Privacy Policy
Last updated: July 2026
1. Who We Are
HealthKunj Clinics Private Limited (“HealthKunj”, “we”, “us”, or “our”) operates the website healthkunj.com, our patient portal, and related services (collectively, the “Services”) from Kharadi, Pune, India. This policy explains what personal and health information we collect through the Services, why, who we share it with, how long we keep it, and the rights you have over it.
2. Which Laws Govern This Policy
We are an Indian healthcare provider, and our primary legal obligation is India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000. This policy is written to meet those obligations.
If you are accessing our Services from the European Economic Area or UK, the rights described in Section 9 are written to align with the General Data Protection Regulation (GDPR) as a matter of good practice, even though GDPR does not independently govern an Indian clinic serving Indian patients.
We are not a covered entity or business associate under the U.S. Health Insurance Portability and Accountability Act (HIPAA) — HIPAA applies to U.S. healthcare providers, insurers, and their contractors, and we have no U.S. operations. We do not claim HIPAA compliance, and any reference to HIPAA-like safeguards below reflects general good-security-practice alignment, not a legal HIPAA obligation.
3. Information We Collect
Identity & contact information: name, email, phone number, city, and (if you sign in with Google) your Google account identifier.
Health & clinical information: the condition or chief complaint you tell us about, your case-intake questionnaire responses (symptoms, history, medications), consultation notes, prescribed remedies, clinical evaluation scores, and — if you choose to link it — your ABHA (Ayushman Bharat Health Account) ID and ABDM consent status. This is the most sensitive category of information we hold, and it is treated accordingly (see Section 7).
Uploaded documents: prescriptions, lab reports, and other medical documents you upload, stored as private files accessible only via short-lived signed links (15 minutes), never as public URLs.
Payment information: we never see or store your card number, CVV, or UPI PIN. Payments are handled entirely by Razorpay; we only retain a payment reference ID, amount, and status to reconcile your order or invoice.
Account & security data: a hashed (never plaintext) password, session and login-attempt records (IP address, device/browser identifier, timestamps) used to keep your account secure and detect abuse.
Technical & usage data: pages visited, browser type, and device information, collected automatically via Google Tag Manager–based analytics.
Cookies: see Section 8.
4. Consultations Involving Children
We treat infants and children for several conditions. If you are booking or providing information on behalf of a minor, you confirm that you are their parent or legal guardian and are consenting on their behalf. We do not knowingly collect information directly from a child without a parent or guardian’s involvement in the booking process.
5. How We Use Your Information
- To schedule, confirm, and conduct your appointments and consultations (in-clinic or telemedicine).
- To record your clinical case history, track your treatment progress, and let your doctor prescribe appropriate remedies.
- To process payments and issue invoices.
- To send appointment reminders, prescription/order updates, and — only if you opt in — health tips and promotional communications.
- To secure your account (fraud/abuse detection, login-attempt monitoring).
- To meet legal, tax, and medical record-keeping obligations.
6. Legal Basis for Processing
We process your personal data on the basis of your explicit, logged consent (captured at the point you submit a booking, contact, or intake form), and, where applicable, to perform the healthcare services you have requested from us. You may withdraw consent at any time; see Section 9.
7. Who We Share Information With
We do not sell your personal information. We share it only with the following categories of service providers, each solely to operate the Services:
- Razorpay — payment processing. Razorpay receives your card/UPI details directly; we never do.
- Google — sign-in (if you use “Continue with Google”) and website analytics (Google Tag Manager).
- Firebase Cloud Messaging — delivering appointment/order push notifications to our mobile app, if you have it installed. Used only for notification delivery, not analytics or advertising.
- Our email provider — transactional emails (appointment confirmations, receipts, account notices).
- Our WhatsApp/automation workflows — your name, phone number, and appointment or order metadata (never your clinical notes or case history) are used to send appointment reminders and order updates over WhatsApp.
- ABDM/ABHA registries — only if you actively choose to link your ABHA ID, in which case data is shared per the consent you give at that step, under India’s Ayushman Bharat Digital Mission framework.
We may also disclose information if required by law, court order, or to protect the rights, property, or safety of HealthKunj, our patients, or the public.
8. Cookies & Tracking
We use a small number of cookies, all described here honestly rather than generically:
- Essential cookies (
access_token,refresh_token) — keep you signed in. These are httpOnly (not readable by scripts) and strictly necessary; they cannot be disabled without signing out. - Analytics cookies — set via Google Tag Manager to understand site usage. These are not essential to using the site.
You can block or delete cookies in your browser settings at any time; blocking analytics cookies will not affect your ability to use the site, but blocking essential cookies will sign you out. We are working toward an on-site cookie consent control for analytics cookies; until it ships, please use your browser’s cookie controls if you wish to opt out of analytics.
9. Your Rights
You have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or outdated information — most of this you can update directly from your account.
- Erase your account — you can request deletion from your patient account settings, or by writing to us. This anonymises your identifying details (name, email, phone, photo, ABHA link) and deactivates your login immediately. Note: your clinical/consultation records are retained even after account erasure— Indian medical record-keeping regulations (National Medical Commission / CDSCO) require clinics to retain treatment records for a minimum period regardless of a patient’s account status; this is not optional on our part.
- Withdraw consent for any communications or optional data use (e.g. promotional messages) at any time, without affecting the lawfulness of processing already carried out.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity, as provided under the DPDP Act.
- Lodge a complaint with us first (Section 12), and, if unresolved, with the Data Protection Board of India.
10. How Long We Keep Your Information
- Clinical/consultation records: retained per Indian medical record-keeping requirements, independent of account status.
- Medical documents you upload: retained for 7 years.
- Payment/invoice records: retained for 8 years, per the Income Tax Act.
- Inactive accounts: anonymised approximately 3 years after your last activity, if not deleted sooner at your request.
- Login sessions: expire after 30 days.
- WhatsApp/automation metadata (name, phone — never clinical content): retained approximately 2 years.
- Conversations with our AI symptom-checker tools (Apps/HoSTs) are not stored beyond the session — only the resulting lead summary (name, contact, general topic) is kept, and it is not linked to your clinic patient record.
11. Where Your Data Is Stored, and Security
Your data is stored on Google Cloud Platform infrastructure in Singapore (asia-southeast1). If you access our Services from outside India, your data may be transferred to and processed in this location; we rely on our cloud provider’s standard data-processing and security safeguards for this.
We protect your information with:
- Passwords stored using industry-standard one-way hashing (bcrypt) — we cannot see or recover your password.
- Optional two-factor authentication (TOTP), mandatory for our clinical and administrative staff accounts.
- Account lockout after repeated failed login attempts.
- Private, access-controlled storage for medical documents, served only via short-lived signed links.
- Audit logging of access to clinical/patient records (who accessed what, and when — not the content itself).
- Encrypted connections (HTTPS/TLS) across the Services.
No method of storage or transmission over the internet is 100% secure, but we take these steps to reduce that risk materially.
12. Grievance Officer & Data Breach Notification
In accordance with the DPDP Act and IT Act rules, queries, complaints, or requests regarding your personal data should be directed to our Grievance Officer at contact@healthkunj.com or +91-9999930823. We aim to acknowledge requests within a reasonable time and resolve them promptly.
In the unlikely event of a personal data breach that poses a risk to you, we will notify the Data Protection Board of India and affected patients as required under the DPDP Act.
13. Changes to This Policy
We may update this Privacy Policy as our Services, legal obligations, or practices change. Material changes will update the “Last updated” date above; continued use of the Services after a change constitutes acceptance of the revised policy.
14. Contact Us
For any privacy-related queries, please contact us at contact@healthkunj.com or call +91-9999930823.