vv1-draftDRAFT — pending counsel review
Privacy Policy
DRAFT — pending counsel review. Do not rely on this as final legal text.
Privacy Policy (Outline)
- Data Fiduciary identity and contact details will be published here.
- Categories of data processed: account details, professional credentials, circle membership, messages, referral metadata, minimal patient-linked data, payment metadata, and device/telemetry data.
- Purposes: operating circles, enabling consented referrals, security, operational-health analytics, and legal obligations.
- Legal basis: consent and legitimate uses as applicable under India's Digital Personal Data Protection Act (DPDP).
- Sharing: limited to payment gateway, hosting, OTP, and verification vendors under data processing agreements. Data is never sold.
- Retention periods will be specified by data tier.
- Rights: access, correction, erasure (subject to legal hold and the medical-record duties of users themselves), grievance redress, and nomination.
- Cross-border processing, if any, will be disclosed here.
- Security measures protecting stored and transmitted data.
- Breach notification approach.
- This service is not intended for use by patients as users in V1; it is not designed to collect children's data.
- This policy is versioned; material changes require re-acceptance.
This outline will be replaced with counsel-reviewed final language before public launch.