Notice under the Digital Personal Data Protection Act, 2023
Caresoft Systems Private Limited, CIN [U72900MH2022PTC387875], registered office [ 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107], is the Data Fiduciary for personal data processed through Nirvaan. You are the Data Principal.
In plain terms: we hold your mobile number, your wallet and payment records, and what you and a practitioner said during a consultation. We use it to run the service, keep the records the law requires us to keep, and nothing else. We never sell it, never share it between practitioners, and never use it to train AI. It stays in India. You can see all of it, correct it, take a copy, and ask us to delete what we are not legally required to keep.
- Who we are
- What personal data we process
- The purposes
- The basis on which we process
- How consent works here
- Withdrawing consent
- Practitioners as separate Fiduciaries
- Our Data Processors
- Children — under 18
- Persons with disability and guardians
- Your rights
- How to exercise them
- Limits on erasure
- Nominating someone
- Your duties under the Act
- Retention and deletion
- Security safeguards
- Breach notification
- Transfer outside India
- Grievance redressal
- Complaining to the Board
- Significant Data Fiduciary status
- Changes
1. Who we are
Data Fiduciary: Caresoft Systems Private Limited
Registered office: [ 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107]
CIN: [U72900MH2022PTC387875]
Data Protection contact: [email protected]
Grievance Officer: Rajeev Pillai, [email protected]
2. What personal data we process
| Category | Detail |
|---|---|
| Identity and contact | Mobile number (verified by OTP); display name you choose; email if you give one. We do not require your real name |
| Health data | What you tell a practitioner; chat transcripts; advice notes; prescriptions; assessment results you claim to your account |
| Consultation records | Which practitioner, when, duration, mode, consent record |
| Financial | Wallet recharges, charges, refunds, tax invoices. Card details are held by our payment gateway, not by us |
| Delivery | Name and address, only if you order from the store |
| Technical | Device, browser, IP, sign-in records, rate-limit records, audit logs |
3. The purposes
Your personal data is processed for these purposes and no others:
- Creating and operating your account, and verifying your mobile number.
- Connecting you to a practitioner and running the consultation by chat, voice or video.
- Masking your identity from practitioners and bridging calls.
- Metering and charging per minute; operating your wallet; issuing tax invoices; processing refunds.
- Recording consent, consultation records and prescriptions as the Telemedicine Practice Guidelines, 2020 require.
- Fulfilling store orders where you place one.
- Moderating reviews and investigating safety or conduct reports.
- Preventing fraud, abuse and misuse of promotional credit.
- Meeting legal obligations, including retention, tax, and mandatory reporting.
- Securing the platform.
We do not process your personal data for advertising, profiling, tracking, research, publication, benchmarking, or the training of any artificial intelligence or machine learning model.
4. The basis on which we process
| Processing | Basis under the Act |
|---|---|
| Account, consultations, wallet, store | Your consent, given at signup and at each consultation |
| Health data in consultations | Your consent, recorded before each consultation |
| Retaining consultation records and prescriptions | Compliance with law — Telemedicine Practice Guidelines and professional record-keeping obligations |
| Tax invoices and financial records | Compliance with law — tax legislation |
| System logs and incident reporting | Compliance with law — CERT-In directions |
| Mandatory reporting where a child has been harmed | Compliance with law — POCSO Act, 2012 |
| Fraud prevention and platform security | Legitimate use permitted by the Act |
| Responding to your support or refund request | Legitimate use — you approached us for it |
5. How consent works here
- Consent is requested in clear language, for specified purposes, and is free, specific, informed, unconditional and unambiguous as the Act requires.
- Consent to a teleconsultation is versioned and recorded separately before each consultation — it is not bundled into signup.
- This Notice is available in English and Hindi, and in the other languages of the Eighth Schedule on request.
- We do not require consent to anything unnecessary as a condition of using the service. Analytics consent, for example, is genuinely optional and refusing it changes nothing about your access.
- Where we introduce a new purpose, we ask again. We do not rely on old consent for new processing.
6. Withdrawing consent
Withdrawing consent is as easy as giving it. One action in your account settings, or one email to [email protected].
- Withdrawal takes effect for future processing. It does not make past processing unlawful.
- On withdrawal, we cease processing and delete your personal data — except what we are legally required to retain (§13), which is then locked down and used only for the purpose requiring it.
- Withdrawing consent to core processing means we can no longer provide the service, and your account closes. Your unused wallet balance is refunded (Refund Policy §13).
- You may withdraw consent to optional processing — analytics, non-essential communications — without affecting your account.
- We will tell you plainly what the consequences of a withdrawal are before it takes effect.
7. Practitioners as separate Fiduciaries
A practitioner you consult has their own record-keeping obligations under the Telemedicine Practice Guidelines, and is an independent Data Fiduciary for the clinical record they keep.
- They are bound by professional confidentiality and by our Practitioner Terms, which prohibit using your information for anything other than your care.
- They see only what Privacy Policy §4 lists — never your real name, number, address, payment history or consultations with anyone else.
- A request about a practitioner's own clinical record may need to go to them. We will route it and support you — you do not have to work out who holds what.
8. Our Data Processors
We engage Data Processors under written contracts imposing obligations equivalent to those we owe you. Each receives only what its function requires:
| Processor function | Receives |
|---|---|
| Hosting (India) | Encrypted data at rest |
| SMS and messaging | Mobile number and message text, worded so as not to reveal the service |
| Email address and message text | |
| Call bridging | Numbers to bridge and duration. Not consultation content |
| Payment gateway | Payment data. Not consultation content |
| Store fulfilment and courier | Delivery details for that order only |
9. Children — under 18
Nirvaan is not available to anyone under 18. We do not knowingly process the personal data of a child, and we do not seek to.
- Age is confirmed at signup. An account found to belong to a person under 18 is closed and the data deleted, except anything a legal obligation requires us to retain.
- A practitioner who becomes aware or suspects a user is under 18 must end the consultation immediately and report it.
- The Act prohibits tracking, behavioural monitoring and targeted advertising directed at children. We do none of these for any user, of any age, so the prohibition is satisfied by design rather than by a filter.
- Where a disclosure indicates a child has been sexually harmed, mandatory reporting under the POCSO Act, 2012 applies and overrides confidentiality. This is stated plainly in Clinical Safety §12 so nobody is surprised by it.
10. Persons with disability and guardians
Where a user is a person with disability who has a lawful guardian, the Act requires verifiable consent from that guardian. Where you are consulting in that capacity, tell the practitioner at the start of the consultation, and contact [email protected] so the account can be configured correctly.
11. Your rights
| Right | What it means here |
|---|---|
| Access and summary | A summary of the personal data we process, the processing activities, and the identities of Fiduciaries and Processors with whom it has been shared |
| Correction | Correct inaccurate or misleading data, complete incomplete data, update it. Clinical notes are corrected by annotation, not overwriting — see below |
| Erasure | Erasure of data no longer needed for the purpose, and not required by law to be retained (§13) |
| Grievance redressal | A readily available means of raising a grievance, answered within the statutory period (§20) |
| Nomination | Nominate another person to exercise your rights in the event of death or incapacity (§14) |
| Withdraw consent | At any time, as easily as it was given (§6) |
On correcting a clinical record. A medical record cannot simply be rewritten — the integrity of the record is itself a protection for you. Where you say something in a consultation record is wrong, your correction is recorded alongside the original entry, dated and attributed, so anyone reading it later sees both. That is how medical records work everywhere, and it is in your interest.
12. How to exercise them
In the app, immediately: see your full consultation history, advice notes and prescriptions; export all your data; change your display name; log out everywhere; close your account.
- By email: [email protected] from your registered account.
- We verify identity through your registered mobile number — we will not ask you for identity documents, because requiring them would defeat the anonymity the platform is built on.
- We respond within 30 days, and usually much sooner.
- There is no charge.
- Where we cannot fully comply, we tell you specifically which data is affected and which legal obligation requires it — not a general refusal.
13. Limits on erasure
Some data cannot be erased on request. This is not our preference — it is a legal obligation, and every healthcare provider in India is subject to the equivalent.
| Cannot be erased | Why | For how long |
|---|---|---|
| Consultation records, advice notes, prescriptions | Telemedicine Practice Guidelines and professional record-keeping obligations | Minimum 3 years, longer if a proceeding is open |
| Tax invoices and financial records | Tax legislation | Up to 8 years |
| System logs | CERT-In directions | Minimum 180 days |
| Safety and conduct investigation records | Legal claims and regulatory obligations | [5] years, or until a proceeding closes |
| Records subject to a court order or lawful direction | Legal compulsion | As directed |
What we do instead. Retained data is locked down — removed from every console, not visible to support, not usable for any purpose except the one requiring retention. When the period expires, it is deleted automatically. Everything not on this list is deleted when you ask.
14. Nominating someone
The Act allows you to nominate a person to exercise your rights if you die or become incapable of doing so. Given what this platform holds, think carefully about whether you want to.
- Nominate through your account settings, or by writing to [email protected].
- You may change or remove a nomination at any time.
- A nominee can request access, correction and erasure. Consider that a nominee would be able to see your consultation history — for many users on this platform, that is a reason not to nominate anyone, and choosing not to is perfectly proper.
- We verify a nominee's identity and entitlement before acting.
15. Your duties under the Act
The Act places duties on Data Principals. In this context they mean:
- Do not impersonate another person when giving your data.
- Do not suppress material information when it is required — in a clinical context, an incomplete history leads to wrong advice, so this one protects you directly.
- Do not register a false or frivolous grievance or complaint.
- Give authentic information when exercising a right to correction.
16. Retention and deletion
We retain personal data only for as long as the purpose requires, or as law requires. The full schedule is in Privacy Policy §16.
Where you have not contacted us and have not used the platform for [24] months, we treat the purpose as served and delete your account data, subject to §13. We notify you before doing so, on your registered contact.
17. Security safeguards
As required by Section 8(5) of the Act, we maintain reasonable security safeguards, including: identity masking enforced at the data layer; encryption in transit and at rest; call bridging so numbers are never exchanged; EXIF stripping on uploads; OTP authentication with reuse prevention; per-actor and per-IP rate limiting; brute-force lockout; authoritative server-side sessions with real revocation; role-based access with multi-factor authentication for administrative accounts; immutable audit logging with a specific watch on identity access; no production data in non-production environments; verified nightly backups; and a maintained security test suite.
The full description is in Privacy Policy §17.
18. Breach notification
- In the event of a personal data breach we notify you and the Data Protection Board of India as the Act requires.
- Our target is notification within [6] hours of confirmation — this is health data and we hold the shortest window we operate.
- Notification to you is deliberately worded so that the notification itself does not disclose what you consulted about — including where it may be read on a lock screen.
- We also report to CERT-In within 6 hours as its directions require.
- Evidence is preserved, and we publish a root cause analysis with corrective actions within [10] working days.
19. Transfer outside India
Your personal data is stored and processed within India, including backups and disaster recovery. Support and engineering access is from India.
We do not transfer your personal data outside India. Should that ever change, it would be done only where Section 16 of the Act and any restriction notified by the Central Government permit, and we would notify you in advance.
20. Grievance redressal
Grievance Officer
Name: Rajeev Pillai
Email: [email protected]
Address: [ 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107]
Also reachable through in-app support.
- Acknowledgement within 24 hours.
- Resolution within 15 days, or sooner.
- Grievances are handled by a named person, not a queue, and you never need to describe your medical problem to raise one.
21. Complaining to the Board
If you are not satisfied with our response, you may complain to the Data Protection Board of India. The Act requires that you exhaust our grievance process first, so please raise it with us before approaching the Board — but nothing prevents you from doing so once you have.
Details of the Board and its procedure are published by the Ministry of Electronics and Information Technology. We will not obstruct, discourage or penalise a complaint to the Board in any way.
22. Significant Data Fiduciary status
The Central Government may notify a Data Fiduciary as a Significant Data Fiduciary based on volume and sensitivity of data, risk to Data Principals and other factors — which brings additional obligations including a Data Protection Officer based in India, independent audit, and periodic Data Protection Impact Assessment.
Given the sensitivity of the data on this platform, we operate on the assumption that these obligations may apply to us. Where we are notified as a Significant Data Fiduciary, this Notice will be updated with the Data Protection Officer's contact details.
23. Changes
We may update this Notice where the law changes, where the Rules under the Act are notified, or where our processing changes. Material changes are notified at least [30] days in advance on your registered contact and in-app.
Where a change would require fresh consent, we will ask for it rather than treating continued use as agreement.