Privacy Policy
Last Updated: 19-Aug-2026
Effective Date: 19-Aug-2026
Website: https://convyodigital.in
Company / Service Provider: Convyo Digital
Email: convyodigital@gmail.com
Phone: +91 76249 37131 / +91 84809 44878
1. About This Privacy Policy
Convyo Digital ("Convyo Digital", "we", "us", or "our") provides technology and business automation services, including WhatsApp-based appointment management, appointment CRM software, dashboards, integrations, websites, and related services for medical stores, clinics, doctors, and other business customers.
This Privacy Policy explains how we collect, use, disclose, store, protect, and otherwise process personal information when:
- you visit our website;
- you contact us;
- a business customer uses our software or services;
- you use a Convyo Digital account or dashboard; or
- information is submitted through an appointment or automation workflow operated for one of our business customers.
2. The Two Different Types of Data We Handle
A. Convyo Digital's own business data
This includes information about our customers, prospective customers, website visitors, users of our own website, billing/contact records, and account administration information.
For this data, Convyo Digital may determine why and how the information is processed.
B. Business-customer data
When a medical store, clinic, or other business uses Convyo Digital to operate an appointment workflow, the business customer may determine the purpose for which patient/customer information is collected and used.
For those records, the business customer may be the primary entity responsible for determining the purpose and lawful basis of processing, while Convyo Digital may provide the technology and act as a service provider/data processor for that customer, subject to the applicable law and the customer's instructions.
The exact legal roles may vary by service and use case and should be documented in the applicable customer agreement/data-processing terms.
3. Information We May Collect
Depending on how you interact with Convyo Digital, information may include:
Contact and business information
- name;
- business name;
- phone number;
- email address;
- business address;
- job title or role; and
- information provided during a demo, enquiry, quotation, or onboarding process.
Account information
- login email;
- authentication identifiers;
- account role;
- store/business identifier; and
- security and access information.
Appointment/patient information
Where Convyo Digital is providing an appointment-management service to a business customer, the customer's configured workflow may collect limited information such as:
- name;
- age;
- gender;
- WhatsApp/phone number;
- appointment date and time;
- selected doctor;
- token number;
- appointment status;
- attendance status;
- waitlist status; and
- information voluntarily submitted by the patient/customer through the configured workflow.
The exact fields depend on the customer's implementation.
Technical information
We may collect limited technical information such as:
- IP address;
- browser and device type;
- operating system;
- pages visited;
- timestamps;
- referring page;
- security logs;
- error logs; and
- cookie or similar technology information where used.
We will not intentionally collect more information than reasonably required for the relevant service.
4. Information We Do Not Intentionally Collect Through the Standard Appointment Form
The standard Convyo Digital appointment workflow is designed to collect only information required for appointment management.
Unless expressly configured and lawfully required for a particular customer use case, the standard appointment form is not intended to collect:
- detailed medical history;
- diagnosis;
- laboratory reports;
- prescriptions;
- payment-card numbers;
- bank passwords;
- Aadhaar numbers;
- passwords; or
- financial account credentials.
Business customers must not configure the service to collect unnecessary personal information.
5. How We Use Information
We may use information to:
- provide, operate, and maintain our services;
- create and manage accounts;
- process appointment requests;
- generate appointment/token numbers;
- send appointment confirmations, reminders, cancellations, or rescheduling notifications;
- provide dashboards and CRM functionality;
- respond to support requests;
- communicate with business customers;
- diagnose technical issues;
- maintain security and prevent abuse;
- improve the reliability and functionality of our services;
- manage contracts, billing, records, and legal obligations;
- comply with applicable law; and
- protect our rights, users, customers, and systems.
We will not sell patient/customer personal data as a business model.
6. Consent and Lawful Collection
Personal information should be collected through lawful and transparent means.
Where a business customer uses Convyo Digital to collect patient information, the business customer is responsible for ensuring that the collection and use of that information has an appropriate legal basis and that required notices/consents are provided to the individual.
Convyo Digital will process business-customer data according to the customer's lawful instructions and the applicable service agreement, subject to our legal obligations.
Where consent is the basis for processing, the relevant workflow should make the purpose understandable and should not use deceptive or bundled consent.
7. Customer / Medical Store Responsibilities
When a medical store, clinic, doctor, or other business customer uses Convyo Digital, the customer is responsible for:
- collecting information lawfully;
- providing the required privacy notice to its patients/customers;
- obtaining consent where required;
- ensuring that the information submitted to Convyo Digital is accurate and appropriate;
- not collecting unnecessary personal information;
- using personal information only for lawful business purposes;
- responding to requests from patients/customers where required;
- providing instructions to Convyo Digital regarding customer data;
- ensuring that any patient/customer communication sent through the customer's account is lawful and appropriate;
- obtaining any required parental/guardian consent when processing children's personal data where required by law; and
- complying with applicable healthcare, consumer, tax, professional, advertising, and other laws applicable to the customer's own business.
The customer confirms that it has authority to provide information to Convyo Digital for the services it has purchased.
8. Third-Party Service Providers
Convyo Digital may use trusted service providers to operate the service, including providers for:
- cloud hosting;
- databases;
- authentication;
- website/application hosting;
- WhatsApp/business messaging;
- email;
- analytics;
- security;
- backups;
- customer support; and
- other infrastructure required to deliver the service.
Depending on the customer's selected setup, these providers may include services such as Supabase, Vercel, Meta/WhatsApp, MapStore, email providers, and other infrastructure providers.
Third-party providers may process information according to their own terms and privacy policies and applicable agreements with Convyo Digital.
Convyo Digital will seek to use providers that provide reasonable security and contractual protections appropriate to the service.
9. WhatsApp and Messaging
Where the service uses WhatsApp, messaging may be delivered through Meta/WhatsApp and/or an authorised messaging provider/integration selected for the customer's account.
Messages may be subject to:
- WhatsApp/Meta policies;
- template approval;
- messaging limits;
- consent requirements;
- provider rules;
- delivery failures;
- pricing changes; and
- technical outages or restrictions outside Convyo Digital's control.
Convyo Digital does not guarantee delivery of every WhatsApp message.
10. Data Security
We take reasonable technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration, loss, misuse, or destruction.
Measures may include:
- encrypted connections;
- authentication and access controls;
- role-based access;
- tenant/data isolation;
- database security controls;
- server-side processing for sensitive credentials;
- secret management;
- logging and monitoring;
- backups;
- software updates; and
- least-privilege access.
No internet-based service can guarantee absolute security.
11. Access to Business-Customer Data
Access to patient/customer data is limited to authorised personnel, systems, and service providers who require access to provide or secure the service.
Convyo Digital will not intentionally use business-customer patient data for unrelated advertising or sale of personal information.
Where practical, access should be logged and limited according to role.
12. Data Retention
We retain personal information only for as long as reasonably necessary for:
- providing the service;
- maintaining business/account records;
- security and fraud prevention;
- resolving disputes;
- complying with legal obligations; or
- following lawful instructions from the relevant customer.
For patient/customer data processed on behalf of a business customer, retention should generally follow the customer's documented instructions and applicable legal requirements.
The business customer remains responsible for determining appropriate patient-record retention where the law places that responsibility on the customer.
Deleted data may remain temporarily in encrypted backups or system logs until those systems rotate according to their normal retention cycle.
13. Data Deletion
Business customers may request deletion of customer/patient data held by Convyo Digital, subject to:
- applicable law;
- contractual obligations;
- legitimate security requirements;
- backup retention cycles; and
- records that must legally be retained.
Where Convyo Digital acts as a service provider/processor for a customer, we may direct the individual to the relevant business customer for correction or deletion requests because that customer may control the underlying patient/customer relationship.
14. Data Accuracy
Convyo Digital does not independently verify all information submitted by patients or business customers.
Business customers are responsible for the accuracy of information used in their appointment workflows and should provide suitable mechanisms for correction.
15. Children's Personal Data
Business customers must not knowingly collect children's personal data through Convyo Digital workflows unless they have a lawful basis and have implemented any legally required parental/guardian consent and safeguards.
Where applicable Indian data-protection requirements for children's data apply, Convyo Digital may require customers to implement additional safeguards before enabling such workflows.
16. International Processing
Some service providers used by Convyo Digital may process or store information in jurisdictions outside India.
Where cross-border processing occurs, Convyo Digital will seek to use contractual, technical, and organisational safeguards appropriate to applicable law.
We do not promise that all data will always remain physically within India unless a specific service agreement says so.
17. Cookies and Similar Technologies
Our website may use cookies or similar technologies for essential functionality, security, preferences, analytics, or performance.
Where required by applicable law, we will provide appropriate controls or notices.
You can generally control cookies through your browser settings, although disabling certain cookies may affect website functionality.
18. Your Rights
Subject to applicable law, individuals may have rights relating to their personal information, including rights concerning:
- access to information about processing;
- correction;
- erasure where applicable;
- withdrawal of consent where consent is the legal basis;
- grievance redressal; and
- other rights provided by applicable law.
For patient/customer records created through a medical store or other business customer, please contact that business first where it is the entity responsible for the patient/customer relationship.
For Convyo Digital's own data, you may contact us directly.
19. Grievances and Privacy Requests
For privacy questions or requests regarding Convyo Digital's own processing, contact:
Convyo Digital
Email: convyodigital@gmail.com
Phone: +91 76249 37131 / +91 84809 44878
Anshuman Pati or Aditya Amlan Pati
We will handle requests in accordance with applicable law.
20. Data Breach
If Convyo Digital becomes aware of a security incident affecting personal data, we will take appropriate steps to investigate, contain, remediate, and notify affected parties or authorities where required by applicable law.
Business customers agree to cooperate with Convyo Digital in relation to incident investigation and legally required notifications.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to our services;
- legal or regulatory requirements;
- security improvements; or
- operational changes.
We will publish the updated version on this website and update the "Last Updated" date.
22. Contact
For privacy and data-protection questions:
Convyo Digital
Email: convyodigital@gmail.com
Phone: +91 76249 37131
Phone: +91 84809 44878
Website: https://convyodigital.in