Privacy Policy
Effective Date: 26 April 2026 · Last Updated: 26 April 2026
Your health data is sensitive. Here is exactly how we collect, use, and protect it.
Table of Contents
1. Overview
Homeo AI Clinic ("we", "us", "Platform") is committed to protecting the privacy and confidentiality of your personal and health data. This Privacy Policy describes how we collect, use, store, disclose, and protect information when you use homeoaiclinic.com. It is prepared in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Digital Personal Data Protection Act, 2023 ("DPDPA") of India.
2. Information We Collect
We collect the following categories of information: (a) Account Information: Name, email address, phone number, password (hashed), and role (patient/doctor). (b) Health & Clinical Data (Sensitive Personal Data): Symptom descriptions, medical history, uploaded tongue/facial/body images, medical reports (PDF/scanned), and audio recordings submitted by you for clinical analysis. This constitutes Sensitive Personal Data under the SPDI Rules. (c) Payment Information: Transaction IDs and payment status. We do not store full card numbers; all card processing is handled by PCI-DSS compliant third-party gateways (Stripe). (d) Usage Data: IP address, browser type, pages visited, timestamps, and session identifiers for security and performance purposes. (e) Communications: Any messages or queries sent to our support team.
3. Legal Basis for Processing
We process your data on the following legal bases under Indian law: (a) Consent: You provide explicit informed consent before submitting health data. You may withdraw consent at any time, though this may prevent us from providing the service. (b) Contractual Necessity: Processing required to fulfil the consultation service you have paid for. (c) Legitimate Interests: Fraud prevention, platform security, and service improvement — balanced against your privacy rights. (d) Legal Obligation: Where required by applicable law or court order.
4. How We Use Your Information
Your information is used to: (a) Deliver the AI-assisted clinical analysis service and facilitate physician review. (b) Process payments and issue receipts. (c) Communicate case status, prescriptions, and follow-up guidance via email or WhatsApp (where opted in). (d) Improve AI model accuracy and clinical output quality using anonymised, aggregated data only. (e) Comply with legal obligations and prevent fraud. (f) Send platform updates and security alerts. We do not use your health data for advertising, profiling, or sale to third parties.
6. Data Retention & Auto-Deletion
(a) Cases where an appointment is booked: Data is retained for the duration of the treatment relationship and for a minimum of 3 years thereafter to comply with medical record-keeping obligations under Indian law. (b) Cases where no appointment is booked after report delivery: Clinical data (images, reports, case notes) is automatically deleted within 30 days of report delivery, unless you request earlier deletion. (c) Account data: Retained for as long as your account is active. You may request account deletion at any time. (d) Payment records: Retained for 7 years to comply with GST and financial record-keeping requirements.
7. Data Security
We implement industry-standard security measures including: (a) Encryption of data in transit (TLS/HTTPS via Nginx + SSL) and at rest. (b) Hashed password storage (bcrypt) — plaintext passwords are never stored. (c) Role-based access controls limiting data access to authorised personnel only. (d) Redis session management with short-lived tokens. (e) Regular security audits and vulnerability assessments. (f) Containerised deployment (Docker) with network isolation. Despite these measures, no system is 100% secure. In the event of a data breach that is likely to cause harm, we will notify affected users and the relevant authority within the timeframe required by applicable law.
8. Your Rights
Under the DPDPA, 2023 and applicable Indian law, you have the right to: (a) Access: Request a copy of personal data we hold about you. (b) Correction: Request correction of inaccurate or incomplete data. (c) Erasure: Request deletion of your data (subject to legal retention obligations). (d) Withdrawal of Consent: Withdraw consent for data processing at any time. (e) Grievance Redressal: Lodge a complaint with our Grievance Officer (see Section 11). (f) Nominate: Designate a nominee to exercise your rights in the event of your incapacity or death (as provided under DPDPA). To exercise any right, email [email protected] with subject line "Privacy Request". We will respond within 30 days.
10. Children's Privacy
The Platform is not directed at children under 18 years of age without parental consent. We do not knowingly collect personal data from children under 13. If you believe a child has submitted data without consent, contact us immediately at [email protected] and we will delete it promptly.
11. Grievance Officer
In accordance with the Information Technology Act, 2000 and the SPDI Rules, the details of the Grievance Officer are: Name: Dr. G.K. Gyan (BHMS) Platform: Homeo AI Clinic Email: [email protected] Response Time: Within 30 days of receipt of complaint. If you are not satisfied with our resolution, you may escalate the matter to the Data Protection Board of India (once operational) as established under the Digital Personal Data Protection Act, 2023.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Platform at least 15 days before taking effect. The "Last Updated" date at the top of this page reflects the most recent revision. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.
Related Legal Documents
Homeo AI Clinic — homeoaiclinic.com · Governed by the laws of India
← Back to Home