1. Data We Collect
We collect different categories of information depending on your role:
a) Patient Health Information (PHI)
- Full name, date of birth, gender, contact details
- ABHA (Ayushman Bharat Health Account) ID / ABHA Address
- Aadhaar number (masked — last 4 digits only, stored AES-256 encrypted)
- Medical history, diagnoses (ICD-10 codes), prescriptions, lab results
- Vitals (BP, weight, SPO2, temperature, etc.)
- Documents and imaging reports uploaded by the treating clinic
- Consent artefacts for ABDM health record sharing
b) Clinic / Healthcare Provider Information
- Organisation name, GST number, registration number
- Doctor MCI / NMC registration numbers
- Billing and payment information (processed via Razorpay — we do not store card data)
- Subscription plan and usage data
c) Usage & Technical Data
- IP addresses and device identifiers (for security and fraud prevention)
- Browser type, OS, screen resolution
- Pages visited, features used, session duration
- API call logs (retained 90 days for debugging)
- Error and performance telemetry
2. How We Use Your Data
- Healthcare delivery — enabling clinics to manage appointments, consultations, prescriptions, and billing
- ABDM compliance — creating and managing ABHA-linked care contexts, consent artefacts, and FHIR R4 health records for the national health data stack
- Communications — appointment reminders via SMS/WhatsApp (Meta WhatsApp Business Platform), lab result notifications (with patient consent)
- Analytics — aggregate, de-identified usage statistics to improve product features
- Security — fraud detection, brute-force protection, audit logging of all PHI access
- Legal compliance — responding to lawful orders from courts or government authorities
- Support — diagnosing bugs and resolving clinic support tickets
3. Data Storage & Security
All data is stored in India on OVH Mumbai servers in an ISO 27001-aligned environment.
Encryption
- Data at rest: AES-256 encryption for all PHI fields and documents
- MySQL Transparent Data Encryption (TDE) for full database encryption
- Data in transit: TLS 1.3 enforced for all API and web traffic
- ABDM Fidelius end-to-end encryption for health record payloads exchanged with the national gateway
- Aadhaar/ABHA identifiers masked in logs (last 4 digits only)
Access Controls
- Role-based access control (RBAC) — doctors, staff, admins have separate permission sets
- All PHI access is audit-logged with timestamp, user ID, and action
- Multi-factor authentication (MFA) available for clinic admin accounts
- Zero-trust network: API keys rotated quarterly, database not exposed to public internet
- Penetration testing conducted bi-annually
Breach Notification
In the event of a personal data breach, we will notify affected clinics within 72 hours of discovery, as required by the DPDP Act 2023, and assist with notification to affected patients where mandated.
4. ABDM Data Sharing
VaidyaOne is a registered Health Information Provider (HIP) and Health Information User (HIU) with the Ayushman Bharat Digital Mission (ABDM) gateway.
- Health records are only shared via the ABDM Health Information Exchange (HIE) after obtaining explicit, informed patient consent through the ABHA consent framework
- Consent artefacts specify the exact data types, purpose, and time window — patients can revoke consent at any time
- No health record is pushed to any HIU without a valid, active consent artefact
- All ABDM data exchanges use Fidelius encryption — data is decryptable only by the requesting HIU with the patient's session key
- ABDM gateway integration is certified under Milestone M1 (ABHA creation), M2 (records exchange), and M3 (consent management)
5. Third-Party Sharing
We do not sell, rent, or trade personal data. We share data with third parties only in these circumstances:
- ABDM National Health Authority (NHA) — health records with patient consent via the HIE gateway
- Meta WhatsApp Business Platform — WhatsApp notifications (masked — only phone number and appointment details, no diagnosis)
- Razorpay — payment processing (we receive only payment status, not card details)
- OVH Cloud — infrastructure hosting (data processing agreement in place, India data residency)
- Lawful orders — courts, CERT-In, or government authorities with valid legal process
All third-party processors have executed Data Processing Agreements (DPAs) with us and are bound to the same data protection standards.
6. Your Rights (DPDP Act 2023)
Under India's Digital Personal Data Protection Act 2023, you have the following rights:
Right to Access
Request a copy of all personal data held about you. We will respond within 30 days.
Right to Correction
Request correction of inaccurate or incomplete personal data.
Right to Erasure (Right to be Forgotten)
Request deletion of your personal data, subject to legal retention obligations (e.g., medical records must be retained per MCI guidelines — see Section 7).
Right to Data Portability
Download your ABHA-linked health records in FHIR R4 format via the ABDM HIE, or request export of your data in JSON/PDF format from the patient portal.
Right to Withdraw Consent
Withdraw consent for data processing at any time. Note: withdrawal does not affect processing that occurred before withdrawal.
Right to Grievance Redressal
Lodge a complaint with our Data Protection Officer (DPO). If unsatisfied, escalate to the Data Protection Board of India once established.
To exercise any right, email dpo@vaidyaone.com with subject line "Data Rights Request — [your name]". We will verify your identity before processing the request.
7. Data Retention
We retain data for the minimum period necessary, guided by Indian law:
| Data Category | Retention Period | Basis |
|---|---|---|
| Medical records (PHI) | Minimum 3 years from last visit | MCI (Ethics) Regulations 2002 |
| Minor patient records | Until age 18 + 3 years | MCI Guidelines |
| Billing / invoices | 8 years | GST Act 2017 |
| Consent artefacts (ABDM) | 5 years post consent expiry | ABDM HIP policy |
| Audit logs | 2 years | IT Act 2000 / CERT-In |
| API call logs | 90 days | Operational necessity |
| Account data (post-cancellation) | 30 days (export window), then deleted | DPDP Act 2023 |
After the retention period, data is securely deleted using NIST 800-88 compliant wiping procedures.
9. Children's Data
VaidyaOne is a B2B healthcare platform used by licensed clinics. Clinics may register minor patients (under 18 years) for medical care purposes. When processing data for minors:
- Consent is obtained from the parent or legal guardian, verified by the treating clinic
- Minor patient records are flagged and subject to enhanced retention rules (until age 18 + 3 years)
- ABHA creation for minors follows NHA guidelines requiring guardian consent
- Minors' data is never used for any purpose other than direct healthcare delivery
VaidyaOne does not directly collect data from children through the internet without clinic mediation.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in law, technology, or our services. When we make material changes:
- We will notify clinic administrators via email at least 30 days before the effective date
- The updated policy will be published at vaidyaone.com/privacy with a revised 'Last updated' date
- Continued use of VaidyaOne after the effective date constitutes acceptance of the revised policy
11. Contact Our Data Protection Officer
For privacy concerns, data rights requests, or to report a suspected breach, contact our designated Data Protection Officer:
Data Protection Officer
VaidyaOne Health Technologies Pvt. Ltd.
Email: dpo@vaidyaone.com
General support: hello@vaidyaone.in
Address: Hyderabad, Telangana, India — 500081
Response time: within 72 hours for urgent matters, 30 days for standard requests
This policy is governed by the laws of the Republic of India. Disputes arising from this policy shall be subject to the jurisdiction of courts in Hyderabad, Telangana.
Questions about this policy? Contact us · Terms of Service · Refund Policy