The healthcare Portal
Legal
Privacy Policy
Effective Date: [DATE]  ·  Version 1.0  ·  Operated by Privea Med Global
Drafting note, not part of the published document: health data is treated as a special, sensitive category under nearly every major privacy law — India's DPDP Act 2023, the EU/UK GDPR, and equivalents across other countries your patients travel from. This draft is built to the general shape those laws share, but the specific consent mechanics, retention periods, and cross-border transfer safeguards need sign-off from a privacy lawyer in India and in your significant patient-origin countries before publication. Bracketed items [LIKE THIS] need real details filled in.
Contents
  1. Who This Policy Covers
  2. Information We Collect
  3. Health Information — Special Category Data
  4. How We Use Your Information
  5. Legal Basis for Processing
  6. Who We Share Information With
  7. International Data Transfers
  8. Contact Protection Between Patients and Providers
  9. Payment Information
  10. Data Retention
  11. Your Rights
  12. Security Measures
  13. Cookies and Tracking
  14. Children's Privacy
  15. Automated Decision-Making and AI Monitoring
  16. Region-Specific Rights
  17. Data Breach Notification
  18. Changes to This Policy
  19. Contact Us / Grievance Officer
1. Who This Policy Covers

This Privacy Policy explains how Privea Med Global ("we," "us," "our"), operator of The Healthcare Portal (the "Platform"), collects, uses, shares, and protects personal information when you use the Platform as a Patient, Provider, Strategic Partner, Institutional Partner, or visitor. It applies wherever you access the Platform from. It should be read together with our Terms & Conditions.

2. Information We Collect
CategoryExamples
Identity & contactName, date of birth, email, phone number, postal address, government ID (where required for treatment or cross-border travel documentation)
Account & usageLogin credentials, device information, IP address, pages viewed, booking history
Health informationMedical history, symptoms, diagnoses, treatment records, clinical images, medication history — see Section 3
Payment informationPayment method details (processed by our payment partner, not stored by us directly — see Section 9), billing address, transaction history
CommunicationsMessages exchanged through Platform messaging, support enquiries, reviews
Provider & Partner business dataLicensing and accreditation documents, facility details, staff credentials, institutional agreements
Travel & logisticsItinerary details, accommodation bookings, where you use Concierge Services through the Platform
3. Health Information — Special Category Data
Medical and health-related information is treated as a special category of sensitive personal data and is handled with additional safeguards beyond our general data practices. We collect it only where necessary to facilitate a consultation, quote, or treatment you have requested, and only with your explicit consent, given separately from your general acceptance of these policies at the point health information is first requested.

Health information you provide is shared only with the specific Provider(s) involved in your care, and, where applicable, with an Institutional Partner that referred you, under the data-sharing terms of that referral. We do not sell health information, and we do not use it for advertising or marketing profiling.

4. How We Use Your Information
  • To create and manage your account and facilitate bookings between Patients and Providers
  • To process payments and manage the milestone-based escrow described in our Terms & Conditions
  • To verify Provider, Partner, and Institutional credentials
  • To provide customer support and respond to enquiries
  • To send booking confirmations, treatment reminders, and service communications
  • To monitor for fraud, safety issues, and attempts to circumvent the Platform (see Section 15)
  • To comply with legal, tax, and regulatory obligations
  • To improve the Platform, in aggregated or de-identified form wherever possible
5. Legal Basis for Processing

Where applicable law requires a stated legal basis (including under the GDPR, for users accessing from the UK or EU), we rely on: performance of a contract with you (facilitating your booking), your explicit consent (particularly for health information), our legitimate interests (fraud prevention, service improvement), and compliance with legal obligations. You may withdraw consent given for a specific purpose at any time, without affecting the lawfulness of processing already carried out.

6. Who We Share Information With
RecipientWhat's shared, and why
Your selected Provider(s)Identity, contact, and health information necessary for the consultation or treatment you've requested
Institutional Partner (if referred through one)Referral and treatment-progress information, under that Partner's framework agreement
Payment processor [Razorpay]Transaction data necessary to process and hold payment under the milestone structure
Allied service providersBooking details for hotels, transport, or recovery-centre services you choose to book through the Platform
Regulators and authoritiesWhere required by law, court order, or to protect safety
Professional advisorsAuditors, lawyers, insurers, where necessary for their engagement

We do not sell personal information to third parties for their own marketing purposes.

7. International Data Transfers

Because Patients, Providers, and Partners are located across many countries, personal information is regularly transferred internationally — most significantly, into India, where treatment coordination and our primary systems are based. Where we transfer personal data out of the UK, EU, or another jurisdiction with its own cross-border transfer restrictions, we rely on the safeguard mechanism required by that jurisdiction's law (such as Standard Contractual Clauses under the GDPR, or an equivalent adequacy or contractual mechanism), details of which are available on request from our Grievance Officer.

8. Contact Protection Between Patients and Providers

To protect your privacy and safety before a booking is confirmed, direct contact details (phone number, personal email) are masked within Platform messaging between Patients and Providers. This is both a privacy safeguard and, as explained in our Terms & Conditions, a measure to keep the milestone payment protections in effect. Full contact details are exchanged once a booking is confirmed, to the extent necessary to coordinate treatment.

9. Payment Information

We do not store your full card or bank details on our own servers. Payment information is collected and processed directly by our payment processing partner [Razorpay], which is subject to its own applicable payment-industry security standards (including PCI-DSS). We receive and retain transaction records (amount, status, milestone stage) but not the underlying payment instrument details.

10. Data Retention

We retain personal information for as long as necessary to fulfil the purposes described in this Policy, including any applicable legal, tax, medical-record, or accounting retention period required in India or the jurisdiction where treatment occurred [specify applicable medical-record retention periods]. Where you close your account, we retain the minimum information necessary for legal compliance and delete or anonymise the rest within [a stated period].

11. Your Rights

Subject to applicable law in your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your information, subject to our legal retention obligations
  • Restrict or object to certain processing
  • Port your data to another service, in a structured, machine-readable format, where technically feasible
  • Withdraw consent previously given, particularly for health information

To exercise any of these rights, contact our Grievance Officer under Section 19. We will respond within the timeframe required by applicable law [e.g., 30 days under India's DPDP Act; one month under GDPR].

12. Security Measures

We use encryption in transit and at rest for sensitive data, role-based access controls limiting who can view a given patient record, and access logging. No system is completely secure, and we cannot guarantee absolute security, but we take reasonable, industry-standard measures to protect your information and review these measures periodically.

13. Cookies and Tracking

We use cookies and similar technologies for essential Platform functionality (keeping you logged in, remembering preferences) and, where you consent, for analytics to understand how the Platform is used. You can control cookies through your browser settings; disabling essential cookies may affect Platform functionality. [Insert cookie table / link to cookie preference centre if applicable.]

14. Children's Privacy

The Platform is not directed at children under 18 for independent use. Where treatment for a minor is being arranged, the account and all consents are held by the minor's parent or legal guardian, who is responsible for the minor's information provided through the Platform.

15. Automated Decision-Making and AI Monitoring

We use automated pattern-detection, including AI-based tools, to monitor Platform messaging for indicators of attempted circumvention (arranging bookings or payment outside the Platform), consistent with Section 11 of our Terms & Conditions. This monitoring flags patterns for human review; it does not make final account-suspension decisions without human oversight. We do not use automated systems to make solely automated decisions about your medical eligibility or treatment.

16. Region-Specific Rights

16.1 India — Digital Personal Data Protection Act, 2023

If you are located in India, you have rights under the DPDP Act, 2023, including the right to access, correct, and erase your personal data, and to nominate another individual to exercise your rights in the event of death or incapacity. Our Grievance Officer (Section 19) is your contact point for these rights.

16.2 European Economic Area / United Kingdom — GDPR

If you are located in the EEA or UK, you have the rights described in Section 11 under the GDPR/UK GDPR, and the right to lodge a complaint with your local data protection supervisory authority.

16.3 Other Jurisdictions

[Add specific clauses as needed for other significant patient-origin countries — e.g., Kenya's Data Protection Act 2019, Nigeria's NDPR, Canada's PIPEDA, or U.S. state privacy laws — once your legal counsel has confirmed which apply based on actual patient volumes from each country.]

17. Data Breach Notification

In the event of a data breach affecting your personal information, we will notify affected individuals and the relevant regulatory authority within the timeframe required by applicable law, and will describe the nature of the breach, the information affected, and the steps we are taking in response.

18. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified through the Platform or by email at least [15 days] before taking effect. The "Effective Date" at the top of this page reflects the most recent version.

19. Contact Us / Grievance Officer

For any question about this Privacy Policy, or to exercise your rights under Section 11, contact our Grievance Officer:

[Name]
[Email address]
Privea Med Global, [registered office address]

↑ Back to top