1.Scope
MolarPlus is operated by Upclick Labs (OPC) Pvt. Ltd. (“MolarPlus”, “we”). This statement sets out how MolarPlus processes digital personal data under the Digital Personal Data Protection Act, 2023 (the “Act”) and the Digital Personal Data Protection Rules, 2025 (the “Rules”). It applies to the MolarPlus clinic management service and its mobile applications.
The Rules bring the obligations of the Act into force in phases, with most taking effect eighteen months after the Rules were notified in November 2025. MolarPlus applies the practices described in this statement now, rather than as each obligation commences.
2.Roles under the Act
For patient records, the clinic determines the purpose and means of processing and is the Data Fiduciary. MolarPlus processes that data only on the clinic’s behalf, under its agreement with the clinic, as a Data Processor within the meaning of section 2 of the Act and as section 8(2) permits.
For the account details of clinic owners and staff, and for enquiries made through this website, MolarPlus determines the purpose of processing and is itself the Data Fiduciary.
3.Obligations and practice
The table below sets each principal obligation of the Act against the practice MolarPlus follows, whether as Data Processor for the clinic or as Data Fiduciary in its own right.
4.Security safeguards
Rule 6 of the Rules sets out the minimum reasonable security safeguards to be taken, including encryption, control of access, visibility of access through logs, and measures such as backups for continued processing after a compromise. MolarPlus applies the following safeguards to all data it processes.
- Encryption at rest
- Patient and clinic records are held in a managed PostgreSQL database on Amazon RDS, encrypted at rest with AES-256. The storage volumes of the application servers are encrypted in the same way.
- Encryption in transit
- Every connection between a browser or the MolarPlus mobile app and the MolarPlus service is encrypted with TLS.
- Network isolation
- The production database accepts no connections from the public internet. It can be reached only from the MolarPlus application servers.
- Role-based access
- The clinic owner decides, section by section, what each staff member can see and do. Staff are given access to the information their work requires and nothing more.
- Authentication
- Every user signs in with an individual account. Passwords are stored only as bcrypt hashes, sign-in and sign-up are verified with one-time codes, and repeated attempts are rate limited.
- Audit trail
- Actions taken within a clinic account are recorded in an activity log, which the clinic owner can review and export.
- Private document links
- Documents, prescriptions and reports are kept in private object storage and are opened only through signed links that expire shortly after they are issued.
- Backups and recovery
- The database is backed up automatically every day, with point-in-time recovery available across a rolling seven-day window.
- Portability
- A clinic owner can download a complete archive of the clinic’s data at any time and export patient records as a spreadsheet, without contacting MolarPlus.
5.Personal data breaches
If MolarPlus becomes aware of a personal data breach affecting data it processes for a clinic, it will inform the clinic without delay. MolarPlus will give the clinic the information it needs to intimate the Data Protection Board of India and each affected Data Principal under section 8(6) and Rule 7, including the nature, extent, timing and location of the breach, its likely impact, and the measures taken to mitigate it, together with the facts required for the detailed report to the Board within seventy-two hours.
Where a breach affects data for which MolarPlus is itself the Data Fiduciary, MolarPlus will intimate the Board and each affected Data Principal directly.
6.Rights of Data Principals
Patients exercise their rights against the clinic, as Data Fiduciary. MolarPlus gives clinics the means to act on those requests within the service.
7.Storage and transfers
All clinic and patient records are stored on Amazon Web Services in the Asia Pacific (Mumbai) region, India. Certain features rely on service providers that process limited data outside India, including in the United States. These providers are listed in the register of sub-processors.
Section 16 of the Act permits the transfer of personal data outside India unless the Central Government restricts transfers to a particular country by notification. MolarPlus will not transfer personal data to any country so restricted.
8.Retention and erasure
MolarPlus retains clinic data for as long as the clinic’s account is active. A clinic may download a complete copy of its data at any time. When a clinic closes its account and instructs MolarPlus to erase its data, MolarPlus erases that data from its production systems, and copies held in automated backups expire as the 7-day backup window rolls over.
Clinics remain responsible for keeping clinical records for any period required by law or by their professional regulator, and should export those records before requesting erasure.
9.Grievance redressal
Any person whose personal data MolarPlus processes as Data Fiduciary may contact the Grievance Officer with a question or grievance about that processing. MolarPlus will respond within the period prescribed under the Rules. A person whose grievance is not resolved may then approach the Data Protection Board of India, as section 13(3) of the Act provides.
Patients should first contact the clinic that holds their records.