Privacy Policy
We are committed to protecting personal data handled through our platform, in line with DPDPA 2023, IT Act 2000, IT (SPDI) Rules 2011, ABDM-style expectations, and MoHFW EHR standards.
Effective date: 1 April 2025 · Last updated: 14 April 2026
1. Introduction
DrForYou Care is a hospital management platform designed for clinics, hospitals, and healthcare groups in India. This Privacy Policy explains how we collect, use, store, disclose, and protect personal data through our marketing website, demo workflows, and subscribed software platform.
2. Who We Are
For website visitors, enquiry contacts, and staff users, DrForYou may act as a data fiduciary. For patient records entered by client organisations, DrForYou acts as a data processor operating only under client instructions and contractual scope.
3. Data We Collect
- Website and demo enquiry data such as name, organisation, email, and phone number
- Platform staff account details including role, work contact information, and credential metadata
- Patient data entered by subscribed healthcare organisations, including identifiers, visit notes, vitals, investigations, prescriptions, billing, and consent artefacts
- Operational logs such as user identity, timestamp, IP address, action history, and audit information
4. How We Use Data
We use personal data to respond to demo requests, provide and secure the platform, maintain role-based access, support audit trails, fulfil regulatory requirements, improve reliability, and operate approved healthcare workflows. Patient health data is not used for unrelated marketing or profiling.
5. Data Sharing
We do not sell personal data. Data may be shared only with approved sub-processors, authorised healthcare clients controlling their own patient records, lawful authorities where required, or consent-driven health information exchange systems where applicable.
6. Data Security
- Encryption in transit and protected storage strategies at rest
- JWT-style authentication and bcrypt-hashed credentials
- Role-based access control across operational modules
- Immutable audit logging and traceability
- India-hosted infrastructure strategy for operational control
- Regular dependency maintenance and security review practices
7. Breach Notification
If a personal data breach occurs, DrForYou will investigate, document, contain, and notify affected clients and appropriate parties in line with contractual commitments and applicable Indian legal requirements.
8. Data Retention
- Website enquiries: typically retained for a limited sales-cycle period
- Platform staff records: retained for subscription duration plus necessary audit retention
- Patient records: retained according to client agreements and applicable regulations
- Audit trails: preserved for compliance and dispute resolution needs
9. Rights Under DPDPA 2023
Depending on the processing context, individuals may have rights relating to information, correction, erasure, grievance redressal, nomination, and consent withdrawal. Where DrForYou acts only as a processor, patient requests should usually be directed through the relevant healthcare provider.
11. Children’s Privacy
Patient records for minors may be processed only through authorised healthcare workflows. Client organisations remain responsible for obtaining guardian consent wherever required by law.
12. Changes to This Policy
This policy may be updated as practices, legal requirements, or product capabilities change. Material changes should be communicated clearly to active clients before taking effect.
13. Grievance Officer
For privacy questions or complaints, contact hello@drforyou.in. Before public launch, this page should be updated with final grievance officer details, response timelines, and lawyer-reviewed escalation language.
Questions about data privacy?
Our team can walk you through how DrForYou handles operational, staff, and patient data in your organisation.