Skip to content

Trust

Security & compliance

How we protect your data and your patients’ data — in plain words.

Your prescriptions are not for sale

Simplis never sells or shares your clinic, patient or prescription data with pharma companies, marketers, advertisers or data brokers. There are no ads and no “sponsored” drug suggestions — medicine suggestions come from your own prescribing and the drug database, never from paid placements.

  • Data Sharing — No Sale of Data

    • We never sell or share clinic, patient or prescription data with pharmaceutical companies, marketers, advertisers or data brokers
    • No ads and no sponsored drug suggestions — medicine suggestions come from your own prescribing and the drug database
    • AI providers (Sarvam AI, OpenAI) process data only after the doctor gives consent, only to provide the service, and do not train their models on it
    • Consent can be revoked anytime in Settings; AI features stay off until it is granted
  • Encryption

    • AES-256 encryption for data at rest (Google Cloud default)
    • HTTPS (TLS) for all data in transit
    • Audio recordings encrypted in transit and at rest, deleted after transcription
    • Encryption keys managed by Google Cloud
  • Data Hosting

    • Primary database and storage hosted on Google Cloud (asia-south1, Mumbai)
    • AI processing uses third-party APIs (OpenAI, Sarvam AI) — data may be processed outside India
    • Per-clinic databases with separate credentials, encrypted at rest
  • Doctor Verification

    • Automated NMC (National Medical Commission) register lookup during signup
    • State Medical Council cross-referencing
    • Unverified accounts have restricted access to clinical features
  • Access Controls

    • Role-based access control (RBAC) — doctors only see their own patient data
    • Per-clinic tenant isolation with separate database credentials
    • JWT-based authentication with session expiry
    • All API endpoints require authentication
  • Data Retention

    • Clinical records retained for a minimum of 3 years per ICMR guidelines
    • Audio recordings deleted immediately after transcription (within minutes)
    • Doctors can request full data export or account deletion
    • Account data retained for 90 days after deletion request before purging
  • AI Models — Clinical Notes & Prescriptions

    • OpenAI GPT-4o — clinical notes, prescriptions, and treatment plans
    • OpenAI GPT-4o-mini — intent detection and search classification
    • Sarvam AI Saaras v3 — speech-to-text in 23 Indian languages
    • All AI outputs are decision support only — the treating doctor must review and approve
  • Indian IT Act Compliance

    • Reasonable security practices followed per IT Act 2000, Section 43A
    • Sensitive personal data handled per Information Technology Rules 2011
    • Privacy policy publicly available
    • Practices aligned with the Digital Personal Data Protection Act, 2023 (consent, purpose limitation, deletion on request)
    • Doctors are data controllers; Simplis acts as data processor

For security concerns or to report a vulnerability, contact security@simplis.in

Start free trial