Privacy Policy

Sentia — the Health OS · last updated July 2026 · product / demo guidance

1. Who we are

Sentia provides event-sourced, consent-bound healthcare software for clinics and hospitals. This Policy explains how personal data is handled in product experiences and this site.

2. What we collect

  • Account data: name, work email, role, password hash (scrypt — never cleartext).
  • Clinical data: only what licensed users write through the kernel, gated by patient consent.
  • Technical data: session tokens, operational metrics without unnecessary PHI.
  • Product site: standard server logs; contact interest may be stored in browser localStorage for this demo.

3. Legal basis & purpose (India DPDP-aligned)

We process data to provide the service you request: authentication, care delivery, auditability, and safety features. Clinical processing is purpose-limited and consent-bound.

4. Consent & access control

Patient records are patient-owned. Clinicians read and write only with an active consent grant. Patients may revoke access in Patient Companion; the kernel enforces this on subsequent reads.

5. Sharing

We do not sell personal data. Infrastructure providers may process data under contract. ABHA / ABDM integrations follow national programme rules when enabled.

6. Retention

Account credentials remain while active. Clinical events are append-only for integrity; access is controlled by consent and role. Demo environments may reset seed data.

7. Security

See Security & Trust. Identity-bound tokens, session encryption, least-privilege roles.

8. Your rights

Depending on applicable law, you may request access, correction, or deletion of account data. Patients manage consent grants in the Companion.

9. Contact

Use the Contact page for pilot interest. This demo build does not operate a public support inbox.

This document is product guidance for evaluation — not formal legal advice.

© Sentia. All rights reserved.