Privacy Policy

1. Introduction

Doctri Healthcare Private Limited (“Doctri”, “we”, “us”, or “our”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how Doctri collects, uses, stores, processes, shares and protects information when you use our website, mobile application, healthcare services, consultation services, screening tools, caregiver services, nursing-related services, digital records, payment facilities and other services provided by Doctri.

This Policy is intended to comply with applicable Indian law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and rules made under it when applicable, the Information Technology Act, 2000 and applicable rules, the Consumer Protection Act, 2019, the Consumer Protection (E-Commerce) Rules, 2020 where applicable, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 where applicable, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 to the extent applicable during any transition period, the Telemedicine Practice Guidelines, 2020 where applicable, and applicable payment-system requirements issued by the Reserve Bank of India (“RBI”) and payment networks.

By accessing or using Doctri, you acknowledge that you have read this Privacy Policy. Where consent is required by law, we will obtain consent through a clear, specific, informed and affirmative action before processing your personal data for the relevant purpose. You may withdraw consent at any time, subject to legal or contractual consequences and lawful processing based on other grounds.

2 Data Fiduciary and Contact Details

For personal data processed for Doctri’s own purposes, Doctri Healthcare Private Limited is the data fiduciary under the DPDP Act.

For personal data processed by an independent healthcare professional, diagnostic provider, nursing provider, payment provider or other third party for that provider’s own purposes, that provider may be a separate data fiduciary or controller. Its own privacy notice may apply.

For privacy questions, data-principal requests and grievances:

Doctri Healthcare Private Limited

Email: admin@doctri.in

Website: www.doctri.in

Doctri will publish the name and contact details of its designated Data Protection Officer, where required under applicable law, on this page or through the relevant service interface. Until separately notified, privacy requests may be sent to the email address above.

3. Information We Collect

Depending on the services you use, we may collect:

Personal Data

– Name

– Age/date of birth

– Gender, where voluntarily provided

– Mobile number

– Email address

– Residential/address information

– Emergency contact details

– Caregiver information

– Account/login information

– Device, browser, IP address, log and usage information

– Communications with Doctri and customer-support records

– Consent, preference and request records

Healthcare Information

Where required for providing healthcare-related services, we may collect information such as:

– Symptoms and health concerns

– Cognitive screening information

– SLUMS or other screening results

– Medical history provided by you

– Existing diagnoses

– Medication information

– Doctor consultation information

– Prescriptions uploaded by users

– Laboratory reports uploaded by users

– Healthcare records and documents

– Caregiver observations and information

– Information relating to healthcare services requested through Doctri

Healthcare information is personal data and may be sensitive or health-related information under applicable law. It is used only for the purposes described in this Policy, the relevant consent or service arrangement, and applicable law.

Payment and Transaction Information

When you make a payment through Doctri, payment information may be processed through our authorised payment gateway or payment service provider.

Doctri may receive information such as:

– Transaction amount

– Transaction date and time

– Transaction/reference ID

– Payment status

– Limited payment-related information required for reconciliation, refunds, fraud prevention and customer support

Where payment details are processed directly by the payment gateway, Doctri does not ordinarily receive or store your complete card, UPI PIN, password or banking credentials. Payment providers may process information under their own privacy notices and applicable RBI, payment-network and security requirements.

4. Purposes and Legal Basis for Processing

We may process personal data for the following purposes:

– Creating and managing your account

– Providing requested healthcare-related services

– Facilitating consultations with healthcare professionals

– Facilitating screening and symptom tracking

– Maintaining digital healthcare records

– Providing caregiver-support features

– Facilitating nursing, diagnostic or other connected services

– Processing payments, refunds and reconciliations

– Sending appointment, payment, safety and service notifications

– Responding to customer-support requests and grievances

– Improving our website, application and services

– Maintaining security and preventing fraud, abuse or misuse

– Complying with legal, regulatory, court, tax, accounting and law-enforcement requirements

– Establishing, exercising or defending legal claims

– Conducting service improvement, research or analytics where legally permitted and appropriately protected

Depending on the purpose, processing may be based on your consent, performance of a requested service, compliance with a legal obligation, protection of vital interests, prevention of fraud or misuse, or another lawful basis recognised by applicable law. We will not make consent a condition for processing that is not necessary for the requested service, and optional processing will be clearly identified.

We will not use healthcare information for advertising, profiling or unrelated commercial purposes without the consent or other lawful basis required by applicable law.

5. Consent and Authorisations

Where consent is required, Doctri will request it separately for distinct purposes, in clear and accessible language. Consent may be provided through a checkbox, button, electronic signature, OTP, recorded verbal consent where legally permitted, or another affirmative action.

You may:

– Refuse optional consent without being denied unrelated services

– Withdraw consent through the relevant account setting or by emailing admin@doctri.in

– Request information about the consent given and the purposes covered

– Request correction or deletion, subject to applicable law and necessary retention

Withdrawal will not affect processing already carried out lawfully before withdrawal. Withdrawal may prevent us from continuing a service that requires the relevant data.

Where you provide another person’s information, including a patient’s, child’s, caregiver’s or emergency contact’s information, you confirm that you have the authority and any consent required by law to do so. Doctri may request evidence of authority where appropriate.

6. Sharing of Information

We may share relevant information with:

– Healthcare professionals selected or engaged by the user

– Service providers required to deliver requested services

– Diagnostic/laboratory partners where the user requests or authorises such services

– Nursing/service partners where applicable

– Payment gateways and payment service providers

– Technology, hosting, cloud, communications and security service providers

– Professional advisers, auditors and insurers where necessary

– Affiliates or successors in connection with a lawful corporate transaction

– Government authorities, courts or law-enforcement agencies where legally required or permitted

We do not sell personal data.

Information shared with healthcare or service providers will be limited to information reasonably required for the relevant service, subject to applicable law and the user’s permissions where required. Service providers processing data on our behalf must be contractually required to maintain confidentiality, security and lawful processing standards.

If personal data is transferred outside India, Doctri will comply with applicable restrictions, notifications and safeguards under Indian law.

7. Automated Processing and Artificial Intelligence

Doctri may use automated tools for scheduling, reminders, security, analytics, customer support or screening support. Such tools are not a substitute for professional medical judgment.

Where required by law, we will provide information about significant automated processing and available safeguards. Users may contact us at admin@doctri.in regarding material concerns about automated processing.

8. Data Security and Breach Notification

Doctri takes reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure, including access controls, authentication, encryption or equivalent safeguards where appropriate, logging, backups and vendor controls.

However, no internet-based system can be guaranteed to be completely secure.

If a personal-data breach occurs, Doctri will take steps required by applicable law, including assessing, containing, investigating and remediating the breach and notifying affected individuals and the Data Protection Board of India or other authorities where required.

Users should maintain the confidentiality of their account credentials and immediately inform Doctri if they suspect unauthorised access.

9. Data Retention and Erasure

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including providing services, maintaining healthcare and transaction records, resolving disputes, preventing fraud, complying with legal obligations and protecting our lawful interests.

Retention periods may differ depending on the type of information and applicable legal requirements. When personal data is no longer required, Doctri will delete it, anonymise it or securely dispose of it, unless retention is required or permitted by law.

Deletion requests may be refused or limited where retention is necessary for legal compliance, public health, medical records, fraud prevention, dispute resolution, exercise or defence of legal claims, or another lawful purpose.

10. Your Rights and Grievance Mechanism

Subject to applicable law, data principals may have the right to:

– Obtain information about processing of their personal data

– Request correction of inaccurate or incomplete personal data

– Request erasure of personal data where retention is not required

– Withdraw consent where processing is based on consent

– Nominate another individual to exercise rights in the event of death or incapacity, where provided by law

– Raise a grievance and seek a response within the period prescribed by applicable law

– Request information about relevant data processing and sharing

Requests may be submitted to:

Email: admin@doctri.in

Please include your name, registered contact details, the nature of the request and sufficient information to identify the relevant account or record. We may need to verify your identity or authority before processing a request.

We will acknowledge and address grievances within the period prescribed by applicable law. If you are dissatisfied with our response or do not receive a response within the prescribed period, you may exercise any statutory right to approach the Data Protection Board of India or another competent authority, as applicable.

11. Children's Information and Persons with Incapacity

If information relating to a child is provided, the person providing that information must have the appropriate parental or lawful authority and consent required under applicable law. Doctri will not knowingly undertake processing of a child’s personal data or targeted behavioural monitoring except in accordance with applicable law and required verifiable parental consent.

Where a person is unable to provide consent, the lawful guardian or authorised representative must act within the authority granted by law. Doctri may request evidence of such authority.

12. Cookies and Similar Technologies

Doctri may use cookies and similar technologies to operate the website, remember preferences, improve security, analyse usage and improve services.

Essential cookies may be used where necessary to provide a service requested by you, maintain security or enable core functionality. Non-essential analytics, advertising or preference cookies will be used only with consent where required by applicable law. You may withdraw or change cookie consent through the cookie settings tool or your browser settings.

Please refer to our separate Cookies Policy.

13. Third-Party Websites and Services

Our website or application may contain links to third-party websites or services.

Doctri is not responsible for the privacy practices, security or content of third-party websites. Users should review the privacy policies of those third parties before providing information.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be notified through the website, application, email, SMS or another appropriate channel where required by law.

The updated version will be published on the Doctri website with the revised “Last Updated” date. Where a new consent is legally required, we will obtain it before continuing the relevant processing.

15. Contact

For privacy-related questions, requests or grievances:

Doctri Healthcare Private Limited

Email: admin@doctri.in

Website: www.doctri.in