Draft document — Fields marked [TBD] must be completed before the app goes live. Pending legal review.

Legal

Privacy Policy

Effective date: [TBD] Last updated: [TBD] DPDP Act 2023 compliant

01

Who We Are

Siha ("we", "us", "our") is a healthcare appointment management platform operated by [COMPANY LEGAL NAME], a company incorporated under the Companies Act 2013, with its registered office at [REGISTERED ADDRESS], India.

We act as the Data Fiduciary under the DPDP Act 2023 for all personal data processed through the Siha mobile application and associated services.

For questions about this policy, contact us at support@sihahealth.in.

02

Data We Collect

We collect two categories of data, kept separate by design through pseudonymization.

2.1 Personal Identification Information (PII)

Collected at registration and stored separately from your medical records:

DataPurposeRequired
Full nameDisplay and identityYes
AgeHealthcare contextYes
GenderHealthcare contextYes
Blood groupHealthcare contextYes
Phone numberAuthentication via OTPYes
Email addressOptional contactNo
Profile photographIdentity displayNo

2.2 Health & Medical Data

Stored under a pseudonymous ID — not directly linked to your name in our database:

DataPurpose
Appointment recordsBooking management
Consultation notes written by your doctorMedical history reference
Prescription photographs uploaded by youPersonal health records
Blood report images and extracted valuesHealth analytics

2.3 Technical Data

DataPurpose
Device FCM tokenPush notifications
Approximate GPS locationFinding nearby doctors
App usage logsBug fixing and improvement
Crash reportsApp stability

2.4 Doctor Data

Collected when a doctor is registered on the platform. Medical license numbers are used solely for internal verification and are not displayed to patients.

DataPurposeRequired
Full nameProfile display to patientsYes
Phone numberAuthentication and account identityYes
Medical specializationSearch and profile displayYes
Medical qualificationProfile displayYes
Years of experienceProfile displayYes
Medical license numberIdentity verificationYes
Profile photographProfile display to patientsNo
Languages spokenProfile displayNo

2.5 Clinic & Receptionist Data

Collected when a receptionist registers their clinic. Clinic license numbers are used solely for internal verification and are not displayed publicly.

DataPurposeRequired
Receptionist nameAccount identityYes
Clinic contact phone numberAuthentication and patient-facing contactYes
Clinic nameSearch and profile displayYes
Clinic address and locationSearch and distance displayYes
Clinic license numberIdentity verificationYes

2.6 Walk-in Patient Data

When a receptionist creates an offline booking for a patient without a Siha account, only minimal information is recorded. No Siha account is created. If a walk-in patient later creates an account with the same phone number, their offline appointment history will become visible.

DataPurposeRequired
Patient nameAppointment recordYes
AgeClinical contextYes
GenderClinical contextYes
Phone numberRecord linkage if account created laterNo

03

How We Use Your Data

We use your data only for the following purposes:

  1. Authentication — verifying your identity via OTP
  2. Appointment management — booking, confirming, rescheduling, and cancelling appointments
  3. Health records — storing consultation notes and prescription photos for your reference
  4. Health analytics — displaying trends from your uploaded blood reports
  5. Notifications — appointment reminders via push notification and WhatsApp
  6. Finding doctors — using your location to show nearby available doctors
  7. Platform improvement — anonymized, aggregated usage data to improve the app
  8. Doctor and clinic verification — verifying license numbers before listing on the platform
  9. Staff notifications — appointment alerts to doctors and receptionists

We do not use your data for advertising, profiling, or selling to third parties.

04

Legal Basis for Processing

Under the DPDP Act 2023, we process your personal data on the basis of your explicit, informed consent, given at the time of registration.

  • You may withdraw consent at any time by deleting your account (see §8.3)
  • Withdrawal of consent will result in permanent deletion of all your data
  • Certain data may be retained for a limited period where required by applicable law

05

Data Sharing & Third Parties

We share your data with the following third-party processors solely for service delivery. All processors are contractually bound to process data only as instructed, maintain security standards, and never use your data for their own purposes.

Third PartyData SharedPurpose
Google Firebase (Google LLC)All app dataCloud storage, authentication, push notifications
Google Cloud Vision APIBlood report imagesOCR text extraction for analytics
Gupshup Technologies Pvt. Ltd.Phone number, appointment detailsWhatsApp reminder messages
Siha Health (WhatsApp Business)Phone number, appointment timeMessage delivery

We do not sell your data to any third party.

5.1 Doctor Access

The doctor associated with your appointment can view your consultation notes (written by them), prescription photos you choose to upload, and your first name, age, and gender for clinical context. Doctors cannot access your phone number, email, or records from other doctors' appointments.

5.2 Receptionist Access

Clinic receptionists can view your appointment date, time, status, and first name for check-in. Receptionists cannot access consultation notes, prescription photos, blood reports, or any medical data.

5.3 Internal Admin Access

Our internal team accesses doctor and clinic license numbers solely to verify credentials before approving a listing. This is limited to authorised personnel and is not shared externally.

5.4 Walk-in Patient Data

Walk-in patient details are visible only to the receptionist who entered them and the doctor associated with that appointment.

5.5 Cross-Border Data Transfer

Your data is stored on Google Firebase servers. Firebase data for Indian users is hosted in the asia-south1 (Mumbai) region. Some Firebase services may process data in other regions. Google complies with applicable data protection laws for cross-border transfers.

06

Data Retention

Data TypeRetention Period
Account & PII dataUntil you delete your account
Appointment recordsUntil you delete your account
Consultation notesUntil you delete your account
Prescription photosUntil you delete your account
Blood report dataUntil you delete your account
Technical / crash logs90 days
Anonymized aggregate analyticsIndefinitely (cannot be linked to you)
Doctor profile and license dataUntil doctor account is removed
Clinic and receptionist dataUntil clinic account is removed
Walk-in patient appointment recordsUntil associated clinic account is removed

Upon account deletion, all identifiable data is permanently deleted within 30 days.

07

Security Measures

  • Pseudonymization — your identity and medical records are stored separately, linked only by an anonymous internal ID
  • Encryption at rest — all data stored in Firebase is encrypted using AES-256
  • Encryption in transit — all data uses TLS 1.2 or higher
  • Access controls — role-based access ensures each user type sees only what they are authorised for
  • Authentication — all access requires OTP-verified phone authentication
  • Audit logging — access to medical records is logged

In the event of a data breach likely to affect your rights, we will notify you and the Data Protection Board of India within the prescribed timeframe.

08

Your Rights Under the DPDP Act 2023

8.1 Right to Access

You can view all your profile data within the app at any time.

8.2 Right to Correction

You can update your name, age, gender, blood group, email, and profile photo from the Profile screen in the app.

8.3 Right to Erasure

Delete your account from Profile → "Delete Account". This action is irreversible, permanently removes all personal data and medical records, and is completed within 30 days.

8.4 Right to Grievance Redressal

Contact our Grievance Officer (see §10). We will acknowledge within 3 business days and resolve within 30 days. Unresolved grievances may be escalated to the Data Protection Board of India once constituted.

8.5 Right to Nominate

You may nominate another individual to exercise your data rights in the event of your death or incapacity. Contact support@sihahealth.in to register a nominee.

8.6 Consent Withdrawal

You may withdraw consent at any time by deleting your account. Note that this makes it impossible for us to continue providing services.

8.7 Rights for Doctors & Receptionists

Doctors can update their specialization, qualification, experience, languages, and profile photo in-app. Name and license number changes require contacting support@sihahealth.in. To remove a doctor or clinic account, contact us — appointment records are retained for patient medical history.

Walk-in patients without a Siha account can request data access, correction, or deletion by contacting support@sihahealth.in with their name and appointment date.

09

Children's Privacy

Our platform is open to users of all ages including individuals under 18. We collect no data beyond what is listed in §2 from any user, regardless of age. If you believe a child's data has been collected inappropriately, contact support@sihahealth.in.

10

Grievance Officer

As required under the DPDP Act 2023 and the IT Act 2000:

Name Nechiketh Surendran
Designation Co-Founder
Address [COMPANY ADDRESS] — TBD
Hours Monday – Friday, 10:00 AM – 6:00 PM IST

Grievances will be acknowledged within 3 business days and resolved within 30 days.

11

Changes to This Policy

  • The "Last Updated" date at the top will be revised on any change
  • Significant changes will be communicated via push notification or in-app prompt
  • Continued use of the app after changes constitutes acceptance of the revised policy

12

Contact Us

[COMPANY LEGAL NAME]
[REGISTERED ADDRESS]
Email: support@sihahealth.in
Phone: +91 96060 50789

This document was drafted to comply with the Digital Personal Data Protection Act 2023 (India), the Information Technology Act 2000, and the IT (SPDI) Rules 2011. It must be reviewed and approved by a qualified legal professional before publication.