1. Data Fiduciary Identity & Scope
SureCure Visit (operating under NLR Group of Companies Private Limited, hereinafter referred to as "we", "us", "our", or "Platform") acts as the Data Fiduciary under the Digital Personal Data Protection Act, 2023. We determine the purpose and means of processing personal data provided by patients, guardians, and medical practitioners using our platform.
This Privacy Policy applies to all users ("Data Principals") accessing or using SureCure Visit via web browsers, mobile applications, or connected APIs. If you have questions regarding data privacy, contact our Grievance Officer at support.kisaankrushi@gmail.com.
2. Categories of Personal Data Collected
We collect personal and sensitive personal data strictly required to facilitate verified doorstep medical consultations, enable continuity of care, and maintain statutory audit compliance under Indian healthcare regulations.
- Account & Identity Identifiers: Full legal name, verified mobile phone number, email address, date of birth, gender, and profile photo.
- Physical Address & Spatial Coordinates: Residential door address, floor/apartment details, nearby landmarks, and precise GPS location coordinates provided for doctor routing.
- Sensitive Personal Health Information (SPHI): Pre-existing medical conditions, drug allergies, current prescriptions, past surgical history, blood group, height, weight, triage symptom descriptions, and attached medical diagnostic reports.
- Household & Dependent Profiles: Names, ages, relationships, and medical profiles of family members or dependents for whom a visit is booked by an authorized account holder.
- Doctor Credentials & Professional Records: National Medical Commission (NMC) or State Medical Council registration numbers, medical qualification degrees, specialization certificates, experience history, government ID verification, and consultation fee schedules.
- Clinical Consultation Artifacts: Attending doctor clinical notes, diagnostic impressions, digital prescriptions issued during visits, doorstep arrival timestamps, and visit confirmation records.
- Real-Time Telemetry & Doctor Transit GPS: Temporary high-frequency GPS fixes transmitted by attending doctors during active transit, used strictly for patient live tracking and route navigation.
- Security, System & Device Telemetry: IP addresses, browser user-agent strings, authentication tokens, session timestamps, audit logs, and crash reports required for platform security and fraud prevention.
3. Lawful Grounds & Specific Purposes of Processing
Personal data is processed based on explicit consent, statutory obligation, or legitimate use under Section 7 of the DPDP Act, 2023. Processing is strictly limited to the following operational purposes:
- Matching patient home visit requests with available, verified doctors in the user's geographic area.
- Enabling attending physicians to review patient medical histories, allergies, and contraindications before prescribing medication or performing clinical examinations.
- Providing live transit tracking and estimated arrival times for patient convenience and safety.
- Verifying medical practitioner credentials against official state medical registries prior to listing.
- Facilitating fixed-fee payment receipts, transaction recording, and billing dispute resolution.
- Complying with record-keeping mandates established under the Telemedicine Practice Guidelines and Clinical Establishments Act.
- Detecting, preventing, and investigating fraudulent requests, security breaches, or unauthorized access.
4. Access Controls & Third-Party Data Disclosures
We enforce zero-trust, role-based access control (RBAC). Personal and health data is never sold, leased, or monetized for advertising or marketing purposes under any circumstance.
- Attending Medical Practitioner Access: Before visit acceptance, doctors see only the general neighborhood locality and chief symptoms. Full residential address, contact number, and medical profile are released ONLY once a doctor formally accepts the visit request.
- Authorized System Administrators: Technical administrators access encrypted system logs solely for operational troubleshooting, dispute resolution, or compliance auditing.
- Cloud Infrastructure Processors: Data is hosted on encrypted Google Cloud Platform (GCP) and Firebase infrastructure under strict Data Processing Agreements (DPAs). Data is stored within secure region datacenters with AES-256 encryption at rest.
- Statutory Authorities & Law Enforcement: Disclosure occurs only when mandated by valid judicial court orders, legal summons, or regulatory directives issued by statutory bodies under Indian law.
5. Data Retention & Erasure Schedule
Data is retained only as long as necessary to fulfill the purpose of collection or satisfy statutory legal obligations:
- Clinical & Consultation Records: Prescriptions, clinical notes, and visit summaries are retained for a minimum of 3 years in accordance with NMC medical record maintenance standards.
- Live Transit Location Data: Doctor GPS coordinates transmitted during travel are permanently purged immediately upon completion or cancellation of the visit.
- Account & Profile Information: Maintained for the active duration of the user account. Upon an account deletion request, personal profile identifiers are purged within 30 days, excluding statutory audit records required by law.
6. Data Principal Rights under the DPDP Act, 2023
Data Principals possess enforceable statutory rights regarding their personal data processed by the Platform:
- Right to Access: Request a readable summary of personal data held by us, alongside processing activities and recipient disclosures.
- Right to Correction & Updating: Request correction of inaccurate, incomplete, or out-of-date health or profile information.
- Right to Erasure: Request deletion of personal data where processing is no longer necessary or consent is withdrawn, subject to statutory retention rules.
- Right to Nominate: Designate another individual to exercise data rights in the event of death or incapacity.
- Right to Grievance Redressal: Seek timely resolution of queries or complaints regarding data processing.
7. Protection of Minors & Dependent Care
Account registration is restricted to individuals aged 18 and above. Minors under 18 may receive care only when added as dependents under a parent or legal guardian's account, with the guardian providing explicit consent for the consultation.
8. Statutory Grievance Redressal Mechanism
In compliance with Section 13 of the DPDP Act, 2023 and the Information Technology Act, 2000, any complaints, data rights requests, or security concerns must be addressed to our designated Grievance Officer:
Attention: NLR Nodal Data Protection & Grievance Officer
Entity: NLR Group of Companies Private Limited
Address: Telangana, India
Email: support.kisaankrushi@gmail.com
We acknowledge all formal grievances within 48 hours and provide resolution within 15 business days. If unsatisfied with our response, you retain the right to lodge a complaint with the Data Protection Board of India.