Legal instrument
Privacy policy
This is the whole of what we collect, why we hold it, where it sits, who can see it and how you get it back or have it erased. It is written as a numbered instrument so that you can quote a clause at us.
- Instrument
- Privacy policy
- Statute
- Digital Personal Data Protection Act, 2023 (India)
- Data location
- Supabase · Mumbai region · row-level security
- Requests
- info@mdthesis.com
- Last reviewed
- Revision 2
Scope
Scope
Part I
What this policy covers, and who is answerable for it
One document, one contact route, and a clear line between your personal data, which this policy governs, and your research, which your institution governs.
Who holds your data
MDThesis, a brand of REDENN Informatics Private Limited operates this site and the student dashboard on it. For the personal data described in Part II we decide why it is processed and how, which makes us the data fiduciary for it under the Digital Personal Data Protection Act, 2023. Every privacy matter — a question, a request, a correction or a complaint — goes to info@mdthesis.com, and that is the only route we publish.
Whose data this policy describes
Students and other registered users of the dashboard, the doctors and medical writers on our panel, and anyone who writes to us about a project or an enquiry. It covers personal data in every form we hold it: in the database, in object storage, in our email, and in the message threads attached to a project record.
What this policy is not
It governs personal data. It does not govern your thesis as an academic record. Your institution's research-governance, ethics and data-protection rules continue to apply to your study, and where any of them is stricter than a clause below, that rule governs and this one yields.
Collection
Collection
Part II
What we collect, and the purpose each category serves
Stated by category, with the purpose beside it. We collect nothing because it might be useful later.
Account and contact details
Your name, email address, telephone number, college, course and specialty. We use them to open and identify your record, to sign you in, and to reach you about your own project. Your specialty is used to assign a mentor from your field.
Project material you give us
Your topic, protocol, synopsis, chapters, tables and figures, the references you are working from, the research datasets described in Part III, and the comments and messages you write in your project thread. We use this material to do the work you engaged us for and for nothing else. Your topic, your data and your text are never recycled into another student's project.
Documents we prepare for you
Drafts uploaded by the team for your review, each version of them, the annotations placed on them, and the uniqueness report attached to each version. We hold these to run the review and to keep the dated record of your project that the dashboard shows you.
Payment records
The amount, currency, milestone, date and status of each payment. Card and bank credentials are entered on the payment gateway's own page, are handled by that gateway, and are never stored on our servers. We can see that a payment succeeded and for which milestone; we cannot see your card.
Technical records
A session record that keeps you signed in, a preference record that remembers the currency you chose, and the access records our hosting produces while serving the site. We do not run third-party advertising or profiling tools on this site.
What we never do with it
We do not sell personal data. We do not rent, trade or share it for advertising, and we do not build a profile of you for anyone else's purposes. We do not use your project material to market to you beyond messages about your own project and your own account.
Patient data
Patient data
Part III
Anonymised datasets only, and what happens if identifiers arrive
This is the part of the policy that matters most, because the data in a medical thesis belongs to patients who never agreed to meet us.
Send anonymised data and nothing else
We require anonymised datasets. Do not upload identifiable patient information. Strip every identifier before a file leaves your hands:
- Names, initials and any coded key that can be resolved back to a name.
- Hospital, registration and UHID numbers, in-patient and out-patient numbers, and laboratory accession numbers.
- Addresses, telephone numbers and email addresses.
- Dates that could identify a single episode of care, including exact admission, procedure and discharge dates.
- Photographs, scans and any image carrying a name, a number or a visible face.
- Free-text fields — history, remarks, operative notes — that name a person or a ward.
If identifiers reach us anyway
We stop work on that file, tell you at once, and delete our copy rather than work on it. We will ask you to send a de-identified replacement. We do not attempt to anonymise a clinical dataset on your behalf, because the person who collected it is the only person who can do that safely.
Approval and consent remain yours
Institutional Ethics Committee approval must precede any data collection, and informed consent is your responsibility as the investigator[5]. We do not begin analysis on a dataset collected before approval was granted, and we will ask for the approval reference before a statistics stage opens.
Confidentiality, and deletion on completion
A non-disclosure agreement is signed on request. Access to your dataset is limited to the people working on your project. We delete project datasets on completion of the project, and on your written request at any time — see clause 6.1 for how to make that request.
Storage
Storage
Part IV
Where your data lives, and how it is protected there
Specific enough to be checked. Each mechanism below is implemented in the platform rather than asserted as a posture.
Location
Personal data and project files are stored in Supabase — managed Postgres and object storage — in the Mumbai region. Keeping the data in the same region as the functions that serve it is both a latency decision and a data-residency one.
Row-level security
Every row that belongs to a project carries its owner, and access policies are enforced in the database itself rather than only in the application that queries it. A request that is not yours returns nothing, not a filtered page.
Watermarked, authenticated document streaming
Drafts are not public files. They are streamed to an authenticated viewer, watermarked with your own name and email address, and served only to the student whose project it is and the team assigned to it. There is no shareable file URL to leak. The download of a final deliverable unlocks on full payment, which is a contractual term rather than a security one — see terms §4.7.
Who can see your project
The mentor, writer and statistician assigned to your project, and the small number of people who operate the platform and support your account. Nobody else, and no other student.
If something goes wrong
If a breach affects your personal data we will tell you, and we will notify the Data Protection Board of India, as the Act requires. We will tell you what happened, what data was involved and what we have done, in writing.
No security statement is a guarantee. What we undertake is to hold the controls above and to tell you promptly if they fail.
Sharing
Sharing
Part V
Who else is involved, cookies, and how long we keep things
Processors
We use a small number of service providers to run the platform: our hosting and database provider, Supabase, in the Mumbai region; a payment gateway, which handles card and bank credentials so that we never hold them; and the email service through which we correspond with you. Each receives only the data it needs to perform its function, and none is permitted to use it for its own purposes.
Disclosure required by law
We disclose personal data where the law of India requires it, or where a court or a statutory authority lawfully directs us to. Where we are permitted to tell you that such a request was made, we will.
Cookies
A session cookie for authentication, and a preference cookie that remembers the currency you chose. There are no third-party advertising cookies on this site, and no cross-site tracking.
Retention
We keep your account record and project history for as long as your account is open, because the dated record is part of what you paid for. Research datasets follow clause 3.4. Payment records are kept for as long as tax and accounting law requires them to be kept.
A category-by-category retention schedule is not yet published. Until it is, a request to info@mdthesis.com will tell you exactly what we hold about you and for how long.
Your rights
Your rights
Part VI
Your rights, and exactly how to use them
One address, a reply you can hold us to, and an escalation route that does not end with us.
Access, correction and deletion
Write to info@mdthesis.com from your registered email address and say what you want: a copy of what we hold, a correction to something inaccurate, or erasure of your data. We may ask one or two questions to be satisfied that the request is really yours. We acknowledge within one working day and tell you then what we will do and by when. Erasure that would break a statutory record we are obliged to keep is explained rather than refused silently.
Withdrawing consent, and nomination
Where we rely on your consent you may withdraw it, and we will stop that processing. Withdrawing consent for processing that the service itself depends on will end the service, and the refund position is then the one in the refund policy. The Act also lets you nominate another person to exercise your rights if you are unable to exercise them yourself.
Complaints
If our answer does not satisfy you, write again and mark it a grievance. We reply in writing with what we found and what we are doing about it. If you are still not satisfied, you may take the matter to the Data Protection Board of India. Nothing in this policy asks you to keep a complaint between us.
Users outside India
Where you are in the United Kingdom or the European Economic Area, we apply the GDPR principles of purpose limitation and data minimisation to the same data, and we honour your rights of access, rectification, erasure and portability through the route in clause 6.1. Your data is processed in India, and by engaging us you are asking us to process it there.
Changes to this policy
The revision number and the date of the last review are printed at the foot of this page. Where a change materially reduces a protection stated here, it applies from the date of that revision and not retrospectively to data already collected under an earlier one.
Document: Privacy policy · Revision 2 · Last reviewed
Issued by MDThesis, a brand of REDENN Informatics Private Limited