HA
Privacy

Privacy Policy

Effective Date: 26 April 2026  ·  Last Updated: 26 April 2026

Your health data is sensitive. Here is exactly how we collect, use, and protect it.

1. Overview

Homeo AI Clinic ("we", "us", "Platform") is committed to protecting the privacy and confidentiality of your personal and health data. This Privacy Policy describes how we collect, use, store, disclose, and protect information when you use homeoaiclinic.com. It is prepared in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Digital Personal Data Protection Act, 2023 ("DPDPA") of India.

2. Information We Collect

We collect the following categories of information: (a) Account Information: Name, email address, phone number, password (hashed), and role (patient/doctor). (b) Health & Clinical Data (Sensitive Personal Data): Symptom descriptions, medical history, uploaded tongue/facial/body images, medical reports (PDF/scanned), and audio recordings submitted by you for clinical analysis. This constitutes Sensitive Personal Data under the SPDI Rules. (c) Payment Information: Transaction IDs and payment status. We do not store full card numbers; all card processing is handled by PCI-DSS compliant third-party gateways (Stripe). (d) Usage Data: IP address, browser type, pages visited, timestamps, and session identifiers for security and performance purposes. (e) Communications: Any messages or queries sent to our support team.

4. How We Use Your Information

Your information is used to: (a) Deliver the AI-assisted clinical analysis service and facilitate physician review. (b) Process payments and issue receipts. (c) Communicate case status, prescriptions, and follow-up guidance via email or WhatsApp (where opted in). (d) Improve AI model accuracy and clinical output quality using anonymised, aggregated data only. (e) Comply with legal obligations and prevent fraud. (f) Send platform updates and security alerts. We do not use your health data for advertising, profiling, or sale to third parties.

5. Disclosure of Information

We share your information only in the following limited circumstances: (a) Treating Physician: The licensed BHMS doctor assigned to your case receives your submitted clinical data to review and issue a prescription. (b) Payment Processors: Stripe and other listed gateways receive payment information solely for transaction processing. (c) Communication Services: WhatsApp Business API or email service providers may receive your contact details to deliver case-related communications. (d) Legal Requirements: We may disclose data if compelled by law, court order, or government authority. (e) Business Transfers: In the event of a merger or acquisition, data may be transferred to the successor entity subject to the same privacy obligations. We do not sell, rent, or trade your personal or health data to any third party for commercial purposes.

6. Data Retention & Auto-Deletion

(a) Cases where an appointment is booked: Data is retained for the duration of the treatment relationship and for a minimum of 3 years thereafter to comply with medical record-keeping obligations under Indian law. (b) Cases where no appointment is booked after report delivery: Clinical data (images, reports, case notes) is automatically deleted within 30 days of report delivery, unless you request earlier deletion. (c) Account data: Retained for as long as your account is active. You may request account deletion at any time. (d) Payment records: Retained for 7 years to comply with GST and financial record-keeping requirements.

7. Data Security

We implement industry-standard security measures including: (a) Encryption of data in transit (TLS/HTTPS via Nginx + SSL) and at rest. (b) Hashed password storage (bcrypt) — plaintext passwords are never stored. (c) Role-based access controls limiting data access to authorised personnel only. (d) Redis session management with short-lived tokens. (e) Regular security audits and vulnerability assessments. (f) Containerised deployment (Docker) with network isolation. Despite these measures, no system is 100% secure. In the event of a data breach that is likely to cause harm, we will notify affected users and the relevant authority within the timeframe required by applicable law.

8. Your Rights

Under the DPDPA, 2023 and applicable Indian law, you have the right to: (a) Access: Request a copy of personal data we hold about you. (b) Correction: Request correction of inaccurate or incomplete data. (c) Erasure: Request deletion of your data (subject to legal retention obligations). (d) Withdrawal of Consent: Withdraw consent for data processing at any time. (e) Grievance Redressal: Lodge a complaint with our Grievance Officer (see Section 11). (f) Nominate: Designate a nominee to exercise your rights in the event of your incapacity or death (as provided under DPDPA). To exercise any right, email [email protected] with subject line "Privacy Request". We will respond within 30 days.

9. Cookies & Local Storage

We use strictly necessary cookies and browser local/session storage to maintain your authenticated session. We do not use third-party advertising or tracking cookies. You can configure your browser to block cookies, but this may prevent certain features from functioning correctly.

10. Children's Privacy

The Platform is not directed at children under 18 years of age without parental consent. We do not knowingly collect personal data from children under 13. If you believe a child has submitted data without consent, contact us immediately at [email protected] and we will delete it promptly.

11. Grievance Officer

In accordance with the Information Technology Act, 2000 and the SPDI Rules, the details of the Grievance Officer are: Name: Dr. G.K. Gyan (BHMS) Platform: Homeo AI Clinic Email: [email protected] Response Time: Within 30 days of receipt of complaint. If you are not satisfied with our resolution, you may escalate the matter to the Data Protection Board of India (once operational) as established under the Digital Personal Data Protection Act, 2023.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Platform at least 15 days before taking effect. The "Last Updated" date at the top of this page reflects the most recent revision. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.

Health Data Commitment: We never sell your health information. Clinical data is used exclusively to provide the consultation service you have requested. You retain ownership of all data you submit.

Homeo AI Clinic — homeoaiclinic.com  ·  Governed by the laws of India

← Back to Home