The short version: we use the minimum account, booking, queue, optional location, notification, feedback and payment metadata needed to run QDoctor. We do not ask for clinical information such as symptoms, diagnoses, prescriptions, test results or medical history. We never sell your data or run advertising trackers.
1. Who we are
QDoctor ("we", "us", "the service") is queue-management and scheduling software for in-person visits to doctors who hold hours at neighbourhood pharmacies in India. QDoctor is operated by Aero Knowledge Solutions Pvt Ltd (India), which acts as the Data Fiduciary (India) and Data Controller (EU) for the personal data described here. QDoctor is not a medical, telemedicine or health-records service — see What QDoctor is.
2. What we collect — and what we don't
We practise data minimisation: we ask for the least we need to run a queue.
Patients
- Account and contact details — such as your name, mobile number and authentication identifiers, so you can sign in and the chamber can identify or contact you about your turn.
- Booking and queue activity — the pharmacy/clinic, doctor, date, sitting, serial, live-queue status, arrival/presence, delay, cancellation, completion and related timestamps needed to provide and improve ETA and queue operations. A booking identifies the provider visited and may therefore reveal a healthcare association even though QDoctor does not collect clinical details.
- Location when you choose to provide it — precise or approximate device location for nearby results, distance, travel guidance or on-site presence features. Location permission can be denied; features that require it may then be unavailable. If you tap a ride option on the Assistant screen, the clinic’s location and, where recent and available, your own approximate pickup are passed to the ride app you chose — see “Ride handoff” below.
- Feedback — doctor, pharmacy/facility and service ratings or review responses you submit after a visit.
- Device, notification and security signals — push tokens, app/platform details, a pseudonymous device identifier, login/security events, IP-derived safety signals and basic usage/error events needed for notifications, trusted-device protection, fraud prevention and reliability. We use no Google Analytics or cross-site advertising trackers.
- Payment references where applicable — order, payment, refund, entitlement and subscription identifiers for a paid booking service or premium feature. QDoctor does not receive full card, bank-account, UPI PIN or store-account credentials.
Doctors and pharmacies
- Doctor profile details (including name, speciality, qualifications, experience, photo, chambers and schedules) and a phone and registration/licence number for verification. Confidential identifiers are access-restricted; only appropriate verification or masked information is displayed publicly.
- Pharmacy/clinic details, contact information, address and location, visiting-doctor schedules, staff relationships, floor/department assignments and operational queue events.
- Doctor Pro or Clinic Pro plan, entitlement, order and transaction identifiers needed to activate, renew, upgrade, restore, cancel or support the plan. QDoctor does not receive full card, bank-account, UPI PIN or mobile-store credentials.
QDoctor does not ask for or provide fields for symptoms, diagnoses, prescriptions, lab results, medical notes or medical history. Clinical information should remain between the patient and doctor; users should not enter it in names, reviews, support messages or other free-text fields.
3. Why we use it (purpose & lawful basis)
- To run the queue — create and track your serial, show live position, and let the pharmacy manage the counter. Lawful basis: performance of the service you requested / your consent.
- To provide optional nearby, presence and notification features — only when you enable or use the relevant device permission or feature. Lawful basis: your request / consent.
- To verify doctors — so the serial you book is with a real person at a real chamber. Lawful basis: legitimate interest in preventing fraud and impersonation.
- To process purchases and entitlements — create an order, confirm payment, activate a paid feature, restore access and handle refunds or disputes. Lawful basis: performance of the purchase contract and legal/accounting obligations.
- To keep the service secure and reliable — abuse prevention, debugging, uptime. Lawful basis: legitimate interest.
We do not use your data for advertising, profiling, or automated decisions that produce legal effects.
4. Who can see your data
- The pharmacy / doctor you booked with — sees your name, mobile and serial, for that visit only.
- Our service providers — depending on the platform and feature, we use Supabase (database and authentication), Cloudflare (hosting, CDN and DNS), Expo, Apple and Google (app distribution, device notifications and store purchases), RevenueCat (subscription entitlement validation) and Razorpay (eligible web/Android payment processing). They process only the data needed to provide their respective service under their own terms and privacy commitments.
- A ride app, only when you tap to use it — the Assistant screen can open Uber with your journey pre-filled. Nothing is sent unless you tap it. The link carries the clinic’s name, address and map coordinates and, where a recent one is available, your own approximate pickup coordinates. It does not carry your name, mobile number, booking or serial, the doctor, or any health information. Uber then handles the ride under its own terms and privacy policy as an independent controller, not as a processor acting for us, and QDoctor receives no fare, trip, driver or payment data back. We record only that the handoff was requested — never the locations themselves. You review the pickup and destination in Uber before booking anything, and you can ignore the option entirely.
- No one else. We do not sell, rent or trade personal data, and we do not share it with advertisers or data brokers.
5. Where your data lives & transfers
Data is stored with our processors' cloud infrastructure and may be processed in data centres outside your country. Where personal data of EU/EEA users is transferred, we rely on appropriate safeguards (such as our processors' Standard Contractual Clauses). We take reasonable steps consistent with the DPDP Act and GDPR for such transfers.
6. How long we keep it
We keep active account and operational data while needed to provide QDoctor. Patient-facing history is deliberately limited; security/audit, transaction, tax, dispute and fraud-prevention records may be retained longer where reasonably necessary or legally required. When an account-deletion request is confirmed, QDoctor provides a 15-day grace period for reversal and then deletes or de-identifies account-linked data, except information that must be retained for legal, security, payment or dispute obligations. Backup copies expire through the applicable backup lifecycle. You can exercise your rights using the contact below.
7. How we protect it
- All traffic is encrypted in transit (HTTPS/TLS), with HSTS and DNSSEC on our domain.
- Database access is governed by row-level security so users can only reach their own data; sensitive tables (verification codes, contact numbers) are not readable through the public interface.
- Doctor phone and licence numbers are access-restricted and shown publicly only as a masked fingerprint.
- Administrative functions are restricted to authenticated administrators.
8. Your rights
Under the DPDP Act 2023 (India) and the GDPR (EU/EEA), you can:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Erase your data ("right to be forgotten").
- Withdraw consent at any time, and object to or restrict certain processing.
- Data portability — receive your data in a usable format (GDPR).
- Nominate another person to exercise your rights in the event of death or incapacity (DPDP).
- Complain — to the Data Protection Board of India, or your EU supervisory authority.
To exercise any right, contact us using the details below. We respond within the timelines required by law.
9. Children
QDoctor is intended for adults booking on their own behalf or for family members. Where a child's details are used to book a visit, that is done by a parent or guardian who is responsible for the child's information.
10. Cookies
We use only the minimal storage needed to keep you signed in and the service working. We set no advertising or cross-site tracking cookies.
11. Changes to this policy
We may update this policy as the service evolves. Material changes will be reflected here with a new effective date.
12. Contact & grievances
For any privacy question, request, or grievance, contact our Grievance Officer / Data Protection contact at support@qdoctor.in, or write to Aero Knowledge Solutions Pvt Ltd, Star Mall, Sisir Kujna, Madhyamgram, Kolkata 700129, West Bengal, India. We aim to acknowledge requests promptly and resolve them within statutory timelines.
Frequently asked
What does QDoctor share with Uber?
Only if you tap the ride option yourself. The link opens Uber with the clinic’s name, address and coordinates and, where a recent one is available, your approximate pickup — no name, mobile number, booking, serial, doctor or health information. Uber then applies its own privacy policy, and no fare, trip or payment data comes back to QDoctor. QDoctor does not book or pay for the ride.
What personal data does QDoctor actually collect?
We use account/contact details, booking and queue events, optional location when you choose nearby or presence features, notification/device identifiers, feedback, and payment or subscription references where applicable. We do not ask for symptoms, diagnoses, prescriptions, test results or medical history.
Do you sell my data or show me ads?
No. We never sell, rent or trade personal data, and we run no advertising or cross-site tracking. QDoctor is queue software, not an ad business.
How do I access, correct or delete my data?
Write to support@qdoctor.in. Under India's DPDP Act 2023 and the EU GDPR you can access, correct, erase or port your data and withdraw consent, and we respond within the timelines the law requires.
Is my data safe?
Yes. Traffic is encrypted in transit (HTTPS/TLS) with HSTS and DNSSEC, database access is governed by row-level security so users only reach their own data, and sensitive fields like doctor phone and licence numbers are access-restricted and shown only as a masked fingerprint.
Who processes my data on QDoctor's behalf?
Depending on the feature and platform, QDoctor uses Supabase, Cloudflare, Apple, Google, Expo, RevenueCat and Razorpay for infrastructure, authentication, notifications, store subscriptions and payments. They receive only what is needed for their service; we do not sell data to them or to advertisers.
Does QDoctor follow GDPR as well as Indian law?
Yes. The policy is built to both India's DPDP Act 2023 and the EU GDPR — data minimisation, purpose limitation, clear consent, and your full rights of access, correction, erasure and portability.
This policy is provided for transparency and reflects our current practices; it is not legal advice. Read alongside our Transparency page and What QDoctor is.
