Privacy policy
Last updated 21 August 2026
This policy explains how Gully System Pvt. Ltd. (“GullyMed”, “we”) handles personal data on gullymed.com, app.gullymed.com and practice websites hosted on our platform.
Two roles
For practice owners and staff who create accounts, we are the data fiduciary. For patient data that a practice records in GullyMed, the practice is the data fiduciary and we act as its data processor under our Data Processing Agreement.
What we collect
- Account data: name, mobile number (used for one-time-code sign-in), practice details.
- Patient data entered by a practice: name, phone, age/sex, visit notes, prescriptions, files, invoices, payments. Health data is sensitive personal data under the DPDP Act 2023 and is processed only on the practice's instructions.
- Patient booking data entered on a practice website: name, phone, chosen appointment, and the one-time code used to confirm.
- Technical data: IP address, device and browser information, audit logs.
Why
To provide the service: appointments, reminders on WhatsApp/SMS, billing, records, websites. To keep accounts secure. To support practices (support access is logged and visible to the practice). We do not sell personal data and we do not run a patient marketplace.
Where
Patient data and media are stored in India (AWS Mumbai region). Messages are delivered through MSG91; payments through Razorpay on the practice's own account.
Your rights
Practices can export or delete their data from the console. Patients should contact their practice; we assist the practice in honouring access, correction and erasure requests. Grievance officer: privacy@gullymed.com.
Retention
Account data for the life of the account plus 90 days. Patient records for as long as the practice keeps them, subject to medical record-keeping rules. Audit logs for 3 years.