Privacy policy
Last updated: Mon, 28 Sept
This Privacy Policy is the notice required by the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025, and the privacy policy required by the Information Technology Act, 2000 and the rules under it. It explains what personal data ForU Healthtech Private Limited ("For U", "we") processes, why, on what basis, with whom it is shared, how long it is kept, and how you can exercise your rights. Health information is sensitive; we treat it with the highest care.
1. Who is responsible
For U is the Data Fiduciary for your account, bookings, orders, payments and consent records. For clinical records created during your care (consultation notes, prescriptions, reports), the treating doctor, clinic or laboratory decides what is recorded under their professional duties, and For U processes those records to provide the Platform to them and to you, under the safeguards in this policy. Contact: Chirag Agarwal, Grievance Officer, foruhealthtech@gmail.com, +91 95895 98887, Zeta-1, Greater Noida, Uttar Pradesh 201308.
2. What we collect and why
We collect only what each feature needs. Every field is listed internally with its purpose, legal basis, retention period and deletion trigger.
- Account: mobile number, name, preferred language — to log you in by one-time password and send service messages (bookings, queue position, order and report updates). Basis: your consent.
- Patient profiles: name, date of birth, sex, optional ABHA number or address, optional emergency contact — to identify the patient correctly on records, prescriptions and at sample collection, and to reach someone in an emergency. Basis: your consent and provision of health services.
- Health records: reason for visit, vitals, complaints, examination, diagnoses, prescriptions, current medicines, allergies, chronic conditions, lab reports, referral letters — created by your doctor, laboratory or you, each marked with who entered it and whether it is verified. Basis: your consent and provision of medical care.
- Bookings and queue: doctor, clinic, session, token and status — to manage your place in the queue.
- Orders and deliveries: the prescription sent, the chemist, items, prices, delivery name and address (kept with that order only), handover photo and one-time code — to fulfil, deliver and resolve disputes about your order.
- Payments: amount, method type and payment reference — to process payments, refunds and tax invoices. Card details are handled only by the licensed payment aggregator; we never see or store full card numbers.
- Consent and access logs: what you allowed, to whom, for what purpose and until when; every opening of your file by a doctor — so that you can see and control who accessed your records.
- Partners (doctors, chemists, labs, riders): contact details, registration or licence numbers, verification results and business details — to verify and onboard them, as required by law.
- Technical data: device and session identifiers, IP address and security logs — to keep your account secure and prevent fraud. We do not put health information in logs, analytics or web addresses.
- Usage counts (only if you accept on the banner): a random ID stored on your device and changed every 90 days, the app, the name of the screen and the action (for example "booking started"). Never your name, number, health details, what you searched for or which doctor you looked at. Kept 12 months. You can withdraw at any time from "Analytics choices" at the bottom of every page. Basis: your consent.
3. What we never do
- We never collect or store Aadhaar numbers.
- We never sell or rent your personal data, and never sell prescribing data to pharmaceutical companies, distributors or anyone else.
- We never use your health data for advertising, profiling for marketing, insurance pricing or credit decisions.
- We never show a doctor where their patients bought medicines or took tests, and never report totals by doctor, chemist or laboratory.
- We never track or build behavioural profiles of children.
- We never let artificial intelligence diagnose, prescribe or counsel you.
4. Who can see your health records
You and anyone you give access to (a caregiver, with full or limited access that you can revoke) can see your records. Limited caregivers see bookings and orders, not clinical records.
A doctor can open your file only when you are in their clinic's queue or have consulted them, when you have been referred to them, or in a declared emergency. Every opening is logged with the doctor, time and purpose, and you can see this log. A doctor you visit sees your allergies, current medicines and ongoing conditions for your safety. Your fuller history from other doctors is shared only with your consent, which is recorded with who may see which records, for what purpose and until when, and which you can withdraw at any time. In an emergency, a doctor may see only the safety information (allergies, current medicines, conditions), and you are informed.
A doctor's private notes stay with that doctor and are shared only inside a referral that you approve. Sensitive results may reach your doctor before you so that they can explain them. HIV test results go only to you and the ordering doctor, never to family members, caregivers or anyone else, and are never named in notifications.
Chemists see only the prescription for the order you send them and the delivery details; they never see your notes, reports or history. Riders see only what is needed to deliver: name, address and a sealed package. Laboratories see the tests you book and the details needed to collect and report. For U staff do not read clinical content, except where you ask us to, where the law requires it, or to investigate a complaint you make, and every such access is logged.
5. Service providers and disclosures
We use carefully selected service providers (Data Processors) under written contracts that bind them to process data only on our instructions and with security at least equal to ours: cloud database and storage hosted in India (Mumbai region); web hosting and content delivery; SMS and WhatsApp messaging providers for one-time passwords and service messages; a licensed payment aggregator; mapping services for delivery; and, when you choose it, the Ayushman Bharat Digital Mission network for record sharing.
We disclose personal data to government authorities, courts or regulators only when required by law or a valid legal order, and, where the law permits, we inform you. We may share data to protect someone's life or health in an emergency. If For U is merged or acquired, your data may pass to the successor, which will remain bound by this policy.
6. Where your data is stored
Your health records and personal data are stored in India. Data is encrypted in transit and at rest. Some service providers may process limited technical data (for example, delivering web pages quickly) outside India, only as permitted under section 16 of the DPDP Act and never including your health records.
7. How long we keep data
We keep personal data only as long as needed for its purpose or as the law requires. Medical records (consultations, prescriptions, reports) are retained for the period required under medical, consumer and limitation laws — at least three years from the last entry, and longer where a medico-legal case or other legal requirement applies — even if you close your account. Order, invoice and tax records are kept as required by tax laws (generally eight years). Account data is deleted when you close your account, subject to these requirements. Partner leads are deleted after twelve months if the partner does not join.
If an account has been inactive for the period set in the DPDP Rules, we will notify you at least 48 hours before deleting data that the law does not require us to keep.
8. Your rights
Under the DPDP Act you may: obtain a summary of your personal data and how it is processed; have inaccurate or incomplete data corrected or updated; have data erased when it is no longer needed and the law does not require us to keep it; withdraw consent at any time, as easily as you gave it (withdrawal does not affect processing already done, and some services may stop working without it); nominate a person to exercise your rights if you die or are incapacitated; and have your grievances redressed.
Most rights can be exercised in the app. Otherwise write to foruhealthtech@gmail.com. We will verify your identity before acting and respond within the timelines in the DPDP Rules, and in any case within 30 days for access and correction and within 90 days for any grievance. If you are not satisfied, you may complain to the Data Protection Board of India.
You also have a duty under section 15 of the DPDP Act not to give false information, not to impersonate anyone, and not to file frivolous complaints.
9. Children
Children under 18 use For U only as dependants on a parent's or lawful guardian's account, who gives consent on their behalf. Data of children is processed only to provide health services to them, as permitted for healthcare by the DPDP Rules. We do not track, profile or advertise to children. When a child turns 18, control of their profile passes to them and the parent's access ends unless the child grants it again.
10. Security
We follow reasonable security practices under section 43A of the Information Technology Act, 2000, including encryption, row-level access controls in the database that allow each person to see only what they are entitled to, logging of access to health records, least-privilege access for staff, regular security reviews, and secure development practices. No system is perfectly secure; we work continuously to protect your data.
If a personal data breach occurs, we will inform the Data Protection Board of India and every affected person without delay, with a detailed report to the Board within 72 hours, describing what happened, the likely consequences and what we are doing about it, as required by the DPDP Rules.
11. Cookies
The website uses only strictly necessary cookies to keep you logged in and secure, and a preference for your language. We do not use advertising cookies or cross-site trackers.
12. Changes and contact
We may update this policy. The date of the latest version is shown on this page, and we will notify you in the app or by message before material changes take effect, and seek fresh consent where the law requires.
Grievance Officer: Chirag Agarwal, foruhealthtech@gmail.com, +91 95895 98887, Monday to Saturday, 10 am to 6 pm. ForU Healthtech Private Limited, Zeta-1, Greater Noida, Uttar Pradesh 201308.