This page explains what information may be processed when patients, hospitals, or staff use OPDly services, websites, and workflows including appointments, billing, pharmacy, and lab.
OPDly is operated by OPDly Technologies. OPDly operates as a data processor. Hospitals that use OPDly are the data fiduciaries under the Digital Personal Data Protection Act, 2023 (DPDP Act). Patient data is collected by hospital staff on behalf of patients — patients do not create accounts on OPDly or interact with OPDly directly.
OPDly does not independently verify the accuracy of any data entered by hospital, pharmacy, or lab staff. Verifying the correctness of patient, billing, pharmacy, and lab data before relying on it remains the responsibility of the hospital, pharmacy, and lab respectively.
OPDly processes information entered by hospital staff during patient registration and appointment workflows. This may include:
OPDly does not collect data directly from patients. Patients are identified by their phone number at the hospital counter.
When a patient is registered for an OPD appointment, hospital staff enter the patient's phone number into OPDly. By providing their phone number at the hospital counter for OPD registration, patients consent to receive a one-time WhatsApp message containing their live queue-tracking link.
This message is delivered through the WhatsApp Business API (provided by Meta Platforms, Inc.), which acts as a sub-processor solely for notification delivery. The message is strictly transactional — it is not used for marketing, promotions, or follow-up communications.
Opt-out: Patients who do not wish to receive a WhatsApp notification may inform hospital staff at the time of registration. Staff can register the patient in OPDly without triggering a WhatsApp notification. Patients may also reply STOP to any received WhatsApp message to block further messages from OPDly's WhatsApp number.
Patient data is shared only with the hospital that registered the patient, and with technical sub-processors (such as WhatsApp/Meta for notification delivery) strictly as required to operate the service. OPDly Technologies does not sell or share patient data with third parties for marketing or unrelated purposes.
OPDly Technologies uses reasonable technical and organizational safeguards to protect platform data. No internet system can be guaranteed as fully secure. Hospital administrators are responsible for securing their own staff credentials.
Under the Digital Personal Data Protection Act, 2023, patients (as data principals) have the right to:
Since patient data is entered and managed by the hospital (data fiduciary), data rights requests should be directed to the hospital where the appointment was registered. Hospitals can export a patient's held data or request erasure directly within OPDly, or contact OPDly support for assistance.
If you have a complaint or concern about how your personal data is handled on the OPDly platform, you may raise it with our designated Grievance Officer:
We aim to acknowledge grievances within 48 hours and resolve them within 30 days, as required under the Digital Personal Data Protection Act, 2023.
For reporting a suspected security incident or vulnerability affecting the OPDly platform, contact our designated Point of Contact:
Data may be retained for as long as needed for appointment operations, legal compliance, dispute resolution, and internal recordkeeping. Hospitals may request deletion of patient records by contacting OPDly support.
For privacy-related questions or data requests, contact [email protected].