Siha is a healthcare appointment platform operated by [COMPANY LEGAL NAME], incorporated under the Companies Act 2013, registered office at [REGISTERED ADDRESS], India.
We are the Data Fiduciary under the DPDP Act 2023 for all data processed through the Siha app and related services. Questions: support@sihahealth.in.
Two categories, kept apart by design. Your identity sits in one place; your medical data sits under a pseudonymous ID that is not directly linked to your name.
Name, age, gender and blood group for healthcare context. Phone number for OTP sign-in. Email and profile photo are optional.
Stored separately from medical records.
Appointment records, consultation notes written by your doctor, prescription photographs you upload, and blood report images with the values read from them.
Device notification token, approximate location to find doctors near you, app usage logs and crash reports.
Doctors give name, phone, specialization, qualification, experience and medical licence number. Clinics give the receptionist's name, clinic name, address and clinic licence number. Licence numbers are used only for our internal verification and are never displayed.
For a walk-in booked at the desk we record only name, age, gender and optionally a phone number. No account is created. If that person later signs up with the same number, those past appointments become visible to them.
We do not use your data for advertising or profiling, and we do not sell it.
We process your data on the basis of the explicit, informed consent you give at registration. You can withdraw it at any time by deleting your account, which permanently deletes your data — some records may be kept for a limited period where the law requires it.
Withdrawing consent means we can no longer provide the service.
Four processors, each contractually bound to use your data only as we instruct and never for their own purposes.
Sees the notes they wrote, prescriptions you chose to upload, and your first name, age and gender for clinical context. Not your phone number, not your email, and nothing from another doctor's appointments.
Sees your appointment date, time, status and first name, for check-in. No consultation notes, no prescriptions, no reports, no medical data of any kind.
Authorised staff see doctor and clinic licence numbers to verify credentials before approving a listing. Nothing is shared outside.
On Google Firebase, in the asia-south1 (Mumbai) region for Indian users. Some Firebase services may process data in other regions under Google's cross-border safeguards.
When you delete your account, identifiable data is permanently deleted within 30 days.
If a breach is likely to affect your rights, we will notify you and the Data Protection Board of India within the prescribed time.
All your profile data is visible in the app, and you can change your name, age, gender, blood group, email and photo from the Profile screen.
Profile → Delete Account. It is irreversible, removes your personal data and medical records, and completes within 30 days.
Our Grievance Officer acknowledges within 3 business days and resolves within 30. Unresolved grievances can be escalated to the Data Protection Board of India once constituted.
You may nominate a person to exercise your rights if you die or become incapacitated — write to support@sihahealth.in.
Doctors can edit specialization, qualification, experience, languages and photo in-app; name and licence changes go through us. To remove a doctor or clinic account, write to us — appointment records stay for patients' medical history. Walk-in patients without an account can ask for access, correction or deletion by writing with their name and appointment date.
Siha is open to users of all ages, including under-18s, and we collect nothing beyond what is listed in section 02 from anyone. If you believe a child's data has been collected inappropriately, write to support@sihahealth.in.
As required under the DPDP Act 2023 and the IT Act 2000.
The "last updated" date above changes whenever this policy does. Anything significant is announced by push notification or an in-app prompt. Continuing to use the app after a change means you accept the revised policy.