Data Privacy & ABDM Compliance

Privacy Policy & Health Data Security

We are committed to absolute patient confidentiality, end-to-end encryption of health records, and rigorous compliance with India’s Digital Personal Data Protection (DPDP) Act 2023 and the Ayushman Bharat Digital Mission (ABDM).

Last Updated: August 2026 • Version: 2.1 • DPDP Act 2023 & ABDM Standard

1. Introduction & Data Fiduciary Details

Dr.Ayya Life Sciences Pvt Ltd acts as a Data Fiduciary under the Digital Personal Data Protection (DPDP) Act 2023 for all personal health data processed across our telemedicine web applications, mobile platforms, and integrated hospital OS.

2. Personal & Health Data We Collect

To deliver comprehensive clinical consultations and diagnostic services, we collect only necessary data with explicit patient consent:

  • Identity & Demographics: Full name, date of birth, biological gender, mobile number, email address, and delivery address for herbal medicines.
  • Clinical & Medical Data: Chief complaints, symptom history, allergies, uploaded clinical documents, doctor examination notes, digitally signed prescriptions, and laboratory reports.
  • ABDM Health Identifiers: 14-digit ABHA ID and ABHA address, captured solely upon your explicit verification to enable national health records exchange.
  • Transaction Data: Razorpay payment identifiers, payment method tokenization, and Dr.Ayya Health Wallet balances (we never store raw credit card numbers or CVVs).

3. Encryption & Data Security Architecture

Our security architecture adheres to global healthcare data protection standards:

Encryption at Rest & Transit

All database tables and electronic health records are encrypted using AES-256 at rest and TLS 1.3 in transit.

WebRTC Video Privacy

Consultation video and audio streams are encrypted end-to-end via WebSockets/WebRTC and are never recorded without explicit consent.

4. Data Disclosure & Zero-Monetization Commitment

We do not sell, rent, or monetize your personal or medical data to insurance companies, pharmaceutical marketers, or data brokers.

Medical data is shared strictly on a need-to-know basis with:

  • The assigned AYUSH doctor for the duration of the clinical encounter.
  • The licensed partner pharmacy preparing your prescribed herbal remedies.
  • The NABL diagnostic partner laboratory processing your booked home collection samples.
  • Statutory regulatory authorities only when required by valid court order or applicable Indian law.

5. Patient Rights Under the DPDP Act 2023

As a patient (Data Principal), you possess the following enforceable rights:

  • Right of Access & Portability: View and export your complete health history, prescriptions, and lab reports in standard FHIR / PDF formats.
  • Right of Correction: Request updates or corrections to incomplete demographic or health profile information.
  • Right of Erasure: Request the deletion of your account and personal identifiers (subject to statutory medical record retention rules required under medical council guidelines).
  • Right of Grievance Redressal: Direct complaints directly to our designated Data Protection Officer.

6. Medical Records Retention Policy

Under the National Medical Commission (Professional Conduct, Etiquette and Ethics) Regulations and state AYUSH guidelines, medical records and digital prescriptions are preserved for a statutory minimum of 3 years from the date of consultation.

Data Protection Officer (DPO)

Reach our privacy officer at dpo@drayya.com