Privacy Policy
Medler AI Private Limited handles health data. This policy explains what we collect, why we collect it, how long we keep it, and the rights you have over it.
Last updated: 4 August 2026
Who this policy covers
This policy applies to this website and to the products operated by Medler AI Private Limited: Medler HMS (medler.store), Medler Health (medler.app) and Medler for doctors (medler.ai).
Where a hospital or clinic uses Medler HMS to manage its patients, that facility is the data fiduciary for its patient records and we act as its data processor. We handle those records on the facility’s instructions and under our agreement with them.
What we collect
- Account details — name, email address, phone number, professional registration details for doctors, and organisation details for facilities.
- Health data — medical records, prescriptions, lab results, vitals, imaging, and the clinical notes created inside our products. This is sensitive personal data and is treated as such.
- Usage data — device type, browser, IP address, pages viewed and actions taken, used to keep the service secure and working.
- Communications — what you send us by email, phone or through the enquiry form on this site.
Why we process it
- To provide the service you or your healthcare provider signed up for.
- To keep clinical and financial records accurate and auditable.
- To meet legal, regulatory and accreditation obligations, including ABDM requirements where a facility participates.
- To secure the service, detect misuse and investigate incidents.
- To answer your enquiries and provide support.
We do not sell personal data, and we do not use identifiable health data for advertising.
Consent and ABDM
Health data is processed on a consent-first basis. Where a facility links records to a patient’s ABHA number under the Ayushman Bharat Digital Mission, that linking and any subsequent sharing happens through ABDM consent flows, and the patient can withdraw consent through the same mechanism.
MedScribe, our voice documentation feature, is used with the patient’s knowledge. Consultation audio is not stored — it is transcribed into a note that the doctor reviews before it is saved.
How we protect it
- AES-256-GCM encryption for data at rest and TLS for data in transit.
- Role-based access control, so staff only see what their role requires.
- Audit trails recording who accessed or changed a record, and when.
- Digital signatures on clinical documents.
- PIN protection and an access log for family sharing in Medler Health.
No system is immune to every risk. We work to industry security practices and we will notify affected users and the relevant authorities if a breach occurs that is likely to cause harm.
Sharing
We share personal data only in these situations:
- With the healthcare provider you are a patient of, or with people you have explicitly given access to.
- With service providers who host, secure or support our infrastructure, under contract and only for those purposes.
- Where required by law, court order or a lawful request from a regulator.
- Through ABDM, where a facility and patient have consented to it.
Retention
Clinical records are retained for as long as the healthcare provider is required to keep them under Indian medical record-keeping rules, and thereafter as agreed with that provider. Account and billing records are kept for the period required by tax and company law. Enquiry emails are kept only as long as needed to deal with the enquiry.
Your rights
Under the Digital Personal Data Protection Act 2023 you may:
- Ask what personal data we hold about you and how it is being processed.
- Ask us to correct data that is inaccurate, incomplete or out of date.
- Ask us to erase data, where we are not required to keep it.
- Withdraw a consent you previously gave.
- Nominate someone to exercise these rights on your behalf.
- Raise a grievance with us, and escalate to the Data Protection Board of India if unresolved.
Where your data sits inside a hospital or clinic’s Medler HMS account, please raise the request with that facility first — they control those records. We will support them in responding.
Cookies
This website uses only the storage needed to make it work. Our applications use cookies and local storage to keep you signed in and to remember your preferences. We do not use third-party advertising cookies on this site.
Children
Medler Health supports profiles for children, created and managed by a parent or guardian. We do not knowingly create accounts directly for children without that supervision.
Grievance contact
For any privacy question, request or complaint, write to contact@medler.ai with “Privacy” in the subject line, or post to Medler AI Private Limited, 2nd Floor, 103/A-1, Sector-6, Rohini, New Delhi – 110085, India. We aim to acknowledge within 72 hours and resolve within 30 days.
Changes
We will update this policy when our products or obligations change. The date at the top reflects the current version, and we will tell you about material changes through the product or by email.
Questions about this document?
Write to contact@medler.ai or call +91-9289363999. You can also write to us at 2nd Floor, 103/A-1, Sector-6, Rohini, New Delhi – 110085, India.