individuals — ensuring user privacy, robust data security, and heavy penalties for violations.

Under this Act, PRA operates as a Data Fiduciary (we determine the purpose of processing) and as a Data Processor on behalf of clinics (who are themselves Data Fiduciaries for their patients).

1

Consent & Notice

Before collecting any personal data, we ensure:

  • Patients receive a clear, itemised notice via WhatsApp explaining what data is being collected and why
  • Consent is obtained freely, specifically, and unambiguously — patients must affirmatively respond to proceed
  • No data is collected beyond what is necessary for the stated purpose (data minimisation)
  • Withdrawal of consent is as easy as providing it — patients can text 'STOP' at any time
✅ Every patient interaction begins with an explicit opt-in. Clinics using PRA do not need to separately build consent flows — PRA handles this at the WhatsApp layer.
2

User Rights Management

Under the DPDP Act, every Data Principal (patient) has enforceable rights:

  • Right to Access — patients can request a summary of all data PRA holds about them
  • Right to Correction — inaccurate or incomplete data must be corrected promptly upon request
  • Right to Erasure — if consent is withdrawn, data is deleted once the original purpose is fulfilled
  • Right to Grievance — every complaint must receive a timely, documented response
  • Right to Nominate — patients may nominate a representative to exercise their rights on their behalf

To exercise any of these rights, patients or clinic administrators may contact: support@parroconnect.com

3

Grievance Redressal

PRA has appointed a Data Protection Officer (DPO) responsible for overseeing compliance and handling grievances.

  • Complaints must be acknowledged within 48 hours
  • Resolution must be provided within 30 days of receipt
  • Unresolved complaints may be escalated to the Data Protection Board of India (DPBI)

DPO Contact: support@parroconnect.com

4

Data Security Safeguards

PRA implements the following technical and organisational measures as legally mandated:

  • AES-256 encryption for all patient data stored at rest
  • TLS 1.3 encryption for all data in transit
  • Role-based access controls — clinic staff see only the data relevant to their role
  • Multi-factor authentication for all dashboard logins
  • Regular third-party security audits and penetration testing
  • Access logs retained for 12 months for audit purposes
  • Vendor agreements with all sub-processors require equivalent security standards
5

Breach Notification

In the event of a personal data breach, PRA will:

  • Contain and assess the breach within 24 hours of discovery
  • Notify the Data Protection Board of India (DPBI) within 72 hours
  • Notify affected patients and clinics without undue delay
  • Provide a detailed incident report including nature of breach, data affected, and remediation steps
⚠️ Clinics using PRA are reminded that they remain independently responsible for notifying the DPBI if they independently discover a breach related to data they manage outside of PRA.
6

Retention & Erasure

Personal data is retained only as long as necessary for its original purpose:

  • Active patient records: retained for the duration of the clinic subscription + 3 years (per MCI guidelines)
  • Appointment logs: 3 years from date of appointment
  • WhatsApp message logs: 12 months rolling window
  • Deleted clinic data: anonymised within 90 days, permanently erased within 12 months of account closure
✅ Automated erasure pipelines run monthly to delete expired data — no manual intervention required by clinic staff.
7

How PRA Helps Your Clinic Stay Compliant

Clinics using PRA benefit from built-in DPDP compliance infrastructure:

  • Consent collection and audit trail — automatically logged at the WhatsApp layer
  • Patient data export tool — allows you to respond to access/portability requests in minutes
  • One-click data deletion — trigger erasure for any patient from the dashboard
  • Grievance log — track and respond to patient complaints within the PRA dashboard
  • DPA (Data Processing Agreement) — available on request for enterprise subscribers
8

Contact the Data Protection Officer

DPO: Data Protection Officer, ParroConnect

Email: support@parroconnect.com

Address: Chennai, Tamil Nadu, India — 600 001

Response SLA: 48 hours acknowledgement · 30 days resolution