DrRemedy — Privacy Policy

Last updated: 14 July 2026 Effective date: [EFFECTIVE DATE]

This Privacy Policy is published by [COMPANY LEGAL NAME] ("DrRemedy", "we", "us", "our"), a company registered at [REGISTERED ADDRESS, INDIA], in compliance with:

It describes what personal data the DrRemedy platform (our website and mobile application, together the "Platform") collects, why we collect it, who can see it, how long we keep it, how we protect it, and the rights you have over it.

If you do not agree with this policy, please do not use the Platform. Providing personal data on the Platform is voluntary; however, certain services (for example, booking an appointment) cannot be provided without the data marked as required.

This notice is available in English. On request, we will make it available in any language listed in the Eighth Schedule to the Constitution of India, as required by the DPDP Act.


1. Who this policy covers

DrRemedy connects patients with healthcare facilities, doctors, pathology labs, and medical stores. This policy applies to:


2. Personal data we collect (itemised)

As required by Rule 3 of the DPDP Rules, the following is an itemised description of the personal data we process and the purpose of each item.

2.1 Patients and guests

DataCollected whenRequired?
First name, last nameRegistration / guest booking / account activationRequired
Email addressRegistration / guest bookingRequired
Phone numberRegistration / guest bookingRequired
Password (stored only as a salted cryptographic hash — we can never read it)RegistrationRequired
Date of birthProfile / activation / guest bookingOptional
GenderProfile / activation / guest bookingOptional
Blood groupProfile / activation / guest bookingOptional
Profile pictureProfile (upload)Optional
Medical documents (prescriptions, reports, scans and similar files you or your treating providers upload)Document uploadOptional
Appointment details (provider, date, time, status, any notes you enter)BookingRequired to book
Subscription plan and statusSubscribing to a planRequired to subscribe
Payment references (Razorpay order ID, payment ID, subscription ID, payment signature, amount, payment status)Online paymentRequired for online payment
QR identity token (a random identifier shown as your QR code; contains no personal details itself)Generated automaticallyAutomatic
QR scan records (which facility scanned your QR code and when)When a provider scans your codeAutomatic

Medical documents, health details (blood group, appointment notes, lab reports) and payment references are sensitive personal data under the SPDI Rules. We treat every one of these items with the heightened protections described in Sections 6 and 8.

2.2 Providers and facilities

DataCollected when
Name, email, phone, password (hashed)Account creation by the facility or self-registration
Facility name, address, city, description, logo, photos, license numberFacility registration and settings
Doctor professional details: specialization, qualifications, medical license number, years of experience, consultation fee, bio, languages, address, photo, weekly availabilityFacility onboarding / doctor profile
Lab and store details: lab/store name, license number, consultation feeFacility onboarding

Provider professional profiles (Section 5.1) are published in our public directory — that is the purpose for which they are collected.

2.3 Technical and security data

DataPurpose
Login attempt records, including your IP address and account identifier on failed loginsBrute-force protection: 5 failed attempts lock the account/IP for 30 minutes
Authentication cookies (see Section 7)Keeping you signed in securely
Request rate metadataAbuse prevention (rate limiting)
Document access records (which lab or store opened which shared document, and when)Accountability over access to your medical records

We do not use any third-party analytics, advertising trackers, or marketing pixels on the Platform.


3. Purposes of processing

We process your personal data only for the following specified purposes:

  1. Creating and operating your account — authentication, session management, profile management.
  2. Providing healthcare booking services — showing available slots, booking, confirming, and cancelling doctor and lab appointments, and sending booking confirmation emails.
  3. Managing medical documents — storing documents you upload, letting your treating doctor upload documents to your record, and sharing them with a pathology lab or medical store only in the circumstances set out in Section 5.
  4. Subscription and payment processing — creating and verifying payments and subscriptions through our payment partner, Razorpay.
  5. Patient identity verification — allowing a provider to scan your QR code to confirm your name and subscription status at the point of care.
  6. Communication — service emails only: password reset, booking confirmations, and account invitations. We do not send marketing communications.
  7. Security and fraud prevention — login protection, rate limiting, access logging, and investigation of misuse.
  8. Legal compliance — meeting obligations under Indian law, including record-keeping and responding to lawful requests from authorities.

We do not use your personal data for advertising, we do not build behavioural profiles, and we never sell your personal data.


4. Lawful basis


5. Who can see your data

Access on DrRemedy is deliberately narrow and role-based:

5.1 Within the Platform

5.2 Data processors (third parties working for us)

We share personal data with the following processors, each bound by contract to process it only on our instructions with appropriate security safeguards, as required by the DPDP Rules:

ProcessorWhat they receiveWhy
Razorpay Software Pvt. Ltd.Name, email, phone, payment details entered at checkoutPayment and subscription processing. Card/UPI credentials are entered directly with Razorpay and never touch or get stored on our servers. Razorpay is PCI-DSS compliant and processes payments under its own privacy policy: https://razorpay.com/privacy/
Cloud infrastructure and storage provider ([HOSTING PROVIDER], [STORAGE PROVIDER — e.g. AWS S3 / Cloudflare R2])Encrypted platform data and uploaded filesHosting the Platform and storing files. Medical documents are held in a private bucket with no public access; every download is authenticated and authorised by our servers first.
Email delivery provider ([EMAIL PROVIDER])Your email address and the content of service emailsDelivering password resets, booking confirmations, and invitations.

5.3 Other disclosures

We may disclose personal data if required by Indian law — for example, to a court, the Data Protection Board of India, CERT-In, or law enforcement acting under lawful authority — or to protect the safety of a patient in a medical emergency. If DrRemedy undergoes a merger, acquisition, or asset sale, personal data may be transferred to the successor entity, which will remain bound by this policy or one no less protective; we will notify you of any such change.

We do not otherwise disclose, publish, or sell your personal data, and we obtain your consent before any disclosure of sensitive personal data not described in this policy, as required by Rule 6 of the SPDI Rules.


6. Where your data is stored and cross-border transfers

Your data is stored on servers located in [SERVER LOCATION(S)]. If any data is stored or processed outside India, we do so only as permitted under Section 16 of the DPDP Act and the DPDP Rules, and never to any country restricted by the Central Government. Regardless of location, all data remains protected under this policy and Indian law.


7. Cookies and local storage

We use no advertising, analytics, or third-party cookies. The Platform sets only what is strictly necessary to keep you signed in:

ItemTypeLifetimePurpose
access_tokenhttpOnly cookie15 minutesAuthenticates your requests. Inaccessible to scripts, mitigating token theft.
refresh_tokenhttpOnly cookie7 daysSilently renews your session. Invalidated (blacklisted) the moment you log out.
CSRF tokenCookieSessionProtects forms against cross-site request forgery.
roleBrowser localStorageUntil logoutRemembers which dashboard (patient/doctor/etc.) to show. Contains no personal details.

Logging out clears all of the above.


8. How we protect your data (reasonable security practices)

As required by Section 8(5) of the DPDP Act, Rule 6 of the DPDP Rules, and Rule 8 of the SPDI Rules, we maintain reasonable security safeguards, including:

No system is perfectly secure, but we review these controls regularly and update them as threats evolve.


9. Your rights

Under the DPDP Act you have the right to:

  1. Access (Section 11) — obtain a summary of the personal data we hold about you, the processing activities performed on it, and the identities of everyone it has been shared with. Download a complete copy of your data (all appointments, documents, subscription records, and QR scan history) anytime via the "Download my data" button on your Profile page. For a full legal summary, contact our Grievance Officer.
  2. Correction and erasure (Section 12) — correct inaccurate or incomplete data (self-service via your Profile page for name, phone, email, date of birth, and similar fields) and request erasure of data no longer needed for the purpose it was collected for. Delete your account permanently via the "Delete my account" button on your Profile page, or by contacting the Grievance Officer.
  3. Withdraw consent — at any time, with effect for the future, by deleting specific documents, cancelling your subscription, or deleting your account.
  4. Grievance redressal (Section 13) — raise a complaint with our Grievance Officer (Section 13 of this policy) and receive a response within the timelines below.
  5. Nominate (Section 14) — nominate another individual to exercise your rights in the event of your death or incapacity. To register a nomination, contact the Grievance Officer.

To exercise any right, use the in-app controls where available or write to the Grievance Officer with your registered email address so we can verify it is really you. We respond to all requests within 30 days, and resolve grievances within the period prescribed under the DPDP Rules (no later than 90 days).

If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Board of India (https://www.dpb.gov.in [VERIFY URL ONCE BOARD PORTAL IS LIVE]).

Duties: the DPDP Act also requires you not to impersonate another person, suppress material information, or file false complaints.


10. Data retention and erasure

We keep personal data only as long as needed for the purpose it was collected, after which it is erased:

DataRetention
Account and profile dataLife of your account; erased immediately on request
Medical documents and appointment recordsRetained for a minimum of 3 years in line with Indian medical record-keeping norms (and any longer period required by applicable clinical regulations), then erased. Patient-uploaded documents can be deleted by you at any time.
Payment and subscription records8 years, as required by Indian tax and accounting law
Guest booking contact details6 months after the appointment, unless you activate an account
Security logs (login attempts, IP addresses, QR scan logs, document access logs)1 year, the minimum retention required for processing logs under the DPDP Rules, then erased
Password reset tokensMinutes — single use, short expiry

Inactive accounts. If you do not use your account — log in, book an appointment, or exercise any of your rights — for 3 years, we will treat the purpose of processing as no longer served (Section 8(7), DPDP Act) and erase or irreversibly anonymise your account data, except records we must keep under the medical-records, tax, and log-retention rules above. We will email you at least 48 hours before this happens so you can keep your account simply by logging in.

Where the DPDP Rules require it, we will notify you at least 48 hours before scheduled erasure of your data so you can retain access if you wish. When you request account deletion, we erase or irreversibly anonymise your data and instruct our processors to do the same, except where a law listed above requires continued retention.


11. Children

DrRemedy accounts are intended for users aged 18 or over. If a patient is under 18, the account must be created and operated by a parent or lawful guardian, and we process the child's data with the guardian's verifiable consent as required by Section 9 of the DPDP Act and the DPDP Rules — limited strictly to providing health services to the child. We do not use children's data for tracking, behavioural monitoring, or advertising of any kind (nor anyone else's — see Section 3). If you believe a child's data was provided without guardian consent, contact the Grievance Officer and we will delete it.


12. Data breach notification

In the unlikely event of a personal data breach, we will, as required by the DPDP Act and DPDP Rules:


13. Grievance Officer and contact

In accordance with the DPDP Act, the DPDP Rules, and Rule 5(9) of the SPDI Rules:

Grievance / Data Protection Officer: [FULL NAME] [COMPANY LEGAL NAME] [REGISTERED ADDRESS] Email: [privacy@drremedy.example] Phone: [+91-XXXXXXXXXX] Hours: Monday–Friday, 9:00–18:00 IST

Acknowledgement within [48 hours]; resolution within the timelines in Section 9. Please write from your registered email address and describe your request or grievance in reasonable detail.


14. Changes to this policy

We may update this policy as the Platform or the law changes. The "Last updated" date at the top will change, and for material changes we will notify you by email or an in-app notice before they take effect. Continued use of the Platform after the effective date constitutes acceptance of the updated policy; where the law requires fresh consent, we will ask for it.


15. Governing law

This policy is governed by the laws of India. Subject to the jurisdiction of the Data Protection Board of India and other competent authorities, the courts at [CITY], India shall have jurisdiction over disputes arising from this policy.


This document was prepared with reference to the Digital Personal Data Protection Act, 2023; the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025); the Information Technology Act, 2000; and the SPDI Rules, 2011. It is a template grounded in DrRemedy's actual data flows and should be reviewed by a qualified Indian lawyer before publication.