Data protection
Plain-language summary of how docbook.ai protects clinic and patient data. Last updated: October 9, 2026.
Roles
When a clinic uses docbook.ai, the clinic controls its patients’ data and docbook.ai processes it only on the clinic’s instructions to run the service. For information you submit on this website, docbook.ai is the controller.
What we collect
- Clinic staff: name, email, phone, role and login details.
- Patients: name, phone number, appointment details and clinical records the clinic enters.
- Website enquiries: name, phone, email, clinic, city, plan interest and your message.
HIPAA-aligned security controls
- Encryption in transit (TLS) and at rest.
- Row-level access control: each role sees only the minimum it needs.
- Staff accounts approved by the clinic admin; least-privilege by default.
- Activity trail of important changes to support investigations.
- Documented breach-response process.
docbook.ai does not claim HIPAA certification and does not currently sign Business Associate Agreements. If you are a HIPAA covered entity, please talk to us before storing protected health information.
Where data is stored
Data is currently hosted on AWS in the Mumbai (India) region via Supabase. Regional hosting for other markets is on our roadmap.
Purpose & consent
Data is used only to book and manage appointments, keep patient records for the clinic, send reminders the clinic has enabled, and provide support. We never sell personal data or use it for advertising.
Your rights
You can ask to access, download, correct or delete your data, and to withdraw consent. Patients can download their own data from their account. Otherwise, contact your clinic or write to us.
Retention
Clinics decide how long patient records are kept, in line with local record-keeping rules. Website enquiries are deleted within 24 months if you don’t become a customer.
Cookies
This website uses no tracking or advertising cookies. We only store your light/dark theme choice in your browser.