DrRemedy — Privacy Policy
Last updated: 14 July 2026 Effective date: [EFFECTIVE DATE]
This Privacy Policy is published by [COMPANY LEGAL NAME] ("DrRemedy", "we", "us", "our"), a company registered at [REGISTERED ADDRESS, INDIA], in compliance with:
- the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), under which we act as a Data Fiduciary and you are a Data Principal; and
- the Information Technology Act, 2000 (Section 43A) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), under which your medical records and health information are sensitive personal data or information.
It describes what personal data the DrRemedy platform (our website and mobile application, together the "Platform") collects, why we collect it, who can see it, how long we keep it, how we protect it, and the rights you have over it.
If you do not agree with this policy, please do not use the Platform. Providing personal data on the Platform is voluntary; however, certain services (for example, booking an appointment) cannot be provided without the data marked as required.
This notice is available in English. On request, we will make it available in any language listed in the Eighth Schedule to the Constitution of India, as required by the DPDP Act.
1. Who this policy covers
DrRemedy connects patients with healthcare facilities, doctors, pathology labs, and medical stores. This policy applies to:
- Patients — individuals who register to book appointments, manage medical documents, and subscribe to plans;
- Guests — individuals who book an appointment without creating an account;
- Healthcare providers — doctors, pathology labs, and medical store staff whose accounts are created by their facility;
- Facilities — hospitals, clinics, and similar establishments that register on the Platform;
- Visitors — anyone browsing public pages such as doctor and lab directories.
2. Personal data we collect (itemised)
As required by Rule 3 of the DPDP Rules, the following is an itemised description of the personal data we process and the purpose of each item.
2.1 Patients and guests
| Data | Collected when | Required? |
|---|---|---|
| First name, last name | Registration / guest booking / account activation | Required |
| Email address | Registration / guest booking | Required |
| Phone number | Registration / guest booking | Required |
| Password (stored only as a salted cryptographic hash — we can never read it) | Registration | Required |
| Date of birth | Profile / activation / guest booking | Optional |
| Gender | Profile / activation / guest booking | Optional |
| Blood group | Profile / activation / guest booking | Optional |
| Profile picture | Profile (upload) | Optional |
| Medical documents (prescriptions, reports, scans and similar files you or your treating providers upload) | Document upload | Optional |
| Appointment details (provider, date, time, status, any notes you enter) | Booking | Required to book |
| Subscription plan and status | Subscribing to a plan | Required to subscribe |
| Payment references (Razorpay order ID, payment ID, subscription ID, payment signature, amount, payment status) | Online payment | Required for online payment |
| QR identity token (a random identifier shown as your QR code; contains no personal details itself) | Generated automatically | Automatic |
| QR scan records (which facility scanned your QR code and when) | When a provider scans your code | Automatic |
Medical documents, health details (blood group, appointment notes, lab reports) and payment references are sensitive personal data under the SPDI Rules. We treat every one of these items with the heightened protections described in Sections 6 and 8.
2.2 Providers and facilities
| Data | Collected when |
|---|---|
| Name, email, phone, password (hashed) | Account creation by the facility or self-registration |
| Facility name, address, city, description, logo, photos, license number | Facility registration and settings |
| Doctor professional details: specialization, qualifications, medical license number, years of experience, consultation fee, bio, languages, address, photo, weekly availability | Facility onboarding / doctor profile |
| Lab and store details: lab/store name, license number, consultation fee | Facility onboarding |
Provider professional profiles (Section 5.1) are published in our public directory — that is the purpose for which they are collected.
2.3 Technical and security data
| Data | Purpose |
|---|---|
| Login attempt records, including your IP address and account identifier on failed logins | Brute-force protection: 5 failed attempts lock the account/IP for 30 minutes |
| Authentication cookies (see Section 7) | Keeping you signed in securely |
| Request rate metadata | Abuse prevention (rate limiting) |
| Document access records (which lab or store opened which shared document, and when) | Accountability over access to your medical records |
We do not use any third-party analytics, advertising trackers, or marketing pixels on the Platform.
3. Purposes of processing
We process your personal data only for the following specified purposes:
- Creating and operating your account — authentication, session management, profile management.
- Providing healthcare booking services — showing available slots, booking, confirming, and cancelling doctor and lab appointments, and sending booking confirmation emails.
- Managing medical documents — storing documents you upload, letting your treating doctor upload documents to your record, and sharing them with a pathology lab or medical store only in the circumstances set out in Section 5.
- Subscription and payment processing — creating and verifying payments and subscriptions through our payment partner, Razorpay.
- Patient identity verification — allowing a provider to scan your QR code to confirm your name and subscription status at the point of care.
- Communication — service emails only: password reset, booking confirmations, and account invitations. We do not send marketing communications.
- Security and fraud prevention — login protection, rate limiting, access logging, and investigation of misuse.
- Legal compliance — meeting obligations under Indian law, including record-keeping and responding to lawful requests from authorities.
We do not use your personal data for advertising, we do not build behavioural profiles, and we never sell your personal data.
4. Lawful basis
- Consent (Section 6, DPDP Act). By creating an account, booking as a guest, uploading a document, or subscribing to a plan, you consent to the processing described in this notice for the purposes above. Your consent is limited to those purposes.
- Voluntary provision / legitimate uses (Section 7, DPDP Act). Where you voluntarily provide data for a specified purpose (for example, entering appointment notes), we process it for that purpose. We may also process data where required to comply with Indian law, a court order, or in a medical emergency involving a threat to life or immediate health.
- Withdrawal. You may withdraw your consent at any time (Section 9 below). Withdrawing consent is as simple as giving it, and does not affect the lawfulness of processing already carried out. After withdrawal we will stop the related processing and delete the related data unless a law requires us to retain it.
5. Who can see your data
Access on DrRemedy is deliberately narrow and role-based:
5.1 Within the Platform
- Your treating doctor can see your name, contact details, and medical documents only after you have had at least one appointment with them. Doctors cannot browse patients they do not treat.
- A pathology lab can see your details and only those documents that (a) were uploaded by a doctor, (b) belong to the same facility, and (c) were explicitly marked as shared with the lab — and only if you have a booking with that lab.
- A medical store in your facility's network can see documents only under the same explicit-sharing controls.
- Your facility (the hospital/clinic you book with) can see the appointments you have booked with its providers, including your name and phone number, in order to run its schedule.
- QR scans reveal only three things to the scanning provider: your full name, your subscription plan name, and whether it is active. Nothing else. Every scan is logged. You can regenerate (rotate) your QR token at any time from your dashboard, which immediately invalidates the old code.
- Public directory: doctor, lab, and facility professional profiles (name, specialization, qualifications, license number, fees, photos, ratings and reviews) are visible to all visitors. Patient data is never public.
5.2 Data processors (third parties working for us)
We share personal data with the following processors, each bound by contract to process it only on our instructions with appropriate security safeguards, as required by the DPDP Rules:
| Processor | What they receive | Why |
|---|---|---|
| Razorpay Software Pvt. Ltd. | Name, email, phone, payment details entered at checkout | Payment and subscription processing. Card/UPI credentials are entered directly with Razorpay and never touch or get stored on our servers. Razorpay is PCI-DSS compliant and processes payments under its own privacy policy: https://razorpay.com/privacy/ |
| Cloud infrastructure and storage provider ([HOSTING PROVIDER], [STORAGE PROVIDER — e.g. AWS S3 / Cloudflare R2]) | Encrypted platform data and uploaded files | Hosting the Platform and storing files. Medical documents are held in a private bucket with no public access; every download is authenticated and authorised by our servers first. |
| Email delivery provider ([EMAIL PROVIDER]) | Your email address and the content of service emails | Delivering password resets, booking confirmations, and invitations. |
5.3 Other disclosures
We may disclose personal data if required by Indian law — for example, to a court, the Data Protection Board of India, CERT-In, or law enforcement acting under lawful authority — or to protect the safety of a patient in a medical emergency. If DrRemedy undergoes a merger, acquisition, or asset sale, personal data may be transferred to the successor entity, which will remain bound by this policy or one no less protective; we will notify you of any such change.
We do not otherwise disclose, publish, or sell your personal data, and we obtain your consent before any disclosure of sensitive personal data not described in this policy, as required by Rule 6 of the SPDI Rules.
6. Where your data is stored and cross-border transfers
Your data is stored on servers located in [SERVER LOCATION(S)]. If any data is stored or processed outside India, we do so only as permitted under Section 16 of the DPDP Act and the DPDP Rules, and never to any country restricted by the Central Government. Regardless of location, all data remains protected under this policy and Indian law.
7. Cookies and local storage
We use no advertising, analytics, or third-party cookies. The Platform sets only what is strictly necessary to keep you signed in:
| Item | Type | Lifetime | Purpose |
|---|---|---|---|
access_token | httpOnly cookie | 15 minutes | Authenticates your requests. Inaccessible to scripts, mitigating token theft. |
refresh_token | httpOnly cookie | 7 days | Silently renews your session. Invalidated (blacklisted) the moment you log out. |
| CSRF token | Cookie | Session | Protects forms against cross-site request forgery. |
role | Browser localStorage | Until logout | Remembers which dashboard (patient/doctor/etc.) to show. Contains no personal details. |
Logging out clears all of the above.
8. How we protect your data (reasonable security practices)
As required by Section 8(5) of the DPDP Act, Rule 6 of the DPDP Rules, and Rule 8 of the SPDI Rules, we maintain reasonable security safeguards, including:
- Encryption in transit — all traffic to the Platform is served over HTTPS/TLS.
- Password hashing — passwords are stored only as salted hashes using Django's audited password hasher; they are never stored or logged in plain text.
- httpOnly, secure session cookies — authentication tokens are not readable by page scripts; refresh tokens are blacklisted on logout.
- Private medical document storage — uploaded files are stored in private storage with no public URLs; every view is streamed through our server only after the requester's identity and authorisation are verified, with hardened response headers.
- Strict role-based access control — the access rules in Section 5.1 are enforced server-side on every request; unauthorized lookups return "not found" so that even the existence of a record is not leaked.
- Upload validation — file type and content checks on every uploaded document and image.
- Brute-force and abuse protection — login lockouts (5 failures / 30 minutes), per-endpoint rate limits, and webhook signature verification (HMAC) for payment events.
- Access logging — QR scans and document opens by labs/stores are logged for accountability.
- Rotating patient QR tokens — you can invalidate and reissue your QR identity code at any time.
No system is perfectly secure, but we review these controls regularly and update them as threats evolve.
9. Your rights
Under the DPDP Act you have the right to:
- Access (Section 11) — obtain a summary of the personal data we hold about you, the processing activities performed on it, and the identities of everyone it has been shared with. Download a complete copy of your data (all appointments, documents, subscription records, and QR scan history) anytime via the "Download my data" button on your Profile page. For a full legal summary, contact our Grievance Officer.
- Correction and erasure (Section 12) — correct inaccurate or incomplete data (self-service via your Profile page for name, phone, email, date of birth, and similar fields) and request erasure of data no longer needed for the purpose it was collected for. Delete your account permanently via the "Delete my account" button on your Profile page, or by contacting the Grievance Officer.
- Withdraw consent — at any time, with effect for the future, by deleting specific documents, cancelling your subscription, or deleting your account.
- Grievance redressal (Section 13) — raise a complaint with our Grievance Officer (Section 13 of this policy) and receive a response within the timelines below.
- Nominate (Section 14) — nominate another individual to exercise your rights in the event of your death or incapacity. To register a nomination, contact the Grievance Officer.
To exercise any right, use the in-app controls where available or write to the Grievance Officer with your registered email address so we can verify it is really you. We respond to all requests within 30 days, and resolve grievances within the period prescribed under the DPDP Rules (no later than 90 days).
If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Board of India (https://www.dpb.gov.in [VERIFY URL ONCE BOARD PORTAL IS LIVE]).
Duties: the DPDP Act also requires you not to impersonate another person, suppress material information, or file false complaints.
10. Data retention and erasure
We keep personal data only as long as needed for the purpose it was collected, after which it is erased:
| Data | Retention |
|---|---|
| Account and profile data | Life of your account; erased immediately on request |
| Medical documents and appointment records | Retained for a minimum of 3 years in line with Indian medical record-keeping norms (and any longer period required by applicable clinical regulations), then erased. Patient-uploaded documents can be deleted by you at any time. |
| Payment and subscription records | 8 years, as required by Indian tax and accounting law |
| Guest booking contact details | 6 months after the appointment, unless you activate an account |
| Security logs (login attempts, IP addresses, QR scan logs, document access logs) | 1 year, the minimum retention required for processing logs under the DPDP Rules, then erased |
| Password reset tokens | Minutes — single use, short expiry |
Inactive accounts. If you do not use your account — log in, book an appointment, or exercise any of your rights — for 3 years, we will treat the purpose of processing as no longer served (Section 8(7), DPDP Act) and erase or irreversibly anonymise your account data, except records we must keep under the medical-records, tax, and log-retention rules above. We will email you at least 48 hours before this happens so you can keep your account simply by logging in.
Where the DPDP Rules require it, we will notify you at least 48 hours before scheduled erasure of your data so you can retain access if you wish. When you request account deletion, we erase or irreversibly anonymise your data and instruct our processors to do the same, except where a law listed above requires continued retention.
11. Children
DrRemedy accounts are intended for users aged 18 or over. If a patient is under 18, the account must be created and operated by a parent or lawful guardian, and we process the child's data with the guardian's verifiable consent as required by Section 9 of the DPDP Act and the DPDP Rules — limited strictly to providing health services to the child. We do not use children's data for tracking, behavioural monitoring, or advertising of any kind (nor anyone else's — see Section 3). If you believe a child's data was provided without guardian consent, contact the Grievance Officer and we will delete it.
12. Data breach notification
In the unlikely event of a personal data breach, we will, as required by the DPDP Act and DPDP Rules:
- notify the Data Protection Board of India without delay, with a detailed report within 72 hours;
- notify you, without delay, in plain language: what happened, what data was affected, the likely consequences, the measures we have taken, and what you can do to protect yourself, with a contact point for questions; and
- report cybersecurity incidents to CERT-In within the timelines under the IT Act where applicable.
13. Grievance Officer and contact
In accordance with the DPDP Act, the DPDP Rules, and Rule 5(9) of the SPDI Rules:
Grievance / Data Protection Officer: [FULL NAME] [COMPANY LEGAL NAME] [REGISTERED ADDRESS] Email: [privacy@drremedy.example] Phone: [+91-XXXXXXXXXX] Hours: Monday–Friday, 9:00–18:00 IST
Acknowledgement within [48 hours]; resolution within the timelines in Section 9. Please write from your registered email address and describe your request or grievance in reasonable detail.
14. Changes to this policy
We may update this policy as the Platform or the law changes. The "Last updated" date at the top will change, and for material changes we will notify you by email or an in-app notice before they take effect. Continued use of the Platform after the effective date constitutes acceptance of the updated policy; where the law requires fresh consent, we will ask for it.
15. Governing law
This policy is governed by the laws of India. Subject to the jurisdiction of the Data Protection Board of India and other competent authorities, the courts at [CITY], India shall have jurisdiction over disputes arising from this policy.
This document was prepared with reference to the Digital Personal Data Protection Act, 2023; the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025); the Information Technology Act, 2000; and the SPDI Rules, 2011. It is a template grounded in DrRemedy's actual data flows and should be reviewed by a qualified Indian lawyer before publication.