Last updated: 24 September 2026
BeyondChats, a product of Paran Ventures Private Limited (“BeyondChats”, “we”, “us”), provides AI-powered patient communication, front-desk, appointment, engagement, and clinical documentation tools to hospitals and clinics (“Hospitals”). This policy explains what data we handle, why we handle it, and who (if anyone) we share it with. It is written for Indian law, mainly the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (“DPDP law”), and the Information Technology Act, 2000.
1. Whose data this covers and our role
- Patient data. When patients or their families talk to a Hospital through BeyondChats, the Hospital is the Data Fiduciary and decides why and how that data is used. BeyondChats is the Hospital’s Data Processor. We handle patient data only on the Hospital’s instructions and under our agreement with them. We call this “Hospital Data”.
- Business data. For our own website visitors, prospects, and the Hospital staff who use our dashboard, BeyondChats is the Data Fiduciary.
2. What information we collect
a) From patient conversations (on behalf of the Hospital)
We collect this data across WhatsApp, website chat, Instagram, phone calls, missed calls, and web forms:
- Contact and identity details: name, phone number, email, age, gender, city, preferred language, and, where the Hospital enables it, ABHA number and OTP verification status.
- Conversation content: chat messages, call recordings, and call transcripts.
- Patient profile and medical history: From conversations, our AI picks out key information such as symptoms, existing conditions, past treatments, medications, allergies, specialty-specific history (for example, IVF cycle history), and preferences. We collect this so the Hospital can give each patient more personalised support and services, for example sending them to the right doctor, preparing staff before a visit, and following up at the right time.
- Appointment and payment details: preferred doctor, department, and branch; booked slots; reminders; and deposit status. Payments go through licensed payment gateways. We do not store full card, UPI PIN, or bank credentials.
- Insurance details: insurer, policy number, and eligibility status, where the Hospital uses insurance verification.
- Feedback: satisfaction ratings, reviews, and complaints.
- Marketing source: which ad, campaign, or channel brought the patient in. We use this to report on conversions to the Hospital.
b) From consultations (AI Scribe, only where the Hospital enables it)
- Consultation audio, transcripts, generated clinical notes, and diagnosis/procedure codes, which are sent to the Hospital’s EMR.
c) From Hospitals and their staff
- Staff names, work email and phone, role, login and activity logs, and billing details for the Hospital account.
- Content the Hospital provides: doctor schedules, pricing, protocols, and approved answers for our knowledge base.
d) From our website visitors
- Name, email, phone, and organisation if you fill a form or book a demo. We also collect device, browser, IP address, and pages visited, using cookies (see Section 8).
3. How we use information
We use Hospital Data only to provide services to that Hospital:
- answering patient queries, booking appointments, and sending reminders, follow-ups, and recalls;
- building patient profiles and pre-consultation summaries for the Hospital’s staff;
- passing conversations to Hospital staff when a human is needed;
- showing the Hospital dashboards and analytics about its own patients and channels;
- keeping the service secure, fixing problems, and meeting legal requirements.
We use business data to run our relationship with Hospitals, provide support, send billing and service messages, and, for website visitors, reply to enquiries.
4. Using PII-redacted data to improve our services
To make our service better for each Hospital, we use Hospital Data with personally identifiable information (PII) removed. We automatically redact names, phone numbers, emails, ABHA and ID numbers, addresses, and other direct identifiers. We then use this redacted data to:
- improve answer accuracy, language understanding, and medical-term handling;
- find gaps in the Hospital’s knowledge base and suggest new answers;
- tune our internal models and workflows.
This redacted data stays within BeyondChats’ own systems. It is never sold, never shared with third parties, and never used to identify any patient again.
5. We do not share Hospital Data
Hospitals trust us with sensitive patient information. We do not sell, rent, license, or share Hospital Data, whether identifiable or PII-redacted, with any third party, including:
- LLM / AI model providers: Hospital Data is never given to them to train, improve, or evaluate their models.
- Marketing and advertising vendors: no ad targeting, data brokering, or lookalike audiences.
- Investors, lenders, or acquirers: they never receive Hospital Data during fundraising or due diligence.
- Other hospitals or clinics: one Hospital’s data is never visible to, or used for, another Hospital.
The only exceptions are:
- When the Hospital tells us to. For example, pushing notes to the Hospital’s own EMR, syncing its Google/Microsoft calendar, or sending messages through its WhatsApp Business account.
- When the law requires it. We share data only when a court, regulator, or government authority lawfully requires it. Where the law allows, we will tell the Hospital first.
- Infrastructure we run on (see Section 6). These providers process data only on our instructions and cannot use it for their own purposes.
6. Service providers (sub-processors)
We run on a small number of infrastructure providers, such as cloud hosting, messaging (for example, the WhatsApp Business Platform), telephony, and payment gateways. Under contract, each one must:
- process data only to deliver our service, and never for its own purposes;
- keep it confidential and secure;
- keep no data, and never use it for training, where it provides AI model processing.
Hospitals can ask us for the current list of sub-processors. We tell Hospitals before adding a new one.
7. Security
- Data is stored in India, encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Each Hospital’s data is logically isolated from every other Hospital’s.
- Access is role-based and limited to staff who need it. It uses multi-factor authentication and every access is logged.
- We run regular security testing and staff training on confidentiality.
- If a personal data breach happens, we will notify the affected Hospital within 24 hours of becoming aware of it. We will help the Hospital notify the Data Protection Board and affected patients as the law requires.
8. Cookies
Our website uses essential cookies to keep it working and secure, and analytics cookies to understand how it is used. We do not use advertising cookies. You can block or delete cookies in your browser settings. Essential features may stop working if you do. The chat widget on Hospital websites uses only the cookies it needs to keep a conversation going.
9. Your rights
Under DPDP law you may ask to access, correct, update, or erase your personal data, withdraw consent, nominate someone to use your rights for you, and raise a grievance.
- Patients: The Hospital controls your data, so please contact the Hospital first. If you contact us, we will send your request to the Hospital and help it respond.
- Hospital staff and website visitors: Write to support@beyondchats.com. We will respond within 30 days.
If you are unhappy with our response, you can complain to the Data Protection Board of India.
10. Children
Where a patient is under 18, the Hospital is responsible for getting verifiable consent from a parent or guardian. We do not track, profile, or target advertising at children.
11. Changes to this policy
We will post any updates on this page and change the “Last updated” date. We will tell Hospitals about material changes by email at least 30 days before they take effect.
12. Contact and Grievance Officer
Paran Ventures Private Limited (BeyondChats)
Registered office: D-1/931, Kanpur Rd, Sector H, LDA Colony, Lucknow, Uttar Pradesh 226012
Offices:
- Delhi: Room 108, Design Innovation Center, Dream Building, Science Block, University of Delhi, Chhatra Marg, Faculty of Science, University Enclave, Delhi 110007
- Mumbai: Malpani Ventures, 4B/01, Phoenix Paragon Plaza, Lal Bahadur Shastri Marg, Sunder Baug Ln, Ashok Nagar, Kurla, Mumbai, Maharashtra 400070
Grievance Officer: Pankaj Baranwal, CEO
Email: support@beyondchats.com
We will acknowledge grievances within 48 hours and resolve them within 30 days.