Skip to content
Privacy policy

How RAKT handles personal data.

This policy covers this website and the RAKT platform. It is written to be read, not skimmed past — if anything here is unclear, write to us.

Who this is for

Which parts of this policy apply to you

Four kinds of people read this page. Start with the card that matches, then read the sections it points to.

You are visiting rakt.org

You are a patient of a hospital that uses RAKT

  • Your hospital is the Data Fiduciary; RAKT processes on its instructions: section 1
  • What we do with records inside the platform, including WhatsApp consent and erasure: section 4
  • Your first point of contact is the hospital; we help them respond: section 6

You work at a hospital that uses RAKT

  • Your account, and the actions you take, are recorded on the activity log with your role
  • Your employer controls your access and your data; we hold it on their instructions: section 1 and section 4
  • Security measures that protect your account are on the Security page

You are evaluating RAKT for your organisation

Last updated 6 September 2026 · RAKT INNOVATIONS (OPC) PVT. LTD. (CIN U72900DL2020OPC360414, GSTIN 07AAKCR0304B1Z0), AN-4D, AN Block, Shalimar Bagh, Delhi 110088, India

1. Who we are and what this covers

“RAKT”, “we” and “us” mean RAKT INNOVATIONS (OPC) PVT. LTD.. This policy covers two things: this website (rakt.org) and the RAKT platform, including RAKT HMS at app.rakt.org. Our role is different for each, and the difference matters.

  • For this website, we decide what data is collected and why. We are the Data Fiduciary in the language of India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).
  • For data inside the platform — patient records, staff accounts, invoices — your hospital, laboratory or blood centre decides what is collected and why. It is the Data Fiduciary; RAKT is the processor acting on its instructions under the Terms of Service and the Data Processing Addendum, which applies automatically. If you are a patient of a RAKT customer, your first point of contact for your data is that organisation.

2. Data we collect on this website

When you contact us

If you request a demo or write to us by email or WhatsApp, we receive what you send: typically your name, email address, phone number, organisation and message. We use it to reply and to arrange the demo you asked for. We keep it for as long as we are in a conversation with you and for a reasonable period afterwards.

Analytics

We use Google Analytics 4, loaded through Google Tag Manager, to understand how the site is used. It runs under Google Consent Mode v2: until you accept cookies, analytics and advertising storage are denied and only cookieless, aggregated measurement runs. If you accept, Google may set cookies such as _ga. You can change your choice at any time by clearing the site’s cookies.

Server logs

Our web server records requests, including IP address, user agent and the pages requested, for security and to keep the site working. Logs are retained for a short period and are not used to identify you.

3. Cookies

  • Strictly necessary — session, security (CSRF) and your cookie choice, stored as rakt_cookie_consent for one year. These are not gated by consent because the site does not work without them.
  • Analytics and advertising — set only after you accept, as described above.

4. Data inside the RAKT platform

The platform processes personal and health data on behalf of our customers. We process it only on their instructions and only to provide the service. In summary:

  • Data is hosted on infrastructure in the Bengaluru region of India, one tenant per organisation, and backed up nightly to encrypted object storage.
  • Access inside a customer’s organisation is controlled by that organisation through roles and permissions; every change is recorded on an audit trail with the actor and their role.
  • Government identity numbers on patient records are encrypted at rest.
  • Patient messages on WhatsApp or SMS are sent only with consent recorded by the customer, per patient, and consent can be withdrawn.
  • Patient erasure requests are handled through the customer, processed after a cooling-off window the customer sets.
  • Customers can export their data in full at any time. When a contract ends, data is returned or deleted as the contract provides.

Our security controls are described in more detail on the Security and data page.

5. Who we share data with

We do not sell personal data. We share it only with service providers we need to run the website and the platform — hosting and object storage, messaging providers (Meta’s WhatsApp Cloud API and SMS gateways), payment gateways, and analytics as described above — and only to the extent needed for the service. The platform’s sub-processors are listed in Annex 3 of the Data Processing Addendum. Cookies are described in the Cookie Policy. We will disclose data where the law requires it, and we will tell the affected customer where we are permitted to.

6. Your rights

Under the DPDP Act you may ask for access to the personal data we hold about you, for it to be corrected or erased, and you may withdraw consent you have given. You may also raise a grievance. Write to support@rakt.in, marked “Privacy”, or to the Grievance Officer at the postal address above. If your data is held inside a customer’s RAKT instance, please contact that organisation first; we will assist them in responding to you.

7. Children

This website is not directed at children and we do not knowingly collect children’s data through it. Patient records for children inside the platform are processed on the instructions of the treating organisation.

8. Security

We use technical and organisational measures appropriate to the sensitivity of the data — encryption in transit and at rest for sensitive fields, access controls, audit logging and tested backups. No system is perfectly secure; if you believe you have found a vulnerability, please email security@rakt.in.

9. Changes to this policy

We will update this page when our practices change and note the date at the top. Material changes affecting platform customers are communicated to them directly.

10. Contact

RAKT INNOVATIONS (OPC) PVT. LTD. · AN-4D, AN Block, Shalimar Bagh, Delhi 110088, India · support@rakt.in · +91 70427 21037