Legal

Privacy Notice (DPDP Act, India)

Last updated: 24 July 2026

This notice explains how Remote Health Navigation & Care Coordination ("we", "us") — operated by Nischidha Imaging Services Pvt Ltd, the data fiduciary — collects, uses, shares, and protects the personal data of individuals ("you") in accordance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and applicable rules.

1. Data we collect

  • Identity and contact: name, email, phone, country/city.
  • Health information you provide: medical reports, imaging, prescriptions, history, and case-related communications.
  • Payment metadata: transaction identifiers from our payment processor. We do not store card numbers.
  • Site data: IP-derived approximate location, device/browser, and cookies (see cookies section).

2. Purpose and lawful basis

We process personal data on the basis of your consent, and where necessary to deliver the services you have requested. Purposes include:

  • Providing case review, coordination, and follow-up services.
  • Communicating with you and your family (with your consent).
  • Legal, tax, and audit obligations.
  • Improving our workflows in aggregated, de-identified form.

3. Consent

We obtain your free, specific, informed, and unambiguous consent before processing your data, especially health data. You can withdraw consent at any time by writing to our grievance officer; withdrawal will not affect processing already carried out.

4. Sharing

We share personal data only with:

  • Providers (hospitals, doctors) selected as part of your care plan, with your consent.
  • Sub-processors under contract (secure hosting, payment processing, communications) bound by confidentiality and data-protection obligations.
  • Authorities where required by law.

5. Retention

We retain case data for the period needed to deliver the service and for legally required record-keeping thereafter. You may request deletion; we will comply subject to legal retention obligations.

6. Your rights (DPDP)

  • Right to access and correction of your data.
  • Right to erasure, subject to legal retention.
  • Right to nominate another individual in the event of death or incapacity.
  • Right of grievance redressal — contact our Grievance Officer.

7. Security

We apply reasonable security safeguards including encryption in transit, access controls, minimum-necessary handling, and audit logging. No system is perfectly secure; we notify affected individuals and the Data Protection Board in the event of a reportable breach.

8. Children

For processing personal data of children (under 18 in India), we obtain verifiable consent from a parent or lawful guardian and do not undertake profiling or targeted advertising toward children.

9. Cross-border transfer

Some sub-processors may be located outside India. Transfers are made in accordance with the DPDP Act and any restrictions notified by the Government of India.

10. Grievance officer

See our grievance page for the officer's name and contact. We aim to acknowledge complaints within 3 business days and resolve them within 30 days.