Privacy Policy
Website, Signup, Healthcare Professional and Patient Data
Effective Date: 22 September 2026 | Last Updated: 22 September 2026
This Privacy Policy explains how BILLIONLIVES BUSINESS INITIATIVES PRIVATE LIMITED ("Pulli.Health", "Pulli", "we", "us" or "our") collects, uses, stores, discloses and protects personal data in connection with the Pulli.Health website, signup process, accounts, application, clinical documentation platform and related services (collectively, the "Service").
1. Who We Are
Pulli.Health is operated by BILLIONLIVES BUSINESS INITIATIVES PRIVATE LIMITED, CIN U74999KL2015PTC037809, with its registered office at House No. 163, Giri Nagar, Kochi, Ernakulam - 682020, Kerala, India.
Pulli.Health provides clinical documentation and related healthcare workflow technology used by healthcare professionals, clinics and healthcare organisations.
2. Who This Policy Applies To
This Policy applies to personal data relating to:
- visitors to the Pulli.Health website;
- healthcare professionals and clinic or hospital staff who create or use Pulli.Health accounts;
- prospective customers, partners and other persons who contact us or request a demonstration; and
- patients whose personal data is processed through Pulli.Health by their healthcare provider.
3. Our Role and the Healthcare Provider's Role
For patient clinical records processed through Pulli.Health on behalf of a clinic, hospital or healthcare professional, the healthcare provider generally determines why the patient information is collected and used for care and record keeping. In that context, the healthcare provider acts as the Data Fiduciary or equivalent responsible party under applicable law and Pulli.Health processes the information on its behalf as a Data Processor, subject to the applicable contract.
Pulli.Health acts as Data Fiduciary for personal data for which we independently determine the purposes and means of processing, including practitioner account information, website enquiries and, where separately consented, copies of patient recordings used by Pulli.Health for model or product improvement.
The exact allocation of responsibilities may also be described in the agreement between Pulli.Health and the relevant clinic, hospital or healthcare organisation.
4. Personal Data We Collect
4.1 Patients
- identity and contact information such as name, age or date of birth, sex and phone number;
- consultation audio recordings, transcripts and clinical notes;
- prescriptions, investigations advised and follow-up instructions entered or approved by the treating healthcare professional;
- pre-consultation information such as symptoms, vital signs and long-term conditions;
- documents uploaded by the healthcare provider, including laboratory or diagnostic reports, and information extracted from those documents;
- information needed to identify and organise encounters, follow-up consultations and clinical records; and
- records of consents provided, refused or withdrawn, together with relevant timestamps and other consent evidence.
4.2 Healthcare Professionals and Clinic Staff
- name, email address, phone number, role and clinic or organisation;
- for doctors, qualification, speciality and professional registration number where required for the Service or patient documents;
- account and authentication information;
- records of access to patient information and other audit events;
- support requests and communications; and
- billing or subscription information where applicable.
4.3 Website Visitors and Prospective Customers
- name, work email address, phone number, role, organisation and information included in an enquiry or demo request;
- communications with our sales, support or business teams; and
- technical data such as IP address, browser type, device type, operating system, referring page, pages visited, date/time, session information and security or diagnostic logs.
Please do not submit patient medical records, consultation recordings, prescriptions, laboratory reports or other patient health information through general website contact, sales or demo-request forms. Clinical information should be submitted only through authorised Pulli.Health workflows.
5. Why We Use Personal Data
| Purpose | What it involves | Primary context / basis |
|---|---|---|
| Clinical recording and documentation | Recording a consultation where enabled, transcribing it and generating a draft clinical note for healthcare-professional review and approval. | Patient consent and the healthcare provider's lawful clinical purpose. |
| Uploaded-document processing | Reading documents uploaded by an authorised healthcare provider so relevant information can be available in the patient record. | Patient consent or other lawful authority available to the healthcare provider, as applicable. |
| Prescription and visit-sheet workflows | Supporting healthcare professionals in preparing patient-facing documents and providing them through authorised channels. | Healthcare provider instructions and applicable patient consent where required. |
| WhatsApp or similar delivery | Sending a patient a link or message relating to their visit documentation where enabled. | Patient consent or other lawful basis applicable to the communication. |
| Optional model/product improvement | Keeping and using a separately authorised copy of a recording to improve transcription, documentation or related Pulli.Health models and workflows. | Separate patient consent and any required healthcare-professional or clinic authorisation. |
| Accounts, security and audit | Authentication, user administration, access controls, support, audit logs, security monitoring and fraud or misuse prevention. | Operating the Service, security and legal/compliance requirements. |
| Website enquiries and demos | Responding to enquiries, arranging demonstrations and managing prospective or existing business relationships. | Your request, consent where applicable, and lawful business administration. |
| Legal compliance | Maintaining required records, responding to lawful requests, investigating incidents and protecting legal rights. | Applicable legal obligations and other lawful grounds. |
6. How Artificial Intelligence Is Used
- Consultation recordings may be transcribed and draft notes may be generated using AI models operated for the Service in India on Google Cloud / Vertex AI in the Mumbai region.
- AI-generated clinical notes are drafts. The treating healthcare professional must review, edit where necessary and sign or approve the final clinical documentation before relying on it as a completed record.
- Pulli.Health is designed as a documentation and workflow-support service and does not replace the treating professional's clinical judgement.
- Where third-party AI infrastructure is used, we use enterprise service arrangements and do not intentionally authorise the provider to use patient clinical data to train the provider's general-purpose models for its own purposes.
7. Service Providers and Other Recipients
We disclose personal data only where reasonably necessary to provide, secure and support the Service, comply with law, or carry out another purpose described in this Policy. Current key providers include:
- Google Cloud (India) - application hosting, storage and AI processing in the Mumbai region;
- Clerk, Inc. (United States) - authentication for healthcare-professional and clinic-staff accounts. Patient clinical data is not intentionally sent to Clerk for authentication;
- MSG91 (India) - messaging/WhatsApp delivery where enabled, which may receive the patient's phone number and information required to deliver the relevant message or link; and
- professional advisers, auditors, insurers, security providers, regulators, courts or governmental authorities where reasonably necessary or legally required.
We do not sell personal data and we do not use patient clinical data for third-party advertising.
8. Where Personal Data Is Processed
Patient clinical data processed through the core Pulli.Health Service is hosted and processed in India, including application hosting, database storage, stored consultation audio/documents and AI transcription/note generation in Google Cloud's Mumbai region.
Practitioner and clinic-staff authentication data may be processed by Clerk, Inc. in the United States. Website, business or support tools may also involve providers operating outside India. Where personal data is processed outside India, we will do so in accordance with applicable Indian law and any restrictions notified by the Government of India.
9. How Long We Keep Personal Data
| Data | Current retention approach |
|---|---|
| Consultation audio recordings | 90 days from the consultation, then deleted unless another consent, legal hold, legal obligation or other lawful reason requires continued retention. |
| Recording copy kept for optional model/product improvement | Up to 1 year while the relevant consent remains valid; deleted from active systems when consent is withdrawn, subject to backup cycles and applicable law. |
| Uploaded clinical documents | For as long as necessary to provide the Service, comply with the healthcare provider's lawful instructions, medical-record requirements and other legal obligations. |
| Signed clinical notes and prescriptions | For the period required by applicable medical-record rules and the healthcare provider's lawful retention obligations. |
| Database backups | Up to 35 days, after which backups expire through the normal backup cycle. |
| Healthcare-professional and staff account data | While the account or customer relationship is active and thereafter for as long as reasonably necessary for administration, security, audit, disputes and legal obligations. |
| Audit and security logs | For as long as reasonably necessary for security, compliance, investigation and applicable statutory or regulatory retention requirements. |
| Website enquiries and demo requests | For as long as reasonably necessary to respond to the enquiry and manage the relevant prospective or existing business relationship, subject to applicable legal and record-keeping requirements. |
10. Consent, Withdrawal and Deletion
Where processing is based on consent, the relevant person may withdraw that consent using the mechanism provided in the Service, through the treating clinic where appropriate, or by contacting us.
- We will stop future processing that depended solely on the withdrawn consent.
- We will delete or restrict data that no longer has another lawful reason to be retained.
- Signed clinical records may need to be retained by the healthcare provider under applicable medical-record rules even where another consent is withdrawn.
- Copies in disaster-recovery backups may remain until the relevant backup expires, up to the normal 35-day backup cycle, and are not ordinarily used except to recover from a system failure.
- If consent for optional model/product improvement is withdrawn, we will stop using the identifiable recording for that purpose and delete it from active improvement datasets, subject to applicable technical and legal limitations.
Withdrawal of consent does not affect processing that was lawful before withdrawal and does not require deletion where another applicable law or lawful requirement requires the information to be retained.
11. Your Privacy Rights
Subject to the laws and provisions applicable at the relevant time, you may have rights to:
- obtain information about personal data processed about you and how it is used;
- request correction, completion or updating of inaccurate or incomplete personal data;
- request erasure where there is no longer a lawful reason to retain the personal data;
- withdraw consent where processing depends on consent;
- raise a grievance concerning our handling of personal data;
- nominate another person to exercise applicable rights on your behalf, where provided by law; and
- exercise any other rights available under applicable data-protection law.
For patient clinical records, your healthcare provider is usually the first point of contact because it controls the clinical record. You may also contact us and we will assist or route the request as appropriate.
12. Children
Where the Service is used in relation to a patient who is a child, the clinic or healthcare professional must ensure that consent or other authority is obtained from the parent, lawful guardian or other person authorised by applicable law, and that any additional requirements applicable to children's data are followed.
The public Pulli.Health website and sales/demo forms are intended primarily for healthcare professionals, organisations and adults, and we do not knowingly solicit children to submit personal data through general website forms.
13. Security
We use reasonable administrative, technical and organisational safeguards designed to protect personal data. Depending on the relevant system, these measures include encryption in transit and at rest, role-based access controls, separation of clinic data, authentication controls, audit logging, security monitoring and regular backups.
No technology service can guarantee absolute security. If a personal-data breach occurs, we will take appropriate containment, investigation and remediation steps and make notifications required by applicable law.
14. Cookies and Website Technologies
The Pulli.Health website may use cookies and similar technologies for essential functionality, security, preferences and analytics. Essential technologies may operate without an optional preference because they are necessary for the site to function or remain secure. Where non-essential analytics or marketing technologies are deployed and consent is required, appropriate choice mechanisms will be provided.
You can also control certain cookies through your browser settings. Disabling essential or functional cookies may affect website operation.
15. Marketing and Business Communications
If you contact us, request a demonstration or have a business relationship with us, we may communicate with you about that request or relationship. Where permitted by law, we may also send information about Pulli.Health products, events or services. You can opt out of marketing messages using an unsubscribe mechanism where provided or by contacting us at admin@pulli.health.
Opting out of marketing does not prevent us from sending communications necessary to respond to your request, administer your account or customer relationship, or provide security or legal notices.
16. Third-Party Links
Our website or Service may contain links to third-party websites or services. Their privacy practices are governed by their own policies. We encourage you to review those policies before providing personal data directly to a third party.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, our practices or applicable law. Each version will show its effective or last-updated date. Where a material change requires further notice or consent, we will take the steps required by applicable law.
18. Contact and Grievance Officer
Questions, privacy requests or grievances may be directed to:
| Legal Entity | BILLIONLIVES BUSINESS INITIATIVES PRIVATE LIMITED |
|---|---|
| CIN | U74999KL2015PTC037809 |
| Registered Office | House No. 163, Giri Nagar, Kochi, Ernakulam - 682020, Kerala, India |
| Phone | +91 97453 33362 |
| admin@pulli.health | |
| Grievance Officer | Srijith Ramakrishnan |
Privacy / Grievance Email: admin@pulli.health
We will handle grievances and privacy requests within the periods required by applicable law and will cooperate with the relevant healthcare provider where a request concerns clinical records it controls.