Privacy Policy

Version 1.0 | Effective Date: January 1, 2025

Last Updated: January 1, 2025

⚖️ Legal Compliance: This privacy policy complies with India's Digital Personal Data Protection Act 2023 (DPDP Act). We are committed to protecting your medical data with the highest standards of security and transparency.

1. Introduction

Welcome to Dharani Hospital App ("we," "our," or "the App"). This Privacy Policy explains how we collect, use, store, and protect your personal and medical data when you use our hospital management and patient care application.

By using Dharani Hospital App, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use the App.

2. Data Controller Information

Data Fiduciary: Dharani Hospital, Warangal
Address: [Your Registered Address], Hyderabad, Telangana, India
Email: contact@rootlynk.com
Data Protection Officer: contact@rootlynk.com
Grievance Officer: contact@rootlynk.com (Response within 30 days as per DPDP Act)

3. What Data We Collect

We collect the following categories of personal and sensitive data:

Data Category Examples Legal Basis
Personal Information Name, phone number, email, date of birth, address, Aadhaar number (optional) User Consent
Medical Records Vitals (BP, SpO2, heart rate), diagnoses, prescriptions, lab reports, imaging scans, surgery notes Healthcare Treatment
Authentication Data Phone number for OTP login, Google Sign-In credentials Service Provision
Financial Data Consultation fees, medication costs, insurance claims Billing & Accounting
Usage Analytics App interactions, feature usage, crash logs, performance metrics Service Improvement
Location Data Clinic/Hospital location (not personal location tracking) Multi-tenancy
AI Chat Logs Health questions asked to AI assistant, chat history User Consent
Document Uploads Scanned prescriptions, lab reports, medical certificates (PDF/PNG/JPG) User Upload

4. How We Collect Data

5. Why We Process Your Data (Purpose Limitation)

We use your data only for the following legitimate purposes:

5.1 Primary Healthcare Purposes

5.2 AI-Powered Services

5.3 Operational Purposes

5.4 Legal Compliance

6. Data Sharing and Third-Party Services

We share your data with the following third-party services:

Service Provider Purpose Data Shared Location
Firebase (Google Cloud) Backend database, authentication, file storage, analytics All patient and medical data India (asia-south1 - Mumbai)
OpenRouter AI health chat assistant (GPT-4o, GPT-4o-mini) Patient questions, chat history (no PHI unless explicitly asked) USA (OpenAI servers)
Google Cloud Vision Document scanning (optional, on-device OCR preferred) Scanned images of prescriptions/reports India (asia-south1)
Firebase Crashlytics App crash reporting and debugging Device info, crash logs (no PHI) Global (Google servers)
⚠️ Important: We do NOT sell your data to advertisers, insurance companies, or pharmaceutical companies. Your medical data is shared only with your healthcare providers and the technical services listed above.

7. Data Security Measures

We implement industry-standard security practices:

7.1 Encryption

7.2 Access Control

7.3 Infrastructure Security

8. Data Retention and Deletion

We retain your data according to the following schedule:

Data Type Retention Period Reason
Medical Records 3 years after last visit Indian Medical Council regulations
Financial Transactions 7 years Income Tax Act compliance
AI Chat Logs Until account deletion Continuity of care
Audit Logs 3 years Legal compliance
Analytics Data 14 months (Firebase default) Service improvement

8.1 Account Deletion Process

If you request account deletion (Settings → Delete Account):

  1. Immediate: Personal identifiers anonymized (name → "Patient-DELETED-[timestamp]", phone → null)
  2. 3 Years: Medical records retained in anonymized form (legal requirement)
  3. After 3 Years: Complete deletion of all data from all systems
Note: This two-step deletion process balances your DPDP Act right to erasure with medical record retention requirements.

9. Your Rights Under DPDP Act 2023

As a data principal, you have the following rights:

9.1 Right to Access

9.2 Right to Correction

9.3 Right to Erasure

9.4 Right to Withdraw Consent

9.5 Right to Grievance Redressal

10. Children's Privacy

The Dharani Hospital App is designed for patients of all ages, including children. Parental consent is obtained during registration for users under 18 years. Parents can exercise all DPDP rights on behalf of their children by contacting contact@rootlynk.com.

11. Cross-Border Data Transfers

While we primarily store data in India (Firebase Mumbai), some third-party services (OpenRouter AI) process data in the USA. We ensure these transfers comply with DPDP Act requirements through:

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

13. Contact Us

For General Inquiries:

Email: contact@rootlynk.com
Phone: +91-XXXX-XXXXXX (9 AM - 6 PM IST, Mon-Sat)

For Privacy Concerns:

Email: contact@rootlynk.com

For Grievances:

Email: contact@rootlynk.com
Response within 30 days as mandated by DPDP Act 2023

14. Consent Acknowledgment

By clicking "I Consent" in the app's consent dialog, you acknowledge that you have read, understood, and agree to this Privacy Policy. You also consent to the collection, processing, and sharing of your data as described above.

✅ Consent Record: Your consent is logged in our database with a timestamp and privacy policy version number for audit purposes.