Privacy Policy
Last Updated: 30-03-2026
1. Introduction
This Privacy Policy explains how MediBank collects, uses, and protects personal and sensitive personal data in compliance with:
- Digital Personal Data Protection Act, 2023 (DPDP Act)
- IT Act, 2000 & SPDI Rules
2. Data We Collect
A. Personal Data
- Name, phone number, email
- Date of birth, gender
B. Sensitive Personal Data (Health Data)
- Medical records
- Prescriptions
- Lab reports
- Health history
C. Technical Data
- IP address
- Device information
- Usage logs
D. Financial Data
- Payment transaction metadata (processed via third parties)
3. Purpose of Data Processing
We process data for:
- Providing core services
- Record storage and retrieval
- Enabling sharing with doctors
- Improving platform functionality
- Legal compliance
4. Consent (DPDP Compliance)
- Data is processed only with your explicit consent
- Consent can be withdrawn at any time
- Withdrawal may limit service functionality
5. Data Sharing
We may share data with:
- Doctors (with user consent)
- Third-party service providers (cloud, AI, analytics)
- Payment gateway providers
- Government authorities (if legally required)
We do not sell personal data.
6. Third-Party APIs
We use APIs such as:
- Google APIs
- AI/ML service providers
- Payment gateway APIs
These providers may process data under their own privacy policies.
7. Data Storage & Security
We implement:
- Encryption (at rest & in transit)
- Access control mechanisms
- Secure cloud infrastructure
However, no system is 100% secure.
8. Data Retention
- Data is retained as long as necessary for service delivery
- Users may request deletion (subject to legal obligations)
9. User Rights (Under DPDP Act)
You have the right to:
- Access your data
- Correct inaccuracies
- Request deletion
- Withdraw consent
- Nominate a representative
Requests can be made via contact details below.
10. Children's Data
- We do not knowingly collect data from minors without parental consent
11. Cross-Border Data Transfer
- Data may be stored or processed outside India
- Only in jurisdictions permitted under Indian law
12. Cookies Policy
We use cookies to:
- Improve user experience
- Analyze traffic
Users can manage cookies via browser settings.
13. Data Breach Notification
In case of a breach:
- Users will be notified as required by law
- Authorities will be informed where applicable
14. Grievance Redressal
Grievance Officer Name: Srilatha Vangaveti Email: complaints@medibank.in Response Timeline: Within 15 days
15. Changes to Policy
We may update this policy periodically. Continued use implies acceptance.