Privacy Policy

Last Update: 25-06-2026
Effective Date: 01-06-2026

1.  Who We Are and How to Contact Us

ArogyaOS is a diagnostic lab intelligence platform operated from Bhilai, Chhattisgarh, India. Under the DPDPA 2023, ArogyaOS acts in a dual capacity:

Our Role

Description

Data Fiduciary

For data about our own users — lab administrators, staff accounts, billing contacts, and website visitors. We determine the purpose and means of processing this data.

Data Processor

For patient data entered into the Platform by your diagnostic lab. We process patient data only as instructed by the lab (the Data Fiduciary) and solely to provide the Platform’s services.

 

CONTACT FOR PRIVACY MATTERS:

Company

ArogyaOS

Address

Bhilai, Chhattisgarh, India

Email

contact@arogyaos.in

Subject Line

Privacy Query / Data Protection Query

Response Time

Within 72 hours on working days

WhatsApp

+91 9981700193

 

2.  What Personal Data We Collect

Under the DPDPA 2023, we are required to provide an itemized description of the specific types of data we collect. Here is the complete list:

2.1  Data About Lab Users (Administrators and Staff)

Category

Specific Data Items Collected

Identity Data

Full name, designation, employee ID

Contact Data

Mobile number, email address, WhatsApp number

Account Data

Username, encrypted password, account creation date, last login

Professional Data

Role type (doctor/technician/receptionist etc.), department, shift timings

Usage Data

Features used, pages visited, session duration, actions performed within the Platform

Device Data

Device type, browser type, IP address, operating system

Payment Data

Subscription plan, billing history, GST number. Payment card details are NOT stored by us — processed by our payment gateway provider.

Communication Data

Support queries, feedback, emails exchanged with us

 

2.2  Patient Data (Processed on Behalf of Your Lab)

When a diagnostic lab enters patient information into ArogyaOS, we process the following data solely to provide the Platform’s services to the lab:

Category

Specific Data Items

Personal Identification

Patient name, age, gender, date of birth, patient ID (auto-generated)

Contact Information

Mobile number (for WhatsApp report delivery), guardian name and contact

Health Information

Test names ordered, test results, blood group, known allergies, symptoms, findings, consultant doctor name

Billing Information

Bill amount, test fees, discounts applied, payment status, referral doctor

Visit History

Appointment dates, OPD case IDs, visit records, recheckup history

WhatsApp Communications

Patient registration responses via WhatsApp bot, report delivery status, audio messages sent

 

IMPORTANT NOTE ON PATIENT DATA

Your diagnostic lab is the Data Fiduciary for patient data. ArogyaOS is a Data Processor. The lab is responsible for obtaining patient consent before entering their data into the Platform. ArogyaOS does not use patient data for any purpose other than providing services to the lab.

 

2.3  Data Collected Automatically

When you visit arogyaos.in or use the Platform, we automatically collect:

  • Log data: pages visited, time spent, errors encountered, referring URLs
  • Technical data: IP address, browser type, device type, screen resolution
  • Cookie data: session cookies necessary for the Platform to function (see Section 9 for cookie details)
  • Analytics data: aggregated and anonymised usage patterns to improve the Platform

 

3.  Why We Collect Your Data — Purpose of Processing

Under DPDPA 2023, we can only process personal data for purposes for which consent has been given or for specific legitimate uses defined by law. Here is exactly why we collect each category:

Purpose

Data Used

Providing the ArogyaOS Platform and its features

Lab user data, patient data (via lab instruction)

Account creation and authentication

Identity, contact, and account data

WhatsApp report delivery and patient communications

Patient mobile number, test results

Billing and subscription management

Payment and billing data

Customer support and grievance redressal

Communication and account data

Platform improvement and analytics

Anonymised usage data

Security monitoring and fraud prevention

Device data, usage data, IP address

Legal compliance and regulatory obligations

All categories as required

ABDM integration (when certified)

Patient ABHA ID, health records

 

4.  How We Handle WhatsApp Data

ArogyaOS uses the WhatsApp Business API (operated by Meta Platforms Inc.) to enable patient communications. Here is specifically what happens with data on WhatsApp:

 

  • Patient registration data entered via the WhatsApp bot is automatically transferred to and stored in ArogyaOS — not retained by WhatsApp beyond message delivery
  • Test reports sent as audio messages are generated by AROGYAOS AI and delivered via WhatsApp. The audio file is created on our servers and transmitted through the WhatsApp API
  • WhatsApp Business API communications are governed by Meta’s Privacy Policy in addition to this Privacy Policy
  • We do not use WhatsApp communications for marketing to patients without explicit consent
  • Labs are responsible for ensuring patients consent to WhatsApp-based health communications

 

5.  Who We Share Your Data With

We do not sell your data or patient data to any third party. Ever. Here is an itemized list of all third parties with whom we share data and the specific data shared:

Third Party / Category

Purpose

Meta Platforms Inc. (WhatsApp Business API)

Patient report delivery, bot registration, staff chat

Cloud Hosting Provider

Data storage and platform infrastructure

Payment Gateway (e.g., Razorpay/PayU)

Processing subscription payments

Email Service Provider

Transactional emails (alerts, invoices, support)

Analytics Provider (anonymised only)

Platform performance analytics

Legal and Regulatory Authorities

Compliance with Indian law, court orders, government directions

 

6.  How Long We Keep Your Data

Data Category

Retention Period

Active lab user accounts

Duration of subscription + 30 days post-termination

Patient data (processed on behalf of lab)

Duration of lab subscription + 30 days post-termination

Billing and payment records

7 years from transaction date

Support communications

3 years from resolution

Security and access logs

12 months on a rolling basis

Website analytics (anonymised)

24 months on a rolling basis

WhatsApp message logs

90 days from message delivery

 

When the retention period expires, data is permanently and irreversibly deleted from all our systems including backups, within 30 days of expiry. We do not retain data beyond legal requirements.

7.  Your Rights Under DPDPA 2023

The Digital Personal Data Protection Act, 2023 gives you the following rights as a Data Principal. These apply to data about you as a lab user. For patient data rights, patients must contact the lab (the Data Fiduciary) directly.

Your Right

What It Means

Right to Access

Obtain a summary of the personal data we hold about you and how it is being processed

Right to Correction

Correct inaccurate or incomplete personal data we hold about you

Right to Erasure

Request deletion of your personal data when it is no longer needed for the purpose it was collected, or when you withdraw consent

Right to Withdraw Consent

Withdraw consent to processing at any time. Note: withdrawal stops future processing but does not affect past lawful processing

Right to Grievance Redressal

Lodge a complaint with our Grievance Officer if you believe your privacy rights have been violated

Right to Nominate

Nominate another person to exercise your rights in the event of your death or incapacity

Right to Complain to the Board

File a complaint with the Data Protection Board of India if your grievance is not resolved by us

 

8.  How We Protect Your Data

8.1  Technical Security Measures

  • Encryption at rest: All data stored on ArogyaOS servers is encrypted using AES-256 encryption
  • Encryption in transit: All data transmitted between your browser/device and our servers uses TLS 1.2 or higher (HTTPS)
  • Access controls: Role-based access ensures staff see only data relevant to their function
  • Audit logging: Every access, modification, and deletion of patient data is logged with timestamp and user identity
  • Regular backups: Data backed up daily with encrypted off-site copies
  • Vulnerability assessments: Regular security reviews and penetration testing

 

8.2  Organisational Security Measures

  • All staff with data access are bound by confidentiality agreements
  • Access to production data is restricted to essential personnel only
  • We conduct regular security awareness training
  • Incident response plan is maintained and tested

 

8.3  Data Breach Notification

In the event of a personal data breach that is likely to cause harm to you, we will:

  • Notify affected labs without undue delay upon becoming aware of the breach
  • Provide details of the breach, data affected, and steps being taken
  • Report to the Data Protection Board of India as required by DPDPA 2023
  • Assist labs in fulfilling their notification obligations to affected patients

 

9.  Cookies and Tracking

ArogyaOS uses the following cookies on our website and Platform:

Cookie Type

Purpose

Strictly Necessary

Session authentication, security tokens, CSRF protection. Required for the Platform to function.

Functional

Remember your language and display preferences

Analytics (Anonymised)

Understand how features are used to improve the Platform. No personal identifiers.

Marketing / Tracking

We do NOT use marketing or advertising cookies on our Platform

 

We do not use third-party advertising cookies or sell data to advertising networks.

10.  Where Your Data is Stored

ArogyaOS stores all personal data on cloud infrastructure primarily located within India, in compliance with applicable data localisation requirements under the DPDPA 2023 and DPDP Rules 2025.

  • Primary storage: India-based cloud servers
  • Disaster recovery: Geographically distributed backups, maintained in compliance with Indian data localisation laws
  • Cross-border transfers: If any data is transferred outside India, it is done only to countries not restricted by the Government of India under the DPDPA negative list model, and with appropriate contractual safeguards in place

 

As DPDPA cross-border transfer provisions come into full force (18 months after November 13, 2025), we will update our practices accordingly and notify you of any material changes.

11.  Children’s Data

ArogyaOS is a B2B platform not designed for direct use by children (persons under 18 years of age). However, patients who are minors may have their health data entered into the Platform by their lab or guardian.

  • We do not knowingly create accounts for persons under 18 as Platform users
  • Patient data of minors processed through the Platform is subject to the same security and retention standards as adult patient data
  • Labs are responsible for obtaining appropriate parental or guardian consent before entering minor patient data into the Platform
  • If you believe a minor’s data has been entered without appropriate consent, contact us immediately at hello@arogyaos.in

 

12.  AROGYAOS AI and Your Data

AROGYAOS AI is our built-in artificial intelligence assistant that processes your lab’s live operational data to answer natural language queries. Here is how it works with your data:

  • AROGYAOS AI accesses only the data within your own ArogyaOS account — it cannot access data from other labs
  • AI responses are generated from your live lab data and are not stored as new data records
  • We do not use your lab’s patient data or business data to train AI models for other customers
  • AROGYAOS AI outputs are informational only and do not constitute medical, clinical, legal, or financial advice
  • AI audio reports generated for patients are created from the test result data entered by your lab staff — this data is processed in accordance with this Privacy Policy

 

13.  Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements, or business practices. When we make material changes:

  • We will notify you by email to your registered address at least 15 days before changes take effect
  • We will display a prominent notice within the Platform
  • For significant changes affecting your rights, we may request renewed consent

 

The date at the top of this Policy indicates when it was last updated. Continued use of the Platform after the effective date of updates constitutes acceptance of the revised Policy.

14.  Contact Us and Grievance Officer

For any privacy-related questions, requests, or complaints, please contact us:

Role

Contact Details

Grievance Officer / Data Protection Contact

hello@arogyaos.in

Subject Line for Privacy Queries

Privacy Query

Subject Line for Rights Requests

[Right Type] Request — e.g., Data Access Request

Subject Line for Complaints

Privacy Grievance

Postal Address

ArogyaOS, Bhilai, Chhattisgarh, India

WhatsApp

+91 86026 65294

Response Commitment

Acknowledge within 48 hours, resolve within 15 working days

 

If your grievance is not resolved by us within 30 days, you have the right to approach the Data Protection Board of India (DPBI) once the Board is operational, or the appropriate consumer forum under the Consumer Protection Act, 2019.