Privacy Policy

Ekansh Portal — Lab & Clinic Management Software

Effective Date: June 12, 2026  •  Last Updated: June 12, 2026  •  Version: 2.0

1. Who We Are

Ekansh Portal is a Software-as-a-Service (SaaS) platform designed for clinical laboratories, diagnostic centres, and healthcare facilities in India. We provide tools for patient management, laboratory report generation, billing, and related workflows.

Data Processor Role: Ekansh Portal acts as a Data Processor under the Digital Personal Data Protection (DPDP) Act, 2023. The registered laboratory or clinic using our software is the Data Fiduciary responsible for obtaining patient consent and ensuring lawful data use. We process patient data only on their behalf and under their instructions.

2. What Data We Collect

2a. Data About Lab / Clinic Staff (Account Users)

2b. Patient Health Data (Entered by Lab Staff)

Note: Patient health data is classified as Sensitive Personal Data under Indian law. It is never used for advertising, profiling, or sold to any third party under any circumstances.

2c. Camera and AI Data

Where camera features are used within the application (e.g., document scanning, image capture for records), images are processed for their stated purpose, uploaded securely to Firebase Storage, and linked to the relevant patient or document record. AI analysis (Google Gemini) may be used to extract text from uploaded documents. Images are not used to train AI models.

2d. Usage and Technical Data

3. How We Use Your Data

Purpose Legal Basis (DPDP Act 2023)
Providing lab management and report generation services Contract performance / Legitimate use
Storing patient records and lab reports Legitimate use; healthcare regulatory requirement
Authenticating users and managing access Security / Contract performance
Generating invoices and billing records Legal obligation (GST, financial records)
Crash reporting and app stability Legitimate interest (service improvement)
Compliance with law enforcement / court orders Legal obligation

We do not use your data for advertising, behavioural profiling, or sale to third parties.

4. Data Sharing and Third-Party Processors

We share data only with the following sub-processors, all of whom operate under appropriate data processing agreements:

We do not share data with any other third party without your explicit consent, except where required by Indian law or a valid court order.

5. Data Retention Policy

We follow a structured data retention schedule in accordance with Indian healthcare regulations:

Data Type Retention Period Action After Period
Patient records and lab reports 3 years from date of last report Flagged for deletion; permanently deleted within 90 days of flag
Billing and invoice records 7 years (GST and financial record requirement) Archived, then permanently deleted
Activity and audit logs 2 years Permanently deleted
Staff account data Until account deletion + 30 days Permanently deleted
Crash and usage analytics 12 months Automatically purged by Firebase
Why 3 years for patient records? Indian medical law requires pathology labs to maintain records for a minimum of 2 years. We retain for 3 years to cover legal dispute windows. Records are not deleted earlier even upon patient request, as this may conflict with regulatory requirements. After 3 years, deletion is automatic unless the lab admin places a hold.

6. Your Rights Under DPDP Act 2023

As a data principal (patient or user), you have the following rights:

To exercise any of these rights, contact us at the details in Section 11. Requests will be responded to within 30 days.

7. Data Security Measures

In the event of a data breach that is likely to cause harm to data principals, we will notify affected parties and the Data Protection Board of India as required under the DPDP Act, 2023.

8. Regulatory Compliance Notice

Ekansh Portal is a software tool used by registered laboratories and clinics. The following compliance responsibilities rest with the registered lab/clinic operator, not with Ekansh Portal:

Ekansh Portal provides tools to support compliance but does not guarantee regulatory compliance on behalf of its users. See our Terms of Service for full details.

9. Cookies and Local Storage

Our web application uses browser local storage and session cookies strictly for authentication session management and user preferences. We do not use advertising cookies or third-party tracking cookies. No cookies are shared with advertisers.

10. Children's Privacy

Ekansh Portal is a B2B professional software intended for use by authorized laboratory and clinical staff. We do not knowingly collect personal information directly from individuals under 18 years of age through our platform sign-up process.

Patient records in the system may include minors' health data (e.g., a child's blood test), which is entered by authorized lab staff on behalf of the treating facility. Such data is handled with the same protections as adult patient data.

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in law or our practices. When we make material changes, we will update the "Last Updated" date at the top of this page and, where feasible, notify registered users via in-app notification. Continued use of the service after the effective date of changes constitutes acceptance of the revised policy.

12. Contact Us & Grievance Officer

For any privacy-related questions, data access requests, or complaints:

Ekansh Portal

Grievance Officer: Ekansh Systems Support Team

Email: chaurasiaservices@gmail.com

Subject Line: Privacy Request — [Your Name]

Response Time: Within 30 days of receipt