Healway.pro ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our healthcare platform.
This policy is designed to comply with the Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology Act, 2000 and the SPDI Rules, 2011, and other applicable Indian regulations.
By using Healway.pro you confirm that you have read, understood, and agree to this Policy.
Under the DPDP Act, 2023, we collect and process your personal data only for the specific purposes listed below. We will seek your explicit consent for each category:
| Purpose | Mandatory? | Description |
|---|---|---|
| Data Processing | Yes | Core healthcare service delivery — scheduling, prescriptions, clinical records |
| AI Processing | Optional | AI-assisted clinical notes, risk assessment, and Healix AI assistant |
| Analytics | Optional | Anonymised aggregated data for clinical dashboards and quality improvement |
| Prescription Sharing | Optional | Sending prescription PDFs via SMS/WhatsApp to patients |
| Communication | Optional | Appointment reminders, follow-up alerts, platform notifications |
You may withdraw optional consents at any time from the Patient Portal. Withdrawal does not affect the legality of processing before withdrawal.
We use your information for the following purposes:
Note: We do not use your health data for advertising purposes or sell your information to third parties.
We retain your data for the following periods, after which data is securely deleted or anonymised:
| Data Category | Retention Period | Basis |
|---|---|---|
| Medical Records | 7 years from last consultation | MCI/NMC guidelines; EHR Standards 2016 |
| Audit Logs | 6 years | IT Act compliance |
| Audio Recordings | Deleted immediately after transcription | Minimal data principle |
| Account Information | Until account deletion request | Contractual necessity |
| Consent Records | 7 years | DPDP Act compliance |
We may share your information with:
All third-party service providers are bound by confidentiality agreements and data protection requirements.
Our primary data store is located in India (Supabase, Mumbai region). However, some AI processing features involve transferring anonymised clinical text to the following international providers:
| Provider | Country | Purpose | Data Sent |
|---|---|---|---|
| Google Gemini | USA | AI clinical notes generation | Anonymised text only |
| OpenAI GPT-4o | USA | AI fallback (if Gemini unavailable) | Anonymised text only |
| Sarvam AI | India | Speech-to-text (Indian languages) | Audio recording (processed in India) |
| Twilio Verify | USA | OTP / SMS verification | Phone number + OTP only |
No direct patient identifiers (name, phone, date of birth, address) are sent to AI providers. We rely on contractual safeguards (Data Processing Agreements) for cross-border transfers. Transfer to AI providers is subject to your AI Processing consent.
We recognise that patients under 18 years of age require additional protection.
Under the Digital Personal Data Protection Act, 2023, you have the right to:
To exercise these rights, please contact our Grievance Officer using the details below. We will respond within 30 days of receipt.
We implement robust security measures to protect your data:
Our platform uses AI-assisted tools for clinical support, including:
Important: All AI-generated content is for clinical decision support only. The treating physician is responsible for reviewing and confirming all clinical information before use. Healway.pro AI tools are not registered medical devices under CDSCO regulations and are not a substitute for professional medical judgment.
AI processing requires your explicit AI Processing consent. You may withdraw this consent at any time; this will disable AI features for your records without affecting core healthcare services.
We have appointed a Grievance Officer as required under the DPDP Act, 2023 and the IT Act, 2000. You may contact our Grievance Officer for any privacy concern, data rights request, or complaint:
Grievance Officer
Name: [To be filled by legal team]
grievance@healway.pro
Response SLA: We will acknowledge within 48 hours and resolve within 30 days.
If you are not satisfied with our response, you may escalate to the Data Protection Board of India once it is constituted under the DPDP Act, 2023.
Note for legal team: This privacy policy (v2.0) incorporates DPDP Act 2023 requirements and should be reviewed by qualified legal counsel before deployment. In particular: (a) confirm the Grievance Officer name and contact; (b) verify DPB notification procedures once the Board is constituted; (c) review cross-border transfer safeguards once DPB notifies restricted countries.