Company: Rentesy Softwares Private Limited • Address: 5-101/5/1/19 Ganga Avenue, Macha Bollaram, Alwal, Tirumalagiri, Hyderabad – 500010, Telangana, India • Email: hello@rentesy.com • Phone: (412) 844-4641
1. Introduction
MediChat, operated by Rentesy Softwares Private Limited ("Company," "we," "us," or "our"), is a communication workflow and automation platform for licensed healthcare professionals. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform at medi-platform.vercel.com ("Service"). By accessing or using MediChat, you agree to the terms of this Privacy Policy.
2. Who We Are and What We Do
MediChat is a technology and communication workflow provider, not a healthcare provider, telemedicine platform, or medical advice service. We provide AI-assisted communication tools that integrate with WhatsApp Business accounts to help licensed doctors manage patient messaging efficiently.
3. Information We Collect
3.1 Account Information
- Full name, professional credentials, and license information
- Email address and hashed password
- Billing information (processed by third-party payment processors; we do not store raw card data)
- Phone number and WhatsApp Business account identifiers
3.2 Platform Usage Data
- Log data: IP addresses, browser type, device identifiers, pages visited, timestamps
- Feature usage patterns and session analytics
- API request and response metadata (not content unless explicitly stored)
3.3 Communication Data
- WhatsApp message content processed through the platform, subject to your WhatsApp Business account's own terms
- AI-generated draft responses created within the platform
3.4 Voice Data
- Audio recordings submitted by healthcare professionals for creating a personalized voice model
- Voice model parameters and synthesized audio outputs
- This data is collected only with explicit, documented consent
3.5 Patient-Related Data
We do not have a direct relationship with patients. Any patient data flowing through the platform is controlled by the healthcare professional (the "Data Controller"). We act solely as a Data Processor with respect to such data.
4. How We Use Information
We use collected information to:
- Provide, maintain, and improve the Service
- Authenticate users and prevent unauthorized access
- Generate AI-assisted message drafts for review by the healthcare professional
- Train and maintain voice models (voice data only, with explicit consent)
- Process payments and manage subscriptions
- Send transactional communications: account alerts, security notifications, invoices
- Comply with legal obligations
- Detect and prevent fraud, abuse, and security incidents
- Analyze aggregate, anonymized usage to improve product features
We do not use patient communication data for advertising, profiling, or sale to third parties.
5. Legal Basis for Processing (GDPR)
For users in the European Economic Area or United Kingdom, our legal bases for processing include:
- Contractual necessity – Processing required to deliver the Service
- Legitimate interests – Security monitoring, fraud prevention, product improvement
- Legal obligation – Compliance with applicable laws
- Consent – Voice data collection and optional analytics features
6. Data Sharing and Disclosure
6.1 Third-Party Service Providers
| Provider | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database hosting, authentication | USA / EU |
| Vercel, Inc. | Application hosting and CDN | USA / Global |
| Meta Platforms (WhatsApp Cloud API) | Message delivery infrastructure | USA |
| OpenAI / AI provider(s) | Draft message generation | USA |
| ElevenLabs, Inc. | Voice synthesis | USA |
| Stripe / Polar / Paddle | Payment processing | USA / EU |
| Cloudflare, Inc. | Network security, DNS | USA / Global |
6.2 Legal Requirements
We may disclose information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of MediChat, our users, or the public.
6.3 Business Transfers
In the event of a merger, acquisition, or asset sale, user data may be transferred. We will provide notice before data becomes subject to a materially different privacy policy.
6.4 No Sale of Data
We do not sell, rent, or trade personal information to third parties for their marketing purposes.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Duration of active account + 90 days post-termination |
| Communication / message data | As configured (default: 12 months) |
| Voice training recordings | Until deletion requested or account termination |
| Voice model parameters | Until deletion requested or account termination |
| Log and analytics data | 90 days rolling |
| Billing records | 7 years (legal / tax requirement) |
| Backup snapshots | Up to 30 days |
Upon account termination, we will delete or anonymize personal data within 90 days, except where retention is required by law.
8. Your Rights
Depending on your jurisdiction, you may have the right to access, rectify, erase, port, object to, or restrict the processing of your personal data, and to withdraw consent at any time. To exercise your rights, email hello@rentesy.com. We will respond within 30 days.
9. International Data Transfers
Our infrastructure is primarily hosted in the United States. For EEA/UK users, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms when transferring personal data outside your jurisdiction.
10. Data Security
We implement AES-256 encryption at rest, TLS 1.2/1.3 in transit, encrypted storage of third-party access tokens, role-based access controls, and regular security reviews. See our Security page for full details.
11. Children's Privacy
The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. Contact hello@rentesy.com immediately if you believe a minor has provided us with personal data.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify registered users by email and update the "Last Updated" date above. Continued use of the Service after changes constitutes acceptance.
13. Contact
Rentesy Softwares Private Limited
5-101/5/1/19 Ganga Avenue, Macha Bollaram, Alwal, Tirumalagiri
Hyderabad – 500010, Telangana, India
Email: hello@rentesy.com
Phone: (412) 844-4641