Privacy & Data Protection Policy
This Privacy & Data Protection Policy explains how MeraDoc Healthtech Private Limited collects, uses, stores, shares, secures, retains, and deletes your personal information across its website, mobile application, and related services, and describes the rights available to you.
Introduction
This Policy describes how MeraDoc Healthtech Private Limited ("MeraDoc", "Company", "we", "us", "our") collects, uses, stores, shares, and protects your personal information when you access or use our website, mobile application, or any related services (collectively, the "Platform").
MeraDoc is a digital health and wellness platform that connects users with verified doctors and medical professionals for consultations, diagnosis support, prescriptions, follow-ups, and wellness services. Because we handle health information, we treat privacy and security as core to our service, not as an afterthought.
This Policy is issued in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), the Information Technology Act, 2000 and rules made thereunder, and other applicable laws. Under the DPDP Act, MeraDoc acts as a Data Fiduciary and you, as an individual whose data we process, are a Data Principal.
By accessing or using the Platform, you acknowledge that you have read and understood this Policy. Where we rely on your consent to process your data, we will obtain it separately and clearly, and you may withdraw it at any time (see Section 7 – Consent and Its Withdrawal).
1. Key Definitions
To help you understand this Policy, the following terms are used:
- Personal Data — any data about an individual who is identifiable by or in relation to such data.
- Health Data — information relating to your physical or mental health, medical history, symptoms, prescriptions, diagnostic reports, and consultation records.
- Processing — any operation performed on personal data, including collection, storage, use, disclosure, sharing, or erasure.
- Data Principal — the individual to whom the personal data relates (i.e., you). Where the individual is a child, this includes a parent or lawful guardian; where the individual is a person with a disability, it includes a lawful guardian.
- Data Fiduciary — the entity that determines the purpose and means of processing personal data (i.e., MeraDoc).
- Data Processor — any third party that processes personal data on our behalf and under our instructions.
- Consent Manager — a registered entity, if used, through which you may give, manage, review, or withdraw consent.
- Data Protection Board / DPB — the Data Protection Board of India, the authority established under the DPDP Act.
2. Information We Collect
We collect only the data necessary for the purposes described in this Policy (the principle of data minimisation).
a. Personal Information
- Name, phone number, and email address.
- Age, date of birth, gender, and profile details.
- Postal address, where required to deliver a service.
- Emergency contact or dependant details, where you choose to provide them.
b. Health Information
- Symptoms, medical history, allergies, prescriptions, and reports.
- Consultation notes and communications shared with doctors.
- Wellness and activity data, and any health-related information you voluntarily provide.
c. Transaction & Account Information
- Booking, appointment, and consultation history.
- Payment status and transaction references (payment card details are handled by our payment partners and are not stored on our servers — see Section 8).
d. Technical Information
- Device information, IP address, operating system, and browser type.
- App and website usage data, log data, cookies, and analytics information (see Section 14 – Cookies and Tracking Technologies).
e. Information from Third Parties
- Data from doctors or healthcare providers you consult through the Platform.
- Data from payment gateways, identity-verification services, or partners assisting our operations, subject to their lawful basis to share it with us.
3. How We Use Your Information
We process your personal data for specific, lawful, and limited purposes, including to:
- Connect you with verified doctors and medical professionals for consultations.
- Provide diagnosis support, medical advice, prescriptions, and follow-up care.
- Manage your appointments, records, reminders, and account.
- Process payments and issue invoices or receipts.
- Improve user experience, Platform performance, and service quality through analytics.
- Communicate service-related information, updates, and (where you have not opted out) relevant notifications.
- Ensure safety, prevent fraud and abuse, and maintain the security and integrity of the Platform.
- Comply with applicable legal, regulatory, and medical record-keeping obligations.
- We do not use your health data for advertising or profiling, and we do not sell your personal or health data.
4. Data Protection Principles
We are committed to processing your personal data in line with the following principles:
- Lawfulness, Fairness & Transparency — we process data lawfully and tell you clearly why and how we do so.
- Purpose Limitation — we use data only for the purposes stated at the time of collection.
- Data Minimisation — we collect only what is necessary for those purposes.
- Accuracy — we take reasonable steps to keep data accurate and up to date.
- Storage Limitation — we retain data only for as long as necessary (see Section 11).
- Integrity & Confidentiality — we protect data with appropriate technical and organisational safeguards (see Section 9).
- Accountability — we maintain records, conduct audits, and remain answerable for how we handle your data.
5. Legal Basis for Processing
We process your personal data on one or more of the following bases:
- Your consent, obtained clearly and separately, for processing that is not covered below.
- Performance of the service you have requested (e.g., booking and delivering a consultation).
- Legal obligation, where processing is required by applicable law or a competent authority.
- Certain legitimate uses permitted under the DPDP Act, such as responding to a medical emergency, ensuring safety during an epidemic or threat to public health, or complying with a legal order.
6. Sharing and Disclosure of Information
We do not sell your personal or health data. We share data only where necessary and only with:
- Verified doctors and medical professionals, to provide you with consultations and care.
- Payment gateway providers, to process transactions securely.
- Technology and service partners (e.g., cloud hosting, communications, analytics) who support our operations under strict confidentiality and data-protection terms.
- Legal, regulatory, or government authorities, where required by law or to protect rights, safety, or the integrity of the Platform.
- Successors in interest, in the event of a merger, acquisition, or reorganisation, subject to this Policy continuing to apply.
7. Consent and Its Withdrawal
Where we rely on your consent, it is:
- Free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action.
- Itemised — you can understand what data is being collected and for what purpose.
You may withdraw your consent at any time, and doing so will be as easy as it was to give it. You can withdraw consent through your account settings or by contacting our Grievance Officer (see Section 13). Where you withdraw consent, we will stop the relevant processing unless we are permitted or required by law to continue, and we will erase the associated data unless retention is legally required (see Section 11). Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may affect our ability to provide certain services to you.
8. Data Processors and Third-Party Agreements
We engage carefully selected third parties ("Data Processors") to process data on our behalf, such as cloud hosting, payment processing, and communications providers. Every such engagement is governed by a written contract that requires the processor to:
- process data only on our documented instructions and only for the agreed purpose;
- implement appropriate security safeguards;
- assist us with breach notification and with responding to Data Principal requests;
- comply with applicable data-protection laws; and
- delete or return data at the end of the engagement.
Payment card and banking details are collected and processed directly by PCI-DSS-compliant payment partners; MeraDoc does not store full card numbers on its systems.
9. Data Security and Protection Measures
Protecting your data is central to our operations. We maintain an information security framework aligned with ISO/IEC 27001 and apply the following technical and organisational safeguards:
- Encryption — personal and health data is encrypted in transit and at rest using strong, industry-standard encryption (AES-256).
- Access Controls — role-based access ensures that only authorised personnel can access sensitive data, on a strict need-to-know basis, protected by authentication controls.
- Audit Trails & Logging — access to and processing of personal data is logged, and logs are retained for the period required by law.
- Network & Application Security — secure servers, firewalls, and secure development practices protect against unauthorised access.
- Regular Audits & Testing — we conduct internal and independent third-party security assessments and reviews periodically.
- Vendor Due Diligence — third parties are assessed and contractually bound to maintain equivalent safeguards.
- Incident Response — a defined process exists to identify, contain, mitigate, and report data breaches (see Section 10).
- Staff Training & Confidentiality — employees and contractors are trained on data protection and bound by confidentiality obligations.
10. Data Breach Notification
In the event of a personal data breach, we will act in accordance with the DPDP Act and DPDP Rules:
- The incident will be escalated to our internal incident-response team and our Grievance Officer / designated data-protection contact.
- We will intimate the Data Protection Board of India and notify each affected Data Principal of the breach, without undue delay.
- Affected individuals will be given a clear, plain-language account of the breach, the data involved, the likely consequences, the measures we are taking, the steps they can take to protect themselves, and a point of contact.
- We will submit a detailed report to the Data Protection Board within 72 hours of becoming aware of the breach (or such longer period as the Board may permit), including the facts, mitigation measures, and steps taken to prevent recurrence.
- Where the Information Technology Act / CERT-In directions apply, we will also meet any separate reporting obligations within their required timelines.
- Corrective and preventive actions will be implemented to reduce the risk of recurrence.
11. Data Retention and Erasure
We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected, to provide our services, or to comply with legal, regulatory, tax, or medical record-keeping obligations.
- When the purpose is no longer served — for example, where you withdraw consent, close your account, or remain inactive beyond the applicable retention period — we will erase your personal data, unless retention is required or permitted by law.
- Certain medical and transaction records may be retained for longer where mandated by applicable healthcare or financial regulations.
- Where required, we will give you advance notice before erasing data at the end of a retention period, so that you have an opportunity to preserve it if you wish.
- On erasure, data is deleted or irreversibly anonymised across our active systems and, in due course, from backups.
12. Your Rights as a Data Principal
Subject to applicable law, you have the following rights in respect of your personal data:
- Right to Access — obtain a summary of the personal data we process about you and the processing activities involved.
- Right to Correction & Updating — request correction of inaccurate or misleading data and completion or updating of incomplete data.
- Right to Erasure — request deletion of your personal data, unless retention is required for legal purposes.
- Right to Withdraw Consent — withdraw previously given consent at any time (see Section 7).
- Right to Grievance Redressal — have your complaints addressed through our grievance mechanism (see Section 13).
- Right to Nominate — nominate another individual to exercise your rights in the event of your death or incapacity.
- Right to Data Portability — where applicable, receive certain data in a structured, commonly used, machine-readable format.
- Right to Restrict / Object — request limitation of processing for specific purposes, and opt out of non-essential communications.
To exercise any of these rights, please use the mechanisms in Section 13. We may need to verify your identity before acting on a request. We will respond within the timelines prescribed by applicable law.
13. Grievance Redressal and How to Contact Us
If you have questions, requests, or complaints about how your data is handled, please contact our Grievance Officer / designated data-protection contact:
- Grievance Officer: Prashant Tiwari
- Email:
- Address: MeraDoc Healthtech Private Limited, 3rd Floor, E-19, Defence Colony, New Delhi, Delhi - 110024
- We aim to acknowledge requests promptly and resolve them within the period required under applicable law.
14. Children's Data and Persons with Disabilities
MeraDoc's services are intended for adults. Where we knowingly process the personal data of a child (a person under 18 years of age) or a person with a disability who has a lawful guardian, we will:
- obtain verifiable consent from a parent or lawful guardian before processing;
- not undertake tracking, behavioural monitoring, or targeted advertising directed at children; and
- not process children's data in a way likely to cause detriment to the child.
If you believe a child's data has been provided to us without appropriate consent, please contact our Grievance Officer so we can take corrective action.
15. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Platform, remember your preferences, maintain security, and understand usage so we can improve our services. You can manage cookie preferences through your browser or device settings, and through any consent banner we provide. Disabling certain cookies may affect Platform functionality. We do not use cookies to build advertising profiles from your health data.
16. Cross-Border Data Transfers
Your data is primarily stored and processed in India. Where we transfer or store data outside India — for example, using cloud infrastructure — we do so only in accordance with applicable law, and we do not transfer data to any country or territory restricted by the Government of India. Such transfers remain subject to appropriate contractual safeguards.
17. Third-Party Services and Links
Our Platform may contain links to, or integrations with, third-party websites or services. This Policy does not cover those third parties, and we are not responsible for their privacy practices. We encourage you to review their privacy policies before providing them with your data.
18. Updates to This Policy
We may update this Policy from time to time to reflect changes in law, technology, or our services. When we make material changes, we will update the "Last Updated" date and, where appropriate, notify you through the Platform. Your continued use of the Platform after an update constitutes acceptance of the revised Policy.
19. Contact
MeraDoc Healthtech Private Limited
Address: 3rd Floor, E-19, Defence Colony, New Delhi, Delhi - 110024
Email:
Website: https://meradoc.com