LiveQueue

Draft — not yet in force. This document has not been reviewed by a lawyer. Every [bracketed] item is a blank that has to be filled, and the whole thing needs a legal read before it is linked anywhere a patient can reach it.

Privacy Policy

How LiveQueue handles the small amount of personal data it holds about patients.

Last updated [DATE] · Governed by India's Digital Personal Data Protection Act, 2023

Who is responsible for your data

When you book a token, you are booking with a clinic. That clinic decides what to collect and why, so under the DPDP Act the clinic is the Data Fiduciary for your information and is the first place to take any question or complaint about it.

LiveQueue is the software the clinic uses to run its queue. We are a Data Processor: we hold and handle patient data only on the clinic's instructions, and never for our own purposes. We do not sell it, we do not use it for advertising, and we do not use it to train anything.

LiveQueue is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [CIN / GSTIN].

What we hold, and why

Deliberately very little. A queue-management system needs to know who to call next and how to reach them — nothing more. We do not hold any clinical information at all: no diagnosis, no prescription, no medical history, no notes. Whatever happens in the consultation room stays in the clinic's own records and never reaches this software.

WhatWhy we need itHow long
Your name So the reception desk and the doctor can call you by name rather than only a number. Until the clinic's retention window ends (see below)
Your mobile number To send your queue number, tell you when to set off, and tell you when it is your turn. Also so the desk can ring you if something changes. Same
Your token and its timings Running the queue, and the clinic's own record of how long its sessions took. Kept, but stripped of your name and number at the end of the retention window
What you typed to the booking bot So that "the bot did not understand me" can be looked into. Same as your name and number

The lawful basis: your consent

We rely on your consent, and we try to be honest about what counts as giving it.

If you booked over WhatsApp

You messaged the clinic and asked for a token. That is your consent to be answered on that number, and to receive the queue updates that are the entire point of the booking. We do not ask a second time inside the reply, because asking a question you have already answered is theatre rather than consent.

If the reception desk booked you

Somebody at the desk took your name and, if you gave one, your number. Being handed a phone number is not the same as being given permission to send automated messages to it, so the desk has to ask, and the software records what you said.

If you say no, you still get your token. Your number is kept only so the desk can ring you, and nothing is sent to you automatically. If you say yes, you get the same updates a WhatsApp booking gets.

Withdrawing consent

You can withdraw at any time, and it is as easy to withdraw as it was to give — that is a requirement of the Act, not a courtesy. Tell the clinic, or reply STOP to any message. Messages stop; your token is unaffected.

How long your data is kept

The purpose your data was collected for — calling you into a consultation room — is finished by the evening. So it is not kept indefinitely.

Each clinic sets its own retention window, within limits the software enforces. At the end of it, your name and number are automatically erased from the record: the token survives with its timings so the clinic can still see how its queues ran, and the part that identifies you is gone. This runs on its own, without anybody having to remember.

[CLINIC NAME] keeps patient names and numbers for [N] days.

Who else sees it

That is the complete list. We do not share patient data with anyone else, for any purpose, ever.

Your rights

Under the DPDP Act you can ask the clinic to:

To exercise any of these, contact the clinic you booked with. If you cannot reach them, or your complaint is about LiveQueue itself, write to our Grievance Officer:

[GRIEVANCE OFFICER NAME] · [EMAIL] · [PHONE]
We respond within [N] days.

Keeping it safe

Passwords are stored hashed and are never recoverable in plain text, including by us. Staff accounts are scoped by role, so a receptionist cannot reach a clinic's billing and a doctor cannot create an administrator. Traffic is encrypted in transit. Clinic data is separated by design, and the separation is covered by automated tests that run on every change.

If a breach affecting your data occurs, the clinic is required to notify you and the Data Protection Board. We will tell the clinic as soon as we know.

Children

[SECTION TO BE COMPLETED — see the note at the top of this file. §9 of the Act restricts processing a child's personal data and requires verifiable parental consent. This has not been resolved in the software.]

Changes to this policy

If we change anything that affects you, we will update the date at the top and tell the clinics using LiveQueue, who will tell you.