๐Ÿฅ MediCare Plus Hospital โ€” 24/7 Emergency: 1800-MED-PLUS-V1
M+
MediCare Plus
Multi-Specialty Hospital
DPDP Act 2023 ยท Compliant

Privacy Policy

How MediCare Plus Hospital collects, uses, protects, and honours your rights over personal data โ€” in plain language.

Effective: [DD Month YYYY]Version 1.0Last reviewed: [DD Month YYYY]

Data Fiduciary Statement

Under the Digital Personal Data Protection Act, 2023

MediCare Plus Healthcare Pvt. Ltd. is the Data Fiduciary for the personal data described in this policy, under the DPDP Act, 2023 and the DPDP Rules, 2025.

Every consent you give produces a consent receipt with a reference ID, viewable in the Privacy Center.

1. Information we collect โ€” and why we tell you

Section 5 ยท Rule 3

We give you a clear notice, in English or any Eighth Schedule language you choose, before or at the time we ask for your data. The notice lists the data we collect, the specific purpose of each use, and how to withdraw consent or raise a complaint.

CategoryData elementsCollected at
IdentificationName, date of birth, genderRegistration, appointment booking
ContactEmail, mobile numberRegistration, appointment booking
HealthMedical history, appointment details, diagnostic reports, prescriptionsConsultation, diagnostics
TechnicalIP address, browser type, device identifiers, cookiesWebsite use
We collect only the personal data necessary for the purpose stated in the notice (Section 6(1)). We do not collect data "just in case".

Cookies. Strictly necessary cookies (session, security, load balancing) are set without consent because the service cannot run without them. Analytics and communication cookies are set only if you accept them, and you can change that choice at any time from the Privacy Center.

2. How we use your data

Section 4 and Section 6

PurposeBasisCan you decline?
Providing medical diagnosis, treatment and careConsent โ€” necessary purposeYes, but we cannot provide clinical care without it
Managing appointments and schedulingConsent โ€” necessary purposeYes, but we cannot manage your appointments without it
Appointment reminders and health communicationsConsent โ€” optionalYes, with no effect on your care
Service improvement using de-identified analyticsConsent โ€” optionalYes, with no effect on your care
Meeting legal, clinical and regulatory obligationsLegal obligation (Section 7(b))No โ€” required by law, continues after withdrawal
Responding to a medical emergencyLegitimate use (Section 7(e)โ€“(f))Not applicable โ€” no consent required by law
We do not sell, rent or trade your personal data. We do not use your health data for advertising.

Where a purpose is described as a necessary purpose, your consent is still free and voluntary โ€” declining simply means we cannot deliver that specific service.

3. Your rights as a Data Principal

Sections 11โ€“14 ยท Rule 14

RightSectionWhat you can do
Right to information / access11Get a summary of your personal data, the purposes it is processed for, and the identities of processors and other fiduciaries
Right to correction, completion, updating and erasure12Correct inaccurate data, complete incomplete data, update outdated data, or erase consent-based data
Right to grievance redressal13Raise a complaint with our Grievance Officer
Right to nominate14Nominate individuals to exercise your rights if you die or become incapacitated
Right to withdraw consent6(4)โ€“6(6)Withdraw any consent at any time, as easily as you gave it

How to exercise them

Use the Privacy Center or write to privacy@medicareplus-eight.vercel.app. We verify your identity before acting โ€” for the Privacy Center, we send a secure single-use link to your registered email. We never ask for your password, OTP or full patient record over email or phone.

Our response times

Request typeWe respond within
Consent withdrawal1 hour of confirmed request
Erasure of consent-based data24 hours, subject to legal retention (see ยง6)
Access, correction, completion, updating15 days
Nomination15 days
Grievance30 days (statutory ceiling: 90 days)
You may escalate to the Data Protection Board of India only after you have used our grievance mechanism first (Section 13(3)).

5. Children's and persons with disability data

Section 9 ยท Rule 10

For a patient under 18, or a person with disability who has a lawful guardian, we obtain verifiable consent from the parent or guardian before processing personal data, and we verify that the adult is an identifiable adult using reliable identity details or a virtual token issued by an authorised entity.

For these patients we do not undertake tracking, behavioural monitoring or targeted advertising, and we do not carry out processing likely to cause a detrimental effect on their well-being. Clinical care of a child, and processing restricted to health services for a child, fall within the exemptions notified under Rule 11 and the Fourth Schedule.

6. Data retention and erasure

Section 8(7) ยท Rule 8

We keep personal data only as long as the purpose it was collected for is still being served, or as long as a law requires us to keep it.

DataRetained forBecause
Clinical and diagnostic records1 years from last consultationMedical record retention obligations for clinical establishments
Consent artefacts, receipts and access logs1 year after the consent lifecycle closesRule 6(1)(f) log retention and audit evidence
Marketing and communication dataUntil withdrawal, then deletedPurpose no longer served
Website analytics (de-identified)12 monthsPurpose no longer served

When the retention period ends, or when you withdraw consent and no legal ground for retention remains, the data is erased and we instruct our Data Processors to erase their copies. Where a record is under legal hold (litigation, statutory inspection, insurance claim), we retain it until the hold is released and tell you so.

7. Sharing, processors and cross-border transfers

Section 8(2), Section 16 ยท Rule 15

We share personal data only with:

Data Processors
acting under a written contract that binds them to our security, purpose and deletion obligations โ€” e.g. diagnostic laboratories, HIS and cloud hosting, SMS/email delivery, payment gateways.
Other Data Fiduciaries
where you have consented or where a law requires it โ€” e.g. insurers for cashless claims, or public health authorities for notifiable diseases.
Government agencies
where disclosure is required under law or a court order.
We do not transfer your personal data outside India except to countries not restricted by the Central Government under Section 16. Where a sectoral law requires health data to remain in India, we keep it in India.

8. How your data is processed, end to end

1
Stage 1 โ€” Notice
Before we collect anything, the consent notice is presented at the touchpoint you are using. It lists each purpose separately, the data elements each purpose needs, the retention period, and links to this policy.
2
Stage 2 โ€” Consent capture
Your choices are recorded as a single, immutable consent transaction, plus one record per purpose. Each record carries the version, language, channel, and a timestamp. You receive a reference ID and a downloadable receipt.
3
Stage 3 โ€” Collection
Only the data elements declared in the notice for the purposes you granted are collected. If a purpose was rejected, its data elements are not collected for that purpose.
4
Stage 4 โ€” Storage
Identifiers are stored separately from clinical content wherever technically possible. Data is encrypted in transit and at rest, access is role-based and logged, and logs are retained for at least one year as required by Rule 6.
5
Stage 5 โ€” Processing and sharing
Each system checks the live consent status before it processes for an optional purpose. Processors receive only the fields they need for the task they perform.
6
Stage 6 โ€” Rights and withdrawal
A request raised in the Privacy Center is verified, ticketed with an SLA, propagated to every system holding the data, and closed with a written outcome. Withdrawal is propagated immediately.
7
Stage 7 โ€” Retention clock and erasure
Every record carries a deletion-eligible date and a deletion-required date. When the clock expires, erasure runs and is logged.
8
Stage 8 โ€” Breach handling
If a personal data breach occurs, we notify the Data Protection Board of India without delay and each affected Data Principal in plain language. CERT-In directions apply within their separate 6-hour timeline.

9. Security

Section 8(5) ยท Rule 6

Encryption, obfuscation or masking of personal data
Role-based access control
Logging and continuous monitoring
Backups sufficient to restore data after a compromise
Contractual security obligations on all processors
One year of retained logs and personal data for investigation

10. Contact and grievances

Section 13 ยท Rule 14

We acknowledge grievances on receipt and respond within 30 days. If you are not satisfied with our response, or we do not respond, you may complain to the Data Protection Board of India through the channel notified by the Board.

11. Changes to this policy

We publish the version number and effective date at the top of this page and keep previous versions available on request. Where a change materially affects the purposes for which we process your data, we notify you and seek fresh consent rather than relying on continued use of the site.

Have questions about your data?

Visit the Privacy Center to exercise your rights, download consent receipts, or file a grievance.

Open Privacy Center