PRIVACY POLICY
Your health information deserves clear boundaries.
This policy explains how Privam Solutions Pvt. Ltd. (“Privam”, “SvasthHub”, “we”) processes digital personal data through the SvasthHub website, mobile application and clinic platform. Effective 5 September 2026.
1. Who controls the data
Privam operates the technology platform. Depending on the workflow, Privam may determine the purpose of processing or process information for the clinic, doctor, laboratory, pharmacy or other verified partner responsible for the service. Healthcare providers remain responsible for their professional records and clinical decisions.
2. Data we may process
- Identity and contact details such as name, mobile, email, age/date of birth, gender and address.
- Account details such as login identifier, role, clinic association, consent choices and security events.
- Care-workflow data such as appointments, queue tokens, consultation information, prescriptions, reports, family profiles, vitals and follow-ups.
- Transaction records such as invoice, amount, payment status, refund and reconciliation reference. We do not intentionally store full card details or UPI PINs.
- Device and usage information such as app version, device type, security logs, crash events and notification token.
- Professional or partner details such as registration, licence, staff role, service and settlement information.
- Location only when you choose nearby search, navigation, ambulance or delivery. Precise background location requires a separate permission.
3. Why we process it
- Create and secure accounts and verify professional roles.
- Provide booking, QR check-in, queues, consultation coordination, reports, billing, reminders and support.
- Fulfil a requested service through an identified clinic, lab, pharmacy, ambulance or equipment partner.
- Process payments, refunds, commissions and accounting records.
- Send essential service updates and separately consented promotional messages.
- Prevent abuse, investigate incidents, maintain audit records and improve reliability using aggregated or de-identified insights.
- Meet applicable legal, professional-record and dispute-resolution duties.
4. Consent and permitted uses
Where consent is required, we present a clear notice describing the data and purpose before collection. Consent can be withdrawn through the relevant settings or by contacting us, although this may stop features that require that data. We may also process data where applicable law permits it without consent, including certain medical emergencies or legal obligations. Withdrawal does not invalidate lawful processing already completed.
5. Children and family profiles
A parent or lawful guardian must create or manage a child’s profile and provide verifiable parental consent where required. We do not knowingly enable behavioural monitoring or targeted advertising directed at children. Report an unauthorised child account to the Grievance Officer.
6. Access and sharing
Only authorised users and processors necessary for the selected workflow receive data: the chosen clinic/doctor, verified fulfilment partner, payment or communication provider, and approved cloud/security provider. Each should receive only what is reasonably required. Super Admin access is limited to operational, account, safety and financial metadata and is not intended for unrestricted clinical-history browsing.
7. AI and external integrations
AI may assist with general information, navigation, transcription, summaries or draft documentation. It does not diagnose or prescribe, and clinical drafts require professional review. We do not use identifiable health conversations to train a public model unless separately and expressly agreed. ABHA/ABDM, wearables, maps, WhatsApp and payment services have separate notices or terms; ABDM exchange occurs only after required onboarding and consent.
8. Retention schedule
Website enquiriesUp to 24 months after the last interaction
Inactive account profileDeleted or de-identified after a verified request, subject to required records
Security/access logsNormally up to 12 months; longer during an investigation
Financial/tax recordsFor the period required by applicable accounting, tax and payment law
Clinical recordsAs directed by the responsible healthcare provider and applicable professional/legal duties
BackupsAge out through the backup cycle after eligible production deletion
9. Security and breach response
We use authenticated access, role and clinic-scoped permissions, encrypted transport, provider-managed encryption at rest, secret management, logs and backups. No system can be guaranteed completely secure. Where applicable law requires breach notice, we will notify affected users and the Data Protection Board in the required manner and timeline.
10. International processing
Approved cloud or communication providers may process data outside India, subject to contractual and security controls and any transfer restrictions notified by the Government of India.
11. Your rights
Subject to applicable law, you may request a summary of your personal data and sharing, correction or completion, erasure of eligible data, withdrawal of consent, grievance redressal and nomination of another person to exercise rights in the event of death or incapacity. You must provide accurate information and protect your credentials.
12. Requests, deletion and grievance
Use Account → Privacy & data, visit the Account Deletion page, or email from your registered address. Identity verification may be required. If another provider controls a record or retention is legally required, we will explain the available route.
Shivam Mantri, Grievance Officer
Privam Solutions Pvt. Ltd.
Main Road, Ranikhera, Nimbahera – 312601, Rajasthan, India
founder@privamsolutions.in
Never email passwords, OTPs or unnecessary medical reports. After using our grievance process, eligible individuals may approach the Data Protection Board of India through its notified mechanism.
Shivam Mantri, Grievance Officer
Privam Solutions Pvt. Ltd.
Main Road, Ranikhera, Nimbahera – 312601, Rajasthan, India
founder@privamsolutions.in
Never email passwords, OTPs or unnecessary medical reports. After using our grievance process, eligible individuals may approach the Data Protection Board of India through its notified mechanism.
13. Policy updates
Material updates will be communicated through the app, website or registered contact. Fresh consent will be requested where a purpose materially changes and consent is required.