Last updated: July 3, 2026 | Effective: July 3, 2026
TALOE MED ("we," "us," "our") is a Clinical Decision Support System (CDSS) operated by Taloe Med LLP. We assist registered medical practitioners by recording doctor-patient consultations, generating structured clinical notes, and providing AI-assisted clinical reasoning.
Data Fiduciary: Taloe Med LLP
Contact: [email protected]
Address: Hyderabad, Telangana, India
| Data Type | Examples | Purpose |
|---|---|---|
| Audio Recordings | Doctor-patient consultation audio (Telugu-English) | Transcription and SOAP note generation |
| Patient Demographics | Name, age, sex, phone number (entered by doctor) | Clinical document identification |
| Clinical Data | SOAP notes, diagnoses, medications, ICD-10 codes | Clinical decision support and export |
| Doctor Profile | Name, qualifications, registration number, clinic details | Document letterhead and authentication |
| Usage Data | Session timestamps, consultation count, feature usage | Service improvement and usage metering |
| Device Data | Browser type, screen size (no device fingerprinting) | UI optimization only |
| Analytics & Diagnostic Data | App usage events (PostHog), error/crash reports (Sentry) — never clinical content | Reliability monitoring and product improvement |
What we DO NOT collect: Aadhaar numbers (unless via ABDM consent flow), financial data, biometric data (beyond voice for transcription), location data, social media profiles.
We NEVER use patient data for advertising, marketing, or sale to third parties.
Under the Digital Personal Data Protection Act 2023 (DPDP Act), our primary legal basis for processing patient data is your consent (Section 6): the treating physician obtains your consent before recording a consultation, through an in-app consent step that must be completed before any recording begins.
You may withdraw consent at any time by informing your treating physician; withdrawal does not affect the lawfulness of processing that already occurred, and stops future processing of your data going forward.
| Category | Purpose | Data Shared | Retention |
|---|---|---|---|
| Speech Recognition Provider | Proprietary ZeroLoss™ transcription pipeline | Audio segments (encrypted in transit) | Not retained after processing |
| AI Clinical Engine Provider | TaloeCore™ SOAP generation and clinical reasoning | Clinical text; structured/labelled identifiers redacted before every call — SOAP generation and clinical reasoning alike | Not retained after processing |
| Redundancy AI Provider | Failover processing for service continuity | Clinical text; structured/labelled identifiers redacted before every call, same as the primary engine above | Not retained after processing |
| Cloud Infrastructure Provider | Secure application hosting | Encrypted session data | Duration of service agreement |
| Analytics & Monitoring Providers | Product usage analytics and error/crash monitoring | Usage events and diagnostic data only — never clinical content or audio | Per provider's standard retention window |
| Content Delivery Network | Secure content delivery and DDoS protection | No patient data (static assets only) | N/A |
We do not sell, rent, or trade personal data to any third party. We identify our processors by category above rather than by name; none of our AI or analytics processors currently has a data processing agreement naming them individually, so we describe them generically until those agreements are finalized.
Our application infrastructure — including our servers, database, and primary AI processing — is hosted in India (Mumbai). This is complete today, not a migration in progress.
Some fallback AI processing and analytics/monitoring providers may process data on servers located outside India. This is permitted under DPDP Act Section 16: personal data may be transferred outside India to any country or territory except one the Central Government specifically restricts by notification, and as of today no country has been so restricted.
| Right | Description | How to Exercise |
|---|---|---|
| Right to Access | Request a copy of your data | Email [email protected] |
| Right to Correction | Request correction of inaccurate data | Doctor can edit SOAP notes; or email us |
| Right to Erasure | Request deletion of your data from our systems | Email [email protected] — processed within 30 days |
| Right to Grievance | File a complaint about data handling | Email [email protected] |
| Right to Nominate | Nominate someone to exercise rights on your behalf | Email [email protected] |
Upon a verified erasure request, we delete your personal data from our systems within 30 days. Where we have shared data with processors for provision of the Services, we expect them to handle such data in accordance with applicable law.
To exercise any right, contact our Grievance Officer at [email protected]. We will respond within 30 days.
Per Section 8(7) of the DPDP Act, we erase personal data once the specified purpose is no longer being served or you withdraw consent, unless retention is required by law. This is our retention schedule by data category. Automated time-based deletion currently runs for Audio Recordings only — see "How It's Handled Today" below for each category's actual practice.
| Data Type | Retention Policy | How It's Handled Today |
|---|---|---|
| Audio Recordings | Retained only as long as needed for transcription; auto-deleted after 30 days | Automatically purged by a recurring server-side sweep after 30 days, or immediately upon your erasure request or account closure |
| Session Data (SOAP, reasoning) | We aim to retain for up to 7 years to meet medical record-keeping norms | No automated time-based deletion runs today; removed upon a verified erasure request |
| Doctor Profile | Retained while your account is active, plus up to 1 year after closure | No automated time-based deletion runs today; removed upon a verified erasure request |
| Usage Analytics | Retained in aggregated, anonymized form for up to 2 years | Aggregated and anonymized — not tied to an individual patient record |
We implement industry-standard security measures aligned with OWASP ASVS 4.0 Level 2:
In the event of a personal data breach, we will notify the Data Protection Board of India within 72 hours of becoming aware of it, as required by the DPDP Act. Where the Board directs us to notify affected individuals, we will do so promptly, describing what happened, what data was affected, and what steps you should consider taking.
TaloeMed is advisory software, not a medical device. All AI-generated outputs (SOAP notes, diagnoses, drug recommendations) are suggestions only. The treating physician reviews, edits, and approves all clinical content before it becomes part of the patient record.
TaloeMed uses minimal cookies, plus the following analytics and monitoring tools:
| Cookie / Tool | Purpose | Duration |
|---|---|---|
| taloemed_token | Authentication (JWT) | Session (24 hours) |
| taloemed_user | User preferences (theme, language) | Persistent (localStorage) |
| PostHog | Product usage analytics (opt-in) | Per PostHog's standard retention |
| Sentry | Error and crash monitoring | Per Sentry's standard retention |
PostHog and Sentry receive usage and diagnostic data only — never your clinical records or audio. Product analytics via PostHog is opt-in through our consent banner. We do NOT use Google Analytics, Facebook Pixel, advertising cookies, cross-site tracking, or device fingerprinting.
TaloeMed is used under the direct supervision of a licensed treating physician; it is not intended for standalone use by children. Where a patient is a minor, we rely on the consent of the accompanying parent or legal guardian, obtained by the treating physician at the point of care. TaloeMed does not use pediatric patient data for tracking, profiling, or advertising of any kind. Pediatric consultations follow the same security and privacy standards as adult consultations.
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via:
Grievance Officer: Taloe Med LLP Privacy Team
Email: [email protected]
Response Time: Within 30 days of receiving your request
Section 13 of the DPDP Act 2023 requires you to raise your concern with us first (above) before escalating further. If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India.
TALOE MED
Taloe Med LLP
Email: [email protected]
Website: taloemed.com
Hyderabad, Telangana, India
TALOE MED v0.8.2 | DPDP Act 2023
© 2025-2026 Taloe Med LLP. All Rights Reserved.