Privacy Policy - Data Security and Protection

Privacy Policy

Effective Date: 10/08/2025

Ovyacare ("we", "us", "our") is committed to protecting your privacy and personal data in accordance with Indian laws including the IT Act 2000, SPDI Rules 2011, and applicable healthcare regulations.

1. Information We Collect

We collect various types of information to provide and improve our healthcare services:

Personal Identifiers

Name, date of birth, gender, contact details (phone, email, address), government-issued IDs (Aadhar, PAN), insurance details.

Health & Medical Information

Medical history, current and past diagnoses, medications, allergies, test results, pregnancy-related data, symptoms, and clinical notes.

Technical and Usage Data

IP address, device information, browser type, app usage logs, cookies, and analytics data.

2. Purpose of Data Collection and Use

We collect and process your information to:

  • Provide, maintain, and improve healthcare services through our EHR and mobile app.
  • Facilitate appointment scheduling, reminders, test reporting, and patient engagement.
  • Deliver personalized health education and communication.
  • Comply with legal, regulatory, and auditing requirements.
  • Protect against fraud, unauthorized access, or security threats.

3. Legal Basis and Consent

Your consent is obtained explicitly before collecting sensitive health information. You may withdraw consent at any time, subject to legal or contractual restrictions. Processing is also necessary for providing healthcare services and complying with laws.

4. Data Sharing and Disclosure

We do not sell, trade, or rent your personal data. We may share your data with:

  • Authorized healthcare providers, hospitals, labs, or clinics strictly for treatment and care coordination.
  • Third-party service providers assisting with data processing are bound by confidentiality and data protection agreements.
  • We may disclose information when required by law, court orders, or to protect safety and rights.

5. Data Security Measures

We implement comprehensive security measures including:

  • Use of encryption in data storage and transmission.
  • Role-based access controls limiting data to authorized users.
  • Regular security audits and vulnerability assessments.
  • Secure authentication mechanisms for user accounts.

6. Data Retention Policy

Data is retained only as long as necessary to provide services or meet legal requirements. Upon request and where applicable, users may request data deletion subject to retention policies.

7. User Rights

You have the following rights regarding your personal data:

  • Right to access your personal and health data.
  • Right to correct inaccurate or incomplete information.
  • Right to request deletion or restriction of processing where applicable.
  • Right to lodge complaints with data protection authorities.

8. Cookies and Tracking Technologies

Our website and app use cookies to enhance user experience, analyze traffic, and deliver personalized content. You may configure your browser settings to refuse cookies; however, some features may not function properly.

9. Children's Privacy

Our Services are not intended for persons under 18 years of age. We do not knowingly collect data from children without parental consent.

10. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted with a new effective date. Continued use of Services constitutes acceptance of changes.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: admin@ovyacare.com

Address: Coimbatore, Tamil Nadu, India

Effective Date: 10/08/2025

Data Security

We implement industry-leading security measures to protect your sensitive health information

End-to-End Encryption

All sensitive data is encrypted both in transit and at rest using industry-standard encryption protocols.

HIPAA Compliance

Full compliance with healthcare data protection standards and Indian IT Act requirements.

Access Controls

Role-based access controls ensure only authorized personnel can access sensitive information.

Regular Audits

Comprehensive security audits and vulnerability assessments conducted regularly.

Your Rights

You have control over your personal and health data

Access & Control

Access your personal and health data
Correct inaccurate information
Request data deletion where applicable
Withdraw consent at any time

Protection & Compliance

HIPAA compliant data handling
End-to-end encryption
Regular security audits
Lodge complaints with authorities