Legal Document

Privacy Policy

This Privacy Policy describes how VaidyaOne Health Technologies Pvt. Ltd. collects, uses, stores, and protects your personal and health information when you use our services.

Effective date: 1 January 2025Last updated: 14 June 2026Jurisdiction: Republic of India
Summary: VaidyaOne is a healthcare data processor. Clinics (our clients) are the data fiduciaries who collect patient information. We process that data strictly under their instructions and applicable Indian law, including the Digital Personal Data Protection (DPDP) Act 2023 and the Information Technology Act 2000. We never sell health data. Ever.

1. Data We Collect

We collect different categories of information depending on your role:

a) Patient Health Information (PHI)

  • Full name, date of birth, gender, contact details
  • ABHA (Ayushman Bharat Health Account) ID / ABHA Address
  • Aadhaar number (masked — last 4 digits only, stored AES-256 encrypted)
  • Medical history, diagnoses (ICD-10 codes), prescriptions, lab results
  • Vitals (BP, weight, SPO2, temperature, etc.)
  • Documents and imaging reports uploaded by the treating clinic
  • Consent artefacts for ABDM health record sharing

b) Clinic / Healthcare Provider Information

  • Organisation name, GST number, registration number
  • Doctor MCI / NMC registration numbers
  • Billing and payment information (processed via Razorpay — we do not store card data)
  • Subscription plan and usage data

c) Usage & Technical Data

  • IP addresses and device identifiers (for security and fraud prevention)
  • Browser type, OS, screen resolution
  • Pages visited, features used, session duration
  • API call logs (retained 90 days for debugging)
  • Error and performance telemetry

2. How We Use Your Data

  • Healthcare delivery — enabling clinics to manage appointments, consultations, prescriptions, and billing
  • ABDM compliance — creating and managing ABHA-linked care contexts, consent artefacts, and FHIR R4 health records for the national health data stack
  • Communications — appointment reminders via SMS/WhatsApp (Meta WhatsApp Business Platform), lab result notifications (with patient consent)
  • Analytics — aggregate, de-identified usage statistics to improve product features
  • Security — fraud detection, brute-force protection, audit logging of all PHI access
  • Legal compliance — responding to lawful orders from courts or government authorities
  • Support — diagnosing bugs and resolving clinic support tickets
We process PHI solely to fulfil the healthcare services requested by the treating clinic. We do not use patient health data for advertising, profiling, or selling to third parties.

3. Data Storage & Security

All data is stored in India on OVH Mumbai servers in an ISO 27001-aligned environment.

Encryption

  • Data at rest: AES-256 encryption for all PHI fields and documents
  • MySQL Transparent Data Encryption (TDE) for full database encryption
  • Data in transit: TLS 1.3 enforced for all API and web traffic
  • ABDM Fidelius end-to-end encryption for health record payloads exchanged with the national gateway
  • Aadhaar/ABHA identifiers masked in logs (last 4 digits only)

Access Controls

  • Role-based access control (RBAC) — doctors, staff, admins have separate permission sets
  • All PHI access is audit-logged with timestamp, user ID, and action
  • Multi-factor authentication (MFA) available for clinic admin accounts
  • Zero-trust network: API keys rotated quarterly, database not exposed to public internet
  • Penetration testing conducted bi-annually

Breach Notification

In the event of a personal data breach, we will notify affected clinics within 72 hours of discovery, as required by the DPDP Act 2023, and assist with notification to affected patients where mandated.

4. ABDM Data Sharing

VaidyaOne is a registered Health Information Provider (HIP) and Health Information User (HIU) with the Ayushman Bharat Digital Mission (ABDM) gateway.

  • Health records are only shared via the ABDM Health Information Exchange (HIE) after obtaining explicit, informed patient consent through the ABHA consent framework
  • Consent artefacts specify the exact data types, purpose, and time window — patients can revoke consent at any time
  • No health record is pushed to any HIU without a valid, active consent artefact
  • All ABDM data exchanges use Fidelius encryption — data is decryptable only by the requesting HIU with the patient's session key
  • ABDM gateway integration is certified under Milestone M1 (ABHA creation), M2 (records exchange), and M3 (consent management)
Your ABHA-linked records are stored locally in VaidyaOne and shared with the national HIE only upon your explicit consent. You can view and manage all your consents at any time through the ABHA mobile app or patient portal.

5. Third-Party Sharing

We do not sell, rent, or trade personal data. We share data with third parties only in these circumstances:

  • ABDM National Health Authority (NHA) — health records with patient consent via the HIE gateway
  • Meta WhatsApp Business Platform — WhatsApp notifications (masked — only phone number and appointment details, no diagnosis)
  • Razorpay — payment processing (we receive only payment status, not card details)
  • OVH Cloud — infrastructure hosting (data processing agreement in place, India data residency)
  • Lawful orders — courts, CERT-In, or government authorities with valid legal process

All third-party processors have executed Data Processing Agreements (DPAs) with us and are bound to the same data protection standards.

6. Your Rights (DPDP Act 2023)

Under India's Digital Personal Data Protection Act 2023, you have the following rights:

Right to Access

Request a copy of all personal data held about you. We will respond within 30 days.

Right to Correction

Request correction of inaccurate or incomplete personal data.

Right to Erasure (Right to be Forgotten)

Request deletion of your personal data, subject to legal retention obligations (e.g., medical records must be retained per MCI guidelines — see Section 7).

Right to Data Portability

Download your ABHA-linked health records in FHIR R4 format via the ABDM HIE, or request export of your data in JSON/PDF format from the patient portal.

Right to Withdraw Consent

Withdraw consent for data processing at any time. Note: withdrawal does not affect processing that occurred before withdrawal.

Right to Grievance Redressal

Lodge a complaint with our Data Protection Officer (DPO). If unsatisfied, escalate to the Data Protection Board of India once established.

To exercise any right, email dpo@vaidyaone.com with subject line "Data Rights Request — [your name]". We will verify your identity before processing the request.

7. Data Retention

We retain data for the minimum period necessary, guided by Indian law:

Data CategoryRetention PeriodBasis
Medical records (PHI)Minimum 3 years from last visitMCI (Ethics) Regulations 2002
Minor patient recordsUntil age 18 + 3 yearsMCI Guidelines
Billing / invoices8 yearsGST Act 2017
Consent artefacts (ABDM)5 years post consent expiryABDM HIP policy
Audit logs2 yearsIT Act 2000 / CERT-In
API call logs90 daysOperational necessity
Account data (post-cancellation)30 days (export window), then deletedDPDP Act 2023

After the retention period, data is securely deleted using NIST 800-88 compliant wiping procedures.

8. Cookies & Tracking

VaidyaOne uses minimal cookies, strictly necessary for functionality:

  • Session cookies — to maintain your logged-in state (httpOnly, Secure, SameSite=Strict)
  • CSRF tokens — to protect against cross-site request forgery
  • Preference cookies — to remember display language and theme settings

We do not use third-party advertising cookies, tracking pixels, or behavioral analytics cookies. We do not use Google Analytics or Meta Pixel on authenticated clinic pages.

The marketing website (pre-login) may use privacy-respecting, cookieless analytics (aggregated, no cross-site tracking). You can disable cookies via your browser settings — note that disabling session cookies will prevent login.

9. Children's Data

VaidyaOne is a B2B healthcare platform used by licensed clinics. Clinics may register minor patients (under 18 years) for medical care purposes. When processing data for minors:

  • Consent is obtained from the parent or legal guardian, verified by the treating clinic
  • Minor patient records are flagged and subject to enhanced retention rules (until age 18 + 3 years)
  • ABHA creation for minors follows NHA guidelines requiring guardian consent
  • Minors' data is never used for any purpose other than direct healthcare delivery

VaidyaOne does not directly collect data from children through the internet without clinic mediation.

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in law, technology, or our services. When we make material changes:

  • We will notify clinic administrators via email at least 30 days before the effective date
  • The updated policy will be published at vaidyaone.com/privacy with a revised 'Last updated' date
  • Continued use of VaidyaOne after the effective date constitutes acceptance of the revised policy

11. Contact Our Data Protection Officer

For privacy concerns, data rights requests, or to report a suspected breach, contact our designated Data Protection Officer:

Data Protection Officer

VaidyaOne Health Technologies Pvt. Ltd.

Email: dpo@vaidyaone.com

General support: hello@vaidyaone.in

Address: Hyderabad, Telangana, India — 500081

Response time: within 72 hours for urgent matters, 30 days for standard requests

This policy is governed by the laws of the Republic of India. Disputes arising from this policy shall be subject to the jurisdiction of courts in Hyderabad, Telangana.

Questions about this policy? Contact us · Terms of Service · Refund Policy