1. Introduction & Who We Are
GrowClinic is a healthcare-focused digital growth brand operated by Cloutrr Grow (OPC) Private Limited, a company incorporated in India. GrowClinic provides patient acquisition, marketing automation, and clinic growth services to doctors, clinics, and hospitals.
- Data Fiduciary / Controller: Cloutrr Grow (OPC) Private Limited
- Registered office: Rath, Hamirpur, Uttar Pradesh 210428, India
- Email: [email protected]
- Phone: +91 97183 04212
By accessing or using our websites and services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use our services.
2. Scope of This Policy
This Policy applies to personal data we process across:
- growclinic.io — our primary marketing website;
- audit.growclinic.io — our AI-assisted clinic audit tool, which analyses publicly available and user-supplied information about a practice to produce a growth assessment;
- sync.growclinic.io— “Sync”, our WhatsApp and booking automation product used by clients to communicate with their patients;
- our sales, onboarding, support, and service-delivery activities conducted by email, phone, messaging, or in person.
3. Information We Collect
We collect the following categories of information:
a) Information you provide directly. Name, email address, phone number, clinic/practice name, speciality, city, website URL, and any details you submit through our contact forms, audit requests, booking flows, or onboarding questionnaires.
b) Account & service data. For products that require an account (such as Sync), login credentials, profile details, and content you create or upload while using the service.
c) Payment information. When we begin accepting online payments, billing details and transactions will be processed by our payment gateway, Razorpay. We do not store your full card number, CVV, or banking credentials on our servers; these are handled directly by Razorpay in line with applicable card-network and RBI standards.
d) Communications data. Where you use or your patients interact with the Sync WhatsApp automation, we process message content, phone numbers, and delivery metadata strictly to operate the service on behalf of the relevant clinic.
e) Technical & usage data. IP address, browser type, device identifiers, pages visited, referring URLs, and interaction data collected automatically via cookies and similar technologies.
f) Marketing & advertising data. Information about how you found us and how you respond to our advertising, collected through analytics and advertising pixels (see Section 5).
4. How We Use Your Information
We use personal data for the following purposes and on the following legal bases:
- To provide, operate, and improve our websites, the AI audit tool, and the Sync product (performance of a contract / legitimate interests).
- To respond to enquiries, schedule consultations, and deliver the services you request (performance of a contract).
- To process payments, invoicing, and accounting once online payments are enabled (performance of a contract / legal obligation).
- To send service updates, and — where you have consented or as otherwise permitted by law — marketing communications you can opt out of at any time (consent / legitimate interests).
- To measure and improve the performance of our website and advertising campaigns (consent for non-essential cookies / legitimate interests).
- To maintain security, prevent fraud and abuse, and comply with legal and regulatory obligations (legal obligation / legitimate interests).
6. AI Features & Automated Processing
Our audit tool and certain service features use third-party artificial-intelligence technologies, including the OpenAI API and Google Gemini API, to analyse information and generate insights, summaries, or recommendations.
- Inputs you provide to these features (for example, a clinic name, website, or audit responses) may be transmitted to these AI providers solely to generate your output.
- We instruct our AI providers to process this data only to deliver the requested functionality. Under OpenAI's and Google's standard API terms, data submitted via the API is not used to train their foundation models.
- AI-generated outputs are provided for informational purposes and may contain inaccuracies; they do not constitute medical, legal, or financial advice and should be independently verified.
- We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without a lawful basis or appropriate safeguards.
7. Third-Party Service Providers & Sub-Processors
We work with trusted third parties who process data on our behalf or provide infrastructure for our services. Each operates under its own privacy terms, linked below.
| Provider | Purpose | Privacy Policy |
|---|---|---|
| OpenAI | AI processing for the audit tool and content/automation features (OpenAI API). | openai.com/policies |
| Google (Gemini API) | AI processing and analysis for audit and automation features. | policies.google.com |
| Google Cloud / Google APIs | Cloud infrastructure, hosting, maps/places, analytics and related developer services. | cloud.google.com |
| Meta Platforms | WhatsApp Business / messaging APIs powering Sync, and advertising measurement (Meta Pixel). | facebook.com/privacy |
| Razorpay | Payment processing, billing, and subscription management (once online payments are enabled). | razorpay.com/privacy |
We share only the data necessary for each provider to perform its function, and we require them to maintain appropriate security and confidentiality protections.
9. International Data Transfers
Some of our service providers (such as OpenAI, Google, and Meta) are located outside India and may process your data in other countries. Where we transfer personal data internationally, we rely on appropriate safeguards — such as the providers’ contractual commitments and standard contractual clauses — and transfer data only in a manner permitted by applicable law, including the DPDP Act and, where relevant, the GDPR.
10. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including to provide our services, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. When data is no longer required, we securely delete or anonymise it.
11. Data Security
We implement industry-standard administrative, technical, and organisational measures — including encryption in transit, access controls, and reputable cloud infrastructure — to protect personal data against unauthorised access, alteration, disclosure, or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; however, we work continuously to protect your information and will notify you and the relevant authorities of any breach as required by law.
12. Your Rights & Choices
Subject to applicable law, you have the right to:
- access the personal data we hold about you and obtain a summary of how it is processed;
- request correction or updating of inaccurate or incomplete data;
- request erasure of your personal data, subject to legal retention requirements;
- withdraw consent at any time, where processing is based on consent;
- object to or restrict certain processing, and request data portability where applicable; and
- nominate another individual to exercise your rights in the event of death or incapacity (as provided under the DPDP Act).
To exercise any of these rights, contact us at [email protected] or our Grievance Officer (Section 16). We may need to verify your identity before acting on a request. You also have the right to lodge a complaint with the Data Protection Board of India or your local supervisory authority.
13. Children's Privacy
Our services are intended for businesses and individuals aged 18 and over. We do not knowingly collect personal data from children. Where processing of a child’s data is necessary and lawful, we will obtain verifiable parental or guardian consent as required by the DPDP Act. If you believe a child has provided us personal data, please contact us so we can delete it.
14. Client & Patient Data (Processor Role)
When we deliver services to a clinic or healthcare provider — including operating the Sync automation — we may process personal data of that client’s patients or contacts on the client’s behalf. In those cases, the clinic is the data fiduciary/controller and we act as a data processor, handling such data only on the client’s documented instructions and for the purpose of providing the agreed services. Clients are responsible for obtaining the necessary consents from their patients. Patients should direct privacy requests to the relevant clinic.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated version on this page with a revised “Effective Date”. Material changes will be communicated through appropriate channels. Your continued use of our services after an update constitutes acceptance of the revised Policy.
16. Grievance Officer & Contact
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, you may contact our Grievance Officer for any questions, concerns, or complaints regarding this Policy or your personal data:
- Grievance Officer: Riya Singh
- Company: Cloutrr Grow (OPC) Private Limited
- Email: [email protected]
- Address: Rath, Hamirpur, Uttar Pradesh 210428, India
- CIN: U73100UP2025OPC222487
We aim to acknowledge and resolve grievances within the timelines prescribed under applicable law.