Legal
Privacy Policy
Last updated: June 2026
This Privacy Policy explains how RDM Associates (“RDM Physio App”, “we”, “our”, “us”) collects, uses, secures, and protects personal data, and the rights available to you under India's Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the DPDP Rules, 2025. It applies to this website and to our relationship with the clinics we serve.
1. Scope & Our Role
It is important to understand the two very different contexts in which data is involved with RDM Physio App:
- Website & enquiry data — when you contact us, request a demo, or make a payment, we act as the Data Fiduciary (controller) for the limited information you provide. This policy governs that data.
- Patient & clinical data — this is stored entirely within each clinic's own private infrastructure (see Section 3). For that data, the clinic is the Data Fiduciary, not us. We have no access to it.
2. What Data We Collect
- Through our contact and demo request forms: your name, clinic name, email address, and phone number.
- Through payment processing: transaction metadata handled securely by Razorpay. We do not see, collect, or store your card number, UPI ID, or any payment credentials.
- Automatically: basic technical and usage data (such as browser type, pages visited, and approximate region) and cookies needed for the website to function.
- Analytics: we use Google Analytics (GA4) to understand aggregate website usage. This sets analytics cookies — see Section 13.
3. Clinic Data Ownership & Our Limited Role
RDM Physio App operates on a fundamentally different model from conventional SaaS platforms. Each clinic that uses RDM Physio App receives its own dedicated, isolated deployment on its own Firebase (Google Cloud) project. This means:
- All patient records, appointment data, clinical notes, and operational data are stored exclusively in the clinic's own private Firebase project.
- RDM Physio App does not have access to, store, transmit, or process any patient or clinical data belonging to any clinic.
- The clinic is the sole data owner and Data Fiduciary (controller) of its patient and operational data.
- We are purely a software provider — we develop and maintain the application code, not your data.
4. How We Use Your Data
- Contact and demo form submissions are used solely to respond to your enquiry and, where relevant, to set up your service.
- Payment data is used only to process and confirm your transaction through Razorpay.
- Technical and analytics data is used to keep the website secure, working, and improving.
- We do not sell, rent, or trade your personal data, and we do not share it with third parties for their own marketing.
5. Legal Basis & Consent
We process your personal data on the basis of your consent and for the specified, lawful purposes described above. You may withdraw your consent at any time — as easily as it was given — by contacting us at rdmappdemo@gmail.com. Withdrawing consent does not affect processing already carried out, and may mean we can no longer respond to your enquiry or provide certain services.
6. Third-Party Services (Sub-processors)
We rely on a small number of trusted providers strictly to deliver our service:
- Razorpay — processes payments under its own PCI-DSS compliant systems. Subject to Razorpay's privacy policy.
- SendGrid — delivers transactional email notifications (e.g. your enquiry reaching us). Used for email delivery only.
- Firebase / Google Cloud — hosting and infrastructure. Subject to Google's privacy policy.
- Google Analytics — aggregate website analytics.
7. Data Security & Cybersecurity
We apply reasonable security safeguards to the website and the data we handle, including:
- Encryption in transit: all traffic is served over HTTPS/TLS.
- HTTP security headers to reduce common web-based attacks.
- Server-side validation and sanitisation of all form input.
- Rate limiting on form and API endpoints to deter abuse and automated attacks.
- Secrets (such as email and payment keys) are held server-side only and are never exposed to your browser.
- No storage of card or payment credentials — these are handled entirely by Razorpay.
No method of transmission or storage over the internet is ever 100% secure, and we cannot guarantee absolute security. We continuously work to improve our safeguards.
8. Authentication & Access
The RDM Physio App software deployed for your clinic uses Firebase Authentication within your own Firebase project. Your clinic provisions and controls its own user accounts and role-based access. We do not hold, manage, or have access to your clinic's user credentials or patient-facing logins. You are responsible for granting, reviewing, and revoking access within your deployment.
9. Your Responsibilities (Clinics)
Because your deployment runs in your own Firebase project, certain security and compliance duties sit with you as the Data Fiduciary for patient data. We strongly recommend that you:
- Keep login credentials confidential and use strong, unique passwords; enable multi-factor authentication where available.
- Configure and maintain appropriate Firebase Security Rules so data is only accessible to authorised users.
- Control and regularly review who has access to your deployment, and revoke access promptly when staff leave.
- Keep your Firebase / Google Cloud project billing active to avoid service interruption or data loss.
- Maintain your own backups of clinical and operational data.
- Obtain and manage patient consents and meet your own DPDP Act obligations for the patient data you control.
- Report any suspected unauthorised access or security incident to us promptly so we can assist.
10. Data Retention
We retain website enquiry and contact data only for as long as needed to respond to you and for our legitimate record-keeping, after which it is deleted. Patient and clinical data is retained entirely under the clinic's control within its own project, for as long as the clinic determines.
11. Data Breach Handling
If a breach affects personal data that we control (website or enquiry data), we will respond in line with the DPDP Rules, 2025 — including notifying affected individuals and the Data Protection Board of India where required. Because each clinic controls its own Firebase project, the clinic is responsible for detecting, remediating, and reporting any breach affecting its own patient data; we will reasonably cooperate.
12. Your Rights Under the DPDP Act, 2023
As a Data Principal, you have the right to:
- Access information about the personal data we hold about you.
- Request correction, completion, updating, or erasure of your personal data.
- Withdraw your consent at any time.
- Grievance redressal in respect of how we handle your data.
- Nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, contact us at rdmappdemo@gmail.com. You also have the right to complain to the Data Protection Board of India if you are not satisfied with our response.
13. Cookies & Analytics
This website uses essential cookies required for it to function, and Google Analytics (GA4) cookies to understand aggregate usage. We do not use cookies for advertising or to sell your data. Where required, we will seek your consent for non-essential (analytics) cookies, and you can control cookies through your browser settings.
14. Cross-Border Data Processing
Some of our providers (such as Firebase / Google Cloud and Google Analytics) may process data on servers located outside India. Such transfers are permitted under the DPDP Act except to countries restricted by the Government of India.
15. Children's Data
This website and our services are intended for clinics and healthcare professionals, not for children. We do not knowingly collect personal data of individuals under 18 through this website.
16. Grievance Officer
In accordance with the DPDP Act and applicable Indian law, you may contact our Grievance Officer for any privacy or data-related concern:
Priyal Shah, Manager
Email: rdmappdemo@gmail.com
We aim to acknowledge and address grievances within 30 days.
17. Changes to This Policy
We may update this policy from time to time. Where changes are material, we will take reasonable steps to notify you. The “Last updated” date above reflects the latest revision.
18. Contact
For any privacy or data-related queries, contact us at rdmappdemo@gmail.com.