Last updated: 7 June 2026
Privacy Policy
Nettur Diacare Online ("we", "us", "the clinic") is operated by Dr. Keerthana Madhu Anand. This policy explains what personal and health information we collect, how we use it, and how we protect it. By using this site or booking an appointment, you agree to this policy.
1. Information we collect
- Identity: name, age, sex, occupation, address, contact number, email.
- Aadhaar number: used solely to securely link your records across visits.
- Health information: reason for consultation, medical/surgical history, current medications, allergies, vitals (weight, height, BP), and any lab reports you upload.
- Consultation records: doctor's notes, prescriptions, follow-up plans.
- Technical: approximate IP (hashed) used only to prevent abuse of patient-lookup.
2. Why we collect it (purpose & lawful basis)
- To provide tele-consultation and follow-up care.
- To maintain medical records as required by applicable medical-council guidelines.
- To contact you about your appointment (email and SMS).
- Lawful basis: your consent at the time of booking, and our legitimate interest in providing care.
3. Who can access your information
- The consulting doctor assigned to your appointment.
- The founder/administrator (Dr. Keerthana Madhu Anand) for clinical supervision and quality.
- No third party receives your data for marketing or analytics.
- We use trusted infrastructure providers (cloud hosting, email/SMS) under contractual confidentiality.
- Every reveal of your full Aadhaar number by a clinician is logged with the viewer's identity and time.
4. How we protect it
- Data is stored on secure servers with encryption in transit (HTTPS) and at rest.
- Access is restricted by role (doctor, admin) and protected by row-level security policies.
- Aadhaar is masked in dashboards by default and shown in full only on explicit reveal, which is logged.
- Lab files are stored in a private bucket; access is via short-lived signed links (30 minutes).
5. Retention
We retain medical records for the period required by applicable law and medical-council guidelines (typically a minimum of three years from the last consultation). You may request earlier deletion where the law permits.
6. Your rights
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or outdated information.
- Erasure — request deletion subject to legal record-keeping obligations.
- Withdraw consent — at any time, by writing to us (this stops future processing; past records may be retained where law requires).
7. Grievance officer
For privacy questions or complaints, please write to us via the contact page. We will respond within 30 days.
8. Changes
We may update this policy. Material changes will be reflected by updating the "Last updated" date above. Continued use of the site after an update constitutes acceptance of the revised policy.
