Digital Personal Data Protection (DPDP) Compliance Policy
1. Introduction
HealthONTime is committed to protecting the privacy and personal data of its users in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable laws of India. This Policy explains how HealthONTime collects, processes, stores, secures, shares, retains, and deletes personal data while respecting the rights of individuals ("Data Principals") under applicable law.
2. Purpose
The objectives of this Policy are to:
- Protect users' personal data
- Promote transparency in data processing
- Ensure lawful and fair processing of personal data
- Explain users' rights under applicable law
- Establish internal data governance practices
- Build trust with users and healthcare partners
3. Definitions
Data Principal
The individual to whom the personal data relates.
Personal Data
Any data about an individual who is identifiable by or in relation to such data.
Processing
Any operation performed on personal data, including collection, storage, organization, use, sharing, disclosure, retrieval, deletion, or destruction.
Consent
A freely given, specific, informed, unconditional, and unambiguous indication of the Data Principal's agreement to the processing of personal data for a specified purpose.
4. Lawful Basis for Processing
HealthONTime processes personal data only where there is a valid legal basis, including:
- Your consent
- Performance of services requested by you
- Compliance with legal obligations
- Protection against fraud and abuse
- Security and operational purposes
- Other lawful grounds recognized under applicable law
5. Consent Management
HealthONTime obtains user consent through website registration, mobile application registration, booking forms, consent checkboxes, OTP verification, electronic confirmations, and acceptance of Terms & Conditions and Privacy Policy. Users may withdraw consent where processing is based on consent.
6. Data Security
HealthONTime implements reasonable technical and organizational measures to safeguard personal data, including encryption during transmission, secure servers and cloud infrastructure, access controls, authentication mechanisms, security monitoring, regular software updates, employee confidentiality obligations, and periodic security reviews.
7. Rights of Data Principals
Subject to applicable law, users may request:
- Confirmation regarding processing of their personal data
- Access to personal data
- Correction of inaccurate personal data
- Updating of personal information
- Withdrawal of consent (where applicable)
- Deletion of eligible personal data
- Information about grievance mechanisms
- Nomination of another individual to exercise rights in circumstances recognized by law
8. Data Breach Management
If HealthONTime becomes aware of a personal data breach that is likely to require action under applicable law, we will assess the nature and scope of the incident, take reasonable steps to contain and investigate the breach, mitigate potential harm where possible, notify relevant authorities or affected individuals where required by law, and review and strengthen security controls.
9. Governing Law
This Policy shall be governed by the laws of India. Any disputes relating to this Policy shall be subject to the jurisdiction of the competent courts located in Bengaluru, Karnataka, unless otherwise required by applicable law.
Contact Us
HealthONTime — Website: https://healthontime.in | Email: info@healthontime.in | Phone: +91 7090002002