This Privacy Policy describes how NeuroOpinion India ("Company", "we", "our", "us"), operating from Hyderabad, Telangana, India, collects, uses, stores, shares and protects the information of patients, doctors, caregivers and visitors (together, "you", "User") who access our website, mobile application, or any service (together, the "Platform"). By using the Platform you agree to this Policy, our Terms of Service, and our Medical Disclaimer.
This Policy is published in compliance with the Information Technology Act, 2000 and the rules thereunder (including the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011), the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Telemedicine Practice Guidelines, 2020 issued under the Indian Medical Council Act, and applicable data-protection laws.
1. Scope & applicability
This Policy applies to all Users of the Platform globally, and specifically to individuals located in India whose personal data is processed by us as a Data Fiduciary under the DPDP Act. If you do not agree with this Policy, please do not use the Platform.
We collect the following categories of information, only to the extent necessary for the Platform to function:
2.1 Information you provide
- Patient account: full name, age, gender, mobile number, state of residence, preferred language.
- Medical & health data (Sensitive Personal Data under IT Rules & DPDP Act): symptoms, medical history you share, medications, MRI/CT/X-ray/DICOM/PDF/JPG scan files, prior diagnosis, allergies, and any free-text you enter during booking or chat.
- Doctor account: full name, email, MCI / NMC / State Medical Council registration number, qualifications, years of experience, specialization, clinic name, uploaded medical-licence document, KYC documents (where required for payouts), profile photo, consultation fee.
- Payment data: the payment identifier, order id, invoice id, amount and status received from our payment processor (Razorpay). We do not store your full card number, CVV, UPI PIN or net-banking credentials.
- Communications: messages in case chat, support emails, feedback.
2.2 Information collected automatically
- Device type, operating system, browser, approximate IP-based location, crash logs.
- Usage analytics (pages viewed, features used, anonymised and sampled).
- Cookies and similar technologies (see Section 9).
2.3 Information from third parties
- OTP delivery status from SMS/WhatsApp providers (Fast2SMS, Meta WhatsApp Cloud API).
- Payment confirmation / failure events via Razorpay webhooks.
- Doctor registration validation against the public NMC / State Medical Council online registry.
3. Purposes & legal basis
- Service delivery — create your account, authenticate you via OTP, match you with a qualified specialist, let the assigned doctor review your scans, and return a written opinion.
- Payments & invoicing — charge the consultation fee, split platform / doctor share, issue GST invoices.
- Communication — send transactional alerts via SMS, WhatsApp, in-app notification and email.
- Safety & fraud prevention — detect abuse, chargeback fraud, fake doctor profiles, spam.
- Legal compliance — respond to lawful requests from Indian authorities, maintain records required under the Telemedicine Practice Guidelines 2020 and the Income-Tax Act.
- Product improvement — analyse usage in aggregate. Medical records are never used for training AI models or shared with advertisers.
The legal basis for processing is (a) your explicit consent given at signup and at the time of scan upload, (b) performance of the service you requested, and (c) compliance with law.
4. Who we share information with
- The assigned doctor only — sees your name, age, gender, symptoms and the scans you uploaded for the specific case they were matched to.
- Razorpay (PCI-DSS Level 1) — for processing payments and refunds.
- Fast2SMS and Meta WhatsApp Cloud API — for sending OTPs and notifications.
- Object-storage provider — encrypted storage of scans and reports.
- Jitsi Meet — for video consultations; we do not record calls.
- Law-enforcement agencies — only pursuant to a valid Indian court order or statutory request.
- Business transfer — successor entities will be bound by this Policy.
We never sell, rent or license your data to advertisers, data brokers or unrelated third parties.
5. Data security
- All traffic is served over TLS 1.2+ (HTTPS only).
- Passwords are hashed with bcrypt; OTPs expire after 10 minutes.
- Scans and reports are stored in encrypted object storage.
- Role-based access control; admins cannot read chat content.
- Audit logs of all administrative actions.
- We follow the Reasonable Security Practices prescribed under Rule 8 of the IT Rules, 2011.
In the unlikely event of a personal-data breach we will notify affected users and the Data Protection Board of India within the timelines required by the DPDP Act.
6. Data retention
- Patient case records: 3 years from opinion date (Telemedicine Practice Guidelines, 2020).
- Tax / payment records: 8 years (Income-Tax Act and GST laws).
- Account profile data: while the account is active, deleted within 30 days of deletion request.
- Analytics and log data: up to 12 months.
7. Your rights (DPDP Act, 2023)
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or outdated information.
- Erasure — ask us to delete your account and associated data.
- Withdraw consent — at any time.
- Grievance redressal — with our Grievance Officer.
- Nominate — nominate another person to exercise your rights.
To exercise any right, email privacy@neuroopinion.in from the mobile number / email associated with your account.
8. Children's data
The Platform is not directed at children under 18. If a minor requires a second opinion, a parent or legal guardian must create the account and provide verifiable consent.
9. Cookies & tracking
We use first-party cookies and localStorage for authentication, language preference, and anonymised product analytics. You can clear cookies from your browser at any time.
10. Cross-border transfers
Primary storage and processing happens within India. Some sub-processors may process data outside India in compliance with the DPDP Act and adequate safeguards.
11. Grievance Officer & contact
Grievance Officer
Name: The Grievance Officer, NeuroOpinion India
Address: Hyderabad, Telangana, India
As per Rule 5(9) of the IT Rules, 2011 and Section 10 of the DPDP Act, the Grievance Officer shall acknowledge your complaint within 48 hours and resolve it within 30 days.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified via email or in-app banner at least 14 days before they take effect.
13. Consent
By creating an account, uploading a scan, or booking a consultation, you confirm that you have read this Policy and explicitly consent to the processing of your Sensitive Personal Data (including health data) for the purposes described above.