1. Who this policy covers
Adozta Softech Private Limited operates Ado Q. This policy explains information handling for our website, enquiries, demos, account administration and hosted application. It also explains the distinction between information we manage for our own business and patient or visitor records we process for a customer organisation.
For records entered by a clinic, hospital, lab or other organisation, that organisation normally decides the purpose, content, access and retention requirements. Contact that organisation first about your visit or clinical record. We assist with requests within our role and applicable law.
2. Information we receive
- Enquiries and demos: name, business email, organisation, sector, selected plan, booking details and the message or answers you submit.
- Accounts: names, contact details, organisation and onboarding answers, roles, sign-in credentials in protected form, trial/subscription status and support correspondence.
- Organisation records: information staff or visitors provide, such as contact details, appointments, queue events, visit history, documents, clinical notes, consultation recommendations and payment-status entries. The fields used depend on the organisation’s configuration.
- Technical information: request and security logs, IP addresses, browser/device information, session identifiers, audit events and troubleshooting details generated when the service is used.
- Consultations: participant details, scheduling, call-connection information and notes entered by staff. The current in-app calling feature does not provide call recording. Microphone/camera access requires browser permission.
Do not enter payment-card details or unrelated sensitive information in enquiry forms. Displaying a payment status in a patient record is not the same as processing a card payment.
3. Why we use information
We use information to respond to enquiries, schedule demos, create and administer accounts, deliver configured queue and record features, provide support, prevent abuse, investigate security issues and meet applicable legal obligations. When you ask us about Ado Q, we may follow up about that enquiry; you can ask us to stop sales follow-ups.
Where applicable law requires a legal basis, processing depends on the context: fulfilling a requested service or contract, consent where required, legal obligations, and permitted legitimate business interests such as service security. Customer organisations are responsible for the authority and notices needed for the records they submit.
6. Retention and deletion
We retain information according to its purpose, active service needs, customer instructions, applicable record-keeping duties, security investigations and disputes. Enquiry correspondence may remain in the business mailbox until reviewed or deleted; it is not automatically erased when an enquiry is answered.
Trial expiry or cancellation does not itself erase stored records. Some in-app delete actions mark records as deleted while retaining underlying entries or audit history. There is currently no universal automatic account-purge schedule. Account erasure is handled through a verified request, with the scope, applicable timetable and any lawful exceptions communicated to the requester. Backup copies, where held, may remain until their applicable retention cycle ends.
Customer organisations should agree the retention and deletion requirements for production data before use. Ado Q’s public test environment is not a permanent records archive. Clinical retention obligations must be assessed by the healthcare provider; we do not apply a single medical-record retention period to every customer.
7. Security and processing locations
Measures used by the application include password hashing, role-based access controls, HTTPS on hosted services and session/request protections. These measures reduce risk but cannot guarantee absolute security. Report suspected misuse or unintended disclosure promptly using the contact below.
Hosting and service providers may process information in India or other countries depending on the service and deployment. We do not promise India-only storage. Customers requiring a particular processing location, data-processing agreement or regulated healthcare arrangement should confirm those requirements with us before uploading production data.
8. Your requests and choices
Depending on applicable law and our role, you may request access, correction, erasure, information about processing, restriction or objection, withdrawal of consent or another available privacy right. Contact adoqsales@adozta.com with enough information to identify your relationship with us; do not email full medical records or passwords. We may ask for proportionate verification before releasing or changing information.
For a patient or visitor record controlled by a customer organisation, we may refer your request to that organisation or assist it on authorised instructions. Withdrawal of consent may prevent the related optional feature from continuing and does not by itself undo prior lawful processing. You may also complain to a competent authority where that right is available.
9. Children and healthcare records
Business administrator accounts are intended for adults. A healthcare provider may hold a minor’s record where it has the required authority, notices and parent/guardian consent or another lawful basis. We do not invite children to create independent business accounts. Contact us if you believe information has been collected or shared without the necessary authority.
10. Contact and policy updates
For privacy requests or complaints, contact our privacy team at adoqsales@adozta.com. We will review the request and respond in accordance with applicable requirements. The registered business address is:
Adozta Softech Private Limited
No.2, Carmel Nagar, Nagai Road, Katuthottam, Mariammancoil, Thanjavur – 613501, Tamil Nadu, India
We may update this policy as the service changes. The effective date is shown above; material changes will receive additional notice where required. This policy is not a claim of a privacy certification or a substitute for a customer’s own patient/privacy notices.