This Privacy Policy explains how DoctoGuide ("we", "us") collects, uses, and protects your personal information when you use the Service. We process personal data in accordance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).
1. Who we are (Data Fiduciary)
[Legal entity name — to be confirmed] (registered at [Registered address — to be confirmed]) is the data fiduciary responsible for your personal data.
2. Information we collect
- Account details: your name, mobile number, and a 4-digit PIN (stored only in hashed form).
- Health information you provide: age, biological sex, symptoms, and the messages you send during a consultation. This is sensitive personal data.
- Generated content: the health summaries we create for you.
- Location: a city/area you type, or device location (only if you grant permission) — used solely to find nearby doctors.
- Technical data: a session identifier and basic device/usage data needed to run the Service.
- Approximate location from your IP address: we detect your approximate country from your IP address using third-party geolocation services (geojs.io and ipwho.is) so we can show you the right local emergency numbers and localised content.
3. Why we use it (purposes)
- To run the symptom interview and generate your health summary.
- To let you create an account and revisit your past consultations.
- To show you doctors near your chosen location.
- To maintain security and improve the Service.
We use your data only for these purposes and do not sell it.
4. Consent
We process your health information on the basis of your consent, which you give before your first interaction and when you create an account. You may withdraw consent at any time (see "Your rights"); withdrawal does not affect processing done before withdrawal.
5. Sharing
We do not sell your personal data. We may share limited data with service providers who help us operate the Service (e.g. hosting, AI processing, map/ directory providers for doctor search) under appropriate safeguards, and where required by law. Doctor listings are retrieved from third-party directories; we do not share your health information with them.
6. Storage & security
Your data is stored on secured servers. PINs are stored using one-way hashing. We apply reasonable security practices to protect your information, though no system is completely secure. [Hosting/data location — to be confirmed]
7. Retention
We keep your personal and health data only as long as needed for the purposes above or as required by law, after which it is deleted or anonymised. [Specific retention periods — to be confirmed]
8. Your rights
- Access and correct your personal data.
- Withdraw consent and request deletion of your data.
- Nominate another person to exercise your rights (as provided under the DPDP Act).
- Raise a grievance with us.
To exercise any right, contact us at [privacy contact email — to be confirmed].
9. Children
The Service is for adults (18+). We do not knowingly process the data of children without lawful consent.
10. Grievance Officer
In accordance with the DPDP Act and IT Rules, you can contact our Grievance Officer: [Grievance Officer name — to be confirmed] ([Grievance Officer email — to be confirmed]), who will respond within [response timeline — to be confirmed].
11. Changes
We may update this policy and will post the updated version here.
This document is a draft pending review by a qualified Indian healthcare/privacy lawyer and does not constitute legal advice. Bracketed items must be completed before launch.