Privacy Policy

Last updated: July 3, 2026 | Effective: July 3, 2026

1. Who We Are

TALOE MED ("we," "us," "our") is a Clinical Decision Support System (CDSS) operated by Taloe Med LLP. We assist registered medical practitioners by recording doctor-patient consultations, generating structured clinical notes, and providing AI-assisted clinical reasoning.

Data Fiduciary: Taloe Med LLP
Contact: [email protected]
Address: Hyderabad, Telangana, India

2. What Data We Collect

Data TypeExamplesPurpose
Audio RecordingsDoctor-patient consultation audio (Telugu-English)Transcription and SOAP note generation
Patient DemographicsName, age, sex, phone number (entered by doctor)Clinical document identification
Clinical DataSOAP notes, diagnoses, medications, ICD-10 codesClinical decision support and export
Doctor ProfileName, qualifications, registration number, clinic detailsDocument letterhead and authentication
Usage DataSession timestamps, consultation count, feature usageService improvement and usage metering
Device DataBrowser type, screen size (no device fingerprinting)UI optimization only
Analytics & Diagnostic DataApp usage events (PostHog), error/crash reports (Sentry) — never clinical contentReliability monitoring and product improvement

What we DO NOT collect: Aadhaar numbers (unless via ABDM consent flow), financial data, biometric data (beyond voice for transcription), location data, social media profiles.

3. How We Use Your Data

  • Transcribing audio recordings into text using AI speech recognition (Sarvam AI)
  • Converting transcripts into structured SOAP clinical notes using AI (Google Gemini)
  • Running clinical reasoning: differential diagnosis, drug interaction checks, ICD-10 coding
  • Validating output quality through 12-layer deterministic quality gates (TrustGate)
  • Generating exportable clinical documents (PDF, DOCX, prescriptions)
  • Improving our AI models and clinical accuracy (anonymized, aggregated data only)

We NEVER use patient data for advertising, marketing, or sale to third parties.

4. Legal Basis for Processing

Under the Digital Personal Data Protection Act 2023 (DPDP Act), our primary legal basis for processing patient data is your consent (Section 6): the treating physician obtains your consent before recording a consultation, through an in-app consent step that must be completed before any recording begins.

  • Consent (Section 6): the treating physician records only after you are informed and consent to the consultation being recorded and processed
  • Where you have voluntarily provided information for a specified purpose (Section 7(a)) — e.g. details you share with your doctor for the purpose of receiving care — we process it only for that same purpose

You may withdraw consent at any time by informing your treating physician; withdrawal does not affect the lawfulness of processing that already occurred, and stops future processing of your data going forward.

5. Who We Share Data With

CategoryPurposeData SharedRetention
Speech Recognition ProviderProprietary ZeroLoss™ transcription pipelineAudio segments (encrypted in transit)Not retained after processing
AI Clinical Engine ProviderTaloeCore™ SOAP generation and clinical reasoningClinical text; structured/labelled identifiers redacted before every call — SOAP generation and clinical reasoning alikeNot retained after processing
Redundancy AI ProviderFailover processing for service continuityClinical text; structured/labelled identifiers redacted before every call, same as the primary engine aboveNot retained after processing
Cloud Infrastructure ProviderSecure application hostingEncrypted session dataDuration of service agreement
Analytics & Monitoring ProvidersProduct usage analytics and error/crash monitoringUsage events and diagnostic data only — never clinical content or audioPer provider's standard retention window
Content Delivery NetworkSecure content delivery and DDoS protectionNo patient data (static assets only)N/A

We do not sell, rent, or trade personal data to any third party. We identify our processors by category above rather than by name; none of our AI or analytics processors currently has a data processing agreement naming them individually, so we describe them generically until those agreements are finalized.

6. Data Location and Cross-Border Transfer

Our application infrastructure — including our servers, database, and primary AI processing — is hosted in India (Mumbai). This is complete today, not a migration in progress.

Some fallback AI processing and analytics/monitoring providers may process data on servers located outside India. This is permitted under DPDP Act Section 16: personal data may be transferred outside India to any country or territory except one the Central Government specifically restricts by notification, and as of today no country has been so restricted.

  • Automated redaction removes structured/labelled identifiers (names, contact numbers, IDs) before every AI call — SOAP generation, clinical reasoning, and entity extraction alike; free-form spoken content may still contain identifying details
  • Stateless API-mode processing — providers do not retain data after generating results
  • Analytics and crash-monitoring providers receive usage/diagnostic data only, never clinical content or audio

7. Your Rights (Data Principal Rights — DPDP Act)

RightDescriptionHow to Exercise
Right to AccessRequest a copy of your dataEmail [email protected]
Right to CorrectionRequest correction of inaccurate dataDoctor can edit SOAP notes; or email us
Right to ErasureRequest deletion of your data from our systemsEmail [email protected] — processed within 30 days
Right to GrievanceFile a complaint about data handlingEmail [email protected]
Right to NominateNominate someone to exercise rights on your behalfEmail [email protected]

Upon a verified erasure request, we delete your personal data from our systems within 30 days. Where we have shared data with processors for provision of the Services, we expect them to handle such data in accordance with applicable law.

To exercise any right, contact our Grievance Officer at [email protected]. We will respond within 30 days.

8. Data Retention

Per Section 8(7) of the DPDP Act, we erase personal data once the specified purpose is no longer being served or you withdraw consent, unless retention is required by law. This is our retention schedule by data category. Automated time-based deletion currently runs for Audio Recordings only — see "How It's Handled Today" below for each category's actual practice.

Data TypeRetention PolicyHow It's Handled Today
Audio RecordingsRetained only as long as needed for transcription; auto-deleted after 30 daysAutomatically purged by a recurring server-side sweep after 30 days, or immediately upon your erasure request or account closure
Session Data (SOAP, reasoning)We aim to retain for up to 7 years to meet medical record-keeping normsNo automated time-based deletion runs today; removed upon a verified erasure request
Doctor ProfileRetained while your account is active, plus up to 1 year after closureNo automated time-based deletion runs today; removed upon a verified erasure request
Usage AnalyticsRetained in aggregated, anonymized form for up to 2 yearsAggregated and anonymized — not tied to an individual patient record

9. Data Security

We implement industry-standard security measures aligned with OWASP ASVS 4.0 Level 2:

  • Encryption in transit: TLS 1.3 on all connections (HTTPS enforced)
  • Encryption at rest: AES encryption for clinical audio; infrastructure-level disk encryption
  • Multi-layer authentication with credential hashing and session management
  • Rate limiting and brute-force protection on all authentication endpoints
  • Role-based access control with minimum-privilege principle
  • Comprehensive audit logging with automated PHI redaction
  • Continuous vulnerability scanning and automated security testing in CI/CD pipeline
  • TrustGate™ 12-layer deterministic quality validation on all AI outputs

10. Data Breach Notification

In the event of a personal data breach, we will notify the Data Protection Board of India within 72 hours of becoming aware of it, as required by the DPDP Act. Where the Board directs us to notify affected individuals, we will do so promptly, describing what happened, what data was affected, and what steps you should consider taking.

11. AI and Automated Decision-Making

TaloeMed is advisory software, not a medical device. All AI-generated outputs (SOAP notes, diagnoses, drug recommendations) are suggestions only. The treating physician reviews, edits, and approves all clinical content before it becomes part of the patient record.

  • AI does not make autonomous clinical decisions
  • All outputs pass through 12 deterministic quality validation gates
  • Hallucination detection (HalluciGuard) flags potentially fabricated claims
  • The doctor always has the final say — this is architecture, not a disclaimer

12. Cookies and Analytics

TaloeMed uses minimal cookies, plus the following analytics and monitoring tools:

Cookie / ToolPurposeDuration
taloemed_tokenAuthentication (JWT)Session (24 hours)
taloemed_userUser preferences (theme, language)Persistent (localStorage)
PostHogProduct usage analytics (opt-in)Per PostHog's standard retention
SentryError and crash monitoringPer Sentry's standard retention

PostHog and Sentry receive usage and diagnostic data only — never your clinical records or audio. Product analytics via PostHog is opt-in through our consent banner. We do NOT use Google Analytics, Facebook Pixel, advertising cookies, cross-site tracking, or device fingerprinting.

13. Children's Privacy

TaloeMed is used under the direct supervision of a licensed treating physician; it is not intended for standalone use by children. Where a patient is a minor, we rely on the consent of the accompanying parent or legal guardian, obtained by the treating physician at the point of care. TaloeMed does not use pediatric patient data for tracking, profiling, or advertising of any kind. Pediatric consultations follow the same security and privacy standards as adult consultations.

14. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via:

  • Banner notification in the TaloeMed app
  • Email to registered practitioners
  • Updated "Last updated" date on this page

15. Grievance Redressal

Grievance Officer: Taloe Med LLP Privacy Team

Email: [email protected]

Response Time: Within 30 days of receiving your request

Section 13 of the DPDP Act 2023 requires you to raise your concern with us first (above) before escalating further. If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India.

16. Contact Us

TALOE MED
Taloe Med LLP
Email: [email protected]
Website: taloemed.com
Hyderabad, Telangana, India

TALOE MED v0.8.2 | DPDP Act 2023

© 2025-2026 Taloe Med LLP. All Rights Reserved.