Legal Document

Privacy Policy

How med96.in collects, uses, and protects your personal data โ€” in compliance with India's Digital Personal Data Protection Act, 2023.

Effective: June 1, 2025 DPDP Act 2023 Compliant Last Updated: June 2025
๐Ÿ”’ DPDP Act, 2023 Notice This Privacy Policy is drafted in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India. As a Data Fiduciary, med96.in is committed to lawful, transparent, and purpose-limited processing of your personal data. You have enforceable rights as a Data Principal under this Act.
1Who We Are

med96.in is operated by Med96 Healthcare Private Limited ("med96", "we", "us", or "our"), a company incorporated under the Companies Act, 2013. We provide an online platform for purchase of pharmaceutical products, diagnostic services, doctor consultation services, and health information.

For the purposes of the DPDP Act, 2023, med96 acts as a Data Fiduciary โ€” meaning we determine the purpose and means of processing your personal data.

Contact: contact@med96.in

2Definitions (as per DPDP Act, 2023)
TermMeaning
Personal DataAny data about an individual who is identifiable by or in relation to such data
Data PrincipalYou โ€” the individual to whom the personal data relates
Data Fiduciarymed96.in โ€” determines purpose and means of processing your data
Data ProcessorThird parties who process data on our behalf under a written contract
ConsentFree, informed, specific, unconditional agreement to process personal data
ProcessingCollection, storage, use, sharing, disclosure, or deletion of personal data
3Personal Data We Collect

We collect only such personal data as is necessary for the purposes described in this Policy ("data minimisation" principle under DPDP Act):

We do not collect sensitive personal data beyond what is strictly necessary to provide healthcare-related services. All sensitive data is collected with your explicit consent as required under the DPDP Act.

4Purposes of Processing & Legal Basis

Under the DPDP Act, we process your data only on the following lawful bases:

PurposeLegal Basis (DPDP Act)
Account registration and authenticationConsent
Fulfilling medicine and diagnostic ordersContractual necessity / Consent
Processing paymentsContractual necessity
Online doctor consultationsConsent
Sending order updates and notificationsLegitimate use / Consent
Personalised health recommendationsConsent
Legal compliance and fraud preventionLegal obligation / Legitimate use
Safety and security of the platformLegitimate use
Marketing communications (opt-in only)Consent

We will not use your personal data for any purpose other than those notified to you at the time of collection or subsequently with your explicit consent.

5How We Collect Your Data

Before collecting any sensitive personal data (medical records, health information), we will present a clear notice and obtain your explicit consent as mandated by the DPDP Act.

6Sharing of Personal Data

We may share your personal data with the following categories of recipients, strictly on a need-to-know basis:

All Data Processors we engage are bound by written agreements requiring them to process data only as instructed by us, implement appropriate security measures, and not retain data beyond the agreed period โ€” consistent with Section 8 of the DPDP Act.

We do not sell your personal data to any third party for commercial purposes.

7Cross-Border Data Transfers

Your personal data is primarily stored and processed in India. Any transfer of personal data outside India will be carried out only to countries notified by the Central Government under the DPDP Act as providing adequate data protection, or under appropriate contractual safeguards.

8Data Retention & Erasure

We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law (e.g., medical record regulations, tax laws).

Once the retention period expires, or upon a valid erasure request from you (see Your Rights below), we will securely delete or anonymise your data. We will not retain data beyond the purpose for which it was collected, in line with the storage limitation principle of the DPDP Act.

9Your Rights as a Data Principal (DPDP Act, 2023)

The DPDP Act, 2023 grants you the following rights, which you may exercise by writing to us at contact@med96.in:

๐Ÿ“‹

Right to Access

Obtain a summary of personal data we hold and processing activities

โœ๏ธ

Right to Correction

Correct inaccurate or incomplete personal data

๐Ÿ—‘๏ธ

Right to Erasure

Request deletion of personal data when no longer necessary

๐Ÿ”•

Withdraw Consent

Withdraw consent at any time without affecting prior lawful processing

๐Ÿ›ก๏ธ

Right to Grievance

Lodge a complaint with our Data Protection Officer

โš–๏ธ

Right to Nominate

Nominate a person to exercise rights on your behalf in case of incapacity

We will respond to your requests within 30 days. For unresolved grievances, you may approach the Data Protection Board of India established under the DPDP Act.

10Children's Data (Persons Below 18)

Our platform is not directed at children below the age of 18. In accordance with the DPDP Act, we will not process personal data of children without verifiable parental or guardian consent. We do not engage in behavioural tracking of children.

If you believe a child's data has been submitted to us without appropriate consent, please contact us immediately at contact@med96.in for prompt deletion.

11Security of Personal Data

We implement appropriate technical and organisational security measures to protect your personal data from unauthorised access, disclosure, alteration, or destruction. These include encryption of data in transit and at rest, access controls, audit logs, and regular security assessments.

In the event of a personal data breach that is likely to result in harm to Data Principals, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Act.

12Cookies & Tracking Technologies

We use cookies and similar technologies to improve your experience, remember preferences, and analyse platform usage. You may manage cookie preferences through your browser settings. Consent for non-essential cookies is obtained separately through our cookie consent mechanism.

13Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. When we make material changes, we will notify you via email or a prominent notice on our platform before the changes take effect, and obtain fresh consent where required.

The date of the latest update will always be displayed at the top of this page.

Data Protection Officer / Grievance Officer

Med96 Healthcare Private Limited

Email: contact@med96.in

For escalated complaints unresolved within 30 days, you may approach the Data Protection Board of India at meity.gov.in