Privacy Notice
Version privacy-1.0-draft · Effective 24 August 2026
This notice is published for transparency and is pending final legal review. The Grievance Officer's name and contact will be added on appointment; everything else on this page describes how Csyte actually works today.
Who we are
Csyte is an appointment-booking platform for hospitals and clinics in India. The registered company details will be published here once incorporation paperwork completes. Csyte books appointments; it is not a medical provider and gives no medical advice.
What we collect, and where
- Account — your mobile number, verified by one-time password through Google Firebase. Optionally a display name and photo.
- Patient registration — for each person you book for: name, father's name, age, gender, phone, address, and Aadhaar number. The address and the Aadhaar number are stored encrypted (AES-256-GCM); only the last 4 Aadhaar digits are ever displayed — in the app, on receipts, or to hospital staff. Aadhaar is optional for children under 10.
- Booking — the doctor, hospital, slot, and the symptom description you type, which is stored encrypted and shown only to you. Hospital staff see the patient's identity for the visit; your symptom text is not part of their appointment screen.
- Payments — order and payment identifiers, amounts, and the tax invoice. Card, UPI and banking credentials are entered directly with Razorpay and never reach or get stored by Csyte. We send Razorpay no name, phone or email with your order.
- Notifications — if you enable push, the device's push token. Notification content is generic ("Appointment confirmed") and never carries medical details.
- Support chat — messages you type are answered automatically and are not stored.
- Cookies — exactly one, the session cookie that keeps you signed in. No analytics, advertising or tracking cookies exist on this site, and no analytics SDK ships in the apps.
Why we process it
To identify the patient to the hospital you book at; to run bookings, payments, refunds and invoices; to send transactional notifications about your appointments; and to keep the service secure (every access to patient records is logged). Csyte does no advertising, no profiling, and never sells personal data.
Who receives it
- The hospital you book at — the patient's identity details for that visit, shown to its signed-in staff only, with every view logged.
- Razorpay — processes payments. Receives the order amount and identifiers; collects your payment credentials directly under its own privacy policy.
- Google (Firebase / Google Cloud) — phone sign-in, push delivery, crash reporting (crash reports carry no personal or medical content), and the cloud infrastructure Csyte runs on. Our databases and storage run in Google Cloud's Mumbai region (asia-south1).
- Talsec freeRASP — device-integrity checks in the mobile apps (root/tamper detection), receiving device-integrity signals, not your records.
There are no other recipients. No data broker, ad network or analytics provider is involved.
How long we keep it
Your account and patient records are kept until you delete them (below). Payments and tax invoices are retained as Indian tax and financial-record law requires, linked to an internal identifier rather than your name once you delete your account. The access log that records who touched which record is append-only and never contains the record's contents. Sign-in sessions are pruned automatically after they expire. Support-chat text is not retained at all.
Your rights, and the buttons that exercise them
- Access / download — Account → Download my data gives you everything Csyte holds about you as one file, including a log of who accessed your records.
- Correction — re-submit your registration to correct your own details, any time. In the Csyte app you can also edit a family member's record directly; on the web, family corrections can be requested.
- Withdraw consent — one tap on the Account page, as easy as granting it. Booking and new data collection stop immediately; you can re-consent whenever you choose.
- Erasure — Account → Delete my account, or see the deletion page. In the Csyte app you can also remove a single family member without deleting your account.
- Grievance — a Grievance Officer is being appointed and their contact will be published here. You may also complain to the Data Protection Board of India.
Children
Appointments for children are booked by a parent or guardian from their own account, on their declaration of that authority. Aadhaar is optional for children under 10. Csyte shows children's records only to the booking account and the treating hospital.
Security
Sensitive fields (Aadhaar, address, symptoms) are encrypted at rest with AES-256-GCM; everything moves over TLS; access to patient records is logged to an append-only audit trail; hospital staff see masked patient lists and every unmasked view is recorded. Csyte stores no payment credentials of any kind.
Changes to this notice
This notice is versioned. A change that matters to you bumps the version at the top of this page, and a change to what you have consented to is re-presented for consent in the app.
Questions: support@csyte.com. See also the Terms & Conditions, which form the binding agreement.