Privacy Policy
How Tokenn collects, uses, and protects information about clinics and their patients.
Last updated 1 September 2026
Short version: Clinics own their patient data. We process it only to run the queue service. We never sell it, never use it for advertising, and never share it with third parties except the sub-processors described below.
1. Who we are
Cyberzio Innovations Pvt Ltd ("Cyberzio", "we", "us") is a company incorporated in Tamil Nadu, India. We operate the Tokenn platform: a WhatsApp-based queue and token management service for outpatient clinics.
Registered address: Tamil Nadu, India
Contact: WhatsApp +91 63851 72443
2. Scope
This policy applies to:
- Clinic staff: owners, doctors, and receptionists who use the Tokenn dashboard.
- Patients: individuals who receive WhatsApp messages when they join a clinic's queue.
- Visitors: anyone who visits tokenn.live.
3. Data we collect
3.1 Clinic account data
| Data | Why we collect it |
|---|---|
| Clinic name, city, doctor name | Display in dashboard and patient messages |
| Staff email / mobile number | Login authentication |
| MPIN (securely hashed) | Authentication: we never store your plain MPIN |
| WhatsApp credentials (AES-256 encrypted) | Send messages via Meta Cloud API on your behalf |
| Payment details (Razorpay) | Booking credit recharges and UPI Autopay: card and UPI details handled by Razorpay, not us |
3.2 Patient data
Tokenn is the queue layer only. It does not hold medical records, lab reports, scan images, clinical photos or treatment notes, and there is no way to upload them to it.
| Data | Source | Why |
|---|---|---|
| Patient name | Entered by clinic staff at token issue | Print on token, display on queue board |
| Phone number | Entered by clinic staff | Send WhatsApp notifications (token confirmation, turn alerts) |
| Token number & timestamp | Generated by Tokenn | Queue management and analytics |
| Visit reason and booking answers (free text / category) | Entered by clinic staff, or given by the patient on WhatsApp when booking | Route the patient to the right queue, order the day and prepare the doctor: encrypted at rest |
| WhatsApp message content | Inbound messages from patient's phone | AI-powered queue status replies via Gemini |
3.3 Usage data
We collect server logs (IP address, endpoint, timestamp) for security and debugging. Logs are retained for 30 days.
4. How we use data
- To operate the queue service (issue tokens, send WhatsApp notifications, advance queue).
- To generate AI-powered replies to patient WhatsApp messages using Google Gemini.
- To show analytics to the clinic owner (average wait time, tokens per day).
- To process booking credit purchases and issue invoices.
- To send platform notifications (few booking credits left, payment confirmation).
- To detect and prevent fraud or abuse.
We do not use patient data for advertising, profiling, or any purpose beyond what the clinic instructs us to do.
5. Sub-processors
To run the service we rely on a small set of trusted sub-processors, by category: cloud database and application hosting, WhatsApp message delivery, AI reply generation, payment processing, and real-time queue infrastructure. Clinic and patient data is stored in the European Union (Helsinki, Finland); WhatsApp message delivery and AI replies are processed by their providers outside India as well.
A current, named list of our sub-processors, with each one's specific purpose and location, is available to clinics on request. We give advance notice before adding any new sub-processor that handles personal data.
6. Data retention
- Tokens: retained for 90 days after creation, then permanently deleted.
- Queue state: reset daily at midnight.
- Staff accounts: retained while the clinic account is active. Deleted 30 days after account closure.
- Clinic data: deleted within 30 days of written deletion request or account cancellation.
- Server logs: 30 days.
7. Data security
- WhatsApp access tokens stored with AES-256 encryption at rest.
- All API traffic over TLS 1.2+.
- MPINs stored as one-way hashes (never reversible).
- Role-based access control: receptionists cannot access billing or staff management.
- JWT authentication with 7-day expiry.
See our Security page for full technical details.
8. Your rights (India DPDP Act 2023)
Under the Digital Personal Data Protection Act 2023, you have the right to:
- Access: request a copy of personal data we hold about you.
- Correction: correct inaccurate or incomplete data.
- Erasure: request deletion of your data.
- Grievance redressal: raise a complaint with our Data Protection Officer.
To exercise these rights, message us on WhatsApp +91 63851 72443. We will respond within 72 hours.
9. Cookies & analytics
We use one essential, secure login cookie solely to keep you signed in: this is required for the service to work and is exempt from consent.
On our public marketing pages we also use Google Analytics (GA4) to understand site usage. Google Analytics sets analytics cookies and is loaded only after you accept via the cookie banner; if you decline, no analytics cookies are set. IP addresses are anonymised. You can change your choice at any time by clearing site data. See Google's privacy policy.
We also use Microsoft Clarity on our public marketing pages to understand how the website is used: it records anonymised session replays and aggregate heatmaps of clicks and scrolling. Like Google Analytics, Clarity is loaded only after you accept via the cookie banner; if you decline, it is never loaded and no recording takes place. Clarity does not run inside the signed-in clinic dashboard, on the display boards, or on our internal platform-admin screens: a recording that began on a marketing page is stopped the moment you sign in.
As a second safeguard, patient names, phone numbers, and reasons for visit are marked in the dashboard so that Clarity could never capture them even if it were running there: they would appear as blanked-out characters in any recording. Text you type into forms is masked by Clarity in all cases.
Clarity is operated by Microsoft and processes data outside India. See Microsoft's privacy statement. If you prefer not to be recorded, Microsoft offers a Clarity opt-out, and browser "Do Not Track" and private-browsing modes also limit what is collected.
We also use the Meta pixel to measure whether our Facebook and Instagram ads bring clinics to Tokenn. Like Google Analytics, it is loaded only after you accept via the cookie banner, and only on our public pages: never inside the clinic dashboard, on the display boards, or on admin screens, so it never sees patient information. It tells Meta that a page was viewed, that a signup was started or completed, or that the WhatsApp demo was opened. We do not send your name, phone number or email to Meta. Meta processes this data outside India under its own privacy policy.
10. Children's data
Tokenn is used by clinics, including paediatric practices, that may process the personal data of patients under 18. Where children's data is processed, the clinic (as data fiduciary) is responsible for obtaining verifiable consent from a parent or guardian as required by the DPDP Act. Tokenn does not knowingly collect children's data directly from minors.
11. Changes to this policy
We will notify clinic owners on WhatsApp and via an in-app notice at least 14 days before any material change to this policy. Continued use after the effective date constitutes acceptance.
12. Contact
Data Protection Officer; WhatsApp +91 63851 72443
Cyberzio Innovations Pvt Ltd, Tamil Nadu, India
Operated by Cyberzio Innovations Pvt Ltd for TOKENN: WhatsApp queue and token management for clinics in India. See also Privacy Policy, Terms of Service, Security and Data Processing Agreement.