Our commitment
Hospitals, colleges and businesses trust our software with patient, student and customer information. This statement summarises how Yanthra Labs designs its products and runs its operations to meet the laws and standards that apply to them. Specific obligations for each customer are set out in that customer's agreement, including a data processing agreement where required.
Data protection in India
- Digital Personal Data Protection Act, 2023. Our products support consent capture, purpose limitation, access control, correction and erasure requests, and breach reporting, so our customers can meet their obligations as data fiduciaries. We act as a data processor on their instructions.
- Information Technology Act, 2000 and the SPDI Rules. We maintain reasonable security practices and procedures for sensitive personal data.
- Healthcare records. eCare360 and the EMR support ICD-10 coding, structured records and audit trails, and are designed with India's Electronic Health Record standards and the Ayushman Bharat Digital Mission in mind. Any ABDM integration is enabled per customer, subject to applicable approvals.
International data protection
- UK GDPR and EU GDPR. For customers in the United Kingdom and Europe, served from our London office, we offer data processing agreements, support data subject rights and apply appropriate safeguards to cross-border transfers.
- United States. For healthcare customers in the United States, our products are designed to support HIPAA Security Rule safeguards, and we will enter into a Business Associate Agreement where we handle protected health information.
Education regulations
edSolutions360 is designed around the National Education Policy 2020, UGC (Conferment of Autonomous Status) Regulations 2023, and NAAC and NBA accreditation requirements, including outcome-based education and criterion-wise reporting.
Financial and tax compliance
Our products generate GST-compliant invoices and receipts. Yanthra Labs is registered under the Goods and Services Tax regime in India.
Security controls
- Encryption of data at rest (AES-256) and in transit (TLS 1.3)
- Role-based access control with multi-factor authentication
- A complete audit trail of user actions
- Automated backups, disaster recovery and point-in-time restore
- Round-the-clock monitoring and a documented incident response process
- Signed, authenticated integrations between systems
- Deployment on our cloud, a private cloud or the customer's own data centre
Responsible use of AI
Our AI features assist professionals and never replace their judgement. Clinical suggestions, generated documents and extracted decisions are shown for review, can be overridden, and are logged. Customer data is used to deliver the service to that customer and is not used to train models for other customers without written agreement.
Certifications
We follow recognised good practice for information security. We do not claim any certification, such as ISO/IEC 27001 or SOC 2, that we do not hold; any certification we hold is available on request with its certificate and scope. Customers may request our security documentation and, under their agreement, audit our controls.
Reporting a concern
To report a security vulnerability, a suspected data incident or a compliance concern, email corporate@yanthralabs.com with the subject line "Security" or "Compliance". We review every report and respond as quickly as possible.
Contact us
Yanthra Labs Private Limited
Block 3/3A, Asvini Amaris, 77 Kalasthamman Koil Street, Saidapet, Chennai, Tamil Nadu 600089, India
UK office: 33 Radnor Avenue, Harrow, Middlesex, London HA1 1SB, United Kingdom
Email: corporate@yanthralabs.com (India) · corporateuk@yanthralabs.com (United Kingdom)
CIN: U62013TN2025PTC178429