DocVerb
Why Doctors Switch What You Get Platform Practices Why DocVerb Pricing FAQ Vision
Login Sign Up

Digital Personal Data Protection (DPDP) Act Compliance

Effective Date: August 2, 2025 | Last Updated: August 2, 2025

DocVerb separates patient identity from clinical documentation. Our server architecture is designed to exclude direct patient identifiers such as names, phone numbers, email addresses, dates of birth, government IDs, locations, and other demographic attributes from clinical processing, storage, and indexing. Clinical conversations are processed exclusively to extract relevant medical information for generating SOAP notes and prescriptions, without creating patient identity profiles.

Only SOAP notes, prescriptions, and a doctor-specific anonymous UID are securely stored. This UID maintains continuity of care exclusively within the same doctor–patient relationship without creating a universal patient identity.

1. Applicability and Scope

This document details DocVerb's compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), as applicable to our operations as a Data Processor providing AI clinical documentation services to healthcare professionals in India. DocVerb also aligns with other applicable regulations including CDSCO (India), HIPAA (US), and other applicable data protection laws.

2. Role Classification Under DPDP

EntityDPDP RoleResponsibilities
DocVerbData Processor (Section 2(i))Process digital personal data on behalf of Data Fiduciary (Doctor/Practice) per contract
Doctor/PracticeData Fiduciary (Section 2(f))Determine purpose/means of processing; obtain consent; ensure rights
PatientData Principal (Section 2(j))Rights under Sections 11-14 exercisable against Data Fiduciary

3. UID Architecture & Data Minimization (Core Technical Design)

DocVerb implements a UID-based anonymization architecture that fundamentally limits personal data exposure. This design is central to our DPDP compliance and data minimization obligations:

3.1 What Is Stored on DocVerb Servers

  • Only SOAP notes and prescriptions are stored for future reference and continuity of care.
  • NO patient name, phone number, email, ID, date of birth, or any identifying information is ever stored on DocVerb servers.
  • Only a UID (Unique Identifier) is used to associate clinical records.

3.2 UID Properties

  • The UID remains with the patient and can be stored on the doctor's personal device (offline, under doctor's control).
  • The UID is not linked to any human identification inside DocVerb systems — it becomes an anonymous token once inside the server boundary.
  • The UID can only be linked to a real identity if the UID is explicitly shared from the outside world (i.e., by the doctor or patient).

3.3 One-Time Display, Never Uploaded

During the consultation, patient name and details are shown on screen exactly once — attached to the prescription/SOAP note for the doctor's verification. This information is NEVER uploaded to DocVerb servers. It exists only transiently in the browser session during the encounter.

3.4 Data Access Control: Doctor ID + Patient ID Matching

Clinical data can only be accessed when Doctor ID + Patient ID (UID) match. Without this dual-key match, data cannot be seen or obtained by any party — including DocVerb staff.

3.5 Full Identification Requires Four Factors

The only way to identify/reconstruct patient data is with all four factors simultaneously:

  1. Doctor ID
  2. Patient ID (UID)
  3. UID token
  4. Timestamp (of the specific consultation)

Any single factor alone — or any subset of three — is mathematically insufficient to identify or retrieve clinical data.

4. Section-by-Section Compliance Mapping

Section 4: Grounds for Processing

DocVerb processes personal data only per Data Fiduciary's documented instructions (Section 8 contract). Lawful basis: Contract performance (Section 7) and legitimate purposes where Fiduciary has obtained consent.

Section 5: Notice

We do not directly collect from Data Principals. Data Fiduciary (you) provides notice. Our Privacy Policy and this page serve as processor transparency. Notice should inform patients that only clinical content (SOAP/prescriptions) is stored, linked to an anonymous UID — no identifying information is processed or stored.

Section 6: Consent

DocVerb does not directly obtain consent from patients. Instead, the Data Fiduciary (Doctor/Practice) obtains explicit consent from each patient before using DocVerb for their consultations. The consent process includes:

  • Doctor-Patient Discussion: The treating Doctor explains how DocVerb works, what data will be processed, and the benefits for continuity of care.
  • Written/Documentary Consent: Patients sign a consent form or digitally acknowledge via the clinic's EMR system, specifying the scope of AI assistance and their right to withdraw consent at any time.
  • Review and Approval: Before processing begins, the Doctor reviews and approves the AI-assisted documentation workflow.
  • Editable Workflow: Patients have the option to request human review of AI-generated documentation before finalization. Any edits or overrides are logged with timestamps and attributed to the reviewing Doctor.

Consent should specifically cover: (a) audio processing for clinical documentation, (b) storage of SOAP notes/prescriptions under anonymous UID, (c) no storage of identifying information, (d) UID remaining under doctor/patient control.

Every consent record is maintained with timestamps by the Data Fiduciary. DocVerb relies on the Data Fiduciary's compliant consent as the lawful basis for processing personal data under Section 6 of the DPDP Act.

Section 7: Legitimate Uses

Processing for medical diagnosis/treatment (Section 7(1)(i)) is a legitimate use. DocVerb enables this by generating documentation drafts for your review.

Section 8: Data Fiduciary Obligations (Our Support)

  • Accuracy (8(1)): We provide editing tools; you ensure accuracy before finalization.
  • Security (8(2)): We implement technical/organizational measures (see Security page). UID architecture ensures identifying data never reaches our infrastructure.
  • Breach Notification (8(3)): We notify you within 24 hours of discovering a personal data breach.
  • Erasure (8(4)): We delete/delete-on-instruction per retention policy.
  • Grievance Officer (8(5)): Available at docverb.no.reply@gmail.com.
  • DPIA (8(6)): We support your Data Protection Impact Assessment with technical details.

Section 9: Data Principal Rights

Rights (Access, Correction, Erasure, Grievance) are exercisable against Data Fiduciary. We provide technical means: export (JSON/PDF), deletion APIs, correction via edit-then-regenerate. Because no identifying information is stored, rights fulfillment operates on UID-linked clinical data only.

Section 10: Children's Data

We do not independently verify age. Data Fiduciary ensures Section 10 compliance (verifiable parental consent for under-18) before processing pediatric consultations.

Section 11-14: Rights and Grievance

We honor Data Fiduciary instructions for rights fulfillment within 15 days. Grievance Officer: docverb.no.reply@gmail.com

Section 15: Data Protection Impact Assessment

We provide: data flow diagrams, subprocessor list, security measures, retention schedules, cross-border transfer details for your DPIA. UID architecture and data minimization design are documented for DPIA inclusion.

Section 16: Cross-Border Transfer

All primary processing occurs in India (Mumbai/Bangalore regions). No patient data is processed outside India. Any subprocess outside India uses adequacy/SCCs per Central Government notification.

Section 17-18: Exemptions and Powers

We comply with lawful government orders. Legal process served on Data Fiduciary; we cooperate per contract.

Section 19-23: Penalties and Adjudication

We maintain compliance to avoid processor liability. Indemnification in Terms of Service addresses allocation.

5. Data Processing Agreement (DPA) Terms

By using DocVerb, you enter into a DPA incorporating:

  • Processing only on documented instructions
  • Confidentiality commitments for personnel
  • Security measures per Section 8(2)
  • Subprocessor management (prior notice, objection right)
  • Data Principal rights assistance
  • Breach notification within 24 hours
  • Deletion/return post-termination
  • Audit/inspection cooperation (reasonable notice)
  • Cross-border transfer safeguards
  • UID architecture compliance: no identifying data processed/stored; dual-key access (Doctor ID + Patient UID); four-factor identification requirement

6. Practical Implementation for Doctors

  1. Obtain patient consent for AI-assisted documentation (verbal/written per your practice policy)
  2. Inform patients: "I use an AI tool to help create my notes. Audio is processed securely and deleted. Only clinical notes are stored under an anonymous ID — your name and details are never uploaded."
  3. Review every AI-generated note before signing off
  4. Export/delete patient records per your retention policy
  5. Direct patient rights requests to your practice; we'll technically assist
  6. Retain UID on your device — the UID stays with you/patient; without it, even DocVerb cannot link records to identity

7. Subprocessor Disclosure

Critical: No subprocessor receives identifying patient information. All subprocessors receive only de-identified clinical content (SOAP/prescriptions) linked to anonymous UIDs. The UID-to-identity mapping never leaves the doctor's controlled environment.

SubprocessorServiceLocationDPA StatusData Received
AWS IndiaCloud hostingMumbaiExecutedDe-identified clinical content + UID only
GPU ProviderAI inferenceBangalore/IndiaExecutedAudio for real-time transcription (ephemeral, not stored)
RazorpayPaymentsIndiaExecutedDoctor billing data only (no patient data)
SendGridTransactional emailIndia regionExecutedDoctor account emails only (no patient data)

8. Contact for DPDP Matters

Grievance Officer / Data Protection Officer: docverb.no.reply@gmail.com

Subject line: "DPDP - [Your Practice Name]"

DocVerb

The Privacy-First AI Clinical Documentation Platform

Legal

  • Terms of Service
  • Privacy Policy
  • DPDP Compliance
  • Cookie Policy
  • Security
  • HIPAA Compliance
  • ABDM Status

© 2025 DocVerb. All rights reserved.