RSX Hospital | Master AI Governance & Privacy Mandate

MASTER DATA PRIVACY &
AI GOVERNANCE MANDATE

RSX Hospital Global Network

DOC REF: RSX-LEGAL-2026-X1
STATUS: BINDING
JURISDICTION: INDIA (DPDP 2023)
SECURITY: ISO 27001

ARTICLE I: PREAMBLE & BINDING AGREEMENT

1.1 Electronic Record & Validity

This document constitutes an “Electronic Record” under the provisions of the Information Technology Act, 2000 and the Digital Personal Data Protection (DPDP) Act, 2023. This Policy governs the relationship between RSX Hospital (hereinafter “Data Fiduciary”) and the Patient/User (hereinafter “Data Principal”). This Policy requires no physical or digital signature to be legally binding. Accessing the RSX Platform, entering an RSX Facility, or initiating an AI Consultation constitutes absolute acceptance.

1.2 Nature of Services (AI-First)

You explicitly acknowledge that RSX Hospital is a technology-first, AI-driven healthcare entity. A significant majority of diagnostic triage, pathology analysis, radiological interpretation, and patient monitoring is performed by autonomous Artificial Intelligence agents, Neural Networks, and Deep Learning algorithms with minimal human intervention.

ARTICLE II: EXTENSIVE LEGAL DEFINITIONS

For the purpose of this Policy, the following terms shall have specific legal meanings:

2.1“AI Doctor / Virtual Agent”

Refers to RSX’s proprietary Large Language Models (LLMs) and Generative Pre-trained Transformers fine-tuned on medical datasets to simulate clinical interaction, history taking, and differential diagnosis.

2.2“Biometric & Body Scan Data”

Refers to high-fidelity physiological data captured via RSX Scanning Modules, including 3D facial mesh points, retinal vascular patterns, thermal maps, gait analysis, and photoplethysmography (PPG) signals extracted from video feeds.

2.3“Inferred Health Data”

New data points generated solely by Algorithms based on raw inputs. (e.g., A “Cardiac Risk Score” calculated from voice tremors, which was not explicitly provided by the User but inferred by the System).

2.4“Human-in-the-Loop (HITL)”

The protocol wherein a Registered Medical Practitioner (RMP) reviews AI-generated critical alerts. Note: HITL is not guaranteed for non-critical, general wellness queries.

ARTICLE III: THE AI INFRASTRUCTURE MANDATE

LEGAL NOTICE: The following technologies are deployed automatically. Your usage of RSX services implies consent to being subjected to these automated analysis tools.
3.1AI Powered Diagnostics & Pathology

RSX employs Convolutional Neural Networks (CNNs) to analyze:

3.2AI Powered Body Scanning (DeepScan™)

When authorized, the RSX App/Terminal utilizes device sensors to perform:

ARTICLE IV: AUTOMATED DATA COLLECTION

RSX operates a “Total-Data” ecosystem. We collect:

4.1Voluntary Direct Input

Information explicitly provided: Name, Age, Gender, Aadhaar Number (KYC), Insurance Policy Details, Current Symptoms, Past Medical History.

4.2Passive Telemetry

Background data collection for safety and diagnostics:

ARTICLE V: PURPOSE OF PROCESSING

5.1Primary Healthcare Delivery

Processing is necessary to generate AI Diagnosis, issue e-Prescriptions, and formulate treatment plans.

5.2Algorithmic Training (RLHF)

CRITICAL CLAUSE: You grant RSX a perpetual, irrevocable, worldwide, royalty-free license to use De-identified (Anonymized) data derived from your interactions to train, fine-tune, and improve our AI Models. This data is stripped of PII (Personally Identifiable Information) and cannot be traced back to you. This is a legitimate business interest for the advancement of medical science.

5.3Public Health Compliance

To report Notifiable Diseases (e.g., TB, HIV) to government authorities (ICMR/NCDC) as mandated by Indian Law.

ARTICLE VI: DPDP ACT COMPLIANCE & RIGHTS

6.1Consent Architecture

Consent is obtained via a “Consent Manager” framework. It is Free, Specific, Informed, Unconditional, and Unambiguous. You may manage consent granularly via the RSX App Settings.

6.2Rights of the Data Principal
6.3Data Localization

All Sensitive Personal Data of Indian citizens is stored exclusively on servers located within the territory of India (MeitY Empaneled Cloud Providers). Cross-border transfer occurs only for specific “International Second Opinions” initiated by the User.

ARTICLE VII: LIABILITY, INDEMNITY & ETHICS

STRICT LIABILITY WAIVER: READ CAREFULLY
7.1Probabilistic Nature of AI

You acknowledge that Medicine is an art of probability, and AI is a statistical tool. RSX AI provides a likelihood of diagnosis, not a certainty. RSX Hospital is NOT LIABLE for errors arising from AI “Hallucinations” (statistical anomalies) if the User fails to consult a Human RMP for critical conditions.

7.2User Responsibility

RSX is not liable for incorrect diagnoses resulting from: (a) False data input by the User; (b) Poor quality of uploaded images/scans; (c) Concealment of medical history.

7.3Force Majeure

RSX shall not be held responsible for data breaches caused by state-sponsored cyber-attacks, Acts of God, or infrastructure failure beyond reasonable control, provided standard ISO 27001 security protocols were in place.

ARTICLE VIII: GRIEVANCE REDRESSAL

In accordance with the DPDP Act 2023, RSX Hospital has appointed a Data Protection Officer (DPO).

OFFICIAL CONTACT

For Legal Notices, DPDP Access Requests, and Grievances:

Support@rsxhospital.in
RESPONSE SLA: 72 HOURS
ESCALATION AUTHORITY: DATA PROTECTION BOARD OF INDIA

END OF LEGAL DOCUMENT.

© 2026 RSX HOSPITAL. ALL RIGHTS RESERVED.