Legal
Privacy Policy
Last updated: 5 September 2026
This policy explains what data Aghor Labs Pvt. Ltd. ('Aghor', 'we') collects through Cerawave, why, and what rights you have. It covers clinic owners and their staff ('the clinic'), the patients whose records a clinic keeps in Cerawave, and visitors to cerawave.app. The stance is simple: patient records belong to the clinic that created them. We do not sell them, mine them, or market to a clinic's patients.
Who controls patient data
For everything a clinic records about a patient - identity, medical history, allergies, clinical notes, tooth charts, prescriptions, treatment plans, invoices, and consent - the clinic is the data fiduciary and Aghor is the data processor. We hold and protect that data, and we act on the clinic's instructions. We do not decide what is recorded about a patient, and we do not use it for our own purposes.
For the clinic's own account - the staff who sign in, what they are billed, how they use the product - Aghor is the data fiduciary.
Patients who want a copy of their record, or want it corrected or erased, should ask their clinic. We will help the clinic answer, but we will not disclose or alter a clinic's patient record on a request made directly to us: we have no way to verify a patient's identity, and the clinic does.
Data we collect
- Clinic account data - name, email, phone number, password (hashed), staff role, clinic name, address, and registration details.
- Patient and clinical data - entered by the clinic: demographics, contact details, allergies, vitals, tooth observations, diagnoses, clinical notes, prescriptions, treatment plans, investigation orders, uploaded documents, and consent records. This includes health data, which we treat as sensitive throughout.
- Consent records - the wording shown, the time it was accepted, and the IP address it was accepted from. The IP address is part of the evidence that a consent was given; it is retained with the consent record.
- Money data- invoices and the payments a clinic records against them. Cerawave does not take patient payments. Patients pay the clinic directly by cash, UPI, or the clinic's own card terminal, and Cerawave only records what the clinic tells it was collected. No card number, UPI PIN, or bank credential ever reaches Cerawave.
- Subscription data - what the clinic pays Aghor for Cerawave. Those payments are processed by Razorpay; we receive transaction status, amount, and reference identifiers, never full card details.
- Usage and device data - log data, IP address, browser type, and interactions with the product, used for security, debugging, and support.
How we use data
- To run the service: appointments, records, prescriptions, invoices, consent.
- To send transactional messages a clinic asks for - appointment confirmations, receipts, and recall reminders - by email and, where a patient has opted in, WhatsApp.
- To secure the platform: authentication, rate limiting, and abuse detection.
- To provide support, when a clinic asks us to look at something.
- To meet legal, tax, and accounting obligations.
What we never do
- We do not sell personal data, and we do not share it with data brokers.
- We do not market to a clinic's patients.
- We do not train machine-learning models on patient records, and we do not send clinical content to a third-party AI provider.
- We do not read a clinic's patient records for our own analysis. Product analytics are drawn from usage events, never from clinical content.
Who else processes data
We use a small number of vendors, each for one job:
- Supabase - database, authentication, and file storage.
- Vercel and Cloudflare - hosting and network protection.
- Amazon SES - transactional email.
- Meta (WhatsApp Business Platform) - reminder messages, only where a patient has opted in.
- Razorpay- the clinic's subscription payments to Aghor.
Each is bound to process data only on our instructions. Where a vendor stores data outside India, that transfer is limited to what the service requires.
Security
- Data is encrypted in transit, and at rest by the storage provider.
- Access is enforced in the database itself through row-level security, so a clinic can only reach its own records - the application cannot grant access the database has not allowed.
- Passwords are hashed and never stored or logged in readable form.
- Uploaded documents are scanned for malware before a clinic can open them. Where scanning is unavailable, uploads are refused rather than passed through unchecked.
- Staff access is limited to the role the clinic assigned.
Retention
Clinical records are kept for as long as the clinic keeps its account, because medical records must remain available to the clinic and, in many cases, must be retained under professional and statutory rules. A clinic may delete individual records at any time.
If a clinic closes its account, we retain its data for 90 days so it can be exported, then delete it. Consent records, invoices, and audit entries are retained where a law requires it. Backups roll off on their own schedule, within 35 days.
Your rights
Under India's Digital Personal Data Protection Act, 2023, you may ask for access to your data, correction of it, erasure, and the withdrawal of consent. You may also nominate someone to exercise these rights on your behalf.
Patients should send these requests to their clinic, which holds the record. Clinic staff can send requests about their own account data to [email protected]. We respond within 30 days.
Children
Cerawave is used by clinics, not by patients directly, and a clinic may record a child's treatment. Where it does, the clinic is responsible for obtaining the consent of a parent or guardian. Cerawave accounts may not be created by anyone under 18.
Changes
We will update this policy as the product changes, and will tell clinics by email before any change that materially affects how patient data is handled.
Cerawave is operated by Aghor Labs Pvt. Ltd. Questions about this document can be sent to [email protected].