Flag of India
India

Digital Personal Data Protection Act, 2023

Act No. 22 of 2023, read with the Digital Personal Data Protection Rules, 2025

How MolarPlus processes the personal data of patients and clinic staff under India’s Digital Personal Data Protection Act.

Applies to
India
Regulator
Data Protection Board of India
The clinic is the
Data Fiduciary
MolarPlus is the
Data Processor
Data is hosted in
Asia Pacific (Mumbai) region, India
Last reviewed
September 2026

1.Scope

MolarPlus is operated by Upclick Labs (OPC) Pvt. Ltd. (“MolarPlus”, “we”). This statement sets out how MolarPlus processes digital personal data under the Digital Personal Data Protection Act, 2023 (the “Act”) and the Digital Personal Data Protection Rules, 2025 (the “Rules”). It applies to the MolarPlus clinic management service and its mobile applications.

The Rules bring the obligations of the Act into force in phases, with most taking effect eighteen months after the Rules were notified in November 2025. MolarPlus applies the practices described in this statement now, rather than as each obligation commences.

2.Roles under the Act

For patient records, the clinic determines the purpose and means of processing and is the Data Fiduciary. MolarPlus processes that data only on the clinic’s behalf, under its agreement with the clinic, as a Data Processor within the meaning of section 2 of the Act and as section 8(2) permits.

For the account details of clinic owners and staff, and for enquiries made through this website, MolarPlus determines the purpose of processing and is itself the Data Fiduciary.

3.Obligations and practice

The table below sets each principal obligation of the Act against the practice MolarPlus follows, whether as Data Processor for the clinic or as Data Fiduciary in its own right.

Sections 5 and 6
Notice to the Data Principal, and consent that is free, specific, informed, unconditional and unambiguous, which may be withdrawn at any time.
Clinics send digital consent forms to patients from MolarPlus. Each signed consent is stored against the patient’s record, so the clinic can show when, and to what, the patient agreed.
Section 8(2)
A Data Fiduciary may engage a Data Processor only under a valid contract.
MolarPlus processes patient data solely to provide the service to the clinic, under its agreement with the clinic, and for no purpose of its own. MolarPlus does not sell personal data.
Section 8(3)
Personal data used to make a decision about a Data Principal must be complete, accurate and consistent.
Authorised clinic staff can correct, complete and update patient records at any time, and changes are recorded in the activity log.
Section 8(5)
Reasonable security safeguards to prevent a personal data breach, including in processing carried out by a Data Processor.
Described in section 4 of this statement.
Section 8(6)
Intimation of a personal data breach to the Board and to each affected Data Principal.
Described in section 5 of this statement.
Section 8(7)
Erasure of personal data once its purpose is served or consent is withdrawn, unless retention is required by law, including by the Data Processor.
Described in section 8 of this statement.
Sections 8(9) and 8(10)
Publication of the contact of a person able to answer questions on processing, and an effective means of grievance redressal.
Described in section 9 of this statement.
Section 9
Verifiable consent of a parent or lawful guardian before processing the personal data of a child.
The clinic obtains that consent where the Act requires it. MolarPlus consent forms can be sent to, and signed by, the parent or guardian.

4.Security safeguards

Rule 6 of the Rules sets out the minimum reasonable security safeguards to be taken, including encryption, control of access, visibility of access through logs, and measures such as backups for continued processing after a compromise. MolarPlus applies the following safeguards to all data it processes.

Encryption at rest
Patient and clinic records are held in a managed PostgreSQL database on Amazon RDS, encrypted at rest with AES-256. The storage volumes of the application servers are encrypted in the same way.
Encryption in transit
Every connection between a browser or the MolarPlus mobile app and the MolarPlus service is encrypted with TLS.
Network isolation
The production database accepts no connections from the public internet. It can be reached only from the MolarPlus application servers.
Role-based access
The clinic owner decides, section by section, what each staff member can see and do. Staff are given access to the information their work requires and nothing more.
Authentication
Every user signs in with an individual account. Passwords are stored only as bcrypt hashes, sign-in and sign-up are verified with one-time codes, and repeated attempts are rate limited.
Audit trail
Actions taken within a clinic account are recorded in an activity log, which the clinic owner can review and export.
Private document links
Documents, prescriptions and reports are kept in private object storage and are opened only through signed links that expire shortly after they are issued.
Backups and recovery
The database is backed up automatically every day, with point-in-time recovery available across a rolling seven-day window.
Portability
A clinic owner can download a complete archive of the clinic’s data at any time and export patient records as a spreadsheet, without contacting MolarPlus.

5.Personal data breaches

If MolarPlus becomes aware of a personal data breach affecting data it processes for a clinic, it will inform the clinic without delay. MolarPlus will give the clinic the information it needs to intimate the Data Protection Board of India and each affected Data Principal under section 8(6) and Rule 7, including the nature, extent, timing and location of the breach, its likely impact, and the measures taken to mitigate it, together with the facts required for the detailed report to the Board within seventy-two hours.

Where a breach affects data for which MolarPlus is itself the Data Fiduciary, MolarPlus will intimate the Board and each affected Data Principal directly.

6.Rights of Data Principals

Patients exercise their rights against the clinic, as Data Fiduciary. MolarPlus gives clinics the means to act on those requests within the service.

Section 11
Access to a summary of the personal data processed and the processing activities.
The clinic can view and export a patient’s complete record and provide it to the patient.
Section 12
Correction, completion, updating and erasure of personal data.
Authorised staff correct, complete and update records directly. Erasure is carried out as described in section 8.
Section 6(4)
Withdrawal of consent, with the same ease as it was given.
The clinic acts on the withdrawal, and MolarPlus erases the data on the clinic’s instruction, subject to any retention the law requires.
Section 13
Readily available means of grievance redressal.
Patients raise grievances with their clinic. Clinic owners and staff may raise them with MolarPlus directly, as section 9 describes.
Section 14
Nomination of another individual to exercise rights in the event of death or incapacity.
MolarPlus supports the clinic in acting on requests from a duly nominated individual as it would on requests from the patient.

7.Storage and transfers

All clinic and patient records are stored on Amazon Web Services in the Asia Pacific (Mumbai) region, India. Certain features rely on service providers that process limited data outside India, including in the United States. These providers are listed in the register of sub-processors.

Section 16 of the Act permits the transfer of personal data outside India unless the Central Government restricts transfers to a particular country by notification. MolarPlus will not transfer personal data to any country so restricted.

8.Retention and erasure

MolarPlus retains clinic data for as long as the clinic’s account is active. A clinic may download a complete copy of its data at any time. When a clinic closes its account and instructs MolarPlus to erase its data, MolarPlus erases that data from its production systems, and copies held in automated backups expire as the 7-day backup window rolls over.

Clinics remain responsible for keeping clinical records for any period required by law or by their professional regulator, and should export those records before requesting erasure.

9.Grievance redressal

Any person whose personal data MolarPlus processes as Data Fiduciary may contact the Grievance Officer with a question or grievance about that processing. MolarPlus will respond within the period prescribed under the Rules. A person whose grievance is not resolved may then approach the Data Protection Board of India, as section 13(3) of the Act provides.

Patients should first contact the clinic that holds their records.

Grievance Officer
Grievance Officer, MolarPlus
Telephone: +91 9594078777
Sky Loft, opposite Golf Course, Shastrinagar, Yerawada, Pune, Maharashtra 411006, India

© 2026 MolarPlus Powered by Upclick labs (OPC) Pvt. ltd.