Legal

Data Processing Terms

In effect from
Version
1.0

The short version

  • Your clinic decides what patient data to record and why. Substrate handles it only to run Substrate Console for you.
  • Patient records are stored only with Cloudflare, in its Asia-Pacific region, currently Singapore. No other provider receives them.
  • If a breach affects your patients’ records, we tell you within 24 hours and help you inform your patients and the Data Protection Board.
  • We give you 30 days’ notice before adding a provider that handles your data, and you can object.
  • When you leave, you have 30 days to export everything. We then delete it, and backups are overwritten within a further 30 days.

Roles

These terms form part of our Terms of Service with your clinic, and apply whenever Substrate Console handles personal data that your clinic records. They use the words of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, “the DPDP Act”).

  • Your clinic is the data fiduciary. It decides what personal data to record about patients and why.
  • Substrate is the data processor. We handle that data only on your clinic’s behalf, to provide Substrate Console.

Where these terms and the Terms of Service differ about personal data, these terms apply. Clinics that need different terms, for example hospitals, can agree a separate data processing agreement with us.

Your instructions

We handle patient data only on your clinic’s instructions. Using Substrate Console, and its settings, are your instructions; so are any written instructions we agree with you. If we believe an instruction would break the law, we tell you and don’t follow it.

What we handle

  • People: your clinic’s patients, including children and people who cannot consent for themselves, their emergency contacts, and your staff.
  • Data: identity and contact details, ABHA number and address, clinical notes, prescriptions, allergies, lab results, summaries, uploaded documents, and records of who did what in Substrate Console.
  • What we do with it: store it, back it up, display it to the people your clinic authorises, search it, produce documents your doctors sign, and carry out the exports and shares your clinic starts.

We never store Aadhaar numbers. We don’t use patient data for our own purposes, sell it, use it for advertising, or use it to train AI models.

People and confidentiality

Only people at Substrate who need access to run, secure or support Substrate Console can reach patient data, and they are bound to keep it confidential. We look at patient records only when your clinic asks for help, or when we need to in order to keep the service secure or meet a legal duty.

Security

We protect patient data with measures suited to health records, including:

  • encryption in transit and at rest
  • access by role, so each person sees what their role needs, and clinic administrators without a clinical role cannot see clinical content
  • an audit log of sign-ins, record changes, signatures, document views, shares and imports, kept in storage that cannot be changed or deleted early
  • signed notes and prescriptions that cannot be changed, only amended with a new version
  • keeping patient data out of system logs and emails
  • 30 days of database history, so data can be restored after a mistake or failure

We review these measures as the service and the risks change.

Other providers

Patient records are stored only with Cloudflare, Inc., which hosts Substrate Console, its database and uploaded documents, in its Asia-Pacific region, currently in Singapore.

These providers handle your staff’s details, never patient records:

  • WorkOS, Inc.: sign-in and sessions (United States)
  • Google LLC: Sign in with Google, when a staff member chooses it (United States)
  • Resend: invitations and administrative emails, which never contain clinical information (United States)
  • Clerk, Inc.: older sign-in accounts, which we are removing (United States)

Each provider is bound by a contract that requires it to protect the data at least as well as these terms do. We tell clinic administrators at least 30 days before we add or replace a provider that handles your clinic’s data. If you object for a reasonable data protection reason and we can’t address it, you can leave before the change takes effect and we refund any fees paid for the time after you leave.

Where data is stored

Cloudflare does not yet offer storage limited to India. The DPDP Act allows processing outside India, except in countries the Government of India restricts. We will not move your data to a restricted country, and we tell you at least 30 days before we change the region where patient records are stored.

Patients’ requests

Patients will usually ask your clinic to see, correct or delete their records, or to name someone to act for them. Substrate Console lets you view, export and amend records to answer them. If you need more help, we provide it. If a patient writes to us directly, we pass the request to you within 5 working days and don’t answer it ourselves, unless the law requires us to.

Breaches

If we become aware of a breach that affects your clinic’s personal data, we:

  • tell your clinic’s administrators without delay, and within 24 hours, with what we know at the time
  • keep you updated as we learn more: what happened, what data and people are affected, what we have done, and what we recommend
  • help you inform affected patients, and help you send the Data Protection Board of India its full report within 72 hours of becoming aware of the breach

As data fiduciary, your clinic informs its patients and the Board. We don’t contact your patients about a breach unless you ask us to or the law requires it.

Your clinic is responsible for getting consent from a parent or lawful guardian when the law requires it. Substrate Console records which version of your clinic’s privacy notice each patient, or the person acting for them, acknowledged, and who recorded it.

Our patient privacy notice template is a starting point for your clinic’s notice.

Keeping and deleting data

While your clinic uses Substrate Console, we keep its data until your clinic deletes it. Medical records law can require records to be kept for years. Your clinic decides how long to keep its records, and must export anything it still needs to keep before leaving.

When your clinic’s use of Substrate Console ends:

  1. You have 30 days to export all your data, including patient records and uploaded documents.
  2. We then delete it from Substrate Console within 30 days.
  3. Backups are overwritten within a further 30 days.
  4. Audit records are kept for one year, as the DPDP Rules require, then deleted.

If you ask, we confirm in writing when deletion is complete. We keep data longer only where the law requires us to, and then only for that purpose.

Records and reviews

We keep records of how we handle your clinic’s data, and give you the information you reasonably need to show that these terms are being followed, such as answers to a security questionnaire. Hospitals and larger clinics can agree further reviews with us in writing.

National health records (ABDM)

Linking with the Ayushman Bharat Digital Mission is not yet available in Substrate Console. When it is, your clinic will act as a health information provider within ABDM, and records will be shared only with the patient’s consent through ABDM’s consent manager. ABDM’s own policies will apply in addition to these terms.

Contact

Write to our Grievance Officer with any question, request or complaint about this page or your data.

Company
Substrate Labs
Registered address
Mumbai, India
Replies
Privacy requests within 30 days. Complaints acknowledged within 24 hours and resolved within 15 days.

If you are not satisfied with our answer, you can complain to the Data Protection Board of India.

Change history

  1. First published.