Skip to content
BookTide by Novatide
  • How it works
  • Features
  • Who it’s for
  • Pricing
  • FAQ
Chat on WhatsApp
Back to BookTide
Legal

Privacy Policy

Last updated: 13 August 2026

What BookTide collects, why we collect it, where it sits, how long we keep it, and how to make us delete it.

Read this first. This is a plain-English policy for a real product, written so a clinic owner can actually read it rather than skip it. It is not legal advice. If your practice is going to rely on anything here — for your own compliance, or in an agreement with someone else — have your own lawyer read it first.

On this page

  • 1. Who we are
  • 2. What this policy covers
  • 3. What we collect
  • 4. Prescriptions: our honest position
  • 5. Why we process it
  • 6. Lawful basis, and who is responsible
  • 7. How messages travel
  • 8. Where the data is stored
  • 9. Who else touches the data
  • 10. How long we keep it
  • 11. Your rights, and how to use them
  • 12. What we never do
  • 13. This website: no cookies, no analytics
  • 14. How we protect the data
  • 15. Children
  • 16. Changes to this policy
  • 17. Contact us

1. Who we are

BookTide is a product of Novatide Consulting. We build and run the software, and we are the company you deal with about anything on this page.

Novatide Consulting
D6, Hub Town, Makarpura Bus Depot, Makarpura,
Vadodara, Gujarat 390010, India
Email: sales@novatideconsulting.com
WhatsApp / phone: +91 77377 38778

Email is the address of record for privacy requests, because it gives both of us a written trail. WhatsApp is fine for a quick question.

2. What this policy covers

Two things, and nothing else:

  • The BookTide assistant that runs on a business’s own WhatsApp number — the conversations it has with that business’s patients and customers, and the bookings dashboard the business uses.
  • This website, booktide.in.

It does not cover what a clinic does with its own records in its own systems, and it does not cover WhatsApp itself, which is run by Meta.

3. What we collect

We kept the list deliberately short. The assistant only needs enough to make and keep an appointment.

From a patient or customer who messages the business

  • The WhatsApp phone number they message from. This is how the assistant replies, and how a reminder reaches the right person.
  • The name they give in the chat. Whatever they type is what we store — we do not verify it.
  • The appointment details they choose: date, time slot, the doctor or service, the location, and a booking ID such as BT-4821.
  • The content of their messages with the assistant, and the assistant’s replies. That is the transcript of the conversation, including which reply buttons they tapped and the language they chose.

From the business that subscribes

  • Account and contact details: business name, the owner or manager’s name, email, phone.
  • Configuration you give us so the assistant can answer correctly: opening hours, consultation fees, address, doctor or staff names and their slots, holiday closures, the languages you want enabled.
  • The identifiers for your own WhatsApp Business account and number.
  • Billing details: what you owe, what you have paid, and your GST number if you give us one.

What we do not collect

  • No identity documents. No Aadhaar, PAN, passport or driving licence.
  • No payment card numbers, UPI PINs, bank credentials or card details of any kind. We never ask a patient to pay through the assistant. (Payments via UPI is a feature we have marked coming soon on our website; when it exists we will update this policy before it goes live, and payment credentials will still go to the payment provider, never to us.)
  • No clinical records — no diagnosis, no test results, no case history. The one exception is described in the next section.
  • No location tracking, no contact-list access, no device fingerprinting, no microphone or camera access. The assistant is a chat on a number, nothing more.

4. Prescriptions: our honest position

After a visit, a clinic can have BookTide deliver the doctor’s prescription to that patient as a PDF, on the patient’s own WhatsApp number.

Here is exactly what that means. The prescription is written and issued by the clinic. BookTide generates the PDF from what the clinic enters and sends it to the number attached to that booking. The file passes through our system so it can be delivered, and is stored so the clinic can re-send it if the patient loses it.

Novatide does not read, interpret, summarise or act on the contents of a prescription. We do not analyse medicines, we do not build a health profile from them, we do not use them to train anything, and we never give medical advice. If something in a prescription is wrong, that is between the patient and the clinician who wrote it — we are the delivery mechanism, and nothing more.

5. Why we process it

Every purpose below is something the business asked us to do on its behalf:

  • To take a booking: understand what the person is asking for, offer real free slots, and confirm the appointment.
  • To send reminders before the visit, so fewer people forget and fewer slots are wasted.
  • To deliver the prescription PDF the clinic issues after the visit.
  • To invite the patient back for a follow-up, and to check in when a medicine course is due to end — where the business has turned that on.
  • To answer common questions around the clock: fees, timings, address, what to bring.
  • To show the business its bookings dashboard, and simple counts of bookings, reminders and no-shows.
  • To run and fix the service: logs, error diagnosis, and support when a business tells us something went wrong.
  • To bill the business and keep the tax records we are required to keep.

We do not use anyone’s data for anything not on this list.

6. Lawful basis, and who is responsible

India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) splits the roles, and it matters who is who.

  • The business is the Data Fiduciary for its patients’ and customers’ data. It decides why the data is collected and what happens to it. It is also the one that must have the person’s consent to message them.
  • Novatide is the Data Processor. We handle that data only on the business’s written instructions, under our contract with them, and for the purposes listed above.
  • For the business’s own account data — the subscriber’s name, email, phone, configuration and billing — Novatide is the Data Fiduciary, because that is our own customer relationship.

The lawful basis for patient data is consent, given to the business. In practice consent is clear: a person picks up their own phone and messages the clinic’s number. Before the assistant does anything else it tells them who they are talking to and what it can do. For reminders and follow-ups sent by the business, the business is responsible for having that consent, and for honouring it when someone withdraws it. Anyone can stop the messages at any time by telling the assistant to stop, by replying STOP, or by blocking the number in WhatsApp — and we act on that.

7. How messages travel

BookTide runs on the business’s own WhatsApp number using the official WhatsApp Business Platform (the Meta Cloud API). That is a plain fact about the plumbing, and it has a plain consequence: messages between a patient and the business pass through Meta’s systems, and are therefore also subject to WhatsApp’s own terms and privacy policy, which we neither control nor can change.

The business’s WhatsApp Business account belongs to the business, not to us. Novatide is not affiliated with, partnered with, endorsed by or certified by Meta Platforms, Inc. We are simply a developer using a public platform, the same as thousands of others.

8. Where the data is stored

BookTide’s application servers and databases are hosted in India. Bookings, chat transcripts, prescription PDFs and account records are stored there. Ask us and we will confirm the current hosting region for your account, in writing.

Two honest caveats. Message delivery itself runs through the WhatsApp Business Platform, whose infrastructure is Meta’s and is not confined to India. And the AI model that reads an incoming message to work out what the person wants may be hosted outside India — see the next section.

9. Who else touches the data

We use a small number of suppliers. In general terms:

  • A cloud hosting provider in India, which runs the machines the application and database sit on.
  • The WhatsApp Business Platform (Meta Cloud API), which carries the messages to and from WhatsApp.
  • An AI language-model provider, which the assistant calls to understand what an incoming message means and to phrase a natural reply. It receives the conversation text needed for that turn of the conversation. It does not receive your billing data, and it is not used to interpret prescriptions.

Each is bound by its contract with us to handle the data only for the service it provides. We choose providers whose business terms prohibit using customer content for their own purposes, including training their own models. We are a small company and we will not pretend to a longer list than we have: ask us and we will tell you exactly who our current providers are. We do not add a supplier that touches personal data without updating this page.

10. How long we keep it

We keep data while the business is a customer, and only as long as it is useful. Our defaults:

  • Booking records (name, number, appointment details, booking ID): 12 months after the appointment date. This is what lets a clinic see a returning patient’s history and lets us resolve a billing or no-show dispute.
  • Chat transcripts: 90 days. They exist so a conversation makes sense and so we can debug a complaint about what the assistant said.
  • Prescription PDFs: stored with the booking, on the same 12-month clock, so the clinic can re-send one.
  • Business account and configuration data: for as long as you are a customer, then 90 days after the subscription ends, then deleted.
  • Invoices and payment records: for as long as Indian tax law requires us to keep our books. These are our financial records and are kept separately from patient data.
  • Server and error logs: a short operational window, typically a few weeks.

A business can ask for shorter. If you want transcripts held for 30 days, or bookings purged at 6 months, tell us and we will set it for your account. We will not, however, set a retention period so short that we cannot meet a legal obligation or resolve a dispute.

When a period expires, or when you ask us to delete, the record is removed from our live systems. Encrypted backups roll off on their own cycle within 30 days, after which it is gone from there too.

11. Your rights, and how to use them

Under the DPDP Act you can ask us to:

  • Access — tell you what data of yours we hold and who we have shared it with.
  • Correct — fix anything wrong, complete anything missing, update anything stale.
  • Erase — delete your data, where we are not required by law to keep it.
  • Withdraw consent — stop the messages, as easily as they started.
  • Nominate — name someone who can exercise these rights for you if you die or become incapable of doing so yourself.
  • Complain — raise a grievance and have it answered.

To use any of them, email sales@novatideconsulting.com from the address or about the number concerned. Say what you want and give us enough to find you — the phone number you messaged from, and the business you booked with.

Our response times: we acknowledge within 7 working days and complete the request within 30 days. If a request is complicated we will tell you why and give you a date, rather than go quiet.

One thing to be clear about: if you are a patient, the clinic is the Data Fiduciary for your booking. We will always help, but for a deletion request we may need to confirm it with the clinic whose records they are, and we will tell you when we do. If you are the business, come straight to us.

Grievance redressal

Send grievances to sales@novatideconsulting.com with “Privacy grievance” in the subject line. It reaches the person at Novatide responsible for data protection. If you are not satisfied with how we handle it, you can escalate to the Data Protection Board of India. We would rather you gave us the chance to fix it first.

12. What we never do

  • We do not sell personal data. Not to anyone, at any price.
  • We do not rent, broker or share contact lists.
  • We do not use a patient’s number or conversation for advertising, and we do not build advertising or marketing profiles.
  • We do not use one business’s data to help another business. Every account is separate.
  • We do not message a business’s patients on our own behalf, ever. Messages go out because the business configured them.
  • We do not put third-party trackers or advertising pixels anywhere — not on the website, not in the product.

We will disclose data if a court or a law enforcement authority lawfully requires it. If that happens and we are permitted to tell the affected business, we will.

13. This website: no cookies, no analytics

booktide.in sets no cookies at all. There is no Google Analytics, no tag manager, no advertising pixel, no heat-mapping, no session recording, no A/B testing tool, no embedded map and no third-party chat widget.

The page loads one stylesheet, one small script and a few images, every one of them from this domain. Nothing on this page makes a request to another company’s server. That is why you never saw a cookie banner — there is genuinely nothing to consent to.

Our hosting provider keeps ordinary server access logs (IP address, page requested, timestamp, browser type) for security and troubleshooting, for a short period. We do not use them to build a profile of you.

The WhatsApp buttons on this site are ordinary links. Nothing happens until you tap one, and then you are in WhatsApp, on Meta’s terms, not ours.

14. How we protect the data

Stated honestly, without the usual padding:

  • Encryption in transit. Every connection — the website, the dashboard, our API calls — runs over HTTPS/TLS.
  • Access control. Only the few Novatide staff who need access to run and support the service have it. Individual logins, no shared accounts.
  • Least privilege. People and services get the narrowest access that lets them do the job, and access is removed when the reason for it ends.
  • Separation. Each business’s data is logically separated. We do not mix accounts.
  • Backups are encrypted, and expire on a schedule.
  • Patching. Servers and dependencies are kept current.

What we will not claim: we do not hold ISO 27001, SOC 2, HIPAA or any other certification, and we will not imply we do. No system is perfect. If personal data we hold is ever breached, we will notify the affected businesses and the Data Protection Board of India as the DPDP Act requires, promptly and in plain language.

15. Children

BookTide is sold to businesses, and we do not knowingly deal directly with anyone under 18. A child’s appointment is booked by an adult on the child’s behalf, from that adult’s own WhatsApp number, and the details we hold are the ones that adult chose to give. We do not profile children, track them, or send them marketing of any kind. If you believe a child has messaged the assistant directly, tell us and we will delete the conversation.

16. Changes to this policy

When we change this policy we update the Last updated date at the top, and the current version always lives at booktide.in/privacy.html.

If a change is material — a new category of data, a new purpose, a new supplier that touches personal data, or a shorter or longer retention period — we email every subscribing business at least 14 days before it takes effect, and say what changed in one paragraph at the top. We will not make a material change quietly and hope nobody reads it.

17. Contact us

Questions, requests, corrections, complaints — one address for all of them:

  • Email: sales@novatideconsulting.com
  • WhatsApp / phone: +91 77377 38778 (opens WhatsApp)
  • Post: Novatide Consulting, D6, Hub Town, Makarpura Bus Depot, Makarpura, Vadodara, Gujarat 390010, India

A human answers. Usually the same day.

Read the Terms of Service Back to BookTide

BookTide

The WhatsApp booking assistant for clinics and small businesses.

A product by Novatide Consulting

Product

  • How it works
  • Features
  • Pricing
  • FAQ
  • Service centres

Company

  • About Novatide
  • Privacy Policy
  • Terms of Service

Talk to us

  • WhatsApp / phone: +91 77377 38778 (opens WhatsApp)
  • Email: sales@novatideconsulting.com

Message us on WhatsApp and a human will reply — we will show you the assistant working on your own phone.

BookTide is a product of Novatide Consulting, D6, Hub Town, Makarpura Bus Depot, Makarpura, Vadodara, Gujarat 390010, India. © 2026 Novatide Consulting. All rights reserved.

Built on the official WhatsApp Business Platform. Not affiliated with or endorsed by Meta Platforms, Inc.