Draft — not yet in force. This document has not been reviewed by a lawyer. Every [bracketed] item is a blank that has to be filled, and the whole thing needs a legal read before it is linked anywhere a patient can reach it.
Privacy Policy
How LiveQueue handles the small amount of personal data it holds about patients.
Who is responsible for your data
When you book a token, you are booking with a clinic. That clinic decides what to collect and why, so under the DPDP Act the clinic is the Data Fiduciary for your information and is the first place to take any question or complaint about it.
LiveQueue is the software the clinic uses to run its queue. We are a Data Processor: we hold and handle patient data only on the clinic's instructions, and never for our own purposes. We do not sell it, we do not use it for advertising, and we do not use it to train anything.
LiveQueue is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [CIN / GSTIN].
What we hold, and why
Deliberately very little. A queue-management system needs to know who to call next and how to reach them — nothing more. We do not hold any clinical information at all: no diagnosis, no prescription, no medical history, no notes. Whatever happens in the consultation room stays in the clinic's own records and never reaches this software.
| What | Why we need it | How long |
|---|---|---|
| Your name | So the reception desk and the doctor can call you by name rather than only a number. | Until the clinic's retention window ends (see below) |
| Your mobile number | To send your queue number, tell you when to set off, and tell you when it is your turn. Also so the desk can ring you if something changes. | Same |
| Your token and its timings | Running the queue, and the clinic's own record of how long its sessions took. | Kept, but stripped of your name and number at the end of the retention window |
| What you typed to the booking bot | So that "the bot did not understand me" can be looked into. | Same as your name and number |
The lawful basis: your consent
We rely on your consent, and we try to be honest about what counts as giving it.
If you booked over WhatsApp
You messaged the clinic and asked for a token. That is your consent to be answered on that number, and to receive the queue updates that are the entire point of the booking. We do not ask a second time inside the reply, because asking a question you have already answered is theatre rather than consent.
If the reception desk booked you
Somebody at the desk took your name and, if you gave one, your number. Being handed a phone number is not the same as being given permission to send automated messages to it, so the desk has to ask, and the software records what you said.
If you say no, you still get your token. Your number is kept only so the desk can ring you, and nothing is sent to you automatically. If you say yes, you get the same updates a WhatsApp booking gets.
Withdrawing consent
You can withdraw at any time, and it is as easy to withdraw as it was to give — that is a requirement of the Act, not a courtesy. Tell the clinic, or reply STOP to any message. Messages stop; your token is unaffected.
How long your data is kept
The purpose your data was collected for — calling you into a consultation room — is finished by the evening. So it is not kept indefinitely.
Each clinic sets its own retention window, within limits the software enforces. At the end of it, your name and number are automatically erased from the record: the token survives with its timings so the clinic can still see how its queues ran, and the part that identifies you is gone. This runs on its own, without anybody having to remember.
[CLINIC NAME] keeps patient names and numbers for [N] days.
Who else sees it
- Clinic staff — the receptionists and doctors at the clinic you booked with. Nobody at any other clinic on our platform can see your data; the software separates clinics from each other and the separation is tested.
- WhatsApp (Meta) — messages are delivered through the WhatsApp Business Platform, so your number and the text of each message pass through Meta's systems, under Meta's own terms and privacy policy.
- Our hosting provider — [HOSTING PROVIDER AND REGION].
That is the complete list. We do not share patient data with anyone else, for any purpose, ever.
Your rights
Under the DPDP Act you can ask the clinic to:
- Tell you what it holds about you, and who it has been shared with.
- Correct or complete anything wrong — a misspelled name, an old number.
- Erase your name and number. The clinic can do this immediately; every visit you have made is cleared at once, and it tells you how many. The token timings stay, with nothing left that identifies you.
- Nominate someone to exercise these rights for you if you die or become incapable of doing so yourself.
- Complain — first to the clinic, and then to the Data Protection Board of India if you are not satisfied.
To exercise any of these, contact the clinic you booked with. If you cannot reach them, or your complaint is about LiveQueue itself, write to our Grievance Officer:
[GRIEVANCE OFFICER NAME] · [EMAIL] · [PHONE]
We respond within [N] days.
Keeping it safe
Passwords are stored hashed and are never recoverable in plain text, including by us. Staff accounts are scoped by role, so a receptionist cannot reach a clinic's billing and a doctor cannot create an administrator. Traffic is encrypted in transit. Clinic data is separated by design, and the separation is covered by automated tests that run on every change.
If a breach affecting your data occurs, the clinic is required to notify you and the Data Protection Board. We will tell the clinic as soon as we know.
Children
[SECTION TO BE COMPLETED — see the note at the top of this file. §9 of the Act restricts processing a child's personal data and requires verifiable parental consent. This has not been resolved in the software.]
Changes to this policy
If we change anything that affects you, we will update the date at the top and tell the clinics using LiveQueue, who will tell you.