Policies
Privacy Policy
Last updated: [date]
How DocFriends collects, uses, and protects your personal data — including health information — in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act).
- Scope. This explains how DocFriends collects, uses, and protects your personal data, including health information, in line with India's DPDP Act, 2023.
- What we collect. Account details (name, email, phone); the medical information you choose to share for your case (symptoms, history, documents); payment status (payments themselves are processed by Razorpay — we do not store your full card/bank details).
- Why, and lawful basis. We process your data with your consent to match you with a suitable doctor, deliver your opinion(s), provide support, and meet legal obligations.
- Who can see your case. Doctors assigned to your case can see the clinical information needed to give an opinion. Our case-management/admin team can see your contact details to operate the service. We do not sell your data.
- Processors we use. Razorpay (payments), Resend (email), Cloudflare (hosting), Turso (database). Each processes data only to provide its service.
- Storage & security. Data is stored securely with access controls and encryption in transit. [Add specifics your team can stand behind.]
- Retention. We keep your data only as long as needed for the service and legal requirements, then delete or anonymise it. [Set a period.]
- Your rights. Under the DPDP Act you may access, correct, or request deletion of your data, and withdraw consent. Contact our Grievance Officer (below) to exercise these rights.
- Children. The service is not directed at children except via a consenting parent/guardian.
- Cookies/sessions. We use a session cookie to keep you signed in.
- Grievance / Data Protection Officer. Rekha Mani — hello@docfriends.co. We respond within [X] days.
- Changes. We will post updates here.
Questions about this policy? Contact us at /contact.