Privacy Policy

Effective Date: 21 June 2026

This Privacy Policy explains how Cloutrr Grow (OPC) Private Limited (“GrowClinic”, “we”, “us”, or “our”) collects, uses, discloses, and safeguards your information when you visit growclinic.io, our subdomains, or otherwise engage our services.

We are committed to protecting your privacy and handling your personal data in accordance with India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and its rules, and, where applicable, the EU/UK General Data Protection Regulation (“GDPR”).

1. Introduction & Who We Are

GrowClinic is a healthcare-focused digital growth brand operated by Cloutrr Grow (OPC) Private Limited, a company incorporated in India. GrowClinic provides patient acquisition, marketing automation, and clinic growth services to doctors, clinics, and hospitals.

  • Data Fiduciary / Controller: Cloutrr Grow (OPC) Private Limited
  • Registered office: Rath, Hamirpur, Uttar Pradesh 210428, India
  • Email: [email protected]
  • Phone: +91 97183 04212

By accessing or using our websites and services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use our services.

2. Scope of This Policy

This Policy applies to personal data we process across:

  • growclinic.io — our primary marketing website;
  • audit.growclinic.io — our AI-assisted clinic audit tool, which analyses publicly available and user-supplied information about a practice to produce a growth assessment;
  • sync.growclinic.io— “Sync”, our WhatsApp and booking automation product used by clients to communicate with their patients;
  • our sales, onboarding, support, and service-delivery activities conducted by email, phone, messaging, or in person.

3. Information We Collect

We collect the following categories of information:

a) Information you provide directly. Name, email address, phone number, clinic/practice name, speciality, city, website URL, and any details you submit through our contact forms, audit requests, booking flows, or onboarding questionnaires.

b) Account & service data. For products that require an account (such as Sync), login credentials, profile details, and content you create or upload while using the service.

c) Payment information. When we begin accepting online payments, billing details and transactions will be processed by our payment gateway, Razorpay. We do not store your full card number, CVV, or banking credentials on our servers; these are handled directly by Razorpay in line with applicable card-network and RBI standards.

d) Communications data. Where you use or your patients interact with the Sync WhatsApp automation, we process message content, phone numbers, and delivery metadata strictly to operate the service on behalf of the relevant clinic.

e) Technical & usage data. IP address, browser type, device identifiers, pages visited, referring URLs, and interaction data collected automatically via cookies and similar technologies.

f) Marketing & advertising data. Information about how you found us and how you respond to our advertising, collected through analytics and advertising pixels (see Section 5).

4. How We Use Your Information

We use personal data for the following purposes and on the following legal bases:

  • To provide, operate, and improve our websites, the AI audit tool, and the Sync product (performance of a contract / legitimate interests).
  • To respond to enquiries, schedule consultations, and deliver the services you request (performance of a contract).
  • To process payments, invoicing, and accounting once online payments are enabled (performance of a contract / legal obligation).
  • To send service updates, and — where you have consented or as otherwise permitted by law — marketing communications you can opt out of at any time (consent / legitimate interests).
  • To measure and improve the performance of our website and advertising campaigns (consent for non-essential cookies / legitimate interests).
  • To maintain security, prevent fraud and abuse, and comply with legal and regulatory obligations (legal obligation / legitimate interests).

5. Cookies & Tracking Technologies

We use cookies and similar technologies to operate our site, remember your preferences, understand usage, and measure advertising. These include strictly necessary cookies (always active) and optional analytics and advertising cookies that we set only where permitted.

Optional technologies may include Google Analytics, the Google Ads conversion tag, and the Meta (Facebook/Instagram) Pixel, which help us understand campaign performance and reach relevant audiences. You can manage cookies through your browser settings and, where shown, through our cookie consent controls. Disabling non-essential cookies will not affect access to core site content.

6. AI Features & Automated Processing

Our audit tool and certain service features use third-party artificial-intelligence technologies, including the OpenAI API and Google Gemini API, to analyse information and generate insights, summaries, or recommendations.

  • Inputs you provide to these features (for example, a clinic name, website, or audit responses) may be transmitted to these AI providers solely to generate your output.
  • We instruct our AI providers to process this data only to deliver the requested functionality. Under OpenAI's and Google's standard API terms, data submitted via the API is not used to train their foundation models.
  • AI-generated outputs are provided for informational purposes and may contain inaccuracies; they do not constitute medical, legal, or financial advice and should be independently verified.
  • We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without a lawful basis or appropriate safeguards.

7. Third-Party Service Providers & Sub-Processors

We work with trusted third parties who process data on our behalf or provide infrastructure for our services. Each operates under its own privacy terms, linked below.

ProviderPurposePrivacy Policy
OpenAIAI processing for the audit tool and content/automation features (OpenAI API).openai.com/policies
Google (Gemini API)AI processing and analysis for audit and automation features.policies.google.com
Google Cloud / Google APIsCloud infrastructure, hosting, maps/places, analytics and related developer services.cloud.google.com
Meta PlatformsWhatsApp Business / messaging APIs powering Sync, and advertising measurement (Meta Pixel).facebook.com/privacy
RazorpayPayment processing, billing, and subscription management (once online payments are enabled).razorpay.com/privacy

We share only the data necessary for each provider to perform its function, and we require them to maintain appropriate security and confidentiality protections.

8. How We Share Your Information

We do not sell your personal data. We may share it only:

  • with the service providers and sub-processors listed in Section 7, to operate our services;
  • with professional advisers (such as auditors, lawyers, and accountants) under confidentiality obligations;
  • with our affiliate group, including our parent company, for legitimate internal business and administrative purposes;
  • where required by law, court order, or a valid request from a public authority;
  • in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards; and
  • with your consent, or at your direction.

9. International Data Transfers

Some of our service providers (such as OpenAI, Google, and Meta) are located outside India and may process your data in other countries. Where we transfer personal data internationally, we rely on appropriate safeguards — such as the providers’ contractual commitments and standard contractual clauses — and transfer data only in a manner permitted by applicable law, including the DPDP Act and, where relevant, the GDPR.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including to provide our services, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. When data is no longer required, we securely delete or anonymise it.

11. Data Security

We implement industry-standard administrative, technical, and organisational measures — including encryption in transit, access controls, and reputable cloud infrastructure — to protect personal data against unauthorised access, alteration, disclosure, or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; however, we work continuously to protect your information and will notify you and the relevant authorities of any breach as required by law.

12. Your Rights & Choices

Subject to applicable law, you have the right to:

  • access the personal data we hold about you and obtain a summary of how it is processed;
  • request correction or updating of inaccurate or incomplete data;
  • request erasure of your personal data, subject to legal retention requirements;
  • withdraw consent at any time, where processing is based on consent;
  • object to or restrict certain processing, and request data portability where applicable; and
  • nominate another individual to exercise your rights in the event of death or incapacity (as provided under the DPDP Act).

To exercise any of these rights, contact us at [email protected] or our Grievance Officer (Section 16). We may need to verify your identity before acting on a request. You also have the right to lodge a complaint with the Data Protection Board of India or your local supervisory authority.

13. Children's Privacy

Our services are intended for businesses and individuals aged 18 and over. We do not knowingly collect personal data from children. Where processing of a child’s data is necessary and lawful, we will obtain verifiable parental or guardian consent as required by the DPDP Act. If you believe a child has provided us personal data, please contact us so we can delete it.

14. Client & Patient Data (Processor Role)

When we deliver services to a clinic or healthcare provider — including operating the Sync automation — we may process personal data of that client’s patients or contacts on the client’s behalf. In those cases, the clinic is the data fiduciary/controller and we act as a data processor, handling such data only on the client’s documented instructions and for the purpose of providing the agreed services. Clients are responsible for obtaining the necessary consents from their patients. Patients should direct privacy requests to the relevant clinic.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated version on this page with a revised “Effective Date”. Material changes will be communicated through appropriate channels. Your continued use of our services after an update constitutes acceptance of the revised Policy.

16. Grievance Officer & Contact

In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, you may contact our Grievance Officer for any questions, concerns, or complaints regarding this Policy or your personal data:

  • Grievance Officer: Riya Singh
  • Company: Cloutrr Grow (OPC) Private Limited
  • Email: [email protected]
  • Address: Rath, Hamirpur, Uttar Pradesh 210428, India
  • CIN: U73100UP2025OPC222487

We aim to acknowledge and resolve grievances within the timelines prescribed under applicable law.