Privacy Notice
This Privacy Notice explains how Rahul Dangi, trading as MindCareOS ("we", "us", "our"), collects, uses, and shares personal data through the MindCareOS platform (the "Service").
1. Controller
Rahul Dangi (trading as MindCareOS) is the data controller of clinician account data and of personal data we process to operate the Service. For patient clinical records, the treating clinician or clinic is the controller and we act as a processor on their behalf under the Terms of Use.
2. Categories of personal data we collect
- Account & identity data — name, email, password hash, clinic name, role, profile photo.
- Clinician professional data — qualifications, specialisation, clinic address, phone number.
- Patient data entered by clinicians — demographics, history, screening responses, mood/sleep notes, MindSketch drawings and handwriting samples, AI-assisted report drafts, clinician notes.
- Guardian data — for minors, the parent/guardian name and consent record.
- Support & communication data — messages you send us, demo-request forms.
- Usage & telemetry — log data, device identifiers, IP address, browser type, pages visited, error reports.
- Cookies — essential cookies for authentication and session.
3. Purposes and legal basis
- Provide the Service (account creation, intake, screening, MindSketch, reports) — performance of contract.
- Process patient data on behalf of clinicians — performance of contract with the clinic; consent is collected by the clinician from the patient/guardian.
- Security, fraud prevention, abuse detection — legitimate interests and legal obligation.
- Product improvement and analytics (aggregated/de-identified) — legitimate interests.
- Customer support — performance of contract / legitimate interests.
- Service announcements — legitimate interests; marketing emails only with consent (opt-out anytime).
- Compliance with law — legal obligation.
4. Data sharing and recipients
We share personal data only with the following categories of recipients:
- Merchant of Record — Paddle. Payments, subscription billing, tax compliance, invoicing and refund handling are provided by Paddle.com as our reseller and Merchant of Record. Paddle processes your billing details directly; see Paddle's Privacy Notice.
- Cloud hosting and database — our infrastructure provider hosts the Service and stores data encrypted at rest.
- AI sub-processor — the AI Gateway model provider that powers AI-assisted draft generation, used solely to return outputs to the clinician.
- Email/communication providers — used to send transactional and support email.
- Analytics & error monitoring — used in aggregate to maintain reliability.
- Professional advisers — legal, accounting, and compliance advisers when required.
- Authorities — where required by law, court order, or to protect safety.
We do not sell personal data.
5. International transfers
Personal data may be processed outside your country of residence by our hosting and sub-processors. Where data leaves the UK/EEA or India, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent measures.
6. Data retention
- Clinical records — retained for the duration of the clinic's account and as required by applicable clinical record-keeping laws; deleted or anonymised when no longer needed.
- Clinician account data — retained while the account is active and for up to 24 months after closure for tax, audit and dispute purposes.
- Billing records — retained by Paddle and by us as required by tax law (typically 7 years in India).
- Support communications — up to 24 months.
- Logs and security telemetry — typically up to 12 months.
- Demo/lead form data — up to 12 months unless you become a customer.
7. Your rights
Subject to applicable law (including India's DPDPA and the UK/EU GDPR), you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Request erasure ("right to be forgotten") subject to record-keeping obligations.
- Restrict or object to processing.
- Data portability.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your supervisory authority (e.g. the Data Protection Board of India, the ICO in the UK, or your EEA DPA).
Patients should generally exercise rights through their treating clinician (who is the controller of their clinical record). To exercise rights against us as controller, contact us using the details below. We aim to respond within one month.
8. Security
We apply appropriate technical and organisational measures including encryption in transit and at rest, role-based access controls, row-level security in the database, audit logging, and least-privilege administration. No system is perfectly secure; we will notify affected users of any material incident as required by law.
9. Cookies
We use a small number of essential cookies required for authentication and session continuity. We do not use advertising cookies. Analytics cookies, where used, are configured to minimise personal data.
10. Children
The Service is intended for use by clinicians. Where minors are patients, the clinician collects guardian consent before any data is captured.
11. Emergency notice
MindCareOS is not an emergency service. In a crisis call Tele-MANAS 14416 / 1800-89-14416.
12. Contact
Controller: Rahul Dangi (trading as MindCareOS). For privacy questions or to exercise your rights, contact our support team via the in-app help or the contact details in your clinic settings.
Last updated: 8/12/2026