गोपनीयता धोरण
Privacy and Data Security Policy
Last updated: 18 September 2026
This Privacy and Data Security Policy explains how healthcare nt sickcare collects, uses, discloses, protects, retains and deletes personal data when individuals visit healthcarentsickcare.com, book diagnostic laboratory services, request home sample collection, make a payment, receive a digital report, contact support or otherwise interact with us.
We process personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and rules brought into force under it, the Information Technology Act, 2000 and applicable rules, the Consumer Protection Act, 2019, the Consumer Protection (E-Commerce) Rules, 2020, and lawful healthcare, accounting and record-keeping obligations. A statutory provision applies only to the extent that it is in force and applicable to the relevant processing activity.
Important Privacy Notice
Visiting this website does not, by itself, amount to blanket consent for every use of personal data. Where consent is required, we request it through a clear notice and affirmative action for the specified purpose.
Diagnostic-service data may also be processed where necessary to fulfil a booking, issue reports, meet legal obligations, protect against fraud, address safety or quality concerns, and resolve grievances, to the extent permitted by applicable law. Optional marketing and non-essential analytics are handled separately.
1. Identity of the Data Fiduciary
For the personal data covered by this Policy, the data fiduciary and service provider is:
- Legal entity: healthcare nt sickcare
- Business constitution: Partnership firm
- Partners: Vivek Narayanankutty Nair, Rachana Vivek Nair and Nivedita Arvind Karanjkar
- PAN: AAKFH0257Q
- Udyog Aadhaar Number: MH26D0249236
- Shop and Establishment Registration Number: 1731000310989039
- Principal place of business: Office No. 2A, 1st Floor, Omkar Complex, New DP Road, Aundh, Pune, Maharashtra 411007, India
- Website: healthcarentsickcare.com
- Privacy contact: support@healthcarentsickcare.com
- Phone and WhatsApp: +91 9766060629
1.1 Our Role
We determine why and how personal data is processed for bookings, customer support, sample collection coordination, payments, laboratory reporting, quality management and related website operations. Certain partner laboratories and technology providers may independently determine limited aspects of processing imposed by law or by their professional responsibilities.
1.1.1 ISO Certification
References to ISO 9001:2015 describe our quality-management certification and do not, by themselves, constitute a certification of every laboratory test, information-security system or third-party processor.
1.1.1.1 Policy Priority
If another website policy conflicts with this Policy on the handling of personal data, this Policy governs that privacy issue, subject always to applicable law and any more protective written commitment made to the data principal.
1.1.1.1.1 Plain-Language Assistance
Anyone who needs help understanding this Policy or exercising a privacy right may contact us using the details in Section 20.
2. Scope
This Policy applies to personal data processed through:
- our Shopify website and checkout;
- online, telephone, email, WhatsApp and form-based bookings;
- direct walk-in and home sample collection services;
- payment links, QR-code payments and refund handling;
- laboratory information management and digital report delivery;
- customer support, complaints and grievance redressal;
- consented marketing, cookies and website analytics; and
- supplier, employment or partnership enquiries submitted through our website.
2.1 Diagnostic Services, Not Physical Goods
We provide diagnostic laboratory services. We do not ordinarily ship physical products to customers. Home collection involves collection and controlled transport of a biological specimen, while completed reports are normally delivered digitally. See our Shipping, Home Sample Collection and Digital Report Delivery Policy.
3. Categories of Personal Data We Collect
3.1 Identity and Contact Data
- name, age or date of birth, sex or gender where relevant to reference intervals;
- mobile number, email address and communication preference;
- residential or collection address, locality and PIN code;
- patient identifier, booking number, laboratory number or account identifier; and
- identity or authorisation information needed to verify a report-access, correction, refund or privacy request.
3.2 Health and Diagnostic Data
- tests ordered, packages booked and prescribing or referring practitioner information;
- relevant symptoms, medical history, medication, fasting status, pregnancy status or other preparation information voluntarily supplied or clinically required;
- specimen type, collection time, accession details, processing status and quality observations;
- test values, reports, interpretive comments and critical-value communication records; and
- information required for quality review, repeat testing, complaint investigation or report correction.
3.2.1 Sensitive Nature of Diagnostic Data
Health and diagnostic information is confidential and receives enhanced access restrictions. We request only information reasonably necessary for the selected test, safe collection, accurate reporting, legal compliance or a legitimate quality investigation.
3.3 Transaction and Payment Data
- order value, invoice, receipt, payment status, transaction reference and refund status;
- limited payer details supplied by the payment processor or bank; and
- information needed to investigate a failed, duplicate, disputed or fraudulent transaction.
We do not intentionally store complete payment-card credentials, card verification values, UPI PINs or online-banking passwords. Payment credentials are entered into the systems of authorised payment or banking providers. Read our Online Lab Test Payment Information.
3.4 Account and Booking Data
Customer-account creation is optional unless a specific feature requires authentication. We process booking history, cancellations, fulfilment status, report availability and support activity whether a booking is made through an account or guest checkout.
3.5 Communications
We may retain emails, support tickets, call or WhatsApp correspondence, consent preferences, delivery confirmations and grievance records. Telephone calls are not recorded unless a notice is provided and any required permission is obtained.
3.6 Device, Cookie and Usage Data
- IP address, browser, device type, operating system and approximate location derived from network information;
- referring page, pages visited, timestamps, links or buttons used and technical error data;
- cookie identifiers and consent-preference records; and
- aggregated performance, accessibility and traffic measurements.
Non-essential analytics, advertising and session-replay technologies should operate only in accordance with the choices available through our cookie controls. See the Cookie Policy.
3.7 Data We Ask You Not to Send
Do not send Aadhaar numbers, full payment credentials, unrelated medical files, passwords or other excessive information through ordinary email, public comments or unsecured forms unless we specifically request it through an appropriate channel and explain why it is required.
4. Sources of Personal Data
- Directly from the patient or customer: through checkout, forms, calls, email, WhatsApp, walk-in registration or sample collection.
- From an authorised representative: such as a parent, lawful guardian, caregiver, family member, employer or practitioner who confirms authority to act.
- From payment providers: transaction status, limited payer information and fraud-prevention signals.
- From referral or partner laboratories: order, specimen, processing, quality and report information necessary to complete the requested service.
- Automatically: through essential logs, cookies and consented analytics technologies.
- From public or advertising platforms: only when a user chooses to interact with our listing, campaign, lead form or social channel.
4.1 Data About Another Person
If you book for another adult, you must be authorised to provide their information and must make this Policy available to them. You must not access another person’s report without lawful authority.
5. Purposes and Legal Grounds for Processing
We process personal data only for specified lawful purposes and on a basis permitted by applicable law. Depending on the context, processing may be based on the data principal’s consent, a voluntarily provided request for a specified purpose, performance of the requested service, compliance with law, response to a medical emergency, or another recognised legitimate use.
5.1 Essential Diagnostic and Transactional Purposes
- registering and confirming bookings;
- coordinating walk-in or home sample collection;
- verifying preparation, identity and specimen details;
- processing payments, invoices, cancellations and refunds;
- performing or arranging tests and conducting quality checks;
- delivering reports and necessary service notifications;
- communicating a critical or clinically significant result through an appropriate channel;
- handling support requests, report corrections and grievances;
- detecting misuse, fraud, security threats or unauthorised access; and
- complying with legal, regulatory, audit, accounting and quality-management requirements.
5.2 Optional Purposes
- promotional email, SMS or WhatsApp messages;
- non-essential analytics, advertising or session-replay tools;
- customer surveys not required to resolve a service issue; and
- personalisation that is not necessary to provide the requested service.
Refusing or withdrawing permission for an optional purpose will not prevent necessary booking, payment, preparation, safety, reporting, cancellation, refund or grievance communications.
5.2.1 No Medical Advertising Based on Reports
We do not use an individual’s diagnostic values or report contents to create targeted advertising audiences without a separate lawful basis and explicit, informed choice where required.
6. Consent and Choice
6.1 Meaningful Consent
Where consent is required, the request will identify the data and purpose in clear language and provide an affirmative method to agree. Consent is not inferred merely because a person visited the website, ignored a notice or failed to untick a preselected box.
6.2 Withdrawing Consent
You may withdraw consent for future processing as easily as reasonably possible through the method offered at collection, an unsubscribe link, cookie controls, or by contacting us. Withdrawal does not invalidate processing already lawfully completed and may not require deletion of information that must be retained by law or for the establishment, exercise or defence of legal claims.
Instructions are available in our Consent Withdrawal Procedure.
6.3 Consequences of Withdrawing Essential Consent
If processing is essential to identify the patient, collect or test a specimen, receive payment or securely deliver a report, withdrawal before completion may require cancellation of the unperformed service. Eligibility for cancellation and refund is governed by the Cancellation and Subscription Policy and Return and Refund Policy.
7. Children and Persons Requiring Lawful Representation
Diagnostic services may be booked for a child by a parent or lawful guardian. Before processing a child’s personal data on consent, we may take reasonable steps to verify the parent or guardian and their authority, as required by applicable law.
- Children should not independently submit bookings, payment information or diagnostic details.
- A parent or lawful guardian should provide necessary information and supervise communications.
- We do not knowingly undertake tracking or behaviourally targeted advertising directed at children.
- Where an adult cannot provide legally valid consent, an authorised lawful guardian must act in accordance with applicable law.
7.1 Incorrect or Unauthorised Submission
If you believe a child’s information was submitted without proper authority, contact us promptly. We will verify the request and restrict or erase the information where legally appropriate, subject to patient-safety and mandatory record-retention requirements.
8. Laboratory Information Management and Report Delivery
Laboratory workflow and reporting may be managed through Doray’s laboratory information management system. Relevant data may include patient identifiers, demographics, referring practitioner, tests ordered, specimen details, results, report history and delivery status.
8.1 Secure Report Handling
- Reports are delivered only through configured digital channels or to an appropriately verified requester.
- Recipients must protect email accounts, devices, download links and forwarded report files.
- We may request verification before resending a report or changing contact details.
- Reports sent to contact details supplied by the customer may be accessible to anyone who controls those details.
8.2 Referring Practitioners and Authorised Recipients
A report may be shared with a referring practitioner or another nominated recipient where the patient or authorised representative requests it, where it is necessary for the specified service, or where another lawful ground applies. Customers must verify recipient details before submission.
9. Service Providers and Data Sharing
We do not sell, rent or trade personal data. We disclose only the data reasonably required for the relevant purpose, under contractual, technical or legal safeguards appropriate to the service.
9.1 Categories of Recipients
- Shopify: website hosting, storefront, checkout and related platform functions. See Shopify’s Privacy Policy.
- Razorpay and banking partners: payment processing, reconciliation, fraud prevention and refunds. See Razorpay’s Privacy Policy.
- Doray’s LIMS: laboratory workflow, reporting and result notifications. See Doray’s LIMS.
- Partner or referral laboratories: specialised or outsourced testing, quality review and report completion.
- Communications providers: transactional email, SMS, WhatsApp and customer-support delivery.
- Analytics providers: consented website measurement and performance analysis, including BragWatch Analytics.
- Professional advisers: accountants, auditors, legal advisers and insurers where access is necessary and confidential.
9.1.1 Provider Changes
Technology and laboratory providers may change. We will update this Policy or the relevant notice when a change materially affects how personal data is processed.
9.2 Marketing and Enquiry Tools
Where used, SendFox, WhatsForm, SMS gateways or comparable tools receive only the information necessary for the chosen communication or enquiry. Marketing messages require the applicable opt-in and include a reasonable opt-out method.
9.3 Social and Advertising Platforms
If you use a social-platform login, lead form, message or sales channel, that platform may separately process information under its own privacy terms. We do not control its independent processing.
9.4 Business Reorganisation
If the business is reorganised, merged, transferred or succeeded, necessary records may be transferred subject to applicable law, confidentiality, purpose limitation and notice obligations.
10. Legal and Regulatory Disclosure
We may preserve or disclose personal data when required by a valid court order, lawful government demand, applicable healthcare or public-health requirement, or other binding legal process. Requests for documents or electronic communications are assessed under applicable law, including the Bharatiya Nagarik Suraksha Sanhita, 2023, where relevant.
- We seek to verify the authority and scope of a request.
- We disclose only information reasonably responsive to the lawful demand.
- We preserve confidentiality and document the disclosure where appropriate.
- We may challenge or narrow an excessive or defective request when legally permitted.
11. Cookies, Analytics and Session-Replay Controls
Essential cookies may be used for security, cart, checkout, consent records and core website functions. Non-essential analytics, advertising or session-replay tools should not activate until the applicable permission is obtained where required.
11.1 Data Minimisation for Behaviour Analytics
Analytics configurations should exclude or mask form entries, account pages, checkout data, diagnostic reports, test results, payment fields and other patient-identifying content. Analytics data is used for website performance, accessibility, error diagnosis and user-experience improvement—not for diagnosis or treatment.
11.2 Cookie Preferences
You may use available cookie controls or browser settings to reject or delete non-essential cookies. Blocking essential cookies may affect checkout, authentication or security functions. Learn more in our Cookie Policy.
12. International Processing
Some platform, cloud, communications or payment providers may process data outside India. Such processing is permitted only subject to applicable Indian transfer restrictions, contractual protections, access controls and any government notification restricting transfer to a particular country or territory.
12.1 No Guarantee of Exclusive Indian Storage
Unless a specific service notice expressly states otherwise, we do not represent that every copy, backup, security log or provider record is stored exclusively in India.
13. Data Retention
We retain each category of personal data only for as long as reasonably necessary for the stated purpose or a legal, quality, accounting, audit, patient-safety, dispute or security requirement. We do not apply a blanket ten-year period to every record.
13.1 Retention Criteria
- the status and nature of the test or service;
- applicable laboratory, clinical-establishment, tax, accounting and consumer-law requirements;
- quality-control, audit, accreditation and report-correction needs;
- limitation periods and pending disputes, complaints or investigations;
- fraud, cybersecurity and system-integrity requirements; and
- whether the information can be securely deleted or irreversibly anonymised.
13.2 Typical Record Categories
- Booking and report records: retained according to applicable diagnostic, quality and legal requirements.
- Invoices and payment records: retained for applicable accounting, tax, audit and dispute periods.
- Grievance and consent records: retained long enough to demonstrate handling, choice and compliance.
- Security logs: retained for a proportionate period needed to investigate misuse and protect systems.
- Marketing data: retained until consent is withdrawn, the purpose expires or suppression is required to honour an opt-out.
13.2.1 Backups and Legal Holds
Deleted data may remain temporarily in protected backups until scheduled overwriting. Deletion may be suspended for a documented legal hold, investigation, patient-safety issue or active dispute.
14. Data Security
We use reasonable security safeguards appropriate to the nature, volume and risk of the personal data. No internet transmission or storage system is completely secure, and this Policy does not promise absolute security.
14.1 Organisational Safeguards
- role-based access and least-privilege practices;
- confidentiality obligations and staff awareness;
- provider review and contractual data-protection obligations;
- incident escalation, complaint handling and access review;
- data minimisation and defined retention practices; and
- quality controls for patient identity and report delivery.
14.2 Technical Safeguards
- encrypted network transmission where supported;
- authentication, account and administrative access controls;
- security logging, monitoring and abuse prevention;
- backup, recovery and software-update practices; and
- masking or exclusion of sensitive fields from analytics tools.
14.2.1 Customer Security Responsibilities
Customers should use a private device and trusted network, maintain control of their email and mobile accounts, avoid forwarding reports unnecessarily, verify links before opening them, and notify us promptly of suspected unauthorised access.
15. Personal Data Breach Response
If we become aware of a personal data breach, we will take reasonable steps to contain it, assess affected systems and data, preserve evidence, reduce harm and restore secure operations.
15.1 Notifications
We will notify affected data principals and the Data Protection Board of India or other competent authority in the form and timeframe required by the law then in force. A notification may describe the nature of the breach, likely consequences, mitigation steps, safety measures and contact point.
15.2 Reporting a Security Concern
Send suspected privacy or security incidents to support@healthcarentsickcare.com. Do not include passwords, UPI PINs or complete payment credentials.
16. Your Rights and Duties
Subject to applicable law, identity verification, exemptions and the commencement of relevant statutory provisions, a data principal may have the following rights:
- to obtain information about personal data being processed and relevant disclosures;
- to request correction, completion or updating of inaccurate or incomplete data;
- to request erasure when retention is no longer necessary and no lawful requirement applies;
- to withdraw consent for future consent-based processing;
- to nominate another individual to exercise rights in the event of death or incapacity;
- to obtain grievance redressal; and
- to complain to the competent authority after using the available grievance process, where required.
16.1 Duties of Data Principals
Individuals must provide authentic information, avoid impersonation, refrain from filing false or frivolous grievances, and furnish verifiable information when seeking correction or erasure, as required by applicable law.
16.2 Limits on Rights
A request may be restricted where necessary to protect another person’s rights, preserve evidence, comply with law, retain diagnostic or accounting records, address fraud, or establish, exercise or defend legal claims. We will explain a refusal where required and legally permitted.
17. How to Exercise a Privacy Right
Submit a request through one of these channels:
- Email: support@healthcarentsickcare.com
- Contact page: Contact healthcare nt sickcare
- Postal address: Office No. 2A, 1st Floor, Omkar Complex, New DP Road, Aundh, Pune, Maharashtra 411007, India
17.1 Information to Include
- your name and verified contact information;
- the booking, invoice or laboratory reference, if applicable;
- a clear description of the requested action; and
- evidence of authority when acting for another person.
17.2 Verification and Response
We may request proportionate verification to prevent unauthorised disclosure or deletion. We aim to acknowledge a valid request within 48 working hours and respond within the period required by applicable law, ordinarily within one month where practicable. Complex or legally restricted requests may require additional time, in which case we will communicate the reason where appropriate.
18. Automated Decisions
Website analytics, fraud controls or laboratory systems may assist operational decisions. We do not intentionally make a decision producing a significant adverse effect on a patient solely through automated profiling without appropriate human involvement where required by law.
19. Third-Party Websites and Services
Links to payment providers, social platforms, WhatsForm, external laboratories or other websites are provided for convenience or service delivery. Their independent processing is governed by their own privacy notices. Review those notices before providing information.
20. Privacy Grievance and Contact Details
Privacy requests and complaints are coordinated through the following designated contacts:
- Vivek Narayanankutty Nair – Partner, Business Management and Privacy Oversight: vivek@healthcarentsickcare.com
- Rachana Vivek Nair – Partner, Administration and Accounts: admin@healthcarentsickcare.com
- Nivedita Arvind Karanjkar – Partner and Laboratory Operations Head: report@healthcarentsickcare.com
- Central support: support@healthcarentsickcare.com
20.1 Escalation
If a response does not resolve your concern, request internal escalation and include the earlier correspondence. You may also pursue an available remedy before the Data Protection Board of India, a consumer commission or another competent authority, subject to the applicable law and procedure.
Read our Grievance Redressal Policy.
21. Changes to This Policy
We may update this Policy to reflect changes in law, diagnostic operations, providers or technology. The revised date will appear at the top. If a change materially alters a consent-based purpose, we will request fresh consent where required. Continued browsing does not retrospectively authorise a new purpose that requires consent.
22. Related Policies and Internal Links
- Terms of Service
- Legal Notice
- Return and Refund Policy
- Cancellation and Subscription Policy
- Shipping, Home Collection and Digital Delivery Policy
- Contact Information
- Cookie Policy
- Consent Withdrawal Procedure
- Grievance Redressal Policy
- Disclaimer Policy
- No Medical Advice Notice
- Accessibility Statement
- Test Preparation Guides
- Diagnostic Tests and Health Checkups
23. Legal Review Note
This Policy is intended to provide transparent information about our data practices. It does not limit any non-waivable right available under Indian law. Operational teams must ensure that the website’s cookie controls, consent records, provider contracts, access permissions, incident procedures and deletion workflows match the statements published here.