Skip to content
Velvet Vizion

§ Legal

Data Protection Terms

Last updated: 23 August 2026

This is the data-processing agreement for clinics on Vizion Flow. Your clinic entrusts patient data to us — clinical records included — and this document sets out exactly what we may do with it, how we protect it, and what happens to it when you leave. It forms part of, and is read together with, our Terms & Conditions.

1. Roles: you decide, we process

Your clinic is the Data Fiduciary for its patients — you decide why and how patient data is used. Velvet Vizion is your Data Processor: we process that data only on your documented instructions to operate Vizion Flow, and for no purpose of our own. These roles follow the framework of the Digital Personal Data Protection Act, 2023.

In plain terms

The patient data stays yours. We are the hands that run your practice software on it — we don't own it, sell it, use it to train anything, or use it for any purpose but the job you hired us for.

2. What we process, and why

The scope is running your practice and your patient follow-up. The clinical side covers patient identity and contact details, medical and dental history, allergies, tooth and periodontal charting, treatment plans and their outcomes, clinical notes, prescriptions, radiographs and clinical photographs, consent records, appointments, invoices and payments, and the operational registers — sterilisation, stock and lab cases — that attach to them.

The follow-up side covers enquiry details, message history and campaign records for instant replies, nurture, reminders, recall, the declined-treatment chase, balance-due recovery, and referral and review requests.

We do not process patient data beyond what running these requires, and never for a purpose of our own.

3. Our security measures

We protect patient data with measures including:

  • Strict separation between clinics — each clinic is its own workspace and its own WhatsApp Business Account, so no clinic can access another's data.
  • Encryption of data in transit.
  • Role-based access inside your clinic, so a receptionist, an assistant and a dentist each see only what their role needs — and role-based limits on our side, so only the people who need access have it.
  • An immutable audit trail recording who viewed and who changed each record, and when. It cannot be edited, including by us.
  • Append-only clinical notes: a note can be added to but not silently rewritten.
  • Authenticated dashboard access for your team, with credentials you control.
  • [Further specific technical measures — e.g. encryption at rest, backup schedule and restore testing, logging retention — to be confirmed and listed here.]

4. Sub-processors and change notice

We use a small set of sub-processors to run the service: Google Cloud Platform for hosting, including clinical records and imaging; Meta's WhatsApp Business Platform for message delivery, which receives message content and patient phone numbers but not clinical records; and Cashfree Payments for plan billing and the UPI Autopay mandate, which handles your clinic's payment details rather than your patients' records. Each is bound to protect the data. Before adding or replacing a sub-processor that handles patient data, we will give you reasonable prior notice so you can raise any concern.

5. Confidentiality and our people

Anyone on our side with access to patient data is bound to keep it confidential and may use it only to operate the service for you. We limit access to those who need it to do their job, and every such access is recorded in the audit trail described in clause 3.

6. Breach notification

If we become aware of a personal-data breach affecting your patients' data, we will notify you without undue delay, share what we know, and support you in meeting your own notification obligations under the DPDP Act, 2023. We will act on breaches promptly to contain and remediate them.

7. Patient consent — who does what

You, as the clinic and Data Fiduciary, are responsible for having the patient consent that your processing and your messages require — including consent to treatment, the consent recorded on a treatment form, and the opt-in that marketing broadcasts require under both the DPDP Act and WhatsApp's messaging rules.

Vizion Flow gives you the tools to do this properly: consent forms presented in the patient's own language and signed on screen, and a DPDP consent ledger recording what each consent covered and when it was given. We provide the tooling and act on your instructions; we do not obtain consent on your behalf.

In plain terms

Service messages patients expect — booking confirmations, reminders — are one thing. Treatment consent and marketing opt-in are the clinic's to obtain, because they're your relationship with your patient. We give you a clean way to record both and a ledger that proves you did.

8. Assisting you with patient requests

If a patient exercises a right — access, correction, or erasure — you handle it as the Data Fiduciary, and we will give you reasonable, timely help to locate, correct, export or delete that patient's data within the service. Where a clinical record must be retained under law or professional rules, that retention obligation is yours to apply; we will help you act on it rather than override it.

9. Data return and deletion on exit

Full export of everything — patient records, clinical history, imaging, billing and lead history — on either plan, at any time, for no fee and with no notice period. Not a support ticket, not a retention call, not a negotiation. A button.

Dashboard history windows follow your plan — last 90 days of dashboard history on Base, lifetime history + full export on Growth — but that governs what the dashboard displays, not what exists. Nothing is deleted because of a plan window, and export covers the whole record on either plan. When your subscription ends, you can retrieve your data before it is decommissioned, and we will delete or return patient data on your request, save where the law requires us to keep specific records for a limited period.

Export is never used as leverage. You can export at any time — including while an account is paused or suspended for non-payment, after a free trial has ended, and once an account has become view-and-export only. We will not withhold a data export to enforce payment or to discourage you from leaving, and we do not charge for it.

In plain terms

Whatever else is going on — an unpaid invoice, a trial that has run out, a cancellation in progress — you can still open a patient's record and get your data out. That one is not negotiable at our end.

10. Cross-border processing

Patient data, including clinical records and imaging, is hosted on Google Cloud Platform in a Google Cloud region within India. Message delivery additionally runs on Meta's infrastructure, which may be located outside India, under Meta's terms. We keep such processing to what the service needs and apply any transfer safeguards the law requires. Our Privacy Policy sets out the hosting region and more detail.

11. How these terms fit together

These Data Protection Terms are part of the agreement between your clinic and Velvet Vizion (Siddharth, trading as Velvet Vizion). Where they and the general Terms & Conditions both speak to how patient data is handled, these more specific terms govern. Questions: legal@velvetvizion.com.

Questions about anything on this page? Reach us at legal@velvetvizion.com before you sign up — we would rather answer than have you guess.