Privacy Policy
This policy explains how Arogya Pramana Trust Infrastructure Pvt. Ltd. (“Arogya Pramana”, “we”) collects, uses, discloses, retains, and safeguards your personal data — in compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Who we are
Data Fiduciary: Arogya Pramana Trust Infrastructure Pvt. Ltd.
Registered address: Bandra Kurla Complex, Mumbai 400051, India.
Data Protection Officer (Grievance Officer): Dr. Ananya Rao — dpo@arogyapramana.in.
2. Personal data we collect
- Identity: name, email, mobile number, professional registration numbers (for doctors).
- Sensitive personal data: symptoms, diagnoses, prescriptions, lab reports, care journey (patient-supplied).
- Provider data: hospital operational KPIs, incident reports, department benchmarks.
- Technical: session cookies (essential only), device metadata for security.
3. Purpose of processing
We process your data strictly to deliver the Arogya Pramana service — provider discovery, appointment booking, Trust Index publication, HCAHPS-based hospital rating, symptom triage guidance, medical record custody, and platform administration. We do not sell your data. We do not use your data for advertising.
4. Legal basis: your consent
Processing is based on the explicit consent you provide at registration. You may withdraw consent at any time from Privacy & Data in your account. Withdrawal will pause future processing and initiate deletion within 30 days, subject to statutory retention requirements (e.g., medical record retention under the Indian Medical Council).
5. Sharing & disclosure
We share only what you explicitly instruct — for example, sending an appointment request to a chosen doctor. We do not sell, rent, or share personal data with advertisers, brokers, or third-party analytics.
6. Retention
Account & profile data: retained while your account is active, deleted within 30 days of a valid deletion request. Medical records: retained for up to 7 years per Indian medical record practice unless earlier erased on request. Consent logs: retained for the life of the account plus 3 years, for audit.
7. Your DPDP rights
- Right to access — download a complete copy of your data (JSON export).
- Right to correction — edit inaccurate data in-product; or request via DPO.
- Right to erasure — delete your account and personal data.
- Right to withdraw consent — for marketing (in-product); for processing (via account deletion).
- Right to nominate — designate a person to exercise these rights in the event of incapacity.
- Right to grievance redressal — reach our DPO or file via /grievance. SLA: 30 days.
8. Security safeguards
Encrypted transport (TLS), bcrypt-hashed passwords, httpOnly cookies, principle of least privilege, role-based access control, audit logs of consent changes, and periodic security review.
9. Children
Users under 18 require verifiable parental consent. We do not knowingly process a child's data without such consent.
10. Cross-border transfer
Data is primarily processed on infrastructure within India. Any transfer outside India will comply with DPDP Section 16 and applicable restricted-country notifications.
11. Changes to this policy
Material changes are notified in-product 30 days before taking effect, and require re-consent where required by law.