Privacy Policy
Last updated DD Month 2026
Before this goes live: fill every
highlighted field and have it reviewed by a lawyer familiar with
the Digital Personal Data Protection Act, 2023. This is a careful draft, not legal advice.
The short version
- We do not sell your data, and we never will.
- We do not use your business's data to train models for anyone else.
- Records you put into the Service belong to you. We hold them to run the Service for you.
- One business cannot see another's records. That is enforced by the database, not only by
our code.
1. Who this covers, and in what role
Xwits Developers Private Limited, CIN CIN,
registered at full registered address, Ahmedabad, Gujarat, operates
Xwits Healthcare and Xwits Startups.
| Data | Our role |
| Your account and billing details |
Data Fiduciary. We decide why and how it is processed. |
| Records you enter — patients, employees, customers, invoices |
Data Processor. You are the Fiduciary; we process on your instructions. |
If you are a patient or a customer of a business that uses Xwits, that business is the Data
Fiduciary for your records. Please contact them first. We will help them respond.
2. What we collect
From you, as a customer
- Name, work email, phone, business name and address.
- Tax details needed to invoice you, including GSTIN where you have one.
- Authentication data — a password stored only as a hash, never in readable form.
- Usage and audit records: what was done in the Service, by whom, and when.
- Technical data such as IP address, browser and timestamps, kept for security.
Through your use of the Service
Whatever you enter or connect: patient records, employee records, customer contacts, invoices,
messages, and data from services you connect such as code hosting, payments or a mailbox.
We do not decide what this contains — you do.
What we do not collect
- We do not track you across other websites, and there is no advertising network in the
Service.
- Where the Service refers to an identity document, it stores a reference and never the
number itself.
- Credentials for a connected mailbox are not stored in our database at all — only a
reference to where the credential lives.
3. Why we process it
| Purpose | Basis |
| Providing the Service you subscribed to | Performance of our contract with you |
| Billing, and the tax records law requires us to keep | Legal obligation |
| Security, fraud prevention, and audit trails | Legitimate interest and legal obligation |
| Support you have asked for | Performance of our contract |
| Product email that is not about your account | Consent, withdrawable at any time |
4. Automated processing
Parts of the Service draft text or suggest actions. Where that involves a language model,
only the data needed for that task is sent, it is not used to train the provider's models,
and anything that leaves your organisation — a message to a patient or a client — requires a
person to approve it. No decision with a legal or similarly significant effect on an
individual is made solely by automated means.
5. Who else sees it
We share personal data only with:
- Infrastructure providers hosting the Service. Data is stored in
region — e.g. AWS ap-south-1, Mumbai.
- Providers you connect yourself, such as a payment or messaging provider.
You control these and their own terms apply.
- Model providers, for the drafting features described above, under
agreements that forbid training on your data.
- Authorities, where the law compels us. We will tell you unless we are
legally prohibited from doing so.
We do not sell personal data, and we do not share it for advertising.
6. How long we keep it
- Your records: for as long as your account is open, and for
N days after it closes so you can export them.
- Invoices and tax records: eight years, as Indian tax law requires.
- Audit and security logs: N months.
- Backups: N days, after which they expire on their own.
7. How it is protected
- Encrypted in transit. Passwords stored only as hashes.
- Every business's data is isolated three times over: a marker on every record, a query
layer that refuses to run when it does not know whose data is being asked for, and
row-level security in the database beneath both. The last of those cannot be talked out of
it by a bug in our code.
- Access to production is limited to staff who need it, and is logged.
- Report a vulnerability to security@xwits.dev.
We will not pursue anyone who reports one in good faith.
8. Your rights
Under the DPDP Act, 2023 you may:
- ask what personal data of yours we hold and why;
- ask us to correct or complete it;
- ask us to erase it, where we are not required to keep it;
- withdraw consent you previously gave, as easily as you gave it;
- nominate someone to exercise these rights if you die or become incapacitated;
- complain to the Data Protection Board of India if we do not resolve your grievance.
Write to hello@xwits.dev. We respond within
N days. See Contact &
grievances for the Grievance Officer.
9. Cookies
The Service uses cookies that are strictly necessary: one that keeps you signed in, and one
that protects against cross-site request forgery. It sets no advertising or analytics
cookies, so there is no consent banner — there is nothing to consent to.
10. Children
The Service is for businesses and is not directed at children. A clinic may hold records
about a child patient; in that case the clinic is the Data Fiduciary and is responsible for
obtaining verifiable parental consent as the Act requires.
11. Changes
We will post material changes here and give at least N days'
notice by email before they take effect.