Legal

Privacy Policy

Last Updated: 30-03-2026

1. Introduction

This Privacy Policy explains how MediBank collects, uses, and protects personal and sensitive personal data in compliance with:

  • Digital Personal Data Protection Act, 2023 (DPDP Act)
  • IT Act, 2000 & SPDI Rules

2. Data We Collect

A. Personal Data

  • Name, phone number, email
  • Date of birth, gender

B. Sensitive Personal Data (Health Data)

  • Medical records
  • Prescriptions
  • Lab reports
  • Health history

C. Technical Data

  • IP address
  • Device information
  • Usage logs

D. Financial Data

  • Payment transaction metadata (processed via third parties)

3. Purpose of Data Processing

We process data for:

  • Providing core services
  • Record storage and retrieval
  • Enabling sharing with doctors
  • Improving platform functionality
  • Legal compliance

4. Consent (DPDP Compliance)

  • Data is processed only with your explicit consent
  • Consent can be withdrawn at any time
  • Withdrawal may limit service functionality

5. Data Sharing

We may share data with:

  • Doctors (with user consent)
  • Third-party service providers (cloud, AI, analytics)
  • Payment gateway providers
  • Government authorities (if legally required)

We do not sell personal data.

6. Third-Party APIs

We use APIs such as:

  • Google APIs
  • AI/ML service providers
  • Payment gateway APIs

These providers may process data under their own privacy policies.

7. Data Storage & Security

We implement:

  • Encryption (at rest & in transit)
  • Access control mechanisms
  • Secure cloud infrastructure

However, no system is 100% secure.

8. Data Retention

  • Data is retained as long as necessary for service delivery
  • Users may request deletion (subject to legal obligations)

9. User Rights (Under DPDP Act)

You have the right to:

  • Access your data
  • Correct inaccuracies
  • Request deletion
  • Withdraw consent
  • Nominate a representative

Requests can be made via contact details below.

10. Children's Data

  • We do not knowingly collect data from minors without parental consent

11. Cross-Border Data Transfer

  • Data may be stored or processed outside India
  • Only in jurisdictions permitted under Indian law

12. Cookies Policy

We use cookies to:

  • Improve user experience
  • Analyze traffic

Users can manage cookies via browser settings.

13. Data Breach Notification

In case of a breach:

  • Users will be notified as required by law
  • Authorities will be informed where applicable

14. Grievance Redressal

Grievance Officer Name: Srilatha Vangaveti Email: complaints@medibank.in Response Timeline: Within 15 days

15. Changes to Policy

We may update this policy periodically. Continued use implies acceptance.

Claim your health identity