Apollo Digital

Privacy Policy

Last updated April 18, 2026

This Privacy Policy explains how Apollo Digital (“we”, “us”, “our”) collects, uses, shares, and protects information when you use our website, request a demo, engage our digital marketing services, or operate your clinic on our practice-management platform.

We follow the principles of India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and apply reasonable security practices consistent with the Information Technology Act, 2000.

1. Who we are

Apollo Digital is an Indian healthcare practice-growth company offering two services: (a) digital marketing services for healthcare practices and (b) a SaaS platform for clinic management. For privacy queries contact [email protected].

2. Data we handle, and in what role

We deal with three broad categories of information. Our role and obligations differ for each.

(a) Visitor data — website & demo requests

  • Email address submitted on the demo request form.
  • Usage data (IP address, browser/device info, pages visited, time spent) collected through server logs and web analytics.
  • Cookies for authentication, preference persistence, and analytics.

Here we act as a Data Fiduciary under the DPDP Act.

(b) Client data — clinics using our services

  • Clinic name, contact details, and billing information.
  • Authentication information (mobile number via MSG91 OTP).
  • Campaign and analytics data from Google Ads, Meta Ads, and Google Business Profile, when we manage these on your behalf.

We act as a Data Fiduciary for this information.

(c) Patient data — managed through our platform on behalf of clinics

  • Patient demographic and contact details, clinical notes, treatment plans, prescriptions, invoices, and feedback submitted into the platform by clinic staff or patients.

For patient data, the clinic is the Data Fiduciary and Apollo Digital acts as a Data Processor. We process patient data only on the clinic’s documented instructions and do not use it for any other purpose. Patient-data ownership remains with the clinic.

3. How we use information

  • To provide, operate, and improve the services.
  • To respond to demo requests, provide proposals, and onboard new clients.
  • To send transactional emails (account notifications, invoices).
  • To perform the digital marketing and reporting services our clients hire us for.
  • To comply with legal obligations and respond to lawful requests from public authorities.

4. Third parties we share data with

We share data with trusted service providers to operate the services. These include:

  • Hosting & infrastructure: Railway (application hosting), Amazon Web Services (file storage, when enabled).
  • Communications: MSG91 (OTP and transactional SMS), WATI (WhatsApp Business messaging), Resend (transactional email).
  • Marketing platforms: Google Ads, Meta (Facebook & Instagram), Google Business Profile — used only when we manage these on a client’s behalf.
  • Analytics: Google Analytics, for aggregated website usage.

We do not sell personal data. We do not share data with third parties for their own marketing purposes.

5. Where data is stored

Patient and clinic operational data is stored on servers operated by our hosting providers. We select providers that meet reasonable security standards and, where practical, store data in regions within India. Some service providers (e.g. Resend, Google) may process information outside India; in those cases appropriate contractual safeguards are in place.

6. Your rights

Subject to the DPDP Act and applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate or outdated information.
  • Request deletion of your personal data.
  • Receive a copy of your data in a portable format (for clinic data, export is available on request).
  • Withdraw consent to processing at any time.
  • Lodge a grievance with our grievance officer (contact details below).

For patient data held by a clinic on our platform, exercise these rights directly with your clinic — they are the Data Fiduciary.

7. Security

We apply reasonable security practices: encrypted transit (HTTPS), access control, least-privilege database access, rotation of secrets, and audit logging for sensitive operations. No system is perfectly secure; we commit to notifying affected users without undue delay if a personal-data breach is detected.

8. Retention

We retain information only as long as needed to provide the services and meet legal obligations. On termination, client and patient data is made available for export for 30 days, then deleted from active systems. Archived backups are rotated out within 90 days.

9. Children

Our services are intended for healthcare practices and the adults operating them. Pediatric and other patient records may include minors, but these are always created and managed by the clinic (the Data Fiduciary) under its consent framework, not by us directly.

10. Changes

We may update this policy from time to time. Material changes will be announced via email to registered clients and by an updated “Last updated” date above. Continued use after the change takes effect constitutes acceptance.

11. Contact & grievance officer

Questions, requests, or grievances? Contact Dhruv Khatkar at [email protected] or +91 78274 70707. We respond within 7 working days.

See also our Terms of Service.