Trust & compliance

Compliant by design — ABDM, DPDP and EHR Standards 2016.

Chartos is built for India's digital‑health framework from the ground up: consent‑based ABDM exchange, coded NRCES FHIR records, a named data‑protection contact, and every byte of patient data resident in India.

Who operates Chartos

A real, accountable Indian health‑tech operation.

Chartos is a clinical operating system for hospitals and clinics in India. We name a responsible person for data protection and grievances — you always know who to reach.

Operating entity

Chartos

Chartos is currently operated by its founder in India; a Private Limited company (Chartos) is being incorporated in India. On incorporation, the registered company name, CIN and registered office address will be published here.

  • Based in Eluru, Andhra Pradesh, India
  • Operations, data, logs & backups resident in India
  • Registered office address available on request
Grievance & Data Protection Officer

Sasank Varma Sagi

Founder & Data Protection Officer. Responsible for privacy, grievance redressal and data‑protection requests under the DPDP Act, 2023.

  • Email grievance@chartos.in
  • Grievances acknowledged promptly, resolved within DPDP timelines (up to 90 days)
  • General contact hello@chartos.in

Our ABDM posture — HIP and HIU

Chartos is built to the Ayushman Bharat Digital Mission (ABDM). We are integrating as both a Health Information Provider (HIP) — publishing care records so a patient can link them to their ABHA — and a Health Information User (HIU) — requesting records from other facilities, only against a valid ABDM consent artefact. ABHA is created or verified at registration with the patient's explicit consent. We describe our product as ABDM‑compliant and sandbox‑ready; we do not claim ABDM/NHA certification we do not yet hold, and we do not display the ABDM or NHA emblem.

Data protection — DPDP Act, 2023

For a patient's health records, the clinic or hospital is the Data Fiduciary and Chartos acts as a Data Processor, processing only on the clinic's documented instruction. For our own account and enquiry data, Chartos is the Data Fiduciary. We process on the basis of the consent obtained by the clinic and, for ABDM sharing, the patient's ABDM consent artefact. We do not use patient data for advertising and we never sell personal data.

Patient consent notice

In plain terms: your clinic collects your demographics, ABHA identifiers, clinical notes, prescriptions, lab results, appointments and billing to provide your care. Your records are shared with another facility or app only when you grant consent through ABDM, for a specific purpose and time — and you may withdraw that consent at any time, after which further sharing under it stops. You can access or correct your records, or raise a grievance, through your clinic (the Data Fiduciary) or by contacting our Data Protection Officer above. The full detail is in our Privacy Policy.

Breach notification

In the event of a personal‑data breach, we will notify the affected individuals and the Data Protection Board of India without undue delay, in line with the DPDP Act, 2023 and its Rules. Clinics are informed promptly so they can meet their own obligations as Data Fiduciary.

Security & residency

Hospital‑grade security. India‑resident, always.

The same controls that pass an EHR‑standards and ABDM security review — applied from day one.

01

Encryption

TLS in transit and encryption at rest for all patient data.

02

Access control

Role‑based access, least‑privilege services, and staff MFA.

03

Tenant isolation

One isolated data project per clinic — strict cross‑tenant separation.

04

Audit trail

ISO 27789 audit on every access and change to a record.

05

Immutable records

Corrections create a new version — never an in‑place edit or delete.

06

India residency

Records, logs, analytics, backups and AI inference all stay in India.

07

DPO & grievance

A named Data Protection Officer and a published grievance route.

08

No data sale

Patient data is never sold and never used for advertising.

Standards we build to
ABDM HIP · HIU EHR Standards 2016 DPDP Act 2023 NRCES FHIR R4 SNOMED CT LOINC labs CDCI drugs ISO 27789 audit

See the full interoperability story on our Standards page.

Policies & frameworks we follow

We build to India's official digital‑health and data‑protection frameworks:

Questions about compliance or data protection?

Talk to us about your clinic's ABDM, DPDP and EHR‑standards obligations — and how Chartos meets them.