PROFESSIONAL AGREEMENT
For Registered Medical Practitioners
Terms of Use · Privacy Policy · Consent Notice · Software Licence · Data Processing Agreement
This Professional Agreement ("Agreement") is a legally binding contract between Pranik Technologies Private Limited, operating as Pranik.ai ("Company," "We," "Us"), having its registered office at Plot No. 114-116, Gafoornagar, Hyderabad, Telangana - 500018, India, and you, the Registered Medical Practitioner ("Doctor," "You").
This single Agreement covers everything that governs your professional relationship with P4D: the terms under which you use the platform, how we protect your data and patient data, what you are consenting to as a Data Principal, the software licence terms, and the data processing arrangements governing patient data you access through the platform. By accepting this Agreement you also accept the Pranik Data Processing Agreement ("DPA"), which is incorporated herein by reference and is available at pranik.ai/legal/dpa and within the App at Settings → Legal.
BY TAPPING "I AGREE" OR CREATING AN ACCOUNT, YOU CONFIRM THAT YOU HOLD A VALID, CURRENT REGISTRATION AS A REGISTERED MEDICAL PRACTITIONER AND THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THIS AGREEMENT IN FULL.
Company
Pranik Technologies Private Limited
Brand
Pranik.ai / P4D
Registered Office
Plot No. 114-116, Gafoornagar, Hyderabad, Telangana - 500018, India
Doctor Support
support@pranik.ai
DPO
dpo@pranik.ai
DPA
pranik.ai/legal/dpa | Settings → Legal → Data Processing Agreement
Website
https://pranik.ai
PART 1 - TERMS OF USE
1. KEY DEFINITIONS
P4D App
The Pranik for Doctors mobile application and associated platform, facilitating teleconsultations, clinical decision support, and Digital Twin creation.
Doctor
A Registered Medical Practitioner (RMP) holding a valid registration with the NMC or any State Medical Council of India, who has created a P4D account.
Patient
A P4P App user seeking medical consultation from a Doctor through the platform.
Digital Twin
The AI-powered physician avatar created within P4D based on the Doctor's Input Data.
Doctor's Input Data
The Doctor's photograph(s), voice samples, and medical knowledge base content provided to create and train the Digital Twin. Treated as biometric-like Sensitive Personal Data.
CDSS Lite
The AI-assisted Clinical Decision Support System providing draft medicine recommendations and treatment suggestions, subject always to the Doctor's independent clinical review.
Live Scribe
The automated post-consultation transcription feature that processes consultation audio into a structured transcript.
NMC
National Medical Commission, the statutory body governing medical education and practice in India.
Telemedicine Guidelines
The Telemedicine Practice Guidelines issued by the Board of Governors in supersession of the Medical Council of India / NMC, as amended from time to time.
Patient Personal Data
Personal Data of patients transmitted to P4D from P4P for consultation purposes.
DPA
The Pranik Data Processing Agreement, incorporated by reference into this Agreement and available at pranik.ai/legal/dpa.
DPDP Act
The Digital Personal Data Protection Act, 2023, as amended, together with all rules framed thereunder.
2. SERVICES PROVIDED BY P4D
2.1 Teleconsultation Platform
Appointment management: scheduling, acceptance, rejection, and reminders.
Pre-consultation information: patient SOAP summary from P4P transmitted to the Doctor prior to consultation.
Secure video, audio, and text-based teleconsultation tools.
Post-consultation documentation and e-signed prescription generation.
2.2 CDSS Lite - Clinical Decision Support
Draft medicine recommendations, differential diagnosis suggestions, and treatment protocol options.
Post-consultation draft prescription generation for the Doctor's review.
CRITICAL: ALL CDSS Lite outputs are DRAFT SUGGESTIONS ONLY. They must be independently reviewed and approved by the Doctor before any clinical reliance. CDSS Lite is NOT a medical device or approved clinical tool.
2.3 Live Scribe
Automated transcription of consultation audio into a structured post-consultation record.
Raw audio is processed through the anonymization pipeline and permanently deleted within 24 hours. The structured transcript is retained as part of the clinical record.
Requires explicit consent of both Doctor and Patient before activation.
2.4 Digital Twin - Optional Premium Feature
AI-powered physician avatar based on the Doctor's image, voice, and knowledge base.
Setup is deferred to after first successful consultation - it is not required for registration.
Purple-highlighted consent items in Part 3 relate to Digital Twin data. This data is treated as biometric-like Sensitive Personal Data with enhanced protections.
2.5 Emergency Disclaimer
P4D IS NOT FOR EMERGENCY CARE. If you identify a life-threatening condition during any consultation, immediately advise the patient to call 112 or 108 and go to the nearest emergency facility.
3. ELIGIBILITY, REGISTRATION, AND VERIFICATION
3.1 Eligibility
You must hold a valid, current, and unsuspended registration as an RMP with the NMC or a recognized State Medical Council of India.
You must not be subject to any regulatory suspension, debarment, or restriction on medical practice.
You must be legally capable of entering into a binding contract under the Indian Contract Act, 1872.
3.2 Registration
You must provide accurate, complete, and current information including your NMC UID, State Council registration number, qualifications, and bank account details for fee disbursement.
You must disclose any ongoing regulatory or disciplinary proceedings against your medical licence.
3.3 Credential Verification
The Company verifies credentials with the NMC and State Medical Councils at registration and periodically thereafter. Misrepresentation results in immediate termination and may be reported to the relevant regulatory authority.
3.4 Institutional Accounts
If you access P4D through a hospital or clinic group account, that institution's administrator may have access to your consultation activity, scheduling data, and platform usage within the scope of your institutional practice. The Company will notify you before linking your account to an institutional account.
4. PROFESSIONAL OBLIGATIONS AND RESPONSIBILITIES
4.1 Professional Conduct
Comply with the Telemedicine Practice Guidelines, 2020.
Comply with the NMC Code of Professional Conduct (including the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002 as deemed under Section 57 of the NMC Act, 2020, and any updated NMC regulations).
Comply with the DPDP Act, 2023 and IT-SPDI Rules, 2011.
Adhere to the highest standards of medical ethics as prescribed by the NMC.
4.2 Human-in-the-Loop - Non-Negotiable
ALL medical advice, diagnosis, treatment decisions, and prescriptions are solely and exclusively your independent professional responsibility.
You must not mechanically rely on CDSS Lite, the Digital Twin, or any AI feature without independent clinical judgment.
The SOAP pre-consultation summary is patient-reported data summarized by AI. You must clinically corroborate all such data during the live consultation.
4.3 Prescriptions
Indian law does not permit AI systems to issue or sign prescriptions.
Every draft prescription generated by P4D must be reviewed, edited where necessary, and e-signed by you before transmission to the patient.
Your e-signature constitutes full clinical ownership and responsibility for the prescription's contents.
4.4 Patient Confidentiality
Maintain strict confidentiality of all Patient Personal Data accessed through P4D.
Do not download, copy, or transfer Patient data outside P4D without the patient's explicit consent and a lawful purpose.
Use Patient data only to provide healthcare to that specific patient.
Immediately notify dpo@pranik.ai if you become aware of any unauthorized access to Patient data through your account.
4.5 Prohibited Conduct
Share your login credentials with any third party.
Allow your Digital Twin to provide autonomous medical advice without your real-time oversight.
Provide consultations outside your registered scope of practice.
Misrepresent your qualifications, registration status, or professional experience.
Use the App outside India unless the Company has expressly confirmed compliance with applicable law in that jurisdiction.
Use the App after your RMP registration has lapsed, been suspended, or been revoked.
5. DIGITAL TWIN - SPECIAL PROVISIONS
This section applies only if you choose to create a Digital Twin. The Digital Twin is entirely optional and is not required for core P4D functionality.
5.1 Nature and Ownership
The Digital Twin is an AI assistant modelled on your likeness, voice, and curated knowledge. You retain full ownership of your Doctor's Input Data (photographs, voice samples, knowledge base content). The Company processes it only under the limited licence in Section 5.2 below.
5.2 Licence to the Company
By providing Doctor's Input Data and activating the Digital Twin, you grant the Company a limited, non-exclusive, non-transferable, revocable licence to use your Input Data solely to: (a) create, render, operate, and update your Digital Twin within P4D; and (b) improve Digital Twin technical quality using anonymized and aggregated data only. This licence does NOT permit the Company to use your likeness for advertising, marketing, or training general AI models unrelated to your specific Digital Twin.
5.3 Revocation and Deletion
You may revoke Digital Twin consent at any time via Settings → Manage Digital Twin or by contacting dpo@pranik.ai. Upon revocation: (a) new processing of your face and voice data ceases; (b) your Digital Twin is deactivated within the App; (c) source files (photographs, voice recordings) are deleted within 30 days, subject to mandatory 1-year audit log retention. Neural network model weights derived from your Input Data exist as aggregate mathematical parameters that cannot be individually identified, attributed, or removed from a trained model - deletion of source files constitutes full compliance with your erasure right in respect of Digital Twin data.
5.4 Your Responsibility for Digital Twin Outputs
You are solely responsible for the medical accuracy, ethical implications, and legal compliance of all outputs from your Digital Twin. You must review and validate all Digital Twin outputs before communicating them to patients.
6. AI FEATURES - DISCLAIMERS AND REGULATORY STATUS
6.1 What AI Features Do NOT Do
No AI feature makes, communicates, or finalises any medical diagnosis, treatment decision, or prescription without the Doctor's explicit review and e-signature.
No AI feature restricts or affects the Doctor's account or practice rights based on automated analysis.
CDSS Lite does not communicate directly with patients.
6.2 AI Output Limitations
CDSS Lite recommendations, Live Scribe transcripts, SOAP summaries, and Digital Twin outputs may contain material clinical errors even where they appear specific and confident.
AI outputs may not reflect current clinical guidelines or recent drug safety updates.
None of the AI features on P4D are substitutes for your independent clinical judgment or physical examination.
6.3 CDSCO / Regulatory Status
CDSS Lite, Live Scribe, and the Digital Twin are NOT currently classified, cleared, or approved as medical devices or Software as a Medical Device (SaMD) by CDSCO under the Medical Devices Rules, 2017. They are assistive tools only. If CDSCO or any regulatory authority reclassifies any P4D feature, the Company will notify Doctors and take all steps required by law.
7. INTELLECTUAL PROPERTY AND SOFTWARE LICENCE
7.1 Ownership
All intellectual property in P4D - including CDSS Lite algorithms, the Digital Twin rendering engine, Live Scribe transcription system, and underlying AI models (excluding Doctor's Input Data) - belongs to the Company or its licensors.
7.2 Licence Grant
Subject to your compliance with this Agreement and your holding a valid RMP registration, the Company grants you a limited, non-exclusive, professional, non-transferable, revocable licence to install and use P4D solely for your lawful professional medical practice.
7.3 Automatic Termination on Loss of RMP Status
Your licence terminates automatically and immediately, without notice, upon: (a) lapse, suspension, cancellation, or revocation of your RMP registration; or (b) any regulatory order prohibiting you from practicing medicine in India. You must immediately cease using P4D and notify the Company at support@pranik.ai upon any change in your registration status.
7.4 Your Clinical Content
Consultation notes, prescriptions, and clinical content you generate remain your intellectual property. By submitting such content, you grant the Company a limited licence to process and store it for platform operation and - in irreversibly anonymized form - for improvement of clinical AI features.
7.5 Feedback and Knowledge Base - No Compensation
No fee, royalty, or other compensation is payable for Feedback or Knowledge Base content you provide, regardless of its contribution to platform improvements. Knowledge Base content is processed solely under the Digital Twin licence in Section 5.2.
7.6 App Store Terms
Google Play Store and Apple App Store terms govern download and installation. This Agreement governs your professional use of P4D. Apple Inc. is a third-party beneficiary for use on Apple devices.
7.7 Open Source Components
A list of material open-source components is available at Settings → Legal → Open Source Notices.
8. DATA PROCESSING AGREEMENT - INCORPORATION BY REFERENCE
When you access Patient Personal Data through P4D, the Company acts as a Data Processor on your behalf as Data Fiduciary, for the purpose of facilitating consultations. The terms governing this processing are set out in the Pranik Data Processing Agreement ("DPA").
By accepting this Agreement, you agree to the DPA. The DPA is incorporated into this Agreement by reference and has the same legal force as if reproduced here in full. It is available at:
pranik.ai/legal/dpa - public URL
Settings → Legal → Data Processing Agreement - within the App
The DPA covers: the subject matter and purposes of patient data processing; the Company's security and confidentiality obligations; sub-processor controls; breach notification procedures; your audit rights; and the retention and deletion obligations for Patient Personal Data. For enterprise or institutional deployments, a negotiated bilateral DPA is available upon request from support@pranik.ai.
Key DPA principle: The Company processes Patient Personal Data only on your instructions as the treating Doctor and for the purposes set out in the DPA. Once patient data is irreversibly anonymized, the Company acts as its own Data Fiduciary for AI model improvement - at that point the data is no longer Personal Data under the DPDP Act, 2023.
9. FEES AND PAYMENTS
Consultation fees are paid to the Doctor on a per-consultation or periodic basis via bank transfer to the Doctor's registered account. Fee structures and payment schedules are communicated separately. The Company reserves the right to revise its fee structure with prior notice. All applicable tax obligations (GST, Income Tax) are the Doctor's independent responsibility.
10. DISCLAIMERS AND LIMITATION OF LIABILITY
THE FOLLOWING DISCLAIMERS APPLY TO THE FULLEST EXTENT PERMITTED BY APPLICABLE INDIAN LAW.
10.1 Platform Technology Provider
P4D IS A TECHNOLOGY PLATFORM ONLY. IT DOES NOT PROVIDE MEDICAL SERVICES, ADVICE, DIAGNOSIS, OR TREATMENT. ALL CLINICAL DECISIONS AND PATIENT CARE ARE THE SOLE RESPONSIBILITY OF THE DOCTOR.
10.2 No Warranty on AI Outputs
CDSS LITE, LIVE SCRIBE TRANSCRIPTIONS, SOAP SUMMARIES, AND DIGITAL TWIN OUTPUTS ARE PROVIDED ON AN "AS IS" BASIS. THE COMPANY MAKES NO WARRANTIES AS TO THEIR CLINICAL ACCURACY, COMPLETENESS, OR FITNESS FOR CLINICAL RELIANCE. YOU ASSUME ALL RISK IN RELYING ON THESE OUTPUTS WITHOUT INDEPENDENT CLINICAL VERIFICATION.
10.3 Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE COMPANY SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM: (I) USE OR INABILITY TO USE P4D; (II) CLINICAL ERRORS IN AI OUTPUTS; (III) MISUSE OF THE DIGITAL TWIN; (IV) PATIENT HARM FROM MEDICAL ADVICE OR PRESCRIPTIONS PROVIDED BY THE DOCTOR.
TOTAL AGGREGATE LIABILITY SHALL NOT EXCEED THE GREATER OF: (A) FEES PAID BY YOU IN THE SIX (6) MONTHS BEFORE THE CLAIM; OR (B) INR 5,000. NOTHING IN THIS AGREEMENT LIMITS LIABILITY FOR DEATH OR PERSONAL INJURY CAUSED BY THE COMPANY'S GROSS NEGLIGENCE OR WILFUL MISCONDUCT, OR ANY LIABILITY THAT CANNOT BE EXCLUDED UNDER APPLICABLE MANDATORY INDIAN LAW.
11. INDEMNIFICATION
You agree to indemnify and hold harmless the Company, its affiliates, officers, and employees from all claims, liabilities, damages, and expenses arising from: (a) your breach of this Agreement; (b) misrepresentation of your RMP registration; (c) your professional negligence, malpractice, or clinical errors; (d) breach of patient confidentiality; (e) claims arising from your Digital Twin outputs; or (f) misuse of your account credentials.
12. TERMINATION
The Company may suspend or terminate your account immediately for: breach of this Agreement; misrepresentation of credentials; regulatory action against your medical licence; or conduct endangering patient safety. You may terminate by closing your account via App settings or by contacting support@pranik.ai.
12.1 Patient Data After Termination
Termination does NOT result in immediate deletion of consultation records or Patient data. Clinical records and prescriptions are retained for mandatory statutory periods (minimum 7 years for records; minimum 5 years for prescriptions) regardless of account status. Raw audio is deleted within 24 hours of processing; raw video is never stored.
12.2 Digital Twin After Termination
On account closure, you may request deletion of your Digital Twin data as described in Section 5.3. Source files are deleted within 30 days of request.
12.3 Inactivity
If your account is inactive for 18 continuous months with no consultations or login activity and you have no active paid subscription, the Company may deactivate it after 30 days' prior notice to your registered email. Health data retention obligations apply regardless of account status.
13. GOVERNING LAW AND DISPUTE RESOLUTION
13.1 Governing Law
This Agreement is governed by the laws of India, without regard to conflict of law principles.
13.2 Dispute Resolution
Disputes shall first be attempted amicably within 30 days. If unresolved, referred to binding arbitration under the Arbitration and Conciliation Act, 1996. Seat and venue: Hyderabad, Telangana. Language: English. Award is final and binding.
13.3 Jurisdiction
Subject to arbitration, the courts at Hyderabad, Telangana have exclusive jurisdiction.
14. GENERAL PROVISIONS
14.1 Amendments
Material amendments require 30 days' prior notice. For changes to core clinical features (Teleconsultation, CDSS Lite, Live Scribe), 30 days' advance notice will be given except where immediate action is required by law or security.
14.2 Relationship of Parties
The Doctor is an independent professional. Nothing in this Agreement creates an employer-employee, partnership, or agency relationship between the Doctor and the Company.
14.3 Severability / No Waiver / Assignment / Force Majeure
Standard provisions apply: invalid clauses are severed without affecting the remainder; no waiver by failure to enforce; no assignment without written consent (Company may assign in corporate restructuring); neither party liable for force majeure events.
14.4 Entire Agreement
This Agreement (including all Parts and the DPA incorporated by reference) constitutes the entire agreement between the Doctor and the Company regarding P4D and supersedes all prior agreements.
14.5 Language
English governs. In case of inconsistency with any translation, the English version prevails.
PART 2 - PRIVACY POLICY FOR REGISTERED MEDICAL PRACTITIONERS
This Part explains how we collect, use, and protect your Personal Data as a Doctor on the P4D platform. You occupy a dual role: service provider AND Data Principal. This Policy addresses both.
15. PERSONAL DATA WE COLLECT ABOUT YOU
15.1 Professional Identity and Verification Data
Full name, date of birth, gender.
Government-issued photo ID reference (last 4 digits only - full Aadhaar not stored).
NMC Unique ID (UID), State Medical Council Registration Number, medical qualifications, specialization.
Professional photograph.
15.2 Account and Contact Data
Email address, mobile phone number, encrypted password.
Bank account details (account number, IFSC code) for fee disbursement.
GST registration details where applicable.
15.3 Doctor's Input Data for Digital Twin - Biometric-Like Sensitive Data
This is the most sensitive category. Processed only with separate, explicit consent. See Part 3 for consent items.
Facial photograph(s) and/or video frames for avatar generation.
Voice samples (audio recordings) for voice synthesis.
Medical knowledge base content: clinical notes, treatment preferences, FAQ responses uploaded to train the Digital Twin.
15.4 Consultation and Clinical Activity Data
Appointment schedule: accepted, rejected, and completed consultation records.
Pre-consultation SOAP summaries received from P4P (patient-reported data).
Live Scribe transcriptions - raw audio deleted within 24 hours; structured transcript retained as clinical record.
Draft and e-signed prescriptions.
CDSS Lite interaction logs (recommendations accepted, modified, or rejected by you).
Doctor's notes and clinical decisions.
15.5 Financial and Platform Data
Consultation fee disbursement records and transaction history.
Device type, OS, IP address, session logs, feature usage (anonymized).
16. PURPOSES OF PROCESSING AND LEGAL BASIS
Processing Activity
Data Involved
Purpose
Legal Basis
Justification
Professional KYC / Credential Verification
Name, NMC UID, qualifications, Govt. ID, photo
Verify RMP status; KYC compliance
Consent; Legal Obligation
Mandatory under KYC regulations and Telemedicine Guidelines 2020. Unverified practitioners could endanger patients.
Account creation and authentication
Name, email, phone, password
Create and manage account
Contract; Consent
Necessary to perform the service contract.
Digital Twin - Face image
Face photograph(s)
Create visual AI avatar
Explicit Consent (separate)
Biometric-like Sensitive Data. Separate explicit consent only. Purpose limited to Digital Twin rendering.
Digital Twin - Voice
Voice recordings
Create voice component of Digital Twin
Explicit Consent (separate)
Biometric-like Sensitive Data. Stored in encrypted restricted-access environment. Independently revocable.
Digital Twin - Knowledge Base
Clinical notes, treatment preferences uploaded by Doctor
Train Digital Twin to reflect Doctor's expertise
Explicit Consent (separate)
Doctor retains ownership. Licence limited to Digital Twin operation.
Teleconsultation Platform
Appointment data, SOAP summaries, consultation records
Facilitate teleconsultations; appointment management
Consent; Contract
Necessary to deliver the core contracted service.
Live Scribe Transcription
Consultation audio (processed, then deleted within 24h)
Post-consultation documentation
Consent
Explicit consent of both Doctor and Patient required. Raw audio deleted within 24 hours of pipeline completion.
CDSS Lite Interaction Logs
Patient pre-consult data; recommendations accepted/modified
Clinical decision support; quality assurance
Consent
Optional. Logs record Doctor's clinical choices for quality assurance only.
E-signed Prescription Generation
Consultation record, CDSS suggestions, Doctor's e-signature
Documentation aid; generate prescriptions
Consent
Doctor's e-signature constitutes full clinical ownership. Not autonomous.
Anonymized AI Model Training
Irreversibly anonymized consultation transcripts and CDSS logs
Improve Live Scribe, CDSS Lite, and clinical AI models
Consent (for anonymization); Legitimate Use (post-anonymization)
Opt-in. Once anonymized, data is no longer Personal Data. Re-identification is technically impossible.
Fee Disbursement
Bank account details, transaction records
Pay consultation fees to Doctor
Contract; Legal Obligation
Required under GST and Income Tax Act.
Fraud prevention
Device signals, login timestamps
Protect accounts; detect unauthorized access
Legitimate Use
Proportionate to the risk. Limited to anomaly detection.
Service notifications
Name, email, phone, appointment schedule
Appointment reminders; compliance alerts
Contract; Consent
Transactional.
Marketing (opt-in only)
Name, email, specialization
Platform updates and professional development offers
Consent (opt-in)
Fully revocable.
17. SHARING AND DISCLOSURE
We do not sell your Personal Data. We share your data only as follows:
With Patients: your name, photograph, qualifications, and availability for appointment booking. You consent to this by registering on P4D.
With Data Processors: cloud hosting, KYC verification, payment processing, Digital Twin technology providers - all bound by data processing agreements.
For legal and regulatory compliance: to the NMC, State Medical Councils, courts, or regulators when required by law.
In a business transfer: successor entity assumes equivalent privacy obligations with notice to you.
With your explicit consent: no other sharing without your specific prior consent.
17.1 No Sale of Data
We do not sell, rent, or barter your Personal Data - including your Doctor's Input Data - to any third party. We do not allow advertising targeting based on your professional data.
17.2 Third-Party AI Infrastructure
No identifiable Personal Data or Doctor's Input Data is transmitted to any third-party foundation model provider. Third-party AI compute providers receive only anonymized or synthetic data. All personal data is stored on servers in India.
17.3 Your Obligations Regarding Patient Data
As the treating Doctor, you access Patient Personal Data in your capacity as an independent medical professional. You are responsible for maintaining patient confidentiality and complying with the IT-SPDI Rules, 2011, the DPDP Act, 2023, and applicable ethics codes. See the DPA for the full framework governing patient data processing.
18. DATA RETENTION - THE FIVE DATA BUCKETS
Data Bucket
What It Covers
Retention Period
Legal Basis and Notes
Bucket 1: Clinical Records
EHR, consultation transcripts (text), e-signed prescriptions, CDSS logs (anonymized), doctor's notes
Consultation records: minimum 7 years. Prescriptions: minimum 5 years.
Telemedicine Guidelines 2020; Clinical Establishments Act; Drugs and Cosmetics Act. Retained even after account closure.
Bucket 2: Raw Audio
Raw voice recordings of consultations processed through Live Scribe
Deleted within 24 hours of anonymization pipeline completing. Not retained.
Collected only to generate transcripts. Automatic deletion upon pipeline confirmation.
Bucket 3: Raw Video
Live consultation video feeds; camera feeds during consultations
Never stored. Real-time processing only.
No video recording capability in the system architecture.
Bucket 4: Doctor's Input Data
Face photographs, voice samples for Digital Twin; knowledge base content
Duration of consent + 30 days post-revocation (source files). Audit logs: minimum 1 year post-deletion.
Biometric-like Sensitive Data. Deletion is of source files; model weights cannot be individually extracted.
Bucket 5: Anonymized AI Data
Irreversibly de-identified consultation transcripts and CDSS logs
Indefinite - no longer Personal Data post-anonymization.
Cannot be traced to any individual or to the Doctor. Outside scope of DPDP Act erasure obligations.
19. YOUR RIGHTS AS A DATA PRINCIPAL
Exercise rights by contacting dpo@pranik.ai or through the App's Privacy Settings:
Right
What It Means
Access and Information
Request a summary of Personal Data held about you and how it is used.
Correction
Request correction of inaccurate data. Credential corrections may require NMC re-verification.
Erasure
Request deletion of your data. Subject to mandatory retention obligations (Bucket 1 above). Digital Twin data deletion governed by Section 5.3.
Data Portability
Request your data in JSON or CSV format for transfer to another platform.
Withdraw Consent
Withdraw consent for any optional processing including Digital Twin and AI training.
Grievance Redressal
Contact dpo@pranik.ai. Acknowledgement within 72 hours; resolution within 30 days.
Nomination
Nominate another individual to exercise your rights in the event of death or incapacity.
Escalation
Data Protection Board of India (once constituted under DPDP Act, 2023).
20. SECURITY, ABDM, AND FUTURE COMPLIANCE
20.1 Security Measures
Encryption in transit (TLS 1.2+) and at rest (AES-256).
Separate, restricted-access storage for Doctor's Input Data.
Role-based access controls; MFA for all personnel accessing Personal Data.
Regular third-party security audits and penetration testing.
Automatic deletion of raw audio within 24 hours of pipeline completion.
Incident response and breach notification procedures.
20.2 ABDM / NDHM Integration
Where ABDM integration is enabled, data flows are additionally governed by the NHA's ABDM Data Policy. Until activated, no data flows to ABDM infrastructure.
20.3 Cross-Border Transfer
Personal Data is stored in India. Only anonymized data may be processed on infrastructure outside India. We will comply with any future transfer restrictions issued by the Central Government under the DPDP Act, 2023.
20.4 Data Protection Impact Assessment
The Company conducts DPIAs for high-risk processing activities including Digital Twin biometric-like data, AI-assisted clinical services, and patient data processing, in accordance with the DPDP Rules, 2025. DPIAs are reviewed annually.
21. CONTACT AND GRIEVANCE REDRESSAL
Company
Pranik Technologies Private Limited
Address
Plot No. 114-116, Gafoornagar, Hyderabad, Telangana - 500018, India
Doctor Support
support@pranik.ai
Data Protection Officer
[Name of DPO to be inserted]
DPO Email
dpo@pranik.ai
Digital Twin Requests
dpo@pranik.ai - Subject: "Digital Twin Data Request"
DPA
pranik.ai/legal/dpa | Settings → Legal → Data Processing Agreement
Escalation
Data Protection Board of India (once constituted under DPDP Act, 2023)
PART 3 - CONSENT NOTICE
Issued under Sections 5 and 6 of the Digital Personal Data Protection Act, 2023
This Part sets out the processing activities we carry out in relation to your data as a Doctor on P4D, and your consent choices. Required items are needed for the platform to function. Optional items - including all Digital Twin items - are your choice. Purple items relate to Digital Twin biometric-like data and carry enhanced protections.
We never sell your data. Every piece of data listed is used only for the purpose stated.
What we do and what data we collect
Your choice
Effect of declining
1. Professional Account Registration [ REQUIRED ]
Required to create your account and verify your identity as a Doctor. Data: full name, NMC UID, State Council registration number, qualifications, email, phone, professional photograph.
Required
Can you decline?
No - core service
2. Credential Verification (NMC KYC) [ REQUIRED ]
Required to verify your RMP status with NMC / State Medical Council. Data: NMC UID, government ID reference (last 4 digits only), medical registration certificate.
Required
Can you decline?
No - core service
3. Teleconsultation Platform [ REQUIRED ]
Core platform functionality. Data: appointment schedule, patient SOAP summaries, video/audio/text consultation records (raw audio deleted within 24h; no video stored), doctor's notes, e-signed prescriptions.
Required
Can you decline?
No - core service
4. Live Scribe - Consultation Transcription [ OPTIONAL ]
Automated transcription of consultation audio. Raw audio permanently deleted within 24 hours of pipeline completion. Data: voice audio recordings (processed then deleted); structured text transcript (retained as clinical record). We never sell your data.
☐ I consent
Can you decline?
Yes - no impact on core
5. CDSS Lite - Clinical Decision Support [ OPTIONAL ]
AI-assisted draft recommendations. Data: patient pre-consult data reviewed during consultation; your acceptance, modification, or rejection of suggestions - logged for quality assurance only.
☐ I consent
Can you decline?
Yes - no impact on core
6. E-signed Prescription Generation [ OPTIONAL ]
Draft prescription for your review and e-signature. Data: consultation record, CDSS suggestions, your e-signature. Your e-signature constitutes full clinical ownership.
☐ I consent
Can you decline?
Yes - no impact on core
7. Fee Disbursement [ REQUIRED ]
Payment of consultation fees to your registered bank account. Data: bank account number, IFSC code, account holder name, transaction records.
Required
Can you decline?
No - core service
8. Anonymized AI Model Training [ OPTIONAL ]
Improving Live Scribe, CDSS Lite, and clinical AI models using irreversibly anonymized consultation transcripts. No personally identifiable information remains post-anonymization. We never sell your data. Note: even if you opt out, safety-flagged interactions may still be used for trust and safety purposes only.
☐ I consent
Can you decline?
Yes - no impact on core
9. Service Notifications [ REQUIRED ]
Appointment reminders, compliance alerts, and platform communications. Data: name, email, phone, appointment schedule.
Required
Can you decline?
No - core service
10. Marketing Communications [ OPTIONAL ]
Platform updates and professional development offers. Data: name, email, specialization. Opt out at any time.
☐ I consent
Can you decline?
Yes - no impact on core
11. Digital Twin - Facial Image [ OPTIONAL ]
Your photograph(s) / video frames used to create the visual component of your AI avatar. Strictly purpose-limited to Digital Twin rendering. Never used for advertising. Independently revocable at any time. We never sell your data.
☐ I consent
Can you decline?
Yes - no impact on core
12. Digital Twin - Voice Samples [ OPTIONAL ]
Your voice recordings used to create the voice component of your AI avatar. Stored in encrypted, restricted-access environment. Separately revocable at any time, independent of other Digital Twin consents. We never sell your data.
☐ I consent
Can you decline?
Yes - no impact on core
13. Digital Twin - Knowledge Base [ OPTIONAL ]
Clinical notes, treatment preferences, and FAQ responses you upload to train your Digital Twin to reflect your expertise. You retain ownership. Licence to Company is limited to Digital Twin operation only. We never sell your data.
☐ I consent
Can you decline?
Yes - no impact on core
How to Withdraw Consent
Withdraw consent for any optional item at any time through Settings → Privacy → Manage Consents, or by contacting dpo@pranik.ai. Digital Twin consent items can each be revoked independently. Withdrawal does not affect the lawfulness of processing already carried out.
PART 4 - SOFTWARE LICENCE
This Part sets out the terms under which P4D software is licensed to you as a professional user. It incorporates and replaces any standalone EULA.
22. SOFTWARE LICENCE TERMS
22.1 Professional Licence Grant
Subject to your compliance with this Agreement and your holding a valid RMP registration, the Company grants you a limited, non-exclusive, professional, non-transferable, revocable licence to install and use P4D solely for your lawful professional medical practice.
22.2 Restrictions
Do not copy, modify, reverse-engineer, or decompile P4D.
Do not redistribute, sublicense, or sell access to P4D.
Do not use P4D to develop competing AI models, clinical decision support systems, or digital physician avatar products.
Do not share account credentials - each Doctor must have their own account.
22.3 Updates
Updates may be delivered automatically (especially for security patches) or manually. For core clinical feature changes (Teleconsultation, CDSS Lite, Live Scribe), 30 days' advance notice will be given except where immediate action is required by law or security.
22.4 Termination of Licence
Your licence terminates automatically on loss of RMP status (Section 7.3) or on account termination. Sections 7 (IP), 10 (Liability), 11 (Indemnification), and 13 (Governing Law) survive termination.