Arogya PranaArogya Prana

Legal

Privacy Policy

How we collect, use, share, and protect personal data, aligned to the Digital Personal Data Protection Act, 2023.

Version 2.0  ·  Effective date: 22 July 2026

Last updated: 22 July 2026

1. Who we are

Arogya Prana operates a healthcare discovery platform that helps people in India find and evaluate doctors, clinics, and hospitals, and helps verified healthcare providers publish their profiles and health information content.

For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we act as a Data Fiduciary in respect of the personal data we determine the purpose and means of processing for. Where we handle personal data on the instructions of a healthcare provider, we act as a Data Processor for that provider.

We are also an intermediary and an e-commerce entity for certain functions, and comply with obligations applicable to us under the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Consumer Protection (E-Commerce) Rules, 2020, to the extent each applies.

Our full legal entity name, registered address, and contact details are published on our Contact page and in Section 14 below.

2. Scope of this policy

This policy explains what personal data we collect, why we collect it, the legal grounds we rely on, who we share it with, how long we keep it, and the rights available to you as a Data Principal under the DPDP Act.

This policy covers:

  • Visitors who browse the platform without an account.
  • Registered users and patients who create an account, save providers, submit enquiries, or write reviews.
  • Doctors who apply for and hold a verified provider profile.
  • Clinics and hospitals that apply for and hold a verified facility listing, and the individuals who administer those listings.

This policy does not govern how a doctor, clinic, or hospital handles your information once you engage them for care. When you consult a provider, that provider is an independent Data Fiduciary for the clinical record it creates, and its own privacy notice and professional obligations apply.

3. What we are not

Arogya Prana is a discovery and information platform. We are not a healthcare provider. We do not practise medicine, do not provide diagnosis or treatment, do not issue prescriptions, and do not operate as a telemedicine service. Content on the platform is for general information and does not substitute for consultation with a registered medical practitioner. See our Medical Advice Disclaimer for details.

Because we are not a provider, we do not maintain clinical health records about you. We ask that you do not send us diagnostic reports, prescriptions, or detailed medical histories through our enquiry, review, or support channels.

4. Personal data we collect

4.1 Data you give us

CategoryExamplesWho it applies to
Account dataName, email address, mobile number, password credentials held by our authentication providerRegistered users, doctors, provider administrators
Profile dataDisplay name, city, profile photo, preferencesRegistered users
Enquiry dataThe free-text message and contact details you submit when contacting a provider or our support teamUsers, visitors
Review and content dataRatings, written reviews, comments, and any content you publishRegistered users
Provider application dataFull legal name, date of birth, gender, registration/licence number and issuing council, qualifications, specialties, years of practice, practice addresses, supporting documents and evidenceDoctors
Facility application dataEntity legal name, registration and licence identifiers, statutory identifiers such as GSTIN where applicable, registered and practice addresses, authorised signatory details, supporting documentsClinics and hospitals
Billing dataBilling name, billing address, tax identifiers, invoice records, and payment statusPaying doctors and facilities

4.2 Data we collect automatically

  • Technical and device data: IP address, browser and device type, operating system, referring page, and timestamps.
  • Usage data: Pages and provider profiles viewed, searches run, and features used.
  • Cookies and similar technologies: We use strictly necessary technologies for authentication, security, fraud prevention, load balancing, and core operation. We may also use functional technologies to remember choices such as location, language, or display preferences. We do not currently use advertising cookies, pixels, or advertising identifiers. Any future non-essential analytics or personalised-advertising technology that requires consent will remain off until the required separate consent is given.

You can block or delete cookies through your browser settings, although disabling necessary cookies may prevent sign-in or other core functions. Optional consent can be withdrawn through the privacy controls made available in your account. We will update this section before introducing a new category of non-essential technology.

4.3 Data we receive from others

  • Authentication provider: We use a third-party identity provider to manage sign-in. It supplies us with a stable user identifier and your verified email address or mobile number.
  • Payment gateway: We receive transaction status, an order reference, and limited masked instrument details. We do not collect or store your full card number, CVV, UPI PIN, or net-banking credentials. Those are handled directly by our PCI-DSS compliant payment gateway.
  • Public and official registries: For provider verification, we may check registration details against publicly available medical council or statutory registers.

4.4 Sensitive personal data

The SPDI Rules treat certain categories, including health information, as Sensitive Personal Data or Information. We deliberately minimise this category:

  • We do not require you to tell us about your medical conditions to use the platform.
  • If a search or enquiry you make reveals a health interest (for example, searching for a specialty), we treat that inference with the same care as sensitive data. We do not use it to build an advertising profile, and we do not disclose it to any advertiser. Section 8 explains the narrow, non-profiling exception for selecting an advertisement from the page you are currently viewing, if advertising is ever introduced.
  • We apply reasonable security practices consistent with the SPDI Rules to any sensitive personal data we do hold.

4.5 Children

Our services are intended for users aged 18 and above. Consistent with Section 9 of the DPDP Act, we do not knowingly process the personal data of a child (a person under 18) or of a person with a disability who has a lawful guardian, without verifiable consent of the parent or lawful guardian.

We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us personal data, contact our Grievance Officer and we will delete it.

4.6 Acting on behalf of another person

You may use the platform for someone else — for example a dependent, an elderly parent, or a patient in your care — only if you are lawfully authorised to do so.

If you provide us another person's personal data, you confirm that you have the authority to do so and that you have informed them how their data will be used under this policy. Where that person is a child or has a lawful guardian, you confirm that you are the parent or lawful guardian and that you are giving the verifiable consent required under Section 9 of the DPDP Act. You must tell us promptly if your authority ends.

We may ask you to evidence that authority before acting on a request made on another person's behalf, and we may decline a request we cannot verify. This is separate from the nomination right described in Section 13, which lets you appoint someone to exercise your rights if you die or become incapacitated.

5. Why we process your data, and on what grounds

Under the DPDP Act, personal data may be processed on the basis of consent or for certain legitimate uses listed in Section 7 of the Act. We do not rely on a broad "legitimate interests" balancing test — that concept does not exist under Indian law and we do not import it.

PurposeGround under the DPDP Act
Creating and operating your accountConsent, and the Section 7 legitimate use where you voluntarily provide data for a purpose you have not objected to
Showing you search results and provider profilesConsent
Routing an enquiry you submit to the provider you selectedConsent — the enquiry is the act of asking us to share it
Verifying a doctor, clinic, or hospital applicationConsent of the applicant, and compliance with law where verification is legally required
Publishing reviews you choose to postConsent
Processing subscription payments and issuing invoicesConsent, and compliance with tax and accounting law
Security, fraud prevention, abuse detection, and platform integrityConsent for the specified platform-service purpose, compliance with applicable law, and a Section 7 certain legitimate use only where its exact statutory conditions apply
Responding to legal process, regulator directions, and court ordersCompliance with law
Service and transactional communicationsConsent, and performance of the service you asked for
Marketing communicationsSeparate, optional consent that you may withdraw at any time
Personalised advertisingSeparate, optional, opt-in consent only — see Section 8

Where we rely on consent, our consent notice is presented in clear plain language. As the relevant DPDP provisions commence, we will provide the legally required option to access the notice in English or a language specified in the Eighth Schedule to the Constitution of India, consistent with Section 5 of the DPDP Act.

5.1 Withdrawing consent

You may withdraw your consent at any time, and withdrawing must be as easy as giving it. You can do this from your account privacy settings, or by contacting our Grievance Officer.

Withdrawal is not retrospective — it does not affect processing already lawfully carried out. If you withdraw consent that is necessary to operate your account, we will explain the consequence, which may include closing the account. We will cease processing within a reasonable time and require our processors to do the same.

5.2 How we communicate with you

We send service and transactional messages — such as sign-in and security notifications, enquiry confirmations, application status updates, and billing receipts — by email and, where you have given us a mobile number for that purpose, by SMS. These are part of the service you asked for and cannot be switched off while your account is open.

Marketing messages are sent only with your separate, optional consent, which you can withdraw at any time from your privacy settings. We do not currently send SMS marketing. If we introduce it, it will require its own opt-in consent and will comply with the applicable TRAI commercial-communication regulations, including registration and preference requirements.

We do not currently operate a telephone support line, and we do not record calls. If we introduce voice support in future, we will tell you before a call is recorded, explain the purpose and retention period, and obtain any consent required before recording. Nothing in this policy should be read as a claim that we record calls today.

6. Reviews and publicly visible content

Reviews you publish are public, and are shown with the display name you choose. Please do not include your full medical history, contact details, or another person's identifying information in a review. You can request removal of a review you posted through your account or our Grievance Officer.

7. Provider verification and public listings

If you apply as a doctor, clinic, or hospital:

  • Certain identity and credential fields are inherently public once your listing is approved — for example your name, qualifications, specialties, registration number where displayed, and practice locations. Publication of these is the purpose of the listing.
  • Supporting evidence documents you upload are not published. They are used for verification review by authorised platform staff, and retained as proof that verification was performed.
  • We may display a verification badge and the date verification was completed.
  • If your application is rejected or your listing is withdrawn, we retain the application record and its audit trail for the period described in Section 10, so we can evidence our verification decisions.

8. Advertising and personalised advertising

We do not currently serve personalised (behaviourally targeted) advertising on Arogya Prana.

We may in future introduce advertising. If and when we do, the following commitments apply, and they are binding on us:

  1. Contextual advertising — advertising selected only from the page or category you are currently viewing — may be shown without separate consent. This is a decision about the page, not about you. Specifically, it does not require an advertising identifier, does not persist what you viewed or searched for into a behavioural or health-interest profile, is not retained as a profile attribute, and does not disclose your search or the page you viewed to the advertiser. Contextual advertising will always be clearly labelled as advertising and visually distinguished from organic search results and editorial content.
  2. Personalised advertising — advertising selected using a profile built from your activity, inferred interests, or identifiers — will be served only if you give separate, specific, opt-in consent for that purpose, and may use only the data covered by that consent.
  3. That advertising consent is a distinct consent purpose. It is never bundled into, or a condition of, accepting our Terms and Conditions, creating an account, submitting a provider application, or using any core feature of the platform.
  4. The advertising consent control is off by default and never pre-checked. Declining costs you nothing and changes nothing about the service you receive.
  5. You may withdraw advertising consent at any time, as easily as you gave it, from your privacy settings.
  6. We will not use health conditions, inferred health conditions, or searches for a specific specialty, treatment, or provider to build a profile or to target personalised advertising, and we will not disclose any of those to an advertiser.
  7. We will not show personalised advertising to users under 18, consistent with Section 9 of the DPDP Act.
  8. We will not sell your personal data.
  9. Sponsored or paid provider placements, if introduced, will be labelled as such at the point of display.

Until we launch any such feature and obtain your consent, no advertising profile is built about you. We will update this policy and notify affected users before any change takes effect.

Advertising and Sponsorship Policy. Our full advertising rules — labelling, the separation of payment from verification, moderation, editorial and organic ranking, the advertising categories we refuse, and the restrictions on what an advertiser may collect — are set out in our Advertising and Sponsorship Policy. No advertiser may place a form, cookie, pixel, tag, or other tracking technology in an advertisement, or collect personal data or health-interest data through one, without our prior approval and any separately required informed consent.

Advertiser landing pages. An advertisement links to a site we do not operate. This Privacy Policy does not apply to those sites. Once you click through, the destination's own privacy policy and terms govern what it collects and does, and clicking is not an endorsement by us. The same applies to any other third-party site linked from the platform, including provider websites.

9. Who we share your data with

We share personal data only as described here:

  • The provider you contact. When you submit an enquiry, we pass your enquiry and the contact details you provided to that specific doctor, clinic, or hospital. That is the purpose of the enquiry.
  • Data Processors acting on our instructions, under written contract, including our cloud hosting and database provider, authentication provider, email and notification delivery provider, object storage provider, payment gateway, and AI content-assistance providers used for editorial drafting. Processors may not use your data for their own purposes.
  • Professional advisers and auditors, under confidentiality obligations.
  • Regulators, courts, and law enforcement, where we are legally required to disclose, or where disclosure is necessary to comply with a lawful order.
  • A successor entity, in the event of a merger, acquisition, or restructuring — in which case we will notify you and the successor remains bound by this policy until lawfully changed.

We do not sell your personal data, and we do not share it with data brokers.

10. Cross-border transfers

Some of our processors may store or process personal data outside India. Under Section 16 of the DPDP Act, we may transfer personal data outside India except to a country or territory restricted by notification of the Central Government. We monitor such notifications and will cease or relocate transfers to any restricted territory.

Where sector-specific law imposes stricter localisation on particular data — for example payment system data under Reserve Bank of India directions — we and our providers comply with that stricter requirement.

11. How long we keep your data

We retain personal data only for as long as necessary for the purpose it was collected for, or for as long as a law requires us to retain it.

DataRetention
Account and profile dataWhile your account is active, then erased or anonymised within a reasonable period after closure, unless retention is legally required
Enquiry recordsA limited period sufficient to resolve disputes about whether an enquiry was delivered
ReviewsUntil you delete them or your account is closed; we may retain an anonymised record
Provider application and verification recordsFor the life of the listing and a defined period afterwards, so we can evidence why a provider was verified
Invoices, tax records, and payment recordsFor the period required under Indian tax and companies law
Security, audit, and access logsA limited period appropriate to security investigation needs
Legal acceptances and optional-consent recordsAs long as reasonably necessary to prove the document accepted, consent given or withdrawn, and compliance with legal obligations
BackupsUntil expiry under the applicable encrypted backup-rotation schedule

Where the DPDP Act and the Digital Personal Data Protection Rules, 2025 prescribe specific erasure timelines and advance-notice obligations for classes of Data Fiduciary, we apply the applicable prescribed period and give you the required notice before erasure.

An account-closure or erasure request triggers a review of active purposes and legal obligations. We may retain limited records where required for tax and accounting, fraud prevention, security, professional verification, complaints, disputes, enforcement of legal rights, or compliance with another applicable law. Where required, we will explain material retention that prevents immediate erasure.

Normal deletion may be suspended for records reasonably required for a complaint, investigation, court order, regulator request, security incident, or anticipated dispute. Access remains restricted and deletion resumes when that legal hold ends. Deletion from live systems may occur before the same data expires from encrypted backups; restored data remains subject to the original deletion instruction.

12. How we protect your data

We implement reasonable security safeguards, including:

  • Encryption of data in transit, and encryption at rest for stored data and uploaded documents.
  • Role-based access control, so staff access only what their role requires, with elevated access for verification review.
  • Audit logging of administrative and verification actions, recording who did what and when.
  • Credential handling delegated to a specialist authentication provider; we do not store your password.
  • Private, access-controlled object storage for uploaded verification evidence.
  • Contractual security obligations imposed on our processors.

12.1 Your part, and reporting a compromised account

Security depends partly on you. Please keep your credentials confidential, do not reuse them on other services, and do not share them with anyone.

If you know or suspect that your account has been accessed without your permission, or that your credentials have been lost or exposed, tell us immediately through the contact route in Section 14. Prompt notice lets us secure the account and limit harm. We may suspend access, force a credential reset, or require re-verification to protect your data, and we will tell you when we do.

We will never ask you for your password, a one-time passcode, or payment credentials by email, SMS, or phone. Treat any such request as fraudulent and report it to us.

No system can be guaranteed perfectly secure. If a personal data breach occurs, we will inform each affected Data Principal without delay, and report to the Data Protection Board of India within the timeframe prescribed under the DPDP Rules, 2025, with the particulars those Rules require.

13. Your rights as a Data Principal

Under Sections 11 to 14 of the DPDP Act, you have the right to:

  • Access — obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of other Data Fiduciaries and processors with whom it has been shared.
  • Correction, completion, updating, and erasure — have inaccurate or misleading data corrected, incomplete data completed, and data erased where it is no longer needed for the purpose it was collected for and no law requires retention.
  • Grievance redressal — use our grievance mechanism as the first route for any complaint, before approaching the Data Protection Board.
  • Nominate — nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
  • Withdraw consent — as described in Section 5.1.

To exercise any right, use the privacy controls in your account or write to our Grievance Officer. We will verify your identity before acting, and will respond within the period prescribed under the DPDP Rules, 2025.

You also have duties. Section 15 of the DPDP Act requires you not to impersonate another person, not to suppress material information when providing personal data for a document or identifier, and not to register a false or frivolous grievance.

14. Grievance Officer and escalation

Our Grievance Officer is designated under the DPDP Act, the SPDI Rules, and the Consumer Protection (E-Commerce) Rules, 2020.

  • Grievance Officer: Designated Grievance Officer, Impec Soft Solutions Private Limited
  • Email: support@arogyaprana.com
  • Postal address: Door No. 6-4-6, Arundelpet 4/5, Guntur, Andhra Pradesh 522002, India

We will handle each grievance within the timeline applicable to its subject. For intermediary content grievances, we aim to acknowledge within 24 hours and resolve within 15 days under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Consumer and privacy grievances will be handled within their applicable statutory timelines.

If you are not satisfied with the outcome, you may escalate to the Data Protection Board of India in the manner prescribed under the DPDP Act and the DPDP Rules, 2025. You may also have recourse under the Consumer Protection Act, 2019.

15. Regulatory commencement note

The DPDP Act, 2023 received assent on 11 August 2023. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 with phased commencement — certain provisions took effect immediately on notification, while the principal operational obligations, including those on consent notices, security safeguards, breach reporting, retention, and Data Principal rights, commence later on the timelines set out in those Rules.

We are aligning our practices to the full DPDP framework ahead of the commencement of those provisions, and continue to comply in the meantime with the IT Act, 2000 and the SPDI Rules, 2011. We will update this policy as further provisions commence.

16. Changes to this policy

This policy is version-controlled. Every published version is retained as an immutable record with its effective date, and the currently active version is always shown on this page.

Where a change materially affects how we use your personal data, we will notify signed-in users and, where the change requires fresh consent, ask you to review and accept before you continue to use affected features. We will not treat continued silence as consent for a change that requires consent.

17. Contact

For any question about this policy or about how we handle your personal data, contact our Grievance Officer using the details in Section 14.