1. Who This Policy Covers
This Privacy Policy explains how Privea Med Global ("we," "us," "our"), operator of The Healthcare Portal (the "Platform"), collects, uses, shares, and protects personal information when you use the Platform as a Patient, Provider, Strategic Partner, Institutional Partner, or visitor. It applies wherever you access the Platform from. It should be read together with our Terms & Conditions.
2. Information We Collect
| Category | Examples |
|---|---|
| Identity & contact | Name, date of birth, email, phone number, postal address, government ID (where required for treatment or cross-border travel documentation) |
| Account & usage | Login credentials, device information, IP address, pages viewed, booking history |
| Health information | Medical history, symptoms, diagnoses, treatment records, clinical images, medication history — see Section 3 |
| Payment information | Payment method details (processed by our payment partner, not stored by us directly — see Section 9), billing address, transaction history |
| Communications | Messages exchanged through Platform messaging, support enquiries, reviews |
| Provider & Partner business data | Licensing and accreditation documents, facility details, staff credentials, institutional agreements |
| Travel & logistics | Itinerary details, accommodation bookings, where you use Concierge Services through the Platform |
3. Health Information — Special Category Data
Health information you provide is shared only with the specific Provider(s) involved in your care, and, where applicable, with an Institutional Partner that referred you, under the data-sharing terms of that referral. We do not sell health information, and we do not use it for advertising or marketing profiling.
4. How We Use Your Information
- To create and manage your account and facilitate bookings between Patients and Providers
- To process payments and manage the milestone-based escrow described in our Terms & Conditions
- To verify Provider, Partner, and Institutional credentials
- To provide customer support and respond to enquiries
- To send booking confirmations, treatment reminders, and service communications
- To monitor for fraud, safety issues, and attempts to circumvent the Platform (see Section 15)
- To comply with legal, tax, and regulatory obligations
- To improve the Platform, in aggregated or de-identified form wherever possible
5. Legal Basis for Processing
Where applicable law requires a stated legal basis (including under the GDPR, for users accessing from the UK or EU), we rely on: performance of a contract with you (facilitating your booking), your explicit consent (particularly for health information), our legitimate interests (fraud prevention, service improvement), and compliance with legal obligations. You may withdraw consent given for a specific purpose at any time, without affecting the lawfulness of processing already carried out.
6. Who We Share Information With
| Recipient | What's shared, and why |
|---|---|
| Your selected Provider(s) | Identity, contact, and health information necessary for the consultation or treatment you've requested |
| Institutional Partner (if referred through one) | Referral and treatment-progress information, under that Partner's framework agreement |
| Payment processor [Razorpay] | Transaction data necessary to process and hold payment under the milestone structure |
| Allied service providers | Booking details for hotels, transport, or recovery-centre services you choose to book through the Platform |
| Regulators and authorities | Where required by law, court order, or to protect safety |
| Professional advisors | Auditors, lawyers, insurers, where necessary for their engagement |
We do not sell personal information to third parties for their own marketing purposes.
7. International Data Transfers
Because Patients, Providers, and Partners are located across many countries, personal information is regularly transferred internationally — most significantly, into India, where treatment coordination and our primary systems are based. Where we transfer personal data out of the UK, EU, or another jurisdiction with its own cross-border transfer restrictions, we rely on the safeguard mechanism required by that jurisdiction's law (such as Standard Contractual Clauses under the GDPR, or an equivalent adequacy or contractual mechanism), details of which are available on request from our Grievance Officer.
8. Contact Protection Between Patients and Providers
To protect your privacy and safety before a booking is confirmed, direct contact details (phone number, personal email) are masked within Platform messaging between Patients and Providers. This is both a privacy safeguard and, as explained in our Terms & Conditions, a measure to keep the milestone payment protections in effect. Full contact details are exchanged once a booking is confirmed, to the extent necessary to coordinate treatment.
9. Payment Information
We do not store your full card or bank details on our own servers. Payment information is collected and processed directly by our payment processing partner [Razorpay], which is subject to its own applicable payment-industry security standards (including PCI-DSS). We receive and retain transaction records (amount, status, milestone stage) but not the underlying payment instrument details.
10. Data Retention
We retain personal information for as long as necessary to fulfil the purposes described in this Policy, including any applicable legal, tax, medical-record, or accounting retention period required in India or the jurisdiction where treatment occurred [specify applicable medical-record retention periods]. Where you close your account, we retain the minimum information necessary for legal compliance and delete or anonymise the rest within [a stated period].
11. Your Rights
Subject to applicable law in your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your information, subject to our legal retention obligations
- Restrict or object to certain processing
- Port your data to another service, in a structured, machine-readable format, where technically feasible
- Withdraw consent previously given, particularly for health information
To exercise any of these rights, contact our Grievance Officer under Section 19. We will respond within the timeframe required by applicable law [e.g., 30 days under India's DPDP Act; one month under GDPR].
12. Security Measures
We use encryption in transit and at rest for sensitive data, role-based access controls limiting who can view a given patient record, and access logging. No system is completely secure, and we cannot guarantee absolute security, but we take reasonable, industry-standard measures to protect your information and review these measures periodically.
13. Cookies and Tracking
We use cookies and similar technologies for essential Platform functionality (keeping you logged in, remembering preferences) and, where you consent, for analytics to understand how the Platform is used. You can control cookies through your browser settings; disabling essential cookies may affect Platform functionality. [Insert cookie table / link to cookie preference centre if applicable.]
14. Children's Privacy
The Platform is not directed at children under 18 for independent use. Where treatment for a minor is being arranged, the account and all consents are held by the minor's parent or legal guardian, who is responsible for the minor's information provided through the Platform.
15. Automated Decision-Making and AI Monitoring
We use automated pattern-detection, including AI-based tools, to monitor Platform messaging for indicators of attempted circumvention (arranging bookings or payment outside the Platform), consistent with Section 11 of our Terms & Conditions. This monitoring flags patterns for human review; it does not make final account-suspension decisions without human oversight. We do not use automated systems to make solely automated decisions about your medical eligibility or treatment.
16. Region-Specific Rights
16.1 India — Digital Personal Data Protection Act, 2023
If you are located in India, you have rights under the DPDP Act, 2023, including the right to access, correct, and erase your personal data, and to nominate another individual to exercise your rights in the event of death or incapacity. Our Grievance Officer (Section 19) is your contact point for these rights.
16.2 European Economic Area / United Kingdom — GDPR
If you are located in the EEA or UK, you have the rights described in Section 11 under the GDPR/UK GDPR, and the right to lodge a complaint with your local data protection supervisory authority.
16.3 Other Jurisdictions
[Add specific clauses as needed for other significant patient-origin countries — e.g., Kenya's Data Protection Act 2019, Nigeria's NDPR, Canada's PIPEDA, or U.S. state privacy laws — once your legal counsel has confirmed which apply based on actual patient volumes from each country.]
17. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify affected individuals and the relevant regulatory authority within the timeframe required by applicable law, and will describe the nature of the breach, the information affected, and the steps we are taking in response.
18. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified through the Platform or by email at least [15 days] before taking effect. The "Effective Date" at the top of this page reflects the most recent version.
19. Contact Us / Grievance Officer
For any question about this Privacy Policy, or to exercise your rights under Section 11, contact our Grievance Officer:
[Name]
[Email address]
Privea Med Global, [registered office address]