Legal

Privacy Policy

How Tokenn collects, uses, and protects information about clinics and their patients.

Last updated 19 May 2026

Short version: Clinics own their patient data. We process it only to run the queue service. We never sell it, never use it for advertising, and never share it with third parties except the sub-processors described below.

1. Who we are

Cyberzio Innovations Pvt Ltd ("Cyberzio", "we", "us") is a company incorporated in Tamil Nadu, India. We operate the Tokenn platform — a WhatsApp-based queue and token management service for outpatient clinics.

Registered address: Tamil Nadu, India
Contact: WhatsApp +91 86674 52543

2. Scope

This policy applies to:

  • Clinic staff — owners, doctors, and receptionists who use the Tokenn dashboard.
  • Patients — individuals who receive WhatsApp messages when they join a clinic's queue.
  • Visitors — anyone who visits tokenn.live.

3. Data we collect

3.1 Clinic account data

DataWhy we collect it
Clinic name, city, doctor nameDisplay in dashboard and patient messages
Staff email / mobile numberLogin authentication
MPIN (securely hashed)Authentication — we never store your plain MPIN
WhatsApp credentials (AES-256 encrypted)Send messages via Meta Cloud API on your behalf
Billing details (Razorpay)Subscription management — card numbers handled by Razorpay, not us

3.2 Patient data

Tokenn is the queue layer only. It does not hold medical records, lab reports, scan images, clinical photos or treatment notes, and there is no way to upload them to it.

DataSourceWhy
Patient nameEntered by clinic staff at token issuePrint on token, display on queue board
Phone numberEntered by clinic staffSend WhatsApp notifications (token confirmation, turn alerts)
Token number & timestampGenerated by TokennQueue management and analytics
Visit reason (free text / category)Entered by clinic staff at token issueRoute the patient to the right queue and order the day — encrypted at rest
WhatsApp message contentInbound messages from patient's phoneAI-powered queue status replies via Gemini

3.3 Usage data

We collect server logs (IP address, endpoint, timestamp) for security and debugging. Logs are retained for 30 days.

4. How we use data

  • To operate the queue service (issue tokens, send WhatsApp notifications, advance queue).
  • To generate AI-powered replies to patient WhatsApp messages using Google Gemini.
  • To show analytics to the clinic owner (average wait time, tokens per day).
  • To process billing and manage subscriptions.
  • To send platform notifications (trial expiry, payment confirmation).
  • To detect and prevent fraud or abuse.

We do not use patient data for advertising, profiling, or any purpose beyond what the clinic instructs us to do.

5. Sub-processors

To run the service we rely on a small set of trusted sub-processors, by category: cloud database and application hosting, WhatsApp message delivery, AI reply generation, payment processing, and real-time queue infrastructure. Clinic and patient data is stored in India; some processing — WhatsApp message delivery and AI replies — necessarily takes place outside India.

A current, named list of our sub-processors — with each one's specific purpose and location — is available to clinics on request. We give advance notice before adding any new sub-processor that handles personal data.

6. Data retention

  • Tokens — retained for 90 days after creation, then permanently deleted.
  • Queue state — reset daily at midnight.
  • Staff accounts — retained while the clinic subscription is active. Deleted 30 days after account cancellation.
  • Clinic data — deleted within 30 days of written deletion request or account cancellation.
  • Server logs — 30 days.

7. Data security

  • WhatsApp access tokens stored with AES-256 encryption at rest.
  • All API traffic over TLS 1.2+.
  • MPINs stored as one-way hashes (never reversible).
  • Role-based access control — receptionists cannot access billing or staff management.
  • JWT authentication with 7-day expiry.

See our Security page for full technical details.

8. Your rights (India DPDP Act 2023)

Under the Digital Personal Data Protection Act 2023, you have the right to:

  • Access — request a copy of personal data we hold about you.
  • Correction — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data.
  • Grievance redressal — raise a complaint with our Data Protection Officer.

To exercise these rights, message us on WhatsApp +91 86674 52543. We will respond within 72 hours.

9. Cookies & analytics

We use one essential, secure login cookie solely to keep you signed in — this is required for the service to work and is exempt from consent.

On our public marketing pages we also use Google Analytics (GA4) to understand site usage. Google Analytics sets analytics cookies and is loaded only after you accept via the cookie banner; if you decline, no analytics cookies are set. IP addresses are anonymised. You can change your choice at any time by clearing site data. See Google's privacy policy.

10. Children's data

Tokenn is used by clinics, including paediatric practices, that may process the personal data of patients under 18. Where children's data is processed, the clinic (as data fiduciary) is responsible for obtaining verifiable consent from a parent or guardian as required by the DPDP Act. Tokenn does not knowingly collect children's data directly from minors.

11. Changes to this policy

We will notify clinic owners on WhatsApp and via an in-app notice at least 14 days before any material change to this policy. Continued use after the effective date constitutes acceptance.

12. Contact

Data Protection Officer — WhatsApp +91 86674 52543
Cyberzio Innovations Pvt Ltd, Tamil Nadu, India

Operated by Cyberzio Innovations Pvt Ltd for TOKENN — WhatsApp queue and token management for clinics in India. See also Privacy Policy, Terms of Service, Security and Data Processing Agreement.