This policy explains how hospiDule, a product of Narra Technologies Private Limited, collects, uses, and protects your personal and health data under applicable data protection law.
Welcome to hospiDule, a product of Narra Technologies Private Limited ("Narra"). We are committed to protecting your privacy and being transparent about how we collect, use, and protect your personal and health data.
This Privacy Policy applies to:
hospidule.com)This policy is designed to comply with applicable data protection law. Concerns can be raised with the relevant data protection authority. If you do not agree with this Privacy Policy, please do not use our services.
Narra is sold in two configurations, and this policy covers both.
Key terms used throughout this policy:
These terms apply to customers using India's national health network.
hospidule.comWe build software for healthcare and commerce organisations and the people they serve.
Which role we hold depends on how you reached us.
For our own website analytics, marketing, and billing, we are always the Controller.
We are not currently registered as a Significant Data Fiduciary under India's DPDP Act 2023. If the Act's thresholds come to apply to an entity of our size, we will register and publish the reference here.
We collect different types of data depending on how you interact with hospiDule.
Full name, date of birth, gender, and unique identifiers including your hospiDule account ID. In a healthcare deployment this may also include a national health identifier such as an ABHA ID, and, only where required by law and with explicit consent, a government identity number. Collected when you sign up or when your healthcare provider creates your record. Name, date of birth, and gender are mandatory to create an account.
Mobile phone number, email address, postal address, and emergency contact information. Phone number and email are required for account recovery and notifications.
Applies to healthcare deployments. Laboratory test results, diagnostic images, vital signs, medical diagnoses, allergies, medications, prescriptions, treatment history, discharge summaries, procedure records, immunisation records, and family health history (if provided).
Health data is only collected with your explicit, informed consent, or on the instruction of the healthcare provider who is the Controller for it. You have control over which data is shared and with whom. Health data is treated as a special category under GDPR Article 9 and as sensitive personal data under India's DPDP Act 2023, because unauthorised disclosure could harm your privacy, medical autonomy, or insurance eligibility.
IP address, browser type and version, operating system, device type, pages visited and time spent, clicks and interactions, and error logs. Collected automatically through cookies and server logs. We do not store raw IP addresses longer than necessary.
Payment method information (card type, last 4 digits), transaction IDs, invoice records, insurance policy numbers, and billing address. Collected only if you purchase paid services. hospiDule does not store full card numbers. Our payment processor handles all sensitive payment data.
Support tickets, email communications, call recordings (only with consent), feedback and survey responses, and chat transcripts. Collected only when you contact us.
Data about minors (if a parent or guardian creates an account for a child), mental health data (if disclosed in clinical records), and genetic or biometric data (only if explicitly shared). None of these categories are mandatory and are collected only with explicit consent.
We do not use identifiable personal or health data to train, fine-tune, or evaluate machine-learning models without your separate, explicit, opt-in consent. We do not sell your data, and we do not use it for advertising. These limits are also written into our Terms of Service and our Business Associate Agreement.
Every use of your data has a legal basis. The list below maps each use to its basis under GDPR Article 6 (and Article 9 for health data) and to the equivalent basis under applicable local law, including India's DPDP Act 2023.
Where we rely on Legitimate Interest, we have carried out a balancing assessment and you may object at any time using the Right to Object below.
Consent is central to our approach. You should have control over your data.
When you authorise a healthcare provider to access your records, you choose what they can see (all data, only test results, only clinical notes, specific date ranges) and set an expiry. You can revoke access at any time.
Withdrawing consent is as easy as giving it, and takes effect from the moment you withdraw.
Withdrawing consent may limit your ability to use hospiDule's features. Withdrawing consent to store health data means we cannot maintain your patient record.
Your health data is private by default. We only share it when necessary and with your permission.
Doctors, hospitals, diagnostic centres, and other providers in our network. You explicitly authorise each provider, can limit what they see, and can revoke access at any time. All providers sign a Data Processing Agreement (DPA) or Business Associate Agreement (BAA).
Where you link a national health account, other providers, personal health record apps, and government health programmes connected to that network may access what you share. In India this is the ABDM ecosystem, linked through your ABHA. Linking is optional and you can revoke consent through that network's consent manager. Once data is shared into such a network, other registered participants may access it. This is the intended purpose of a national health network.
Encrypted data is processed by our cloud infrastructure, payment processors, SMS gateways, and email services. Raw health data is never shared unencrypted. The complete, current list of these sub-processors, with purpose and location, is published in our Data Processing Agreement, and we give 30 days notice before adding a new one. All vendors sign data processing agreements with strict security requirements including AES-256 encryption, access controls, and breach notification within 24 hours.
Staff with a legitimate need (support, compliance), governed by strict Role-Based Access Control (RBAC), mandatory MFA, and comprehensive audit logging. Access is granted only to resolve support issues or technical problems.
Government agencies, courts, and tax authorities, only in response to valid legal process. We object to overly broad requests, share only what is legally required, and notify you when legally permitted to do so. We do not voluntarily share your data with law enforcement.
De-identified and anonymised health data only, with your explicit opt-in consent, and under a written agreement that prohibits re-identification.
We keep your data only as long as necessary for the purpose it was collected. These periods are the same in our Terms of Service, Data Processing Agreement, Business Associate Agreement, and Data Security Statement.
Under applicable data protection law, and under GDPR where it applies to you, you have the following rights. Exercising them is free, and we respond within 30 days.
You may request a copy of all personal data we hold about you. Email dpo@narrahealthcare.com with the subject "Data Access Request" or use Account Settings → Privacy → Download My Data. We will respond within 30 days at no cost.
You may correct inaccurate or incomplete data. Update contact data directly in Account Settings → Profile. For health data, contact your healthcare provider or email our DPO. Timeline: 30 days.
You may request permanent deletion of your data via Account Settings → Delete Account. Data will be irreversibly deleted within 30 days. We may retain de-identified data where you have consented, and must retain records required by law. Deleted health records cannot be recovered.
You may ask us to limit how we use your data while investigating an issue. Email dpo@narrahealthcare.com with the subject "Request to Restrict Processing". Timeline: 30 days.
You may request your data in a portable format (CSV, JSON, PDF) via Account Settings → Privacy → Download My Data. Timeline: 30 days.
You may object to processing of your data for marketing or research by unsubscribing or emailing our DPO. Marketing objections take effect immediately; other processing within 30 days.
We do not make decisions that produce legal or similarly significant effects about you by automated means alone. If that ever changes, we will tell you, explain the logic involved, and give you the right to obtain human review.
Where India's DPDP Act 2023 applies to you, you may nominate another individual to exercise your rights in the event of your death or incapacity. Contact our DPO to record a nomination.
This section applies to California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and we extend the same rights to residents of other US states with comparable privacy laws. It supplements, and does not replace, the rest of this policy.
The categories of personal information we collect, the purposes we collect them for, and how long we keep them are set out in "What Data We Collect", "How We Use Your Data", and "Data Retention" above. In CCPA terms we collect identifiers, personal records, commercial information, internet activity, geolocation inferred from IP address, and, in a healthcare deployment, sensitive personal information in the form of health data.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months, including for consumers we knew to be under 16. Because we do not sell or share, there is no "Do Not Sell or Share My Personal Information" opt-out to operate. If that ever changes, we will update this section and provide the required opt-out before any such disclosure begins.
We use sensitive personal information only to provide the service you asked for, to secure it, and to comply with law. We do not use it to infer characteristics about you. This is within the exemptions in the CCPA regulations, so the "Limit the Use of My Sensitive Personal Information" right does not change how we handle it. You may still ask us to restrict processing under the Right to Restrict Processing above.
Email dpo@narrahealthcare.com with the subject "US Privacy Request", or use Account Settings → Privacy. We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days if we tell you why. We verify your identity against information already in your account before acting.
An authorised agent may submit a request on your behalf. We will ask for written permission signed by you, and we may ask you to verify your own identity directly with us.
Protected Health Information handled under our Business Associate Agreement is exempt from the CCPA. Requests about that data are handled under HIPAA and the relevant health data law, and we will route them to the healthcare provider who is the covered entity.
We honour the Global Privacy Control (GPC) signal. Because we do not sell or share personal information, GPC has no sale to stop, but we treat it as an opt-out of all non-essential analytics and tracking.
Our production platform runs on Google Cloud Platform in the asia-south1 (Mumbai, India) region, which is our primary hosting region for all customers. Backups are replicated within India. Our managed database and application hosting services run in the same region.
This is a statement of current fact, not a promise about the future. We will update this section before we change region, and material changes are notified under the Changes to This Policy section.
Additional residency regions, including the EU, the UK, and the United States, are on our roadmap and are not available today. We do not currently offer a contractual data-residency commitment outside India. If regional residency is a requirement for you, raise it before you sign: we will tell you honestly whether we can meet it, and any commitment we can make will be recorded in your Order Form rather than implied here.
If you are in the EU, the EEA, the UK, or another country whose law restricts international transfers, using our service today means your personal data is transferred to and stored in India. India has not received an adequacy decision from the European Commission or the UK government. We rely on the following safeguards for that transfer:
Onward transfers to a sub-processor are made only under the same or equivalent safeguards, and only to the sub-processors listed in our Data Processing Agreement.
Appointment of an EU representative under GDPR Article 27 and a UK representative under UK GDPR Article 27 is in progress and is not yet complete. Until a representative is appointed and named here, EU and UK data subjects should contact our Data Protection Officer directly at dpo@narrahealthcare.com. We will publish the representative's name and address in this section as soon as the appointment is made. This does not limit your right to complain to your own supervisory authority.
hospiDule is not intended for children under 18 years of age except in specific healthcare scenarios.
A parent or legal guardian may create an account on behalf of a child. The guardian is the Data Principal and manages all access and consent. This is the recommended approach for accessing a child's healthcare (test results, appointments, and so on).
24/7 automated monitoring with immediate alerts. Potential breaches are investigated on detection. If a breach occurs, affected systems are isolated without undue delay and in any event within 1 hour, and notification follows the timelines below. These are the same timelines as in our Data Processing Agreement, Business Associate Agreement, and Data Security Statement.
We state our certification status plainly. Nothing below is claimed as achieved unless it says so.
Full details are provided in our separate Cookie Policy. Here is a summary:
Withdrawing cookie consent is as easy as giving it, through the same control. If your browser sends a "Do Not Track" signal or a Global Privacy Control signal, we honour it and disable non-essential tracking.
Our website and apps may contain links to third-party websites. We are not responsible for their privacy practices. Before clicking external links, review their privacy policy. We do not share your data when you click external links.
We may update this Privacy Policy to reflect changes in applicable law, new requirements from a national health network, changes to how hospiDule processes data, or user feedback.
If you don't agree with updated terms, you can opt out before the change takes effect, request deletion of your account, or withdraw consent.
You may complain to the relevant data protection authority at any time. You do not have to contact us first, and you also retain the right to seek a legal remedy through the courts.