Legal
Privacy Policy
Last updated: 2 October 2026
Fine Solves LLP ("Fine Solves", "we", "us") is a limited liability partnership based in Ahmedabad, Gujarat, India. We build custom AI and enterprise software, and we operate a cloud billing and revenue platform for hospitals and clinics.
This policy explains what personal data we handle, why, who we share it with and the choices you have. It is written to meet the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 and its rules.
1. Our two roles
We handle personal data in two different capacities, and your rights work differently in each.
- As a Data Fiduciary for our own website, enquiries, sales conversations and business contacts. We decide why and how that data is used, and this policy governs it directly.
- As a Data Processor for our clients. When a hospital, clinic or business uses software we build or operate, the data in that software (for example patient records in our billing platform) belongs to that client. The client is the Data Fiduciary; we process the data only on its documented instructions and under our agreement with it.
If you are a patient of a hospital or clinic that uses our platform, that hospital is responsible for your data. Please contact it first; we will support it in responding to you.
2. Data we collect through finesolves.com
- Enquiry form: your name, company, work email, the problem you describe, budget range and timeline. Submissions are delivered to our team by email.
- Discovery-call booking: when you book through our Cal.com scheduler, Cal.com collects your name, email, chosen time and any notes you add, and shares them with us.
- Email and other correspondence you send us, including attachments.
- Analytics: Google Analytics records how the site is used, such as pages viewed, approximate location derived from IP address, device and browser type, and referring site, using cookies or similar identifiers.
- Hosting logs: our hosting provider records technical data such as IP address, browser and request time to deliver and secure the site.
We do not ask for sensitive personal data through the website. Please do not include patient information or other confidential personal data in an enquiry.
3. How we use website and enquiry data
- To reply to your enquiry, schedule calls, prepare proposals and manage our business relationship with you.
- To understand how the site is used and improve it.
- To keep the site and our systems secure and to prevent spam and abuse.
- To comply with legal obligations and enforce our agreements.
Legal basis. When you send an enquiry, book a call or email us, you voluntarily give us your details for that purpose, which is a legitimate use under section 7(a) of the DPDP Act; we use them only for that purpose. We use Google Analytics only if you choose "Accept analytics" in the cookie banner, on the basis of your consent. Hosting logs and security measures rely on the legitimate uses and legal obligations permitted by the Act.
We do not sell personal data, and we do not send marketing messages to people who have not asked to hear from us.
4. Our hospital and clinic billing platform
Our healthcare platform covers registration, OPD and IPD billing, discharge and final bills, packages, pharmacy and store, OT and labour-room charge capture, maternity and newborn billing, TPA and insurance claims, consultant payouts, leakage checks, dashboards and reports. Each hospital is a separate, isolated tenant.
Data processed on behalf of the hospital may include:
- Patient identity and contact details: name, age or date of birth, sex, mobile number, address, emergency contact, and mother–newborn linkage.
- Payer details: insurer or TPA, policy number, policy holder, sum insured, PMJAY or corporate identifiers, and images of insurance cards, ID proof and referral letters.
- ABHA number and address, where the hospital enables ABDM integration and the patient authenticates (for example by Aadhaar or mobile OTP).
- Admission, bed, procedure, pharmacy, package and billing records, and documents such as bills, receipts and discharge summaries.
- Hospital staff and doctor accounts: name, mobile, email, role, login history, and audit records including IP address and device type.
How we protect it:
- Patient data and backups are hosted in India.
- Data is encrypted in transit (TLS 1.2 or above) and at rest.
- Each hospital's data is isolated at the database level, and access inside a hospital is limited by role.
- Two-factor authentication is mandatory for owner and administrator accounts.
- Every create, edit, approval, print and export is written to an append-only audit log that the hospital can review.
- Uploaded files are served only through signed links that expire, never public links.
- Fine Solves staff have no standing access to a hospital's data. Support access is a time-limited grant the hospital owner approves, which expires automatically and appears in the hospital's own audit log.
WhatsApp and SMS: bills, receipts and discharge documents are sent to patients only where the hospital has recorded the patient's consent, and messaging stops as soon as consent is withdrawn. Message bodies contain no clinical details; documents travel as attachments or secure, expiring links. Messages are delivered through a WhatsApp Business Solution Provider and SMS gateway engaged for this purpose.
We do not sell patient data, use it for advertising, or use it for any purpose other than providing the service to the hospital that owns it, including training general-purpose AI models.
5. Custom software we build for clients
When we build or support software for a client, we may access the client's systems and data to develop, test, deploy and maintain it. We do so only as needed for the engagement, under the client's instructions and the confidentiality and data-protection terms of our agreement with that client.
7. Where data is stored
Patient data in our healthcare platform is stored in India. Some website and business tools, such as Google Analytics, FormSubmit and Cal.com, may process data outside India. Where they do, we rely on transfers permitted under Indian law and on the provider's contractual safeguards.
8. How long we keep data
- Enquiries and business correspondence: for as long as needed to respond and manage the relationship, and generally no more than 24 months after our last contact unless an engagement follows.
- Analytics data (only if you accepted analytics): kept in Google Analytics for 14 months.
- Healthcare platform data: for the duration of the hospital's subscription. After it ends, the hospital keeps read-only access to view and export its data for 12 months, after which we delete or return it as agreed, except where the law requires the hospital to retain medical or financial records for longer.
- Audit logs are kept for the life of the hospital's account, because they are the hospital's record in billing, insurance and legal disputes.
Whatever the period above, the DPDP Rules require personal data and the logs of its processing to be kept for at least one year so that security incidents can be investigated. We keep them for that minimum period and then erase them, unless another law requires us to keep them longer.
9. Your rights
Under the DPDP Act you may, for data where Fine Solves is the Data Fiduciary:
- ask for a summary of the personal data we hold about you and how it is used;
- ask us to correct, complete, update or erase it;
- withdraw consent at any time, which does not affect processing already carried out;
- nominate another person to exercise your rights if you die or become incapacitated; and
- raise a grievance with us, and if it is not resolved, with the Data Protection Board of India.
How to make a request:
- Email admin@finesolves.com with the subject "Privacy request", saying which right you want to exercise.
- So we can find your data, include your name and the email address or mobile number you used with us (for example, the email you entered in our enquiry form). We may ask for more information if we need to confirm it is you.
- To nominate someone, send their name and contact details; to act for someone else, include proof that you are their nominee or lawful guardian.
- To withdraw consent to analytics, choose "Cookie settings" in the footer of any page and select Decline. To withdraw anything else, email us; it takes no more effort than giving it did.
We will respond within 30 days, and in any case within the 90 days allowed by the DPDP Rules. Requests about patient data should go to the hospital concerned, which we will support; erasure of medical records may be limited by the hospital's legal duty to retain them.
11. Security and breaches
We use technical and organisational measures appropriate to the data we handle, including encryption, access control, logging and monitoring, and regular backups. No system is perfectly secure.
If a personal data breach occurs:
- Where we are the Data Fiduciary, we will tell each affected person without delay what happened, its likely consequences, what we are doing about it, what they can do to protect themselves, and who to contact. We will inform the Data Protection Board without delay and send it a detailed report within 72 hours.
- Where we act for a hospital or other client, we will inform that client without delay and give it the information it needs to notify affected people and the Board.
12. Children
Our website and services are intended for businesses and are not directed at children, and we do not knowingly collect children's data through the website.
Hospitals using our platform record data about minors and newborns as Data Fiduciaries. Under the DPDP Rules, clinical establishments and healthcare professionals do not need verifiable parental consent when the processing is limited to providing health services to the child; in other cases the hospital obtains consent from a parent or lawful guardian.
13. Changes to this policy
We may update this policy as our services or the law change. The date at the top shows the latest version. If a change materially affects how we use data you have already given us, we will tell you before it takes effect.
14. Contact and grievance officer
Nakshatra Gupta, Grievance Officer, Fine Solves LLP, Ahmedabad, Gujarat, India — admin@finesolves.com. Write to this contact with any question about how we process your personal data, to exercise your rights, or to make a complaint.
We acknowledge grievances within 48 hours and resolve them within 30 days, and in any case within the 90 days allowed by the DPDP Rules.
If you are not satisfied with our response, you may complain to the Data Protection Board of India, which accepts complaints online through its digital platform. The Act asks that you use our grievance process first.
This notice is in English. If you would like it in Hindi, Gujarati or another language listed in the Eighth Schedule to the Constitution, email us and we will provide it.
